In particular, we need to remove dependencies that may introduce perception of vulnerabilities. For example, we've received dependabot PRs like #192 which upgrades the declared postgresql dependency in the rds-bootstrap custom resource, despite the fact that that dependency is used nowhere in the resource.
Other information