Postgres JDBC 42.6.0 has a highly rated vulnerability reported against it, CVE-2024-1597.
Postgres JDBC 42.6.1 was released to address this vulnerability.
Can you please include this dependency update in tomorrow's scheduled Spring Boot 3.2.2 release?
Comment From: scottfrederick
There is no need to ask for a dependency upgrade.
As mentioned in our issue template:
You DO NOT need to raise an issue for a managed dependency version upgrade as there's a semi-automatic process for checking managed dependencies for new versions before a release.
We run the dependency upgrade process just before each release.
Duplicates #39662