CogniRunner is no longer open source. Here is what that changes, and what it does not.
Mihai Perdum
Author
5 min readSeptember 22, 2026
Key takeaways
CogniRunner is now a commercial app: sold on the Atlassian Marketplace and delivered to client teams as scoped work, with the rules, listeners and jobs built, tested, documented and handed over.
Nothing changes inside your Jira. Releases that were published under an open-source licence stay under that licence as published; current releases grant no source rights.
Sentinel Vault is LeanZero's one open-source Atlassian app and stays that way, public on GitHub under MIT.
CogniRunner is no longer open source. It is a commercial Atlassian Marketplace app, and the way we sell it changes with it: instead of a repository you can read, you get a team that builds the rules, listeners and jobs your workflow needs, tests them in your Jira, documents them and hands them over. Sentinel Vault, our Confluence app, stays open source and is now the only one of our Atlassian apps that is.
The source is no longer public. The GitHub repository is private, the portfolio page no longer carries a GitHub button, and the terms of service say it in one sentence: CogniRunner is not open source, and no source-code rights are granted for it.
The offer changes shape. CogniRunner stays on the Marketplace, paid through Atlassian, free for sites of up to ten users. What we add is the delivery: for teams that want the work done rather than the tool handed over, we scope it, build the validators, conditions and post-functions, the listeners on Jira events and the scheduled jobs, test them in your Jira, write the handover, and name who to contact afterwards. That is what I mean by clear deliverables, and it is how we sell the app now.
What does not change
Your installation. The app is a Forge app, it runs in Atlassian's infrastructure, and your data stays there. A licence on the source has nothing to do with the rules you configured; they keep running as they did.
The code that already shipped. CogniRunner started under AGPL-3.0 in February 2026 and moved to Apache-2.0 in July; the commit that did it gives the reason, that the Forge developer terms do not allow copyleft in a Forge app. Every release that went out under one of those licences stays under it, as published. We are not withdrawing anything, and we are not asking anyone to stop using a copy they already have. What we are saying is narrower: the releases from here on are proprietary.
The product itself. The workflow conditions the 3.1.0 post describes, the listeners, cron jobs and REST API from the 3.3.0 post, the rule memory in the byte-budget tutorial: all of it is still there, and those articles stay up. Where a post pointed at the source on GitHub, that line now says the work is handed over with the release instead.
Why
The short version is the true one: we are moving CogniRunner to clear deliverables for its clients. A defined piece of work, built and tested in your Jira, documented and handed over, with somebody accountable for it. That is a service, and it is what we sell now.
It is a decision about how we sell, not a judgement on open source. Sentinel Vault stays where it is: public on GitHub, its README states MIT, and its detect-and-restore approach to Confluence edits is the kind of thing that is better for being readable.
If you are already a customer
Nothing is required of you. Your Marketplace licence is what it was. If you read the Trust Center for the security review, the architecture, data flows and permission model are documented on the product page, and we will answer questions about them the way we always have. If you would rather have the rules built for you than build them, that is now a thing you can ask us for directly.
If you were reading the source
Thanks. The releases you could read are still under the licence they were published with. What you cannot do is read the next one, and I would rather say that here than have you find out from a 404.
The product page carries the updated FAQ, and the contact form on this site reaches me.