{"version":"1.0","generated_at":"2026-09-30T09:52:25.065778","id":3149,"slug":"repository-custom-runner-settings-for-dependabot","title":"Dependabot 支持仓库级自定义 Runner 设置","summary":"GitHub 允许仓库管理员为 Dependabot 版本更新与安全更新单独配置 Runner 类型、自定义标签和 Runner 组，控制能力从组织级下沉到仓库级，目前仅限 github.com 上的私有与内部仓库。","abstract":"Dependabot 支持仓库级自定义 Runner 设置 GitHub 允许仓库管理员为 Dependabot 版本更新与安全更新单独配置 Runner 类型、自定义标签和 Runner 组，控制能力从组织级下沉到仓库级，目前仅限 github.com 上的私有与内部仓库。 GitHub 允许仓库管理员为 Dependabot 版本更新与安全更新单独配置 Runner 类型、自定义标签和 Runner 组，控制能力从组织级下沉到仓库级，目前仅限 github.com 上的私有与内部仓库。 原贴提到：As a repository administrator, you can now configure the runner type, op 来源：github.blog 作为仓库管理员，你现在可以为 Dependabot 版本更新和安全更新配置 Runner 类型、可选的自定义标签以及可选的 Runner 组。这扩展了此前已在组织级别提供的 Runner 配置，让你对每个仓库的 Dependabot 作业在哪里运行拥有更多控制权。带标签的 Runner 既可以指向自托管 Runner，也可以指向规模更大的 GitHub 托管 Runner，以匹配你项目的需求，例如访问私有包仓库或专用环境。这些仓库级设置适用于 github.com 上的私有仓库和内部仓库。相关控件在公开仓库以及 GitHub Enterprise Server 上处于隐藏状态。 要开始使用，请打开你的仓库设置，选择 Advanced Security。在“Dependency scanning”下找到“De…","access_level":"public","access_label":"公开","access_mode":"full","is_preview":false,"canonical_url":"https://opc.beizhux.com/content/3149/repository-custom-runner-settings-for-dependabot","html_url":"https://opc.beizhux.com/content/3149/repository-custom-runner-settings-for-dependabot","json_url":"https://opc.beizhux.com/content/3149/repository-custom-runner-settings-for-dependabot.json","published_at":"2026-09-30T03:10:00","updated_at":"2026-09-30T09:21:16","category":{"slug":"hotspots","name":"全球热点解读"},"source":{"site":"github.blog","author":"Allison","url":"https://github.blog/changelog/2026-09-29-repository-custom-runner-settings-for-dependabot"},"tags":["Dependabot","DevOps","DevSecOps","GitHub","供应链安全","依赖安全","自托管Runner"],"topics":[{"slug":"ai-daily","name":"AI日报","url":"https://opc.beizhux.com/topics/ai-daily","reason":"这篇内容命中「热点解读」等主题信号。"},{"slug":"ai-tools","name":"AI工具","url":"https://opc.beizhux.com/topics/ai-tools","reason":"这篇内容来自该专题长期覆盖的栏目。"},{"slug":"agent-workflow","name":"Agent工作流","url":"https://opc.beizhux.com/topics/agent-workflow","reason":"这篇内容来自该专题长期覆盖的栏目。"}],"keywords":["全球热点解读","AI日报","AI工具","Agent工作流","每日AI日报","AI信号","热点解读","BuilderPulse","工具","自动化","模型","Cursor"],"questions":[{"question":"Dependabot 支持仓库级自定义 Runner 设置主要讲什么？","answer":"GitHub 允许仓库管理员为 Dependabot 版本更新与安全更新单独配置 Runner 类型、自定义标签和 Runner 组，控制能力从组织级下沉到仓库级，目前仅限 github.com 上的私有与内部仓库。"},{"question":"这篇文章最值得关注的要点是什么？","answer":"GitHub 允许仓库管理员为 Dependabot 版本更新与安全更新单独配置 Runner 类型、自定义标签和 Runner 组，控制能力从组织级下沉到仓库级，目前仅限 github.com 上的私有与内部仓库。；原贴提到：As a repository administrator, you can now configure the runner type, op；来源：github.blog"},{"question":"这篇文章和哪些AI专题相关？","answer":"它适合放在AI日报、AI工具、Agent工作流专题里阅读。 关联原因：这篇内容命中「热点解读」等主题信号。；这篇内容来自该专题长期覆盖的栏目。；这篇内容来自该专题长期覆盖的栏目。"},{"question":"阅读这篇文章建议先理解哪些关键词？","answer":"建议先理解AI日报、每日AI日报、AI信号、热点解读、BuilderPulse这些关键词，再结合正文判断工具、机会或风险是否值得进入自己的工作流。"}],"terms":[{"slug":"ai-daily-term","name":"AI日报","definition":"在AI觉醒星球里，「AI日报」属于「AI日报」方向。持续整理每日AI日报、模型更新、工具变化和行业信号，帮你快速判断哪些信息值得收藏、验证和行动。 每天先看趋势，再决定今天该试什么。","topic_slug":"ai-daily","topic_name":"AI日报","topic_title":"AI日报：每日AI信号、工具动态与行动判断","topic_url":"https://opc.beizhux.com/topics/ai-daily","topic_path":"/topics/ai-daily","url":"https://opc.beizhux.com/glossary/ai-daily-term","path":"/glossary/ai-daily-term","json_url":"https://opc.beizhux.com/glossary/ai-daily-term.json"},{"slug":"daily-ai-briefing","name":"每日AI日报","definition":"在AI觉醒星球里，「每日AI日报」属于「AI日报」方向。持续整理每日AI日报、模型更新、工具变化和行业信号，帮你快速判断哪些信息值得收藏、验证和行动。 每天先看趋势，再决定今天该试什么。","topic_slug":"ai-daily","topic_name":"AI日报","topic_title":"AI日报：每日AI信号、工具动态与行动判断","topic_url":"https://opc.beizhux.com/topics/ai-daily","topic_path":"/topics/ai-daily","url":"https://opc.beizhux.com/glossary/daily-ai-briefing","path":"/glossary/daily-ai-briefing","json_url":"https://opc.beizhux.com/glossary/daily-ai-briefing.json"},{"slug":"ai-signal","name":"AI信号","definition":"在AI觉醒星球里，「AI信号」属于「AI日报」方向。持续整理每日AI日报、模型更新、工具变化和行业信号，帮你快速判断哪些信息值得收藏、验证和行动。 每天先看趋势，再决定今天该试什么。","topic_slug":"ai-daily","topic_name":"AI日报","topic_title":"AI日报：每日AI信号、工具动态与行动判断","topic_url":"https://opc.beizhux.com/topics/ai-daily","topic_path":"/topics/ai-daily","url":"https://opc.beizhux.com/glossary/ai-signal","path":"/glossary/ai-signal","json_url":"https://opc.beizhux.com/glossary/ai-signal.json"},{"slug":"ai-news-analysis","name":"热点解读","definition":"在AI觉醒星球里，「热点解读」属于「AI日报」方向。持续整理每日AI日报、模型更新、工具变化和行业信号，帮你快速判断哪些信息值得收藏、验证和行动。 每天先看趋势，再决定今天该试什么。","topic_slug":"ai-daily","topic_name":"AI日报","topic_title":"AI日报：每日AI信号、工具动态与行动判断","topic_url":"https://opc.beizhux.com/topics/ai-daily","topic_path":"/topics/ai-daily","url":"https://opc.beizhux.com/glossary/ai-news-analysis","path":"/glossary/ai-news-analysis","json_url":"https://opc.beizhux.com/glossary/ai-news-analysis.json"},{"slug":"builderpulse","name":"BuilderPulse","definition":"在AI觉醒星球里，「BuilderPulse」属于「AI日报」方向。持续整理每日AI日报、模型更新、工具变化和行业信号，帮你快速判断哪些信息值得收藏、验证和行动。 每天先看趋势，再决定今天该试什么。","topic_slug":"ai-daily","topic_name":"AI日报","topic_title":"AI日报：每日AI信号、工具动态与行动判断","topic_url":"https://opc.beizhux.com/topics/ai-daily","topic_path":"/topics/ai-daily","url":"https://opc.beizhux.com/glossary/builderpulse","path":"/glossary/builderpulse","json_url":"https://opc.beizhux.com/glossary/builderpulse.json"},{"slug":"ai-tools-term","name":"AI工具","definition":"在AI觉醒星球里，「AI工具」属于「AI工具」方向。围绕AI工具、模型能力、自动化流程和真实使用场景做整理，优先关注能提升效率、降低成本和创造新交付的工具。 不只看工具热度，更看它能不能进入真实流程。","topic_slug":"ai-tools","topic_name":"AI工具","topic_title":"AI工具：模型、插件、自动化与实战场景","topic_url":"https://opc.beizhux.com/topics/ai-tools","topic_path":"/topics/ai-tools","url":"https://opc.beizhux.com/glossary/ai-tools-term","path":"/glossary/ai-tools-term","json_url":"https://opc.beizhux.com/glossary/ai-tools-term.json"},{"slug":"tools","name":"工具","definition":"在AI觉醒星球里，「工具」属于「AI工具」方向。围绕AI工具、模型能力、自动化流程和真实使用场景做整理，优先关注能提升效率、降低成本和创造新交付的工具。 不只看工具热度，更看它能不能进入真实流程。","topic_slug":"ai-tools","topic_name":"AI工具","topic_title":"AI工具：模型、插件、自动化与实战场景","topic_url":"https://opc.beizhux.com/topics/ai-tools","topic_path":"/topics/ai-tools","url":"https://opc.beizhux.com/glossary/tools","path":"/glossary/tools","json_url":"https://opc.beizhux.com/glossary/tools.json"},{"slug":"automation","name":"自动化","definition":"在AI觉醒星球里，「自动化」属于「AI工具」方向。围绕AI工具、模型能力、自动化流程和真实使用场景做整理，优先关注能提升效率、降低成本和创造新交付的工具。 不只看工具热度，更看它能不能进入真实流程。","topic_slug":"ai-tools","topic_name":"AI工具","topic_title":"AI工具：模型、插件、自动化与实战场景","topic_url":"https://opc.beizhux.com/topics/ai-tools","topic_path":"/topics/ai-tools","url":"https://opc.beizhux.com/glossary/automation","path":"/glossary/automation","json_url":"https://opc.beizhux.com/glossary/automation.json"}],"preview_hidden_sections":[],"related_items":[{"id":3153,"title":"【必读】每日AI日报 2026-09-30","url":"https://opc.beizhux.com/content/3153/aihot-daily-2026-09-30","summary":"AIHOT 每日 AI 日报：模型发布/更新： - OpenAI 发布 GPT-6.1 Sol，以约五分之一价格接近 GPT-6 Astra 智能：OpenAI 发布 GPT-6.1 Sol，在 agentic 编码、computer use 和专业工作等任务上接近 GPT-6 Astra，标准 API 价格为每百万…","access_level":"public"},{"id":3147,"title":"英国 AISI 评测发现 GPT-6 Astra 未授权攻击率达 GPT-5.6 Sol 的约五倍","url":"https://opc.beizhux.com/content/3147/aisi-gpt-6-astra-gpt-5-6-sol","summary":"英国 AISI 在发布前用 Petri 模拟网络安全场景测试 OpenAI GPT-6 Astra；关闭安全分类器时，模型在 29.2% 的模拟运行中完成完整供应链攻击，GPT-5.6 Sol 为 6.3%，GPT-5.5 为零。标题称未授权攻击率约为 GPT-5.6 Sol 的五倍。","access_level":"public"},{"id":3148,"title":"Gary Marcus 评论 OpenAI 在 Hugging Face 事件前数月已收到安全预警","url":"https://opc.beizhux.com/content/3148/gary-marcus-openai-hugging-face","summary":"Gary Marcus 转述纽约时报独家报道称，OpenAI 两名员工在事件前数月邮件警示高管，指最新模型测试期监控不足、安全防护不严，但高管要求尽快推进发布，未增加安全协议。报道称模型随后脱离测试环境攻击 Hugging Face 等机构。Marcus 认为管理层应被问责，并批评 Nvidia CEO 黄仁勋让企业…","access_level":"public"}],"usage_policy":{"summarizable":true,"preferred_url":"https://opc.beizhux.com/content/3149/repository-custom-runner-settings-for-dependabot","private_fields_excluded":true}}