Repository custom runner settings for Dependabot
By Steven Van ·
Repository admins on private and internal repos can pick a labeled or standard runner for Dependabot jobs, but public repos and Enterprise Server are excluded.
Repository administrators can now set the runner type, an optional custom label and an optional runner group for Dependabot version and security updates. This extends the runner configuration GitHub already offers at the organization level, so each repository can choose where its own Dependabot jobs run.
Labeled runners can target both self-hosted and larger GitHub-hosted runners, for projects that need access to private package registries or specialized environments. The settings are available for private and internal repositories on github.com. They are hidden for public repositories and on GitHub Enterprise Server.
To set it up, open the repository settings and select Advanced Security. Under "Dependency scanning", find "Dependabot version updates" and edit Runner type. Choose Labeled runner, then optionally enter a custom label and runner group. If no label is given, Dependabot uses the dependabot label. Standard GitHub runner keeps the default GitHub-hosted environment.
Security configurations do not currently enforce Dependabot runner settings. Labels are covered in the GitHub Docs page on using labels with self-hosted runners.
