We specify major-only versions, e.g. `actions/checkout@v7`, which automatically uses the latest minor+patch of that release.
The documentation is super flaky tbh
I prefer TOML and JSON anyway...
Turns out those get new major releases somewhat often, and we get deprecation warnings and brownouts and all that. Automatic bumps should help us avoid that, though I've set a *very* large scan interval to shield us from churn.