incident.io
Nexus does the diagnosis; the rest is on-call plumbing
A side-by-side editorial comparison of Testomat.io and ZoneMinder — release velocity, themes, recent moves, and the top alternatives to consider.
| Feature | Testomat.io | ZoneMinder |
|---|---|---|
| Sector | Infra & APIs | Infra & APIs |
| Velocity score | 2.5 | 2.5 |
| Sparks · 30d | 0 | 0 |
| Top themes | test-management, defect-tracking, agent-native, mcp | security-hardening, rbac, api-authorization, maintenance-branch |
| Last editorial update | 4d ago | 4h ago |
| Website | — | Visit → |
Testomat is closing the loop from failing test to tracked defect, one quarterly digest at a time
Testomat ships in large periodic digests rather than continuous drops, and each one pairs a structural addition with a batch of interface work. The August release adds a per-project Defects page listing the bug-tracker issues raised against failing tests, plus defects in analytics, milestone insights, and comment mentions. Underneath it, the past year laid down Requirements, Milestones, a Public API v2, and an MCP server.
1.38.4 is a security release in all but name, closing ACL gaps across the API.
The 1.38 line is in maintenance, and 1.38.4 is almost entirely authorization work: per-monitor access control enforced on event, frame, zone, tag and media endpoints, two auth bypasses fixed in token validation, and SQL injection and overflow hardening. The 1.36 branch still receives backports, with 1.36.38 carrying its own SQL injection fix. The last feature release was 1.38.0 in February, which brought role-based access control, WebRTC and Go2RTC streaming, and the split of monitor function into separate capturing, analysing, and recording settings.
Testomat ships in large periodic digests rather than continuous drops, and each one pairs a structural addition with a batch of interface work. The August release adds a per-project Defects page listing the bug-tracker issues raised against failing tests, plus defects in analytics, milestone insights, and comment mentions. Underneath it, the past year laid down Requirements, Milestones, a Public API v2, and an MCP server.
Two arcs run in parallel here. One is structural test management — Requirements, Milestones, tree navigation, plans — filling out what a QA team needs to run a release cycle rather than just store cases. The other is machine access: an MCP server, a v2 public API, AI quality review, AI test-data suggestions, and an analytics chat, which together make the test corpus readable by something other than a person clicking through the UI. Defects is where the first arc finally reaches the bug tracker.
The next digest most likely deepens the defect loop, linking defect state back to test status or analytics, since that is the newest structural piece and currently a listing rather than a workflow. The API and MCP thread points at more agent-facing surface, though these entries do not indicate what it would cover.
The 1.38 line is in maintenance, and 1.38.4 is almost entirely authorization work: per-monitor access control enforced on event, frame, zone, tag and media endpoints, two auth bypasses fixed in token validation, and SQL injection and overflow hardening. The 1.36 branch still receives backports, with 1.36.38 carrying its own SQL injection fix. The last feature release was 1.38.0 in February, which brought role-based access control, WebRTC and Go2RTC streaming, and the split of monitor function into separate capturing, analysing, and recording settings.
Every release since 1.38.0 has been consolidation of what that release opened up. RBAC shipped as a headline feature in February, and the four maintenance drops since have been finding the endpoints it did not cover — the familiar pattern when a permission model is retrofitted onto an API that predates it. Cadence is slow and irregular, months apart, with a 1.39 spec bump already visible in the repo but nothing from that series shipped.
Expect more per-endpoint ACL fixes on the 1.38 line before anything from 1.39 reaches release.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Testomat.io or ZoneMinder.
Nexus does the diagnosis; the rest is on-call plumbing
Four channels, one fix stream — werf's releases are mostly concurrency repairs.
PAM and PKI now take up most of the lines in Infisical's release notes.
Biome's patch train keeps adding rules — and is quietly growing a Markdown linter.
DNSControl is rewriting its record internals in public, one release candidate at a time
Fission's release feed carries only RC tags, and none of them say what shipped
See all Testomat.io alternatives → · See all ZoneMinder alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Testomat.io and ZoneMinder are shipping at a similar cadence (velocity 2.5 vs 2.5, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Testomat.io and ZoneMinder are shipping at a similar cadence (velocity 2.5 vs 2.5, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Testomat.io alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Testomat.io alternatives" section above for the current picks, or visit /alternatives/testomat for the full list with editorial commentary on each.
Top ZoneMinder alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "ZoneMinder alternatives" section above for the current picks, or visit /alternatives/zoneminder for the full list with editorial commentary on each.