<!-- Thanks for making a bug report or feature request! Please note, repo-review is a framework for running checks. If you have an issue with a particular check, please open the issue with the plugin that provides the check. The repo-review demo uses the sp-repo-review plugin, which lives at http://github.com/scientific-python/cookie, for example. --> I think it should be viable to have Renovate or dependabot to manage updates. If you aren't aware it's a highly configurable dependency manager https://docs.renovatebot.com.