Dependabot is something like a modern plague of open source, together with the bot that closes issues automatically.
Did you read through the security issues identified, familiar with the codebase enough that you can see that these issues are actually affecting the product?
Most issues Dependabot opens on repositories I'm involved in, points to issues that has no bearing on the actual code, since it's security issues that are involving passing user code to specific functions, or simply regarding APIs that are never used in the first place.
You don't have to be on the newest version of every single library, in most cases it doesn't make any sense to just upgrade for the sake of upgrade.