You can configure self-hosted runners that Dependabot uses to access your private registries and internal network resources.
Who can use this feature?
Organization owners and repository administrators
Dependabot is installed and enabled.
GitHub Actions is enabled and in use.
Adding self-hosted runners for Dependabot updates
Provision self-hosted runners, at the repository or organization level. For more information, see Self-hosted runners and Adding self-hosted runners .
Configure your environment and runners to meet the requirements for Dependabot. See Requirements for using Dependabot with self-hosted runners .
Assign the default dependabot label or a custom label to each runner you want Dependabot to use. See Using labels with self-hosted runners .
Optionally, enable workflows triggered by Dependabot to use more than read-only permissions and to have access to any secrets that are normally available. For more information, see Troubleshooting Dependabot on GitHub Actions .
Configuring self-hosted runners for Dependabot updates
Before selecting Labeled runner , make sure a runner has the label you plan to use. If you specify a runner group, make sure the group exists and the repository can access it. See Dependabot on GitHub Actions runners .
Once you have configured self-hosted runners for Dependabot updates, you can select them at the organization or repository level.
Changing the runner setting does not trigger a new Dependabot run.
For your private repository
On GitHub, navigate to the main page of the repository.
On GitHub, navigate to the main page of the repository.
Under your repository name, click Settings . If you cannot see the "Settings" tab, select the dropdown , then click Settings .
Under your repository name, click Settings . If you cannot see the "Settings" tab, select the dropdown , then click Settings .
In the "Security and quality" section of the sidebar, click Advanced Security .
In the "Security and quality" section of the sidebar, click Advanced Security .
Under "Dependency scanning", in the "Dependabot version updates" section, to "Runner type", click .
Under "Dependency scanning", in the "Dependabot version updates" section, to "Runner type", click .
From the "Runner type" dropdown , select Labeled runner .
From the "Runner type" dropdown , select Labeled runner .
Optionally, enter a runner group name and a custom runner label. If you do not enter a label, Dependabot uses the dependabot label.
Optionally, enter a runner group name and a custom runner label. If you do not enter a label, Dependabot uses the dependabot label.
Click Save runner selection . Note If you cannot change the runner setting, your organization may restrict actions and self-hosted runners for the repository. your organization owner for more information.
Click Save runner selection .
If you cannot change the runner setting, your organization may restrict actions and self-hosted runners for the repository. your organization owner for more information.
For your organization
You can enable Dependabot on self-hosted runners for all existing private repositories in an organization. Only repositories already configured to run Dependabot on GitHub Actions will be updated to run Dependabot on self-hosted runners the time a Dependabot job is triggered.
In the upper-right corner of GitHub, click your profile picture, then click Organizations .
In the upper-right corner of GitHub, click your profile picture, then click Organizations .
Select an organization by clicking on it.
Select an organization by clicking on it.
Under your organization name, click Settings . If you cannot see the "Settings" tab, select the dropdown , then click Settings .
Under your organization name, click Settings . If you cannot see the "Settings" tab, select the dropdown , then click Settings .
In the "Security" section of the sidebar, click Advanced Security then Global settings .
In the "Security" section of the sidebar, click Advanced Security then Global settings .
In the "Dependabot" section, to "Runner type", click .
In the "Dependabot" section, to "Runner type", click .
Select the "Runner type" dropdown , then click Labeled runner and provide any additional information. If you applied a custom label to your self-hosted runners, type that label in the "Runner label" text box.
Select the "Runner type" dropdown , then click Labeled runner and provide any additional information. If you applied a custom label to your self-hosted runners, type that label in the "Runner label" text box.
To enable the feature for all new repositories in the organization, click Save runner selection .
To enable the feature for all new repositories in the organization, click Save runner selection .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
