Dependabot watches a repository's manifests and opens pull requests when a dependency is outdated or has a published advisory. Being built into GitHub is the point: the update arrives as a reviewable PR with a changelog and the CI result attached, rather than as a task nobody schedules.
The control it provides is time to patch, which is what an auditor asks about for OWASP A06 — not whether you scan, but how long a known vulnerable version stays in production.