GitHub added repository-level runner controls for Dependabot version and security updates. An administrator can choose the runner type and add a custom label or runner group. The change applies to private and internal repositories on GitHub.com. GitHub says the controls are hidden for public repositories and GitHub Enterprise Server.
The useful case is clear. A labeled runner can reach a private package registry or run in a specialized environment. The risk is clear too. The dependency updater now runs where that runner can reach. A routing label says where the job should land. It does not prove the runner exists, the group is accessible, the network path is narrow, or the next update succeeds.
There is a policy seam worth pinning to the dashboard. GitHub's changelog says security configurations do not currently enforce these Dependabot runner settings. The product documentation also says Dependabot jobs run on GitHub Actions when Dependabot is enabled, regardless of Actions policy checks or disablement at repository or organization level.