Yes, looks like October 2019 is the end: https://support.google.com/nexus/answer/4457705?hl=en#pixel_...

What should he do if he finds out about a vulnerability then? Does he need a new phone?

Yes, but not necessarily Oct 2019. My Nexus 5X is running Android 8.1.0 with security patch level: December 5, 2018, so it's likely Pixel will also get updates after the guaranteed dates.

He needs to weigh the risk versus the cost of a new phone.

There is a custom firmware card LineageOS but it's a community effort. It may get up to date security updates merged in but it could be vulnerable in other ways.

