Skip to content

Stale MQTT stack (paho-mqtt/Flask-MQTT) and no automated dependency updates #7

Description

@Friedjof

Summary

Two related long-term maintenance gaps that let dependency drift (like the one fixed in #4) go unnoticed until manually audited.

1. MQTT stack is stale

paho-mqtt is pinned to 1.6.1 (released 2022) and Flask-MQTT to 1.2.1, which appears unmaintained. No known CVEs currently, but:

  • paho-mqtt has since released a 2.x line with a reworked API (breaking changes on upgrade).
  • Flask-MQTT hasn't seen a release in years and is a thin wrapper — worth evaluating whether it's still worth the dependency vs. using paho-mqtt directly.

Not urgent, but worth tracking as an EOL risk before it becomes a forced, breaking upgrade.

2. No automated dependency update tooling

There's no Dependabot or Renovate config in the repo, so pinned versions only get bumped when someone manually audits them (as happened here). This is how the issues in #4 accumulated unnoticed.

Suggested fix: add a .github/dependabot.yml covering the pip/uv ecosystem (and github-actions for the workflow action versions), so security patches surface as PRs automatically.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions