Back to updates
New releaseAug 26, 2026

jsch jsch-2.28.7

Pure Java SSH client library supporting modern signature algorithms (RSA-SHA2, Ed25519) and drop-in replacement for legacy JSch.

Share

Fork of JSch-0.1.55

See original README

GitHub release Maven Central Java CI with Maven

Why should you use this library?

As I explained in a blog post the main points are:

  • OpenSSH has disabled ssh-rsa in release 8.8 per default and you need a library which supports rsa-sha2-256 and rsa-sha2-512.
  • Drop in replacement: just change dependency coordinates and you are good to go.
  • No active maintenance of JSch at SourceForge.
  • Stay in sync with OpenJDK features so there is no need for additional dependencies.

Is there any documentation?

Not much. Check the example code in the examples folder. And there are some wiki pages, i.e. Jsch-Configuration and Jsch-Logging.

Versioning

Up until 0.2.26 the versioning followed the original jsch scheme, from 2.27.0 on, we switched to semantic versioning, expressing that the library api is stable and used in production.

How to use this library as a replacement for com.jcraft:jsch

Make sure, that you only have one jsch dependency on your classpath. For example you can check the output of mvn dependency:tree.

by replacing a direct maven dependency

replace

<dependency>
    <groupId>com.jcraft</groupId>
    <artifactId>jsch</artifactId>
    <version>0.1.55</version>
</dependency>

with

<dependency>
  <groupId>com.github.mwiede</groupId>
  <artifactId>jsch</artifactId>
  <version>2.28.0</version>
</dependency>

by replacing jsch as a transitive maven dependency

When you have an artifact foo:bar, which contains com.jcraft:jsch as a transitive dependency, you need to add com.github.mwiede:jsch as another dependency and exclude the jcraft one:

<dependency>
  <groupId>com.github.mwiede</groupId>
  <artifactId>jsch</artifactId>
  <version>2.28.0</version>
</dependency>
<dependency>
  <groupId>foo</groupId>
  <artifactId>bar</artifactId>
  <exclusions>
        <exclusion>  
          <groupId>com.jcraft</groupId>
          <artifactId>jsch</artifactId>
        </exclusion>
      </exclusions> 
</dependency>

Addition: You can further exclude any of com.jcraft:jsch.agentproxy.jsch, com.jcraft:jsch.agentproxy.core or com.jcraft:jsch.agentproxy.pageant, because these modules where integrated in this fork (see release notes of 0.1.66).

Categories