Deps should be updated when you need some features or bugfixes from the new versions; not just when DependaBot prompts you to do it.
I see value in DependaBot and things like that only to check that your module still passes your CI with upgraded dependencies (and if not, then it's worth looking at the failure, to be prepared for the updgrade in the future).