”As we’d like to provide some time for you to transition, we’re designating Celery 4.x an LTS release. Celery 4.x will be supported until the 1st of August, 2021.” [from the op]
An LTS version supported for less then a year from being designated as LTS?
However 7 breaks your pipeline.
What do you do? Fix the vulnerability yourself on an outdated version (high effort) Upgrade your entire pipeline to the new version (High effort) Leave the vulnerability in place (terrible idea)
That's honestly the only viable choice with such libraries if you want to deploy your software in production environments.
Thankfully, there are alternatives around and you're not forced to migrate every task at the same time
But that's a mitigation strategy, not a place you actually want to be. I would not consider selecting a dependency with the intent of doing things that way to be a sound policy, because infrequent big-bang updates like that have a tendency to be expensive and risky. There aren't a lot of development ethics that I find less palatable than "move fast and break things," but "move slow and break things" is definitely one of them.
There was a sequence of releases in 4.x that each had their own game-breaking bug for us, which has meant we have been stuck for a while (I've tried personally contributing fixes to this project, and fixed one bug, but another got introduced in the same release).
I would be happy about more granular releases, but I hope they could make more "bugfix-only" releases so I can make some forward progress on not having a busted task queue.