Do I need CSRF protection if I use bearer tokens?
Not if the token lives in memory and is sent in a header, because the browser will not attach it automatically. The moment it moves into a cookie for convenience, CSRF is back, and SameSite=Lax becomes load-bearing.
How often should a small project bump dependencies?
Monthly for a project with a test suite, immediately for anything with a published advisory. Batch the routine bumps into a single change so the diff is reviewable, and keep security updates separate so they can go out without waiting for a release.
Where should a local app keep an API key?
In the OS keychain, through the platform API rather than a file you encrypt yourself. Any scheme where the app can decrypt the key without user interaction is obfuscation, so the honest choice is the keychain, and telling the user plainly that anything on their disk is readable by anything running as them.
Any downside worth knowing before I commit?
It commits you to a format that is tedious to migrate away from later. The first weeks also look worse than doing nothing, which is when most people abandon it.