| ▲ | jonhohle 7 hours ago | |
At a previous job I wrote a docker build for patching individual Java class files on top of a monolithic docker image. This was not runtime patching, but allowed a single layer that was only a few kilobytes to be deployed quickly in emergency situations. Interestingly, it had similar constraints and checked them at build time: it could not be a public ABI change and only one patch at a time. | ||
| ▲ | itintheory 5 hours ago | parent [-] | |
Was it for the log4shell vulnerability? I did something similar there. | ||