I've never tried, but it seems we can keep the actions we use in our workflow up to date with Dependabot. https://docs.github.com/en/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot