github GitHub Changelog ·

GitHub adds custom runner settings for Dependabot at repository level

securitygaengineer
feature

Repository administrators can now configure custom runner types, labels, and groups for Dependabot version and security updates. This enhancement extends existing organization-level controls, providing greater flexibility for individual repository needs, such as access to private package registries or specialized environments. These settings are available for private and internal repositories on github.com, accessible via the repository's Advanced Security settings. Security configurations do not currently enforce Dependabot runner settings.

Features (1) ›
  • Configure custom runners for Dependabot in repositories

    Repository administrators can now specify the runner type, optional custom label, and runner group for Dependabot updates. This granular control, available for private and internal repositories, allows projects to use self-hosted or larger GitHub-hosted runners tailored to their specific requirements.

Read the original announcement →

https://github.blog/changelog/2026-09-29-repository-custom-runner-settings-for-dependabot

Related releases