Dependabot has basic support for tracking and upgrading dependencies expressed using git submodules (https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#package-ecosystem). Consider setting it up for this repository to get notified whenever a dependency can be upgraded.
Note that we might need to wait for or contribute to dependabot/dependabot-core#1639 first, as currently dependabot will try to upgrade to the latest commit, not to the latest tag.