add a rule that does "npm update" and creates a merge request if the resulting package-lock.json is different.