Hacker News new | ask | show | jobs
by mpitt 3887 days ago
I see it like this: 1) let the user handle the security updates of the JVM; 2) push out security updates in a centralised, controlled fashion.

IMHO, in a corporate solution like that described in the OP, 2) makes a lot more sense.