Repository custom runner settings for Dependabot

As a repository administrator, you can now configure the runner type, optional custom label, and optional runner group for Dependabot version and security updates. This extends the runner configuration already available at the organization level, giving you more control over where each repository’s Dependabot jobs run.

Labeled runners can target both self-hosted and larger GitHub-hosted runners suited to your project’s needs, such as access to private package registries or specialized environments.

These repository-level settings are available for private and internal repositories on github.com. The controls are hidden for public repositories and on GitHub Enterprise Server.

To get started, open your repository settings and select Advanced Security. Under “Dependency scanning”, find “Dependabot version updates”, then edit Runner type. Choose Labeled runner, then optionally enter a custom label and runner group. If you do not specify a label, Dependabot uses the dependabot label. Alternatively, choose Standard GitHub runner to use the default GitHub-hosted environment.

Security configurations do not currently enforce Dependabot runner settings.

Check out the docs to learn more about using custom labels with self-hosted runners and managing Dependabot on self-hosted runners.

social
添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论