1) Do not update dependencies (because updating to the latest version just because is silly) 2) Update dependencies (because security)
Personally, I fall into the second group (with caveats). I've found that Dependabot helps with the tedious work of updating versions by hand but at the same time provides a check so that I manually approve. This seems to work out to be a decent balance. I've also moved away from using :latest or @v2 etc. and switched to using commit hashes/image digests. Once again, Dependabot is helpful for tracking changes/updates once you switch over.
The one annoying thing is that Dependabot does not always trigger on a regular basis (once a day) but I've found that bumping .github/dependabot.yml reliably triggers it.