Tracecat
Tracecat 1.0 stable lands with workspace entitlements, SSRF hardening, and an open-source MCP skills catalog
A side-by-side editorial comparison of Camunda and Vikunja — release velocity, themes, recent moves, and the top alternatives to consider.
Camunda 8.10 alpha cycles through broad platform bug fixes while 8.7 gets routine security patches
Camunda is a monorepo platform spanning Zeebe (workflow engine), Operate, Tasklist, and Optimize. The 8.7 line is in maintenance mode—receiving dependency security patches and Jetty/log4j CVE bumps. The 8.10 alpha series is active, working through a wide backlog of correctness issues: Raft reconfiguration deadlocks, RDBMS physical tenant bugs, CSL authentication failures in Optimize, and a write-retry backoff regression that had slowed Zeebe processing 3–16x.
Vikunja crossed the v1.0 finish line and pivoted hard into security hardening.
Vikunja shipped two v1.0 release candidates through late 2025 and early 2026, then jumped to a v2 series whose first widely-tagged point release, v2.2.1, is dominated by security work. The latest release patches multiple SSRF and IDOR vulnerabilities, enforces disabled/locked-account semantics across every auth surface (OIDC, API tokens, CalDAV, LDAP), and adds a shared SSRF-safe HTTP client that webhooks and migrations now route through. User-facing feature work has slowed; the visible energy is in plumbing and audit cleanup.
Camunda is a monorepo platform spanning Zeebe (workflow engine), Operate, Tasklist, and Optimize. The 8.7 line is in maintenance mode—receiving dependency security patches and Jetty/log4j CVE bumps. The 8.10 alpha series is active, working through a wide backlog of correctness issues: Raft reconfiguration deadlocks, RDBMS physical tenant bugs, CSL authentication failures in Optimize, and a write-retry backoff regression that had slowed Zeebe processing 3–16x.
The 8.10 alpha indicates Camunda is working toward a release that resolves accumulated platform debt across the distributed engine, secondary storage, and observability stack. The scale of the bug list—covering everything from Raft membership changes to Swagger UI regressions—suggests 8.10 is a stabilization release rather than a feature milestone. No major architectural or capability-surface changes are visible in this window.
8.10 will move to beta once the Raft, RDBMS physical tenant, and CSL authentication issues are resolved. The pattern of fixing fundamental distributed-engine correctness bugs suggests the team is clearing blockers before announcing a GA.
Vikunja shipped two v1.0 release candidates through late 2025 and early 2026, then jumped to a v2 series whose first widely-tagged point release, v2.2.1, is dominated by security work. The latest release patches multiple SSRF and IDOR vulnerabilities, enforces disabled/locked-account semantics across every auth surface (OIDC, API tokens, CalDAV, LDAP), and adds a shared SSRF-safe HTTP client that webhooks and migrations now route through. User-facing feature work has slowed; the visible energy is in plumbing and audit cleanup.
The arc moves from feature-completion (S3 storage, drag-and-drop project moves, hover previews in late 2025) toward platform credibility — closing security gaps a self-hosted task tool needs to clear before serious team adoption. The rapid version-number jump from v1.0.0-rc4 to v2.2.1 in two months suggests v1.0 shipped and the team tagged a v2 line aimed at addressing accumulated authz debt. Expect the next several releases to keep the security-first posture rather than return to a feature push.
The next release will likely continue closing remaining authz edges (more IDOR audits, additional credential-stripping in API responses) and bundle a translations and dependency sweep. A user-facing feature push probably waits until the security work plateaus.
Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Camunda or Vikunja.
Tracecat 1.0 stable lands with workspace entitlements, SSRF hardening, and an open-source MCP skills catalog
NocoBase adds an AI knowledge base retrieval API, connecting no-code workflows to external knowledge sources.
RentRedi embeds AI into its maintenance workflow end-to-end, handling tenant intake and drafting landlord replies.
Asana embeds AI into Slack threads and closes the rich-text gap with Notion
Rize pivots from solo time tracker to agency operations platform with invoicing, profitability reporting, and a ChatGPT integration.
Hive is building shared AI automation infrastructure into the core of its PM platform.
See all Camunda alternatives → · See all Vikunja alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Camunda is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Camunda is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.
Top Camunda alternatives in PM are ranked by recent ship velocity. Browse the "Camunda alternatives" section above for the current picks, or visit /alternatives/camunda for the full list with editorial commentary on each.
Top Vikunja alternatives in PM are ranked by recent ship velocity. Browse the "Vikunja alternatives" section above for the current picks, or visit /alternatives/vikunja for the full list with editorial commentary on each.