The goal is to make the allowlist more maintainable - [ ] If we want to run the application with JDK 11 but the allowlist is generated with 8, then we get a false positive - [ ] Classes like `$Proxy` do not have the same name across different JVM versions so proxy class in JDK 11 would be not the same as JDK 17 ### Fixes - [ ] We cannot just rely on bytecode hashing to allowlist a class. Maybe we can also rely our trust on classloader. - [ ] Dynamic classes (Proxy) can be analyzed in different versions and common representation can be established.
The goal is to make the allowlist more maintainable
$Proxydo not have the same name across different JVM versions so proxy class in JDK 11 would be not the same as JDK 17Fixes