News Date and Time
Aug 11 2026 18:00
We are pleased to announce the 2.9.0 LTS minor release of the JS7 JobScheduler
The release brings a number of bug-fixes and features to the JobScheduler Controller, Agent and JOC Cockpit. JobScheduler is rebranded to JS7 JobScheduler to indicate major changes to architecture and features. Branch 2.9 receives Long Term Support for 4 years.
JS7 is the next generation Open Source Job Scheduler designed for performance, resilience and security.
Getting Started
- The JS7 Online Demo is available for immediate access.
- Consider the Getting Started section of the Product Knowledge Base.
Release
- Release Notes
- Features (major)
- JS-2155: Log file web service
- JOC-1875: Offer access to Controller and Agent log files
- JOC-2219: Offer post-quantum cryptography for digital signing of inventory objects
- JOC-2209: Offer switching between fewer and more options in the JOC Cockpit GUI
- JOC-2252: User confirmation for fail-over in Controller Cluster and Agent Cluster
- JOC-2211: Add context videos to JOC Cockpit GUI
- JOC-2220: Support for Russian Interface Language
- YADE-651: Add support for alternative ProtocolFragments and Profiles
- Bug-fixes (major)
- JS-2258: Controller and Agent stop logging when used with OpenTelemetry Java Agent
- JOC-2224: Releasing a Calendar or Schedule can result in duplicate Orders
- JOC-2222: Deployment History should consider relocation of workflows
- JOC-2256: YADE Deployment takes too long
- JOC-2163: Missing Script Include Dependencies in Workflow
3rd-Party Vulnerability Remediation
- JS-2256: Upgrade log4j-core to version 2.26.1 due to 3rd-party vulnerability CVE-2025-68161
- JOC-2268: org.eclipse.parsson version 1.1.7 flagged with 3rd Party Vulnerability issue CVE-2026-9563
- JOC-2266: Upgrade PostgreSQL Driver to version 42.7.12 due to 3rd party vulnerability CVE-2026-54291
- JOC-2264: Upgrade jackson-databind 2.22.0 to 2.22.1 due to 3rdparty vulnerability CVE-2026-59889
- JOC-2253: Use Jetty 12.1.10 instead of 11.0.26, due to multiple 3rd party vulnerabilities in 11.0.26
- JOC-2245: Upgrade jackson-databind 2.21.1 to 2.22.0 due to multiple 3rd party vulnerabilities CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515, CVE-2026-54516, CVE-2026-54517, CVE-2026-54518, CVE-2026-50193
- JOC-2216: Upgrade bouncycastle to version 1.84 due to 3rd-party vulnerabilities CVE-2026-3505, CVE-2026-5598
- JOC-2189: Remove unused railroad-diagrams 1.0.0 due to 3rd-party vulnerability CVE-2024-26467
- JOC-2187: Upgrade jersey-client to version 4.0.2 due to 3rd party vulnerability CVE-2025-12383
- JOC-2182: Drop c3p0 and mchange-common-java due to 3rd party vulnerability issues (CVE-2026-27727, CVE-2026-27830)
Important
- Branch 1.13 of JobScheduler reached its end-of-life in August 2023.
- Users of JobScheduler branches 1.x should consider changes and migration tools being available to upgrade to JS7.
- Please also take note of our Change Management information.



