@icedquinn @novenary @lanodan
An immutable base system is a workaround, and a costly one: consider all the copies of webp parser that will never be updated and will stay vulnerable forever.
A proper solutions would be ABI compatibility guarantee from userspace libraries, like the one you get from Linux kernel