Repository custom runner settings for Dependabot
GitHub allows repository administrators to configure Dependabot runner types, custom labels, and runner groups. This extends organization-level controls to specific repositories, enabling jobs to run on self-hosted or larger GitHub-hosted runners. The feature supports private and internal repositories on github.com, allowing access to private registries or specialized environments for dependency updates.

GitHub repository administrators can now set specific runner details for Dependabot updates. This includes selecting a runner type, adding a custom label, and defining a runner group. These options extend controls that previously existed only at the organization level. The feature allows jobs to target self-hosted machines or larger hosted instances. Administrators manage these settings through the Advanced Security section of their repository page. This update gives teams finer control over where dependency updates execute. Repositories can now access private package registries or specialized environments for security updates. The capability supports private and internal repositories on the main GitHub platform. It enables developers to match runner resources to their project's specific infrastructure needs. Security configurations do not currently enforce these Dependabot runner choices. The available controls are hidden from public repositories. They are also unavailable on GitHub Enterprise Server. If a custom label is missing, the system defaults to a specific tag. Standard GitHub runners remain an option for default environments. The source text does not specify how these settings interact with existing security scans beyond runner location.