IP Library › Granted Patent US 12,423,089
Granted Patent B1
US 12,423,089 · App. 19/191,013 · Granted Sep 23, 2025

Software image update management platform

Inventors: John Morello (Baton Rouge, LA); Ben Bernstein (New York, NY); Dima Stopel (Herzliya, IL)
Assignee: MINIMUS LTD
G06F8/65G06F21/577G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,423,089
App. No.
19/191,013
Filed
Apr 28, 2025
Granted
Sep 23, 2025
Kind
B1
Examiner
LUU, CUONG V
Art Unit
2192
USPC
717/169
Abstract

A system and method for software image management. A method includes generating a plurality of software packages, wherein each software package is generated using a respective set of code; building a plurality of software images based on a plurality of files, wherein building each software image further comprises combining a subset of the plurality of software packages according to a corresponding file of the plurality of files, wherein each file includes a set of instructions for combining the subset of the plurality of software packages in order to build the corresponding software image; and storing the plurality of software images in a repository.

Claims (58)

1. A method for software image management, comprising:

generating a plurality of software packages, wherein each software package is generated using a respective set of code,

building a plurality of software images based on a plurality of files, wherein building each software image further comprises combining a subset of the plurality of software packages according to a corresponding file of the plurality of files, wherein each file includes a set of instructions for combining the subset of the plurality of software packages in order to build one of the plurality of software images;

storing the plurality of software images in a repository;

monitoring for changes to a plurality of portions of code among the plurality of software packages, wherein the plurality of portions of code among the plurality of software packages is a plurality of first portions of code;

identifying an update based on the monitoring, wherein the update includes a change in at least one portion of code of the plurality of portions of code among the plurality of software packages; and

rebuilding at least one software image of the plurality of software images using a new version of the at least one portion of code;

wherein the monitoring for the changes to the plurality of portions of code among the plurality of software packages further comprises:

establishing a pipeline with respect to the plurality of software packages, wherein the pipeline is defined such that a software package of the plurality of software packages containing a dependency to a second portion of code is downstream of the second portion of code; and

detecting an upstream change for at least one software package of the plurality of software packages, wherein the update is identified based on the detected upstream change.

2. The method of claim 1 , further comprising:

configuring each of the plurality of software images based on the plurality of files, wherein the set of instructions for each file further defines a configuration for one of the plurality of software images.

3. The method of claim 1 , further comprising:

classifying the update into a classification; and

selecting the at least one software image to be rebuilt based on the classification.

4. The method of claim 3 , wherein the classification indicates that the change in the at least one portion of code is a change to patch a vulnerability.

5. The method of claim 1 , wherein the plurality of software images corresponds to a plurality of software components, further comprising:

ingesting cybersecurity data from a computing environment in which the plurality of software components is deployed; and

identifying a vulnerability being exploited based on the ingested cybersecurity data,

wherein the at least one software image includes a vulnerable software package of the plurality of software packages, wherein the vulnerable software package has the identified vulnerability.

6. The method of claim 5 , further comprising:

redeploying the at least one software image.

7. The method of claim 1 , wherein each software package is a unit of code defined with respect to at least one function.

8. A non-transitory computer-readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

generating a plurality of software packages, wherein each software package is generated using a respective set of code,

building a plurality of software images based on a plurality of files, wherein building each software image further comprises combining a subset of the plurality of software packages according to a corresponding file of the plurality of files, wherein each file includes a set of instructions for combining the subset of the plurality of software packages in order to build one of the plurality of software images;

storing the plurality of software images in a repository;

monitoring for changes to a plurality of portions of code among the plurality of software packages, wherein the plurality of portions of code among the plurality of software packages is a plurality of first portions of code;

identifying an update based on the monitoring, wherein the update includes a change in at least one portion of code of the plurality of portions of code among the plurality of software packages; and

rebuilding at least one software image of the plurality of software images using a new version of the at least one portion of code;

wherein the monitoring for the changes to the plurality of portions of code among the plurality of software packages further comprises:

establishing a pipeline with respect to the plurality of software packages, wherein the pipeline is defined such that a software package of the plurality of software packages containing a dependency to a second portion of code is downstream of the second portion of code; and

detecting an upstream change for at least one software package of the plurality of software packages, wherein the update is identified based on the detected upstream change.

9. A system for software image management, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

generate a plurality of software packages, wherein each software package is generated using a respective set of code;

build a plurality of software images based on a plurality of files, wherein the instructions further configure the system to combine a subset of the plurality of software packages according to a corresponding file of the plurality of files, wherein each file includes a set of instructions for combining the subset of the plurality of software packages in order to build one of the plurality of software images;

store the plurality of software images in a repository;

monitor for changes to a plurality of portions of code among the plurality of software packages, wherein the plurality of portions of code among the plurality of software packages is a plurality of first portions of code;

identify an update based on the monitoring, wherein the update includes a change in at least one portion of code of the plurality of portions of code among the plurality of software packages; and

rebuild at least one software image of the plurality of software images using a new version of the at least one portion of code;

wherein the instructions further configure the system to:

establish a pipeline with respect to the plurality of software packages, wherein the pipeline is defined such that a software package of the plurality of software packages containing a dependency to a second portion of code is downstream of the second portion of code; and

detect an upstream change for at least one software package of the plurality of software packages, wherein the update is identified based on the detected upstream change.

10. The system of claim 9 , wherein the system is further configured to:

configure each of the plurality of software images based on the plurality of files, wherein the set of instructions for each file further defines a configuration for one of the plurality of software images.

11. The system of claim 9 , wherein the system is further configured to:

classify the update into a classification; and

select the at least one software image to be rebuilt based on the classification.

12. The system of claim 11 , wherein the classification indicates that the change in the at least one portion of code is a change to patch a vulnerability.

13. The system of claim 9 , wherein the plurality of software images corresponds to a plurality of software components, wherein the system is further configured to:

ingest cybersecurity data from a computing environment in which the plurality of software components is deployed; and

identify a vulnerability being exploited based on the ingested cybersecurity data,

wherein the at least one software image includes a vulnerable software package of the plurality of software packages, wherein the vulnerable software package has the identified vulnerability.

14. The system of claim 13 , wherein the system is further configured to:

redeploy the at least one software image.

15. The system of claim 9 , wherein each software package is a unit of code defined with respect to at least one function.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2026
From: MINIMUS LTD
To: ECHO SOFTWARE LTD.
Reel/Frame 075796/0322 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2025
From: MORELLO, JOHN; BERNSTEIN, BEN; STOPEL, DIMA
To: MINIMUS LTD
Reel/Frame 070962/0725 →
Continuity (1)
Provisional Application 63720901 · Nov 15, 2024
References Cited (38)
US 9959104B2 · Chen et al. · 2018 [cited by applicant]
US 9983891B1 · Christensen · 2018 [cited by applicant]
US 10505830B2 · Mishalov et al. · 2019 [cited by applicant]
US 10885378B2 · Li et al. · 2021 [cited by applicant]
US 11062022B1 · Kalamkar et al. · 2021 [cited by applicant]
US 11182140B2 · Riek et al. · 2021 [cited by applicant]
US 11599348B2 · Goldmann et al. · 2023 [cited by applicant]
US 11669362B2 · Singh et al. · 2023 [cited by applicant]
US 11972333B1 · Horesh et al. · 2024 [cited by applicant]
US 12095806B1 · Nemtsov et al. · 2024 [cited by applicant]
US 12099414B2 · Mitkar et al. · 2024 [cited by applicant]
US 12242994B1 · Aggarwal et al. · 2025 [cited by applicant]
US 12267345B1 · Erlingsson et al. · 2025 [cited by applicant]
US 20120324446A1 · Fries et al. · 2012 [cited by applicant]
US 20150365437A1 · Bell, Jr. et al. · 2015 [cited by applicant]
US 20170147813A1 · McPherson et al. · 2017 [cited by applicant]
US 20190347127A1 · Coady et al. · 2019 [cited by applicant]
US 20200159536A1 · Saidi · 2020 [cited by applicant]
US 20200213357A1 · Levin et al. · 2020 [cited by applicant]
US 20200285504A1 · Siegmund · 2020 [cited by applicant]
US 20200326931A1 · Nadgowda · 2020 [cited by examiner]
US 20210157623A1 · Chandrashekar et al. · 2021 [cited by applicant]
US 20210208916A1 · Wang et al. · 2021 [cited by applicant]
US 20210255840A1 · Novy · 2021 [cited by applicant]
US 20210319109A1 · Weng et al. · 2021 [cited by applicant]
US 20220147378A1 · Tarasov et al. · 2022 [cited by applicant]
US 20220166626A1 · Madisetti et al. · 2022 [cited by applicant]
US 20230168986A1 · Larkin et al. · 2023 [cited by applicant]
US 20240069883A1 · Griffin et al. · 2024 [cited by applicant]
US 20240103833A1 · Shemer · 2024 [cited by examiner]
US 20240134967A1 · Yaron · 2024 [cited by examiner]
US 20240411674A1 · Zmigrod et al. · 2024 [cited by applicant]
US 20250004741A1 · Hubik · 2025 [cited by examiner]
US 20250123819A1 · Khemka et al. · 2025 [cited by applicant]
US 20250156535A1 · Keller et al. · 2025 [cited by applicant]
CN 111522628A · 2020 [cited by applicant]
Ian Gorton et al.; Components in the Pipeline; IEEE; pp. 34-40; retrieved on Jul. 18, 2025 (Year: 2025). [cited by examiner]
“Announcing ‘Yum + RPM for Containerized Applications’—Nulecule & Atomic App,” Red Hat Blog (Jun. 23, 2015) (available at https://www.redhat.com/en/blog/announcing-yum-rpm-containerized-applications-nulecule-atomic-app)… [cited by applicant]