Summary
Two related long-term maintenance gaps that let dependency drift (like the one fixed in #4) go unnoticed until manually audited.
1. MQTT stack is stale
paho-mqtt is pinned to 1.6.1 (released 2022) and Flask-MQTT to 1.2.1, which appears unmaintained. No known CVEs currently, but:
paho-mqtt has since released a 2.x line with a reworked API (breaking changes on upgrade).
Flask-MQTT hasn't seen a release in years and is a thin wrapper — worth evaluating whether it's still worth the dependency vs. using paho-mqtt directly.
Not urgent, but worth tracking as an EOL risk before it becomes a forced, breaking upgrade.
2. No automated dependency update tooling
There's no Dependabot or Renovate config in the repo, so pinned versions only get bumped when someone manually audits them (as happened here). This is how the issues in #4 accumulated unnoticed.
Suggested fix: add a .github/dependabot.yml covering the pip/uv ecosystem (and github-actions for the workflow action versions), so security patches surface as PRs automatically.
Summary
Two related long-term maintenance gaps that let dependency drift (like the one fixed in #4) go unnoticed until manually audited.
1. MQTT stack is stale
paho-mqttis pinned to1.6.1(released 2022) andFlask-MQTTto1.2.1, which appears unmaintained. No known CVEs currently, but:paho-mqtthas since released a 2.x line with a reworked API (breaking changes on upgrade).Flask-MQTThasn't seen a release in years and is a thin wrapper — worth evaluating whether it's still worth the dependency vs. usingpaho-mqttdirectly.Not urgent, but worth tracking as an EOL risk before it becomes a forced, breaking upgrade.
2. No automated dependency update tooling
There's no Dependabot or Renovate config in the repo, so pinned versions only get bumped when someone manually audits them (as happened here). This is how the issues in #4 accumulated unnoticed.
Suggested fix: add a
.github/dependabot.ymlcovering thepip/uvecosystem (andgithub-actionsfor the workflow action versions), so security patches surface as PRs automatically.