logoalt Hacker News

jonhohle • yesterday at 11:12 PM • 1 reply • view on HN

At a previous job I wrote a docker build for patching individual Java class files on top of a monolithic docker image. This was not runtime patching, but allowed a single layer that was only a few kilobytes to be deployed quickly in emergency situations.

Interestingly, it had similar constraints and checked them at build time: it could not be a public ABI change and only one patch at a time.


Replies

itintheory • today at 12:57 AM

Was it for the log4shell vulnerability? I did something similar there.