I imagine there could be some risk-averse Java-powered companies out there willing to pay good money to keep their old JVMs patched, to avoid the risks of upgrading.
I imagine there could be some risk-averse Java-powered companies out there willing to pay good money to keep their old JVMs patched, to avoid the risks of upgrading.
There millions of them. But if anything I would expect that risk aversion to translate into not back porting discretionary performance fixes. For example, the fix I linked to improves BufferedReader performance by swapping a thread-safe underlying class for a non-thread-safe version. That could introduce race conditions and other synchronization issues into its behavior. Thread safety was never specified in the API so that's fine for prospective versions, but having this land unexpectedly in a minor version update bundled with security patches .... is almost the opposite of what I would want.
https://developers.redhat.com/blog/2018/09/24/the-future-of-...
But that particular bug was backported by someone at Oracle.