megachangelog
Feature

Repository custom runner settings for Dependabot

Repository administrators can now configure the runner type, custom labels, and runner groups for Dependabot version and security updates, extending existing runner configuration capabilities.

As a repository administrator, you can now configure the runner type, optional custom label, and optional runner group for Dependabot version and security updates. This extends the runner configuration already available at the organization level, giving you more control over where each repository’s Dependabot jobs run.

Labeled runners can target both self-hosted and larger GitHub-hosted runners suited to your project’s needs, such as access to private package registries or specialized environments.

These repository-level settings are available for private and internal repositories on github.com. The controls are hidden for public repositories and on GitHub Enterprise Server.

To get started, open your repository settings and select Advanced Security. Under “Dependency scanning”, find “Dependabot version updates”, then edit Runner type. Choose Labeled runner, then optionally enter a custom label and runner group. If you do not specify a label, Dependabot uses the dependabot label. Alternatively, choose Standard GitHub runner to use the default GitHub-hosted environment.

Security configurations do not currently enforce Dependabot runner settings.

Check out the docs to learn more about using custom labels with self-hosted runners and managing Dependabot on self-hosted runners.

social

The post Repository custom runner settings for Dependabot appeared first on The GitHub Blog.

dependabotrunnersci-cdconfigurationsecurity-updates

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →