Dependabot runner choice moves down to the repository level
GitHub has made Dependabot's runner configuration available per repository. Until now it could be set at the organization level; from 29 September a repository administrator can choose the runner type, an optional custom label and an optional runner group for Dependabot version and security updates.
A labeled runner can be self-hosted or one of GitHub's larger hosted runners. The changelog names the typical reasons: access to private package registries or other specialized environments that a standard hosted runner cannot reach. If no label is given, Dependabot uses the dependabot label; choosing Standard GitHub runner keeps the default hosted environment.
The setting lives under the repository's Advanced Security settings, in Dependency scanning, where "Dependabot version updates" now has a Runner type option. It applies to private and internal repositories on github.com. The controls are hidden for public repositories and are not available on GitHub Enterprise Server. GitHub also notes that security configurations do not yet enforce Dependabot runner settings, so an organization cannot currently mandate one runner choice through them.

Why it matters
Dependabot updates fail quietly when the job cannot reach the registry that hosts a private dependency, and the usual fix was to give the whole organization the same runner setup. Per-repository control lets a team route only the repositories that need it to a runner inside its network, without changing everyone else's, at the cost of one more setting that security configurations do not police yet.