authentik
authentik 2026.8 ships: Actors, domain-joined Agents, and a push past browser-mediated SSO
A side-by-side editorial comparison of Greenbone Vulnerability Manager and incident.io — release velocity, themes, recent moves, and the top alternatives to consider.
| Feature | Greenbone Vulnerability Manager | incident.io |
|---|---|---|
| Sector | Infra & APIs | Infra & APIs |
| Velocity score | 6.3 | 6.3 |
| Sparks · 30d | 1 | 1 |
| Top themes | vulnerability management, web application scanning, gmp protocol, report modeling | incident-response, nexus-agent, on-call, status-pages |
| Last editorial update | 11d ago | 4h ago |
| Website | Visit → | Visit → |
Greenbone's scanner daemon is growing a web-application scanning class beside its network roots.
gvmd releases every week or two, and the changelog splits cleanly in three: a sustained build-out of web application scanning, a rewrite of how reports are modeled and exported, and a long tail of memory-management fixes in the C core. Recent versions added web application scanner preferences, scanner verification, and a Web Application VT subtype with a database migration. The report work moved from ad-hoc XML toward a structured report model addressable through new GMP commands.
Nexus does the diagnosis; the agent is now reaching into the status page too.
Investigations went generally available earlier this month, with Nexus posting a root-cause hypothesis and its evidence into the incident channel within minutes of declaration. The releases since have been the operational surround: a 24/7 schedule coverage policy that flags gaps before someone is missing from a rotation, more filtering in Insights, escalation reassignment, and now status page updates written by the agent alongside Pingdom uptime metrics and self-serve language settings.
gvmd releases every week or two, and the changelog splits cleanly in three: a sustained build-out of web application scanning, a rewrite of how reports are modeled and exported, and a long tail of memory-management fixes in the C core. Recent versions added web application scanner preferences, scanner verification, and a Web Application VT subtype with a database migration. The report work moved from ad-hoc XML toward a structured report model addressable through new GMP commands.
Greenbone is widening what gvmd can orchestrate. Network and container scanning were the existing surface; web application scanning is being brought to parity, with its own VT class, preferences, validation, and verification path. In parallel the GMP protocol is gaining first-class report retrieval commands, which makes report data consumable by tooling rather than only renderable. The bug-fix stream is dominated by frees and cleanup in long-lived report paths, the signature of a codebase under memory pressure at scale.
Web Application VTs now have a subtype, a migration, and scanner verification, but the audit and scan report commands were added separately; expect the report model work to fold web application results into the same structured retrieval path rather than leaving a parallel one.
Investigations went generally available earlier this month, with Nexus posting a root-cause hypothesis and its evidence into the incident channel within minutes of declaration. The releases since have been the operational surround: a 24/7 schedule coverage policy that flags gaps before someone is missing from a rotation, more filtering in Insights, escalation reassignment, and now status page updates written by the agent alongside Pingdom uptime metrics and self-serve language settings.
Two threads are converging. Nexus started inside the incident channel doing diagnosis, and it is now writing the customer-facing artifact as well — the status page is the first place its output leaves the responder's view and reaches the people affected. The rest is steady on-call plumbing: coverage policies, escalation routing, workflow secrets and signing. That split is consistent, with the agent taking judgment work and the platform hardening the mechanics around it.
Expect the agent to keep moving along the incident's outward path — customer comms, post-incident drafting — now that it writes to the status page, and expect more policy checks of the schedule-coverage kind that catch gaps before an incident finds them.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Greenbone Vulnerability Manager or incident.io.
authentik 2026.8 ships: Actors, domain-joined Agents, and a push past browser-mediated SSO
Rancher's public feed is a build-tag stream: three branches bumped the same Go image on one afternoon
Buildkite keeps converting hand-rolled agent workarounds into first-class CI primitives.
Cursor's agents stop waiting to be asked - they subscribe, and they hold a goal until it's done.
Warp turned its quarter of software-factory essays into infrastructure you can buy.
Okta's developer blog is a Cross App Access campaign, now diluted by advocacy-team storytelling.
See all Greenbone Vulnerability Manager alternatives → · See all incident.io alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Greenbone Vulnerability Manager and incident.io are shipping at a similar cadence (velocity 6.3 vs 6.3, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Greenbone Vulnerability Manager and incident.io are shipping at a similar cadence (velocity 6.3 vs 6.3, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Greenbone Vulnerability Manager alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Greenbone Vulnerability Manager alternatives" section above for the current picks, or visit /alternatives/greenbone-gvmd for the full list with editorial commentary on each.
Top incident.io alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "incident.io alternatives" section above for the current picks, or visit /alternatives/incident-io for the full list with editorial commentary on each.