What about using github (maybe a private repository if you do not want it open source) and then adding dependabot?