I haven't given too much thought to how this would work, but given that they usually contain security fixes, we should probably keep everything up to date and ensure the code still passes tests.
Ideal scenario is we find an RSS feed somewhere of pg jdbc releases and add a cronjob which pings it, updates it and submits a PR.