Zoho Sign
Zoho Sign adds the EU's highest signature tier, one week after wiring itself to agents.
A side-by-side editorial comparison of CommaFeed and EGroupware — release velocity, themes, recent moves, and the top alternatives to consider.
CommaFeed is patching its way through the attack surface a self-hosted reader inherits
CommaFeed's 7.x line has become a sustained security pass. The newest patch closes Host header injection on the password recovery endpoint and adds a commafeed.password-recovery-public-base-url setting so the email base URL is configured rather than taken from the request. Behind it: local address blocking made secure by default alongside Google Reader API support in 7.3.0, javascript: URLs filtered at parse time in 7.2.1, and SSRF limits on the image proxy in 7.2.0.
EGroupware's feed has become a security treadmill, with the 23.1 branch days from end of life.
Almost every release in this window is a security release, and most ship as a pair — one build for 26.x, an identical-scope backport for 23.1. Feature work exists but arrives as single lines inside those security notes: WebAuthN two-factor moving out of the former EPL add-on, OpenID bumped to current upstream libraries, invoice XML gaining reverse-charge exemption codes. The recurring theme in the fixes themselves is authentication — OAuth bearer tokens, OpenID regressions, an inverted email_verified check, passkeys broken by a missing proxy config.
CommaFeed's 7.x line has become a sustained security pass. The newest patch closes Host header injection on the password recovery endpoint and adds a commafeed.password-recovery-public-base-url setting so the email base URL is configured rather than taken from the request. Behind it: local address blocking made secure by default alongside Google Reader API support in 7.3.0, javascript: URLs filtered at parse time in 7.2.1, and SSRF limits on the image proxy in 7.2.0.
Every release in this stretch closes a path where content or a request from outside the instance was trusted too far - feed URLs reaching internal addresses, proxied images, javascript: links, and now a header shaping an outbound email. That is the checklist of a project being run as a multi-user hosted service rather than a single-user tool, and it follows directly from the 7.0.0 decision to sandbox filter expressions. Feature work continues in parallel but is clearly the smaller half.
The remaining untrusted-input surfaces - OPML import and the feed fetcher's redirect handling - are the likely next targets. The pattern of shipping each fix as its own patch release should continue rather than batching them.
Almost every release in this window is a security release, and most ship as a pair — one build for 26.x, an identical-scope backport for 23.1. Feature work exists but arrives as single lines inside those security notes: WebAuthN two-factor moving out of the former EPL add-on, OpenID bumped to current upstream libraries, invoice XML gaining reverse-charge exemption codes. The recurring theme in the fixes themselves is authentication — OAuth bearer tokens, OpenID regressions, an inverted email_verified check, passkeys broken by a missing proxy config.
The project is consolidating everyone onto 26.x and has put a date on it: security coverage for 23.1 ends August 15, 2026, repeated as a warning in every 23.1 build since July. After that the twin-release pattern should stop and the cadence should halve. The authentication stack is the least settled part of the codebase right now — the July and August releases keep re-fixing OpenID and WebAuthN regressions introduced by their own predecessors.
Expect 23.1 builds to cease after August 15 and the feed to become single-track 26.x. On the evidence of the last six releases, expect at least one more OpenID or WebAuthN regression fix to follow the recent upstream library bump.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either CommaFeed or EGroupware.
Zoho Sign adds the EU's highest signature tier, one week after wiring itself to agents.
Read the Docs is rebuilding its build farm around uv and isolated builders, one week at a time.
SiYuan stabilises 3.8.1 after a seven-build beta run, all of it widening the agent surface it opened in 3.8.0
Hive ships in batches, and this one is all planning accuracy and admin control.
Teable ships daily, and the work has moved from grid features to platform governance.
Simpplr publishes the research that names the gap, then ships the product that closes it.
See all CommaFeed alternatives → · See all EGroupware alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. CommaFeed and EGroupware are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. CommaFeed and EGroupware are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top CommaFeed alternatives in Collab are ranked by recent ship velocity. Browse the "CommaFeed alternatives" section above for the current picks, or visit /alternatives/commafeed for the full list with editorial commentary on each.
Top EGroupware alternatives in Collab are ranked by recent ship velocity. Browse the "EGroupware alternatives" section above for the current picks, or visit /alternatives/egroupware for the full list with editorial commentary on each.