Release Notes
1 Administration
1.1 Discontinuation of the Jetty Web Server
With FirstSpirit 2023.9, the integrated Embedded Tomcat Web Server for web applications was introduced.
Starting with version 2024.12, the Embedded Tomcat will replace the previous Jetty Web Server as the default server for web applications.
Support for the Jetty Web Server will be discontinued with FirstSpirit 2026.2.
Crownpeak recommends switching the web applications to the Embedded Tomcat Web Server at an early stage.
For productive operations, an external web server is still recommended.1.2 Update of internally used software
As of the release 2025.9, the following internally used software has been updated.
- Apache Commons Net
Update from version 3.1 to version 3.11.1 - Google Web Toolkit („GWT“)
Update from version 2.11.0 to version 2.12.2
Please note the general advice that when developing modules or scripts, only the FirstSpirit API should be used. When using third-party libraries, they should be integrated as "isolated".
1.3 Discontinuation: Deactivation of the Java SecurityManager
The SecurityManager has been part of Java since version 1.0 and allows the configuration of security policies that apply to the entire application. However, it has been discussed for more than four years now to remove it from Java. This goal is now approaching: while Java 17 already marked the class as "to be removed", it is no longer functional in versions from Java 24 onwards.
In addition, the use of the SecurityManager causes further disadvantages:
- Newer software components are no longer compatible, such as Apache Tomcat 11.
- When using concurrency, a set SecurityManager can lead to errors that are difficult to diagnose.
- The permission checks can cause significant performance losses.
FirstSpirit currently uses the SecurityManager in various areas, for example, to secure access to certain program parts or to address potential security vulnerabilities in serialization. Replacement mechanisms have been created for these in recent releases, so disabling it does not pose a security risk. However, there are areas that could not be converted:
- Securing executions in scripts or templates is no longer possible.
- Manual adjustments in the file
fs-server.policyno longer have any effect.
The default deactivation of the SecurityManager is scheduled for version 2025.10. If you use one of the two options mentioned above or have any other questions about the SecurityManager, please contact Customer Support.
2 Administration / Modules
No support for modules with legacy resources
Modules with resources that are not marked as "isolated" access internal classes of FirstSpirit as well as internally used libraries, and thus run the risk of no longer functioning after a server upgrade.
As already announced with 2025.2, support for modules with legacy resources was discontinued with FirstSpirit 2025.9.
3 ContentCreator
New UI languages for ContentCreator
The current FirstSpirit version now supports the UI languages Chinese, Japanese, Korean, and Portuguese in the ContentCreator.
On the FirstSpirit start page, you can select the language in which the labeling of the menu bar and the dialogs are displayed.
4 FirstSpirit Content Experience Tools (CXT)
4.1 Latest module versions
FirstSpirit 2025.9 supports the following module versions for FirstSpirit Content Experience Tools.
| Module / file name | Version number |
FirstSpirit CXT Plattformplatform-[version].fsm | 6.1.19 |
FirstSpirit CXT DAP Bridgedataservice-[version].fsm | 1.44.37 |
FirstSpirit CXT FragmentCreatorfragment-creator-[version].fsm | 5.0.24 |
FirstSpirit Fragment DAPfragmentdap-[version].fsm | 1.40.47 |
FirstSpirit Media DAPmediadap-[version].fsm | 1.31.35 |
FirstSpirit PageRef DAPpageref-[version].fsm | 1.9.35 |
FirstSpirit Markdown Editormarkdown-editor-[version].fsm | 1.29.35 |
FirstSpirit Tagging Editortagging-editor-[version].fsm | 1.29.35 |
FirstSpirit CXT FragmentCreator - CaaS Integrationcaas-integration-[version].fsm | 1.31.34 |
FirstSpirit Image Assistantimagerecognition-module-[version].fsm | 1.0.64 |
FirstSpirit Analyze AsisstantFirstSpirit-AiAnalyze-[version].fsm | 0.9.10 |
Template Development MicroAppfs-sitedev-microapp-[version].fsm | 0.9.46 |
FirstSpirit Multisite Managementfs-multisite-[version].fsm | 1.5.9 |
FirstSpirit Collaboration (Beta)fs-collaboration-[version].fsm | 0.9.0 |
4.2 Support for customized root contexts
A new configuration option of the CXT platform now also enables connection to FirstSpirit servers whose homepage is accessible via a customized context path:
cxt.platform.firstspirit.root-context=/fs5root5 AI-powered tools
Support for Function Calls in FirstSpirit AI
Support for Function Calls in the FirstSpirit AI API has been implemented to enable the execution of external functions and actions directly via the API.
Modules or project scripts can define functions with this. This allows, among other things, the provision of data or information that can be evaluated in prompts, as well as the triggering of actions such as text changes, alt-text generation, or the creation of new pages.
6 Module: Collaboration
FirstSpirit Collaboration - open beta phase
With the FirstSpirit version 2025.9, the new feature "Collaboration" enters an open beta testing phase.
FirstSpirit Collaboration enables direct collaboration with other project users within the ContentCreator.
- Language-specific comments can be added to individual input components, such as headings or images.
- Other project users can respond to comments.
- The FirstSpirit AI agent is available to assist. It understands the context and provides appropriate responses accordingly.
For more information on installation and user introduction, please also refer to the documentation.
7 Language-dependent Release
Language-dependent release - open beta phase
With the FirstSpirit version 2025.9, the new feature "Language-Dependent Release" enters an open beta testing phase.
It enables authorized editors to selectively approve and publish content per language in multilingual projects.
By default, the language-independent release is enabled for all projects.
The feature language-dependent release can be activated individually for each project in the server manager under the project settings.

FirstSpirit logs an error if the database column necessary for the language-dependent release is missing to prevent incorrect releases.
For more information, see also the documentation.
Overview
| ID | Description | Categories |
|---|---|---|
| CORE-15033 | Support for modules with legacy resources was discontinued with the FirstSpirit version 2025.9. |
Project Administrator, Server Administrator |
| CORE-16962 | FirstSpirit AI API unterstützt jetzt Function Calls zur Integration externer Funktionen. OpenAI Connector wurde auf die offizielle Java Library umgestellt und ein experimentelles Responses API Plugin hinzugefügt. |
AI-powered tools |
| CORE-17054 | The memory usage of ContentTransport has been optimized, especially for packages with many pages and sections. |
Content Transport |
| CORE-17126 | Open beta phase for the new feature "Language-dependent release" |
Language-dependent Release |
| CORE-17169 | A problem with duplicate GIDs in the target project after the installation of a feature via ContentTransport was fixed, provided that the installed package in the target project already contained deleted elements. |
Content Transport |
| CORE-17207 | An error in the reference calculation of incoming references in remote projects has been fixed. |
Delta generation |
| CORE-17244 | Update of internally used software Further information can be found in chapter “Administration: Update of internally used software”. |
Integrated software |
| CORE-17265 | In certain system environments, invoking the Java SecurityManager can significantly slow down actions. A section of code during generation has been adjusted here to minimize these delays. |
Generation, Server Administrator |
| CORE-17280 | FirstSpirit Content Experience Tools: Latest module versions |
FirstSpirit Content Experience Tools (CXT) |
| CORE-17293 | Beta phase for the new feature "Collaboration" |
Collaboration |
| CORE-17302 | A problem with importing images in SVG format via External synchronization has been fixed. |
External synchronization |
| CORE-17303 | New UI languages for ContentCreator Further information can be found in chapter “ContentCreator: New UI languages for ContentCreator”. |
ContentCreator, Languages |
| CORE-17315 | A bug that prevented the deployment of large bundles has been fixed. |
Multisite Management |
| CORE-17318 | Since FirstSpirit 2025.6, exceptions could occur when sending emails via the MailService if the call is made from an executable whose module defines dependencies such as Angus Activation. |
FirstSpirit API, Module development, Tasks |
| CORE-17341 | Deactivation of the Java SecurityManager |
Server Administrator |
| CORE-17343 | Discontinuation of the Jetty Web Server |
FirstSpirit Jetty Web Server, Server Administrator |
| CXT-3549 | The CXT platform now supports the configuration of a customized root context for FirstSpirit servers. |
FirstSpirit Content Experience Tools (CXT) |
| CXT-3585 | Within the language selection in the toolbar, the workflow status per language is now only displayed when language-dependent approval is activated. |
ContentCreator |
Deprecations
| Functionality | Deprecated as of | Will be removed / Was removed as of |
|---|---|---|
| Input component CMS_INPUT_CONTENTAREALIST | 5.2R3 | |
| Input component CMS_INPUT_CONTENTLIST | 5.2R3 | |
| Input component CMS_INPUT_FILE | 5.2R3 | |
| Input component CMS_INPUT_LINKLIST | 5.2R3 | |
| Input component CMS_INPUT_OBJECTCHOOSER | 5.2R3 | |
| Input component CMS_INPUT_PAGEREF | 5.2R3 | |
| Input component CMS_INPUT_PICTURE | 5.2R3 | |
| Input component CMS_INPUT_TABLIST | 5.2R3 | |
| FirstSpirit Access API: de.espirit.firstspirit.agency.GroupsAgent | 5.2R15 | |
| FirstSpirit Access API: delete (de.espirit.firstspirit.access.AccessUtil) | 5.2R18 | |
| FirstSpirit Access API: release (de.espirit.firstspirit.access.AccessUtil) | 2018-06 | |
| FirstSpirit Access API: getLastLoginAsDate (de.espirit.firstspirit.agency.UserStatisticsAgent) | 2018-07 | |
| FirstSpirit Access API: remainingDurationOfCurrentStageInMillis (de.espirit.firstspirit.server.MaintenanceModeInfo) | 2018-07 | 2025-13 |
| FirstSpirit Access API: getStartingTimeOfStageAsDate (de.espirit.firstspirit.server.MaintenanceModeInfo) | 2018-07 | 2025-13 |
| FirstSpirit Access API: getSelectedWebserverConfiguration (de.espirit.firstspirit.access.serverConfiguration) | 2018-10 | 2025-13 |
| FirstSpirit Access API: setSelectedWebserverConfiguration (de.espirit.firstspirit.access.serverConfiguration) | 2018-10 | 2025-13 |
| FirstSpirit Access API: getSelectedWebServer (de.espirit.firstspirit.access.project.Project) | 2018-10 | 2025-13 |
| FirstSpirit Access API: setSelectedWebServer (de.espirit.firstspirit.access.project.Project) | 2018-10 | 2025-13 |
| FirstSpirit Access API: getLostAndFoundStoreNodes(); (de.espirit.firstspirit.feature.FeatureInstallResult) | 2018-10 | |
| FirstSpirit Access API: getDeletedStoreNodes(); (de.espirit.firstspirit.feature.FeatureInstallResult) | 2018-10 | |
| FirstSpirit Access API: de.espirit.firstspirit.access.store.Previewable | 2019-01 | |
| WebSphere Application Server support for FirstSpirit | 2019-05 | |
| FirstSpirit Access API: redirectTemplateLogToDefaultLog() (Interface RenderingAgent.Renderer) | 2021-05 | |
| Omnichannel Manager 2.x | 2025-01 | |
| FragmentCreator | 2025-01 | 2025-12 |
| Modules with legacy resources | 2025-02 | 2025-09 |
| Jetty Web Server | 2025-09 | 2026-02 |
| Java SecurityManager | 2025-09 | 2025-11 |