authentik
authentik 2026.8 ships: Actors, domain-joined Agents, and a push past browser-mediated SSO
A side-by-side editorial comparison of Casdoor and oVirt — release velocity, themes, recent moves, and the top alternatives to consider.
Casdoor is spending its release cadence moving auth checks from the client to the server
Casdoor is in a tight patch cadence: six tagged releases inside a week, most carrying a single commit. The substance is concentrated in identity enforcement rather than features - password rotation and MFA setup are now enforced server-side, admin updates to a user respect the column whitelist, sessions and tokens are revoked when a user is forbidden, and phone numbers are normalised before they are stored. The remainder is release plumbing and a PostgreSQL query fix.
A virtualization manager coasting on backports, with releases years apart
oVirt Engine's release feed is sparse and slowing: 4.5.5 in late 2023, 4.5.6 and a pair of 4.5.3.x backports in early 2024, then nothing until 4.5.7 in December 2025. Almost every entry is a list of targeted fixes and backports rather than features — OVF import edge cases, template handling, NVRAM save/restore logic, CA generation as a non-root user, Keycloak group handling. One CVE, CVE-2024-0822, appears in 4.5.6 and its 4.5.3 backport.
Casdoor is in a tight patch cadence: six tagged releases inside a week, most carrying a single commit. The substance is concentrated in identity enforcement rather than features - password rotation and MFA setup are now enforced server-side, admin updates to a user respect the column whitelist, sessions and tokens are revoked when a user is forbidden, and phone numbers are normalised before they are stored. The remainder is release plumbing and a PostgreSQL query fix.
Read together, these commits describe one job: closing the gap between what the console enforces and what the backend enforces. Several of them move a check that previously lived in the UI into the server, which is the work of a project being deployed into environments that audit it. New authentication providers and integrations have thinned relative to this hardening pass.
The next releases most likely continue the same sweep - remaining endpoints where an admin or user request is trusted more than the server verifies - rather than adding a new identity provider.
oVirt Engine's release feed is sparse and slowing: 4.5.5 in late 2023, 4.5.6 and a pair of 4.5.3.x backports in early 2024, then nothing until 4.5.7 in December 2025. Almost every entry is a list of targeted fixes and backports rather than features — OVF import edge cases, template handling, NVRAM save/restore logic, CA generation as a non-root user, Keycloak group handling. One CVE, CVE-2024-0822, appears in 4.5.6 and its 4.5.3 backport.
This reads as a mature platform in maintenance rather than one being developed. The parallel 4.5.3.x stream exists purely to carry fixes back to deployments that cannot move, and the two-year gap between 4.5.6 and 4.5.7 says more about the project's momentum than any individual change does. Nothing in these entries points toward new capability.
The entries do not support a confident call on where this goes next; the only observable pattern is long gaps punctuated by accumulated fix rollups, so another such rollup is the most that can be inferred.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Casdoor or oVirt.
authentik 2026.8 ships: Actors, domain-joined Agents, and a push past browser-mediated SSO
Rancher's public feed is a build-tag stream: three branches bumped the same Go image on one afternoon
Buildkite keeps converting hand-rolled agent workarounds into first-class CI primitives.
Cursor's agents stop waiting to be asked - they subscribe, and they hold a goal until it's done.
Nexus does the diagnosis; the agent is now reaching into the status page too.
Warp turned its quarter of software-factory essays into infrastructure you can buy.
See all Casdoor alternatives → · See all oVirt alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Casdoor is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Casdoor is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Casdoor alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Casdoor alternatives" section above for the current picks, or visit /alternatives/casdoor for the full list with editorial commentary on each.
Top oVirt alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "oVirt alternatives" section above for the current picks, or visit /alternatives/ovirt for the full list with editorial commentary on each.