DependaBot is a useful tool to regularly check for dependency updates. By helping to keep your project up to date, DependaBot can reduce technical debt and immediately apply security vulnerabilities when patches are released. How does DependaBot work? * DependaBot regularly checks dependencies for updates * If an update is found, DependaBot creates a new branch with this upgrade and Pull Request for approval * You review the new Pull Request, ensure the tests passed, review the code, and decide if you can merge the change Reference: https://samlearnsazure.blog/2019/12/20/github-using-dependabot/