The solution at my workplace is a bot that opens PRs to bump dependencies and automatically merges if the tests pass.
It's taken a lot of workload off devs to meet security targets. But I worry it makes supply-chain attacks more attractive. If an attacker can compromise a package and it's instantly merged into the codebases of thousands of different companies that's a huge danger.