Dependabot
Automated dependency updates, built into GitHub.
Watches your manifests, opens pull requests for outdated or vulnerable packages, and can be configured to group them. Free, on by default for security alerts, and the lowest-effort maintenance win available.
Best for
Keeping a project patched with zero ongoing effort.
Watch out for
Without tests, auto-merging updates is how a working app quietly breaks.
Using this and stuck anyway?
Knowing the tool isn't the same as finishing the project. If yours has stopped moving, we'll take a look at it.
Tell us what's broken