Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

When you can't upgrade: open source examples of Endor Patches

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Shristi Nadakatti
Word Count
1,043
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

Endor Patches are security backports that apply narrowly scoped CVE fixes to older Java library versions when upgrading to a current release would require disruptive API changes, rewrites, or dependency updates. Designed as compatible drop-in JAR replacements, the patches retain existing APIs and behavior, include only security-related changes, and are validated against full upstream test suites. Endor Labs has published reproducible examples for vulnerabilities in woodstox-core and Eclipse JGit through its endor-patches repository, including source diffs, CVE mappings, build and test attestations, artifact locations, checksums, and Docker/Bazel-based rebuild instructions. The repository distinguishes upstream backports from Endor-authored changes, allowing users to review modifications, reproduce builds from pinned source commits, compare generated artifacts with published checksums, and install the patched dependencies through Maven or Gradle.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.