I discovered since the aquisition you can also configure the automatic PRs for security updates directly in Github:

I believe it uses Dependabot still and can be a lower friction avenue for getting some of these benefits.

