docs.github.com New Configuration Options for Dependabot Runners on GitHub
Article Content
- •New runner settings for Dependabot enhance control for repository administrators.
- •Labeled runners can target both self-hosted and GitHub-hosted environments.
- •Security configurations for Dependabot runners are currently optional.
GitHub has introduced new settings for repository administrators to configure Dependabot runners, allowing for more control over where Dependabot jobs run. This feature is available for private and internal repositories, enabling the use of labeled runners that can target both self-hosted and GitHub-hosted environments. Administrators can specify a custom label and runner group, enhancing access to private package registries. The settings are not applicable to public repositories or GitHub Enterprise Server. The changes aim to improve security and flexibility in managing dependency updates. Security configurations currently do not enforce these runner settings, meaning they are optional. This update was announced in a blog post dated September 29, 2026, just before the documentation release on September 30, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…