next-forge has Dependabot configured in .github/dependabot.yml to check for updates every month. When there are package updates, a pull request will be opened.

You may want to consider a dependency analysis tool like Socket to check for issues with dependencies in pull requests. We also recommend enabling GitHub Secret Scanning or a tool Gitleaks or Trufflehog to check for secrets in your code.