Document how the switch to Jackson 3 is a breaking change. For example, users with custom Security classes that are mapped with Jackson 2 may need to update to Jackson 3. We should also document how users can explicitly choose to use Spring Security with Jackson 2 for classes like JdbcOAuth2AuthorizationService