I gave Dependabot a go at work today. I really liked it. It splits up each dependency upgrade into an individual PR with vulnerability notes. It’s also a lot cheaper than most the comparable services.