Postgres JDBC 42.6.0 has a highly rated vulnerability reported against it, CVE-2024-1597.

Postgres JDBC 42.6.1 was released to address this vulnerability.

Can you please include this dependency update in tomorrow's scheduled Spring Boot 3.2.2 release?

Comment From: scottfrederick

There is no need to ask for a dependency upgrade.

As mentioned in our issue template:

You DO NOT need to raise an issue for a managed dependency version upgrade as there's a semi-automatic process for checking managed dependencies for new versions before a release.

We run the dependency upgrade process just before each release.

Duplicates #39662