When and how frequent is DAZ fixing insecure PostgreSQL in Studio
Secunia PSI is reporting that the third party PostgreSQL database-engine in DAZ-Studio is insecure (not the first time and I'm running 4.9 with latest PostgreSQL-installation from DIM). I don't want to have insecure, but still developed stuff on my computer (for "end-of-life"-programs I'll decide on my own risk).
As far as I appreciate an Open Source database-engine for all the content-stuff, I don't see any reason for using engines which are deprecated. I don't have any ideas how sincere the bug-fixes are: http://www.postgresql.org/docs/9.3/static/release-9-3-11.html , but the list doesn't make me to trust on the deprecated version.
So, when and how frequently will DAZ deploy security-fixes of essential to Studio used third party components (from my little knowledge of Linux it should be 1 or 2 days, after a repository was updated)?
(Yeah, and the DAZ-listening port is unusual, but security through obscurity in 2016? really?)

Comments
It will maybe updated when they release the next version od Studio
Which shouldn't be that far away...as the release candidate thread was recently posted.