Use dependabot for Python
You can get Dependabot to help you with keeping your Python dependencies up to date, if it is based on pip
# Basic dependabot.yml file
# REF:
version: 2
# Enable version updates for pip (Python)
- package-ecosystem: "pip"
directory: "/"
interval: "weekly"
# Only allow updates to the lockfile for pip and
# ignore any version updates that affect the manifest
versioning-strategy: lockfile-only