CommaFeed
CommaFeed is patching its way through the attack surface a self-hosted reader inherits
A side-by-side editorial comparison of HedgeDoc and Hive — release velocity, themes, recent moves, and the top alternatives to consider.
HedgeDoc 1.x releases are now mostly advisories — security in, features rarely.
The 1.x line ships on a roughly six-to-eight-week rhythm, and almost every release leads with security fixes: HTML injection through an email localpart, YAML frontmatter denial-of-service, CSRF in the Gist export, a rate-limit bypass via the CF-Connecting-IP header, SVG upload script execution. Around that, the recent additions are operator controls — an external-link warning page with a whitelist, configurable login and signup rate limits, an option to restrict uploads to registered users or disable them entirely.
Hive ships in batches, and this one is all planning accuracy and admin control.
Hive publishes its changelog as clusters of single-feature entries dated the same day — seven on August 18, three on August 14. The current batch splits between planning integrity (time estimates surviving assignee changes, a rebuilt Unsubmitted Timesheets view, reorderable Gantt columns), governance (a default restricted-member role applied across every onboarding path, custom-field edits appearing in activity feeds), and small chat conveniences. Nothing in the batch is a new product area; it is the existing surface being tightened.
The 1.x line ships on a roughly six-to-eight-week rhythm, and almost every release leads with security fixes: HTML injection through an email localpart, YAML frontmatter denial-of-service, CSRF in the Gist export, a rate-limit bypass via the CF-Connecting-IP header, SVG upload script execution. Around that, the recent additions are operator controls — an external-link warning page with a whitelist, configurable login and signup rate limits, an option to restrict uploads to registered users or disable them entirely.
This reads as a mature collaborative editor in hardening mode. New settings appear where an administrator needed a lever, not where a user asked for a feature, and the one substantial correctness fix in the window — data loss when five or more people edited a document at once — was a repair to the existing operational-transform client rather than new ground. Node 24 support and the removal of dead config options point the same direction: keeping a working product current.
Expect the next 1.x release to follow the same shape — one or more advisories plus a small configuration option — since every release in this window has done so.
Hive publishes its changelog as clusters of single-feature entries dated the same day — seven on August 18, three on August 14. The current batch splits between planning integrity (time estimates surviving assignee changes, a rebuilt Unsubmitted Timesheets view, reorderable Gantt columns), governance (a default restricted-member role applied across every onboarding path, custom-field edits appearing in activity feeds), and small chat conveniences. Nothing in the batch is a new product area; it is the existing surface being tightened.
Two themes have been running through recent batches. The first is making planned time trustworthy — estimates that no longer vanish when work is reassigned, timesheet views built for scanning who has not submitted. The second is administrative control that scales: a least-privilege default that holds across SAML, SCIM, invite links and domain auto-join, and an audit trail that now covers custom-field edits. Both point at larger deployments, where the failure modes are silent data loss and inconsistent permissions rather than missing features.
The audit-trail and permissions work looks incomplete rather than finished — activity coverage for other object types and per-field visibility rules are the obvious next steps. Expect the same batched cadence, roughly twice a month.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either HedgeDoc or Hive.
CommaFeed is patching its way through the attack surface a self-hosted reader inherits
SiYuan stabilises 3.8.1 after a seven-build beta run, all of it widening the agent surface it opened in 3.8.0
Teable ships daily, and the work has moved from grid features to platform governance.
Simpplr publishes the research that names the gap, then ships the product that closes it.
NetNewsWire's 7.1.3 train has moved from rebuilding sync to sweeping up what the rebuild disturbed.
Document360 rebuilt its API for agents; now it's turning the AI inward on authoring.
See all HedgeDoc alternatives → · See all Hive alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Hive is currently shipping more aggressively (velocity 10.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Hive is currently shipping more aggressively (velocity 10.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top HedgeDoc alternatives in Collab are ranked by recent ship velocity. Browse the "HedgeDoc alternatives" section above for the current picks, or visit /alternatives/hedgedoc for the full list with editorial commentary on each.
Top Hive alternatives in Collab are ranked by recent ship velocity. Browse the "Hive alternatives" section above for the current picks, or visit /alternatives/hive for the full list with editorial commentary on each.