Renovate makes it easier to keep the dependencies up-to-date, as it automatically creates PRs when there are new packages available.
The easiest step is to enable the GitHub App, but it likely requires configuration on Zuehlke org-level.
Just make sure to configure some cooldown for dependencies to counter the on going NPM package hijacking.