Emergency Patching Events¶
An emergency patching event is declared when a security vulnerability affecting the example service requires a fix outside the normal release schedule.
Emergency patches bypass the normal review window
Emergency patches still require a second engineer's approval, but the standard soak time in a lower environment may be shortened or skipped depending on the severity of the vulnerability. This tradeoff should be made deliberately, not by default.
The process starts with an assessment of severity and exposure, followed by a fix, an abbreviated test pass, and a production deployment outside the normal window. A summary of the event, including timeline and root cause, is written up afterward regardless of how minor the patch seemed at the time.