Prerequisites
- Dependabot is installed and enabled.
- GitHub Actions is enabled and in use.
Adding self-hosted runners for Dependabot updates
- Provision self-hosted runners, at the repository or organization level. For more information, see Self-hosted runners and Adding self-hosted runners.
- Configure your environment and runners to meet the requirements for Dependabot. See Requirements for using Dependabot with self-hosted runners.
- Assign the default
dependabotlabel or a custom label to each runner you want Dependabot to use. See Using labels with self-hosted runners. - Optionally, enable workflows triggered by Dependabot to use more than read-only permissions and to have access to any secrets that are normally available. For more information, see Troubleshooting Dependabot on GitHub Actions.
Configuring self-hosted runners for Dependabot updates
Warning
Before selecting Labeled runner, make sure a runner has the label you plan to use. If you specify a runner group, make sure the group exists and the repository can access it. See Dependabot on GitHub Actions runners.
Once you have configured self-hosted runners for Dependabot updates, you can select them at the organization or repository level.
Note
Changing the runner setting does not trigger a new Dependabot run.
For your private repository
-
On GitHub, navigate to the main page of the repository.
-
Under your repository name, click Settings. If you cannot see the "Settings" tab, select the dropdown menu, then click Settings.

-
In the "Security and quality" section of the sidebar, click Advanced Security.
-
Under "Dependency scanning", in the "Dependabot version updates" section, next to "Runner type", click .
-
From the "Runner type" dropdown menu, select Labeled runner.
-
Optionally, enter a runner group name and a custom runner label. If you do not enter a label, Dependabot uses the
dependabotlabel. -
Click Save runner selection.
Note
If you cannot change the runner setting, your organization may restrict actions and self-hosted runners for the repository. Contact your organization owner for more information.
For your organization
You can enable Dependabot on self-hosted runners for all existing private repositories in an organization. Only repositories already configured to run Dependabot on GitHub Actions will be updated to run Dependabot on self-hosted runners the next time a Dependabot job is triggered.
-
In the upper-right corner of GitHub, click your profile picture, then click Organizations.
-
Select an organization by clicking on it.
-
Under your organization name, click Settings. If you cannot see the "Settings" tab, select the dropdown menu, then click Settings.

-
In the "Security" section of the sidebar, click Advanced Security then Global settings.
-
In the "Dependabot" section, next to "Runner type", click .
-
Select the "Runner type" dropdown menu, then click Labeled runner and provide any additional information. If you applied a custom label to your self-hosted runners, type that label in the "Runner label" text box.
-
To enable the feature for all new repositories in the organization, click Save runner selection.