See comment by @jenshnielsen here: #40 (comment)
We should set up dependabot to keep the requirements that we perform most of the actual ci testing against (in requirements.txt) up to date and automatically open new pull requests when a new package is released. See also the Qcodes repo for how this is set up.