Grub2 Debian Security Advisory

I checked the zfs-grub git repo, but I don't see any updates since the end of 2019.

Will the Proxmox team be updating the grub packages to address this advisory soon?

no plans right now since we don't support secure boot/lockdown anyway

If not, is it safe to replace with the upstream non-pve versions if we're not using zfs?

probably, as long as you keep os-prober disabled.