Teable
Secrets get encrypted at rest while the computed-field engine keeps getting shored up
A side-by-side editorial comparison of HumHub and Miniflux — release velocity, themes, recent moves, and the top alternatives to consider.
HumHub's public feed carries only betas, and 1.19's is still about surviving the upgrade.
The four releases visible here are all pre-release: 1.19.0-beta.2 and beta.1, and 1.18.0-beta.6 and beta.5 before them. The 1.19 line is dominated by upgrade-path and data-integrity repair — a foreign key violation aborting the comment content_id migration on databases with orphaned rows, fatal errors when purging content whose underlying record was gone, and in beta.2 a fatal SCSS build loop left behind when the 1.19 move of static/themes into protected/humhub stranded an empty theme skeleton. Beta.2 also fixes a real leak: activities from private spaces appearing in the summary mail and dashboard of users holding only a pending invite or join request.
A minimal RSS reader that made passkeys the only way in, then went back to polishing the reading experience.
Miniflux ships a release roughly monthly, and the 2.2.19-through-2.3.1 stretch was almost entirely security work: OIDC token signature verification, PKCE state cleanup, SHA1 replaced with HMAC-SHA256 for Google Reader API auth, an OAuth account-binding vulnerability, an open redirect, and a possible SQL injection in dynamically built ORDER BY clauses. The two most recent releases return to product — full-text search on PostgreSQL's websearch_to_tsquery, an expanded API v1, and feed language detection.
The four releases visible here are all pre-release: 1.19.0-beta.2 and beta.1, and 1.18.0-beta.6 and beta.5 before them. The 1.19 line is dominated by upgrade-path and data-integrity repair — a foreign key violation aborting the comment content_id migration on databases with orphaned rows, fatal errors when purging content whose underlying record was gone, and in beta.2 a fatal SCSS build loop left behind when the 1.19 move of static/themes into protected/humhub stranded an empty theme skeleton. Beta.2 also fixes a real leak: activities from private spaces appearing in the summary mail and dashboard of users holding only a pending invite or join request.
The 1.19 cycle is being spent making the migration survivable on real installations rather than adding capability, which is the usual shape when a schema and directory-layout change meets databases and webroots that have accumulated years of drift. Beta.2 extends that into the installer itself, where an unreachable database was offering to re-set-up a live instance during a transient outage. The permission and visibility fixes point the same way: tightening authorisation and content boundaries is cleanup of an existing model, not an extension of it.
Only beta tags appear in this feed, so a 1.19.0 stable is the obvious next milestone, but nothing here dates it. The beta.1-to-beta.2 gap of about a month is a faster rhythm than the roughly six months between the 1.18 and 1.19 betas.
Miniflux ships a release roughly monthly, and the 2.2.19-through-2.3.1 stretch was almost entirely security work: OIDC token signature verification, PKCE state cleanup, SHA1 replaced with HMAC-SHA256 for Google Reader API auth, an OAuth account-binding vulnerability, an open redirect, and a possible SQL injection in dynamically built ORDER BY clauses. The two most recent releases return to product — full-text search on PostgreSQL's websearch_to_tsquery, an expanded API v1, and feed language detection.
Two threads run in parallel. The security thread has systematically closed off every authentication path that was not cryptographically strict, culminating in 2.3.0 restricting WebAuthn login to discoverable passkeys only. The product thread is API-shaped: entry ID pagination, bulk starred updates, tag filtering, and a Go client that now exposes the full feed record — all aimed at people driving Miniflux from other software rather than its own UI.
The API surface is the area with visible momentum, so the next release most likely extends filtering or bulk operations further. Whether the passkey-only stance loosens to accommodate post-password MFA is the open question these notes raise but do not answer.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either HumHub or Miniflux.
Secrets get encrypted at rest while the computed-field engine keeps getting shored up
Security and governance controls catch up to the Copilot build-out
A social-networking engine in careful maintenance across two supported branches.
7.1.3 ships on the Mac, closing a release spent almost entirely on rebuilding Feedly sync.
Hive keeps tightening the same three seams: planned time, admin control, and AI review scope
A dated canary most days, with the beta line carrying the same commits later.
See all HumHub alternatives → · See all Miniflux alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. HumHub is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. HumHub is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top HumHub alternatives in Collab are ranked by recent ship velocity. Browse the "HumHub alternatives" section above for the current picks, or visit /alternatives/humhub for the full list with editorial commentary on each.
Top Miniflux alternatives in Collab are ranked by recent ship velocity. Browse the "Miniflux alternatives" section above for the current picks, or visit /alternatives/miniflux for the full list with editorial commentary on each.