https://github.blog/news-insights/product-news/keep-all-your...
They are tools that automatically check your repo for dependencies and create PRs when there are updates. It supports a wide range of package managers and other places dependencies may be specified.
Dependabot is another solution which is more „GitHub-native“ maybe.
(a blog post I wrote, prior to joining Mend and working as a Renovate maintainer)