Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
28 commits
Select commit Hold shift + click to select a range
b228c11
Clarify GHES organization membership 2FA requirements for UI and API …
Copilot Sep 29, 2026
5df4e11
External custom properties public preview (#63531)
isaacmbrown Sep 29, 2026
30e9daf
Fix Next.js cache restore-keys prefix (#63477)
heiskr Sep 29, 2026
e25cc2f
Tighten code comments in src/workflows/tests (#63447)
heiskr Sep 29, 2026
cf102cd
Narrow moda-ci workflow permissions (#63508)
heiskr Sep 29, 2026
524ed7a
Make analyze-text honor --not-language (#63480)
heiskr Sep 29, 2026
ad4064a
Clarify REST API rate limit status guidance (#63588)
gregbrunk Sep 29, 2026
a624e62
Fix survey language test heading selector (#63509)
heiskr Sep 29, 2026
b5f9b81
Clarify autocomplete fuzzy test coverage (#63507)
heiskr Sep 29, 2026
a9e2ff1
Exclude hidden products from search scraping (#63481)
heiskr Sep 29, 2026
a81d4a1
Block invalid Next data prefix lookalikes (#63505)
heiskr Sep 29, 2026
9703f5f
Bump the npm_and_yarn group across 1 directory with 1 update (#63594)
dependabot[bot] Sep 29, 2026
4d328ee
Transition to primer/brand components on discovery pages (#63558)
V-halfaro Sep 29, 2026
70d210f
Remove unused dotcom path script (#63501)
heiskr Sep 29, 2026
771cb11
Make the enterprise-cloud search filter test prove filtering (#63482)
heiskr Sep 29, 2026
6411bfc
Fix false layout handling (#63500)
heiskr Sep 29, 2026
0e48ff3
Fix top-level oneOf required body params (#63510)
heiskr Sep 29, 2026
bc67798
Remove dead REST auth version guard (#63502)
heiskr Sep 29, 2026
39cdf46
Remove unreachable URL decode fallback (#63478)
heiskr Sep 29, 2026
2406e0d
Unskip invalid path server test (#63506)
heiskr Sep 29, 2026
bde6fb5
Remove dead GHES release notes fallback (#63503)
heiskr Sep 29, 2026
2d325fc
Remove translation .git directories from the Docker image (#63491)
heiskr Sep 29, 2026
55b5291
Fix pages content validation tests (#63513)
heiskr Sep 29, 2026
ca47eaa
Unskip sidebar custom link aria-current test (#63479)
heiskr Sep 29, 2026
e9bd383
Document repository-level Dependabot runner settings (#63563)
v-kbukum1 Sep 29, 2026
6cc6985
Tighten code comments in src/rest/scripts (#63456)
heiskr Sep 29, 2026
f1d0f90
Fix generic TOC faux subcategory detection (#63484)
heiskr Sep 29, 2026
f187b6c
Sync secret scanning data (#63600)
docs-bot Sep 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/actions/cache-nextjs/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,4 +15,4 @@ runs:
key: ${{ runner.os }}-nextjs-${{ hashFiles('**/package-lock.json') }}-${{ hashFiles('**/*.ts', '**/*.tsx') }}
# If source files changed but packages didn't, rebuild from a prior cache.
restore-keys: |
${{ runner.os }}-nextjs-v13-${{ hashFiles('**/package-lock.json') }}-
${{ runner.os }}-nextjs-${{ hashFiles('**/package-lock.json') }}-
39 changes: 28 additions & 11 deletions .github/workflows/moda-ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,25 +11,30 @@ on:
merge_group:
types: [checks_requested]

permissions: {}

jobs:
##########################
# Generate Vault keys
##########################
set-vault-keys:
permissions: {}
runs-on: ubuntu-latest
outputs:
modified_vault_keys: ${{ steps.modify_vault_keys.outputs.modified }}
steps:
- name: Set vault-keys output
id: modify_vault_keys
env:
VAULT_KEYS: ${{ vars.VAULT_KEYS }}
run: |
if [ -z "${{ vars.VAULT_KEYS }}" ]; then
if [ -z "$VAULT_KEYS" ]; then
# We want to add the DOCS_BOT_PAT_BASE to the list of keys
# so that builds fetch the secret from the docs-internal vault
# where --environment is "ci"
echo "modified=DOCS_BOT_PAT_BASE" >> $GITHUB_OUTPUT
echo "modified=DOCS_BOT_PAT_BASE" >> "$GITHUB_OUTPUT"
else
echo "modified=${{ vars.VAULT_KEYS }},DOCS_BOT_PAT_BASE" >> $GITHUB_OUTPUT
echo "modified=${VAULT_KEYS},DOCS_BOT_PAT_BASE" >> "$GITHUB_OUTPUT"
fi

#############
Expand All @@ -39,6 +44,13 @@ jobs:
if: ${{ github.repository == 'github/docs-internal' }}
name: ${{ matrix.ci_job.job }}
needs: set-vault-keys
permissions:
actions: read
attestations: write
checks: read
contents: read
id-token: write
statuses: read
strategy:
fail-fast: false
matrix:
Expand All @@ -58,6 +70,13 @@ jobs:
if: ${{ github.repository == 'github/docs-internal' }}
name: ${{ matrix.ci_job.job }}
needs: set-vault-keys
permissions:
actions: read
attestations: write
checks: read
contents: read
id-token: write
statuses: read
strategy:
fail-fast: false
matrix:
Expand All @@ -80,6 +99,12 @@ jobs:
if: ${{ github.repository == 'github/docs-internal' }}
name: ${{ matrix.ci_job.job }}
needs: set-vault-keys
permissions:
actions: read
checks: read
contents: read
id-token: write
statuses: read
strategy:
fail-fast: false
matrix:
Expand All @@ -93,11 +118,3 @@ jobs:
secrets:
dx-bot-token: ${{ secrets.INTERNAL_ACTIONS_DX_BOT_ACCOUNT_TOKEN }}
datadog-api-key: ${{ secrets.DATADOG_API_KEY }}

permissions:
actions: read
checks: read
contents: read
statuses: read
id-token: write
attestations: write
7 changes: 0 additions & 7 deletions .github/zizmor.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,13 +4,6 @@ rules:
dangerous-triggers:
disable: true

# moda-ci uses reusable workflows (uses:) which don't support job-level
# permissions. id-token:write and attestations:write are needed by docker-image
# for attestation but can't be scoped to that job alone.
excessive-permissions:
ignore:
- moda-ci.yaml

# actions/* has immutable tags, so ref-pinning is sufficient.
# github/internal-actions is a private GitHub org repo, ref-pin is fine.
# Everything else must be hash-pinned.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
---
title: Custom properties
intro: 'Custom properties allow you to add structured metadata to repositories and organizations, enabling better organization, governance, and automation across your {% data variables.product.github %} environment.'
permissions: 'Repository custom properties can be managed by organization owners and users with admin permissions to the repository. Organization custom properties can be managed by enterprise owners and users with the "Manage the Enterprise''s custom properties definitions" permission.'
versions:
ghec: '*'
ghes: '>= 3.21'
Expand All @@ -15,15 +14,11 @@ category:

Custom properties are structured metadata fields that you can attach to repositories or organizations in {% data variables.location.product_location %}. They allow you to decorate your repositories or organizations with information such as compliance frameworks, data sensitivity, or project details.

An enterprise can have up to 100 property definitions. An allowed value list can have up to 200 items.

There are two types of custom properties:

* **Repository custom properties**: Metadata attached to individual repositories.
* **Organization custom properties**: Metadata attached to organizations within an enterprise.

{% data reusables.enterprise-accounts.org-custom-properties-public-preview %}

## What are the benefits of using custom properties?

As well as providing improved discovery, automated workflows, compliance tracking, targeted policy enforcement, and better reporting capabilities, custom properties enable powerful governance through **ruleset integration**.
Expand All @@ -35,10 +30,20 @@ Both repository and organization custom properties can be used as targeting crit

## How do I add and manage custom properties?

{% ifversion ghec %}
There are multiple ways to manage custom properties. To manage properties within {% data variables.product.github %}, you can use:

Custom properties are fully supported through {% data variables.product.github %}'s REST API, enabling programmatic management and integration with external systems. See [AUTOTITLE](/rest/enterprise-admin/custom-properties).
* Your organization or enterprise settings. See [AUTOTITLE](/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization) and [AUTOTITLE](/admin/managing-accounts-and-repositories/managing-organizations-in-your-enterprise/managing-custom-properties-for-organizations).
* {% data variables.product.github %}'s [AUTOTITLE](/rest/enterprise-admin/custom-properties).

{% endif %}
{% ifversion external-custom-properties %}

You can also set up an integration to automatically update custom properties with metadata from an external system, such as a software catalog or internal developer portal. External properties can be used in the same places as standard repository custom properties. See [AUTOTITLE](/organizations/managing-organization-settings/sync-external-custom-properties)

You can add custom properties through {% data variables.product.github %}'s UI. See [AUTOTITLE](/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization) and [AUTOTITLE](/admin/managing-accounts-and-repositories/managing-organizations-in-your-enterprise/managing-custom-properties-for-organizations).
Both standard custom properties and external properties can be managed at scale with the REST API and {% data variables.product.prodname_github_apps %}. External properties are more suitable when the external system should be the source of truth, because they are:

* Namespaced (`external_system.property_name`), so their provenance is clear and they don't conflict with other custom properties in the organization.
* Read-only on {% data variables.product.github %}, so users cannot edit them and bring them out of line with the external system.

External properties are **not** available for organization custom properties (metadata attached to organizations).

{% endif %}
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,19 @@ When you create a single-select or multi-select property, {% data variables.prod
This feature is available with {% data variables.copilot.copilot_business_short %} or {% data variables.copilot.copilot_enterprise_short %}. By default, suggestions are enabled for enterprise-level properties and each organization can decide whether to enable suggestions. Enterprise owners can instead enable or disable suggestions everywhere with the **Repository custom property suggestions** policy. See [AUTOTITLE](/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-enterprise-policies).
{% endif %}

## Adding custom properties
{% ifversion external-custom-properties %}

## Syncing custom properties with an external system

> [!NOTE] {% data reusables.organizations.external-properties-preview %}
{% data reusables.organizations.external-properties-intro %}

External custom properties are configured separately for each organization. For setup instructions, see [AUTOTITLE](/organizations/managing-organization-settings/sync-external-custom-properties).

{% endif %}

## Adding custom properties on {% data variables.product.github %}

You can add custom properties to your enterprise to make those properties available in all of your organizations.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -39,14 +39,28 @@ You may see workflow runs named `dynamic/dependabot/dependabot-updates` or check
You can run {% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} using:
* **Standard {% data variables.product.prodname_dotcom %}-hosted runners.** These are the default runners used by {% data variables.product.github %} to execute {% data variables.product.prodname_actions %} jobs.
* **{% data variables.actions.hosted_runners_caps %}.** These are {% data variables.product.prodname_dotcom %}-hosted runners with advanced features like more RAM, CPU, and disk space. For more information, see [AUTOTITLE](/actions/how-tos/manage-runners/larger-runners).
* **Self-hosted runners.** These runners grant you greater control over {% data variables.product.prodname_dependabot %} access to your private registries and internal network resources. Be aware that for security reasons, {% data variables.product.prodname_dependabot_updates %} on self-hosted runners will not run on public repositories. For more information on assigning a `dependabot` label on self-hosted runners, see [AUTOTITLE](/code-security/how-tos/secure-your-supply-chain/manage-your-dependency-security/configure-on-self-hosted-runners).
* **Self-hosted runners.** These runners grant you greater control over {% data variables.product.prodname_dependabot %} access to your private registries and internal network resources. Be aware that for security reasons, {% data variables.product.prodname_dependabot_updates %} on self-hosted runners will not run on public repositories. For more information on assigning labels to self-hosted runners, see [AUTOTITLE](/code-security/how-tos/secure-your-supply-chain/manage-your-dependency-security/configure-on-self-hosted-runners).

Running {% data variables.product.prodname_dependabot %} on standard {% data variables.product.prodname_dotcom %}-hosted or self-hosted runners **does not** count towards your included {% data variables.product.prodname_actions %} minutes. For {% data variables.product.prodname_dependabot %} on {% data variables.actions.hosted_runners %}, {% data variables.product.prodname_dotcom %} will bill your organization at the regular rate. See [AUTOTITLE](/billing/reference/actions-runner-pricing).

{% data reusables.dependabot.vnet-arc-note %}

## How runner settings interact

{% ifversion dependabot-repository-runner-settings %}

You can select a runner type for {% data variables.product.prodname_dependabot %} at the organization or repository level:

* **Standard {% data variables.product.company_short %} runner** uses the default {% data variables.product.company_short %}-hosted environment.
* **Labeled runner** sends jobs to self-hosted or {% data variables.actions.hosted_runners %} that match the configured label. If you do not specify a label, {% data variables.product.prodname_dependabot %} uses the `dependabot` label. You can also specify a runner group to limit jobs to matching runners in that group.

> [!WARNING]
> If the specified runner group does not exist, {% data variables.product.prodname_dependabot %} reports an error immediately. If the group exists but no online runner in the group matches the configured label, the job remains queued until a matching runner is available. Make sure the repository can access the specified runner group.

Labeled runners are not available for public repositories. These repositories use standard {% data variables.product.company_short %}-hosted runners.

{% else %}

The {% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} runners and {% data variables.product.prodname_dependabot %} on self-hosted runners settings are interdependent:

* Enabling "{% data variables.product.prodname_dependabot %} on self-hosted runners" automatically enables "{% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} runners". Disabling "{% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} runners" automatically disables "{% data variables.product.prodname_dependabot %} on self-hosted runners".
Expand All @@ -55,6 +69,8 @@ The {% data variables.product.prodname_dependabot %} on {% data variables.produc
> [!WARNING]
> If both settings are enabled but no self-hosted runners or {% data variables.actions.hosted_runners %} with a `dependabot` label are available, {% data variables.product.prodname_dependabot %} jobs will remain queued indefinitely. Ensure runners with this label are configured before enabling "{% data variables.product.prodname_dependabot %} on self-hosted runners".

{% endif %}

## Access and permissions

If you are transitioning to using {% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} runners and you restrict access to your organization's or repository's private resources, you may need to update your list of allowed IP addresses. For example, if you currently limit access to your private resources to the IP addresses that {% data variables.product.prodname_dependabot %} uses, you should update your allowlist to use the {% data variables.product.prodname_dotcom %}-hosted runners IP addresses sourced from the meta API endpoint. For more information, see [AUTOTITLE](/rest/meta).
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -101,7 +101,7 @@ The recommended way to customize default setup at scale is to set an organizatio

We recommend testing the configuration file on a single repository before setting the organization-wide default. See [AUTOTITLE](/code-security/concepts/code-scanning/repository-properties#testing-changes-before-applying-them).

1. The configuration file will be automatically detected and merged with the configuration default setup generates the next time {% data variables.product.prodname_code_scanning %} runs on each repository in the organization. Repositories that already have an explicit value set for the `github-codeql-config-file` property continue to use that value instead of the organization-wide default. For more information about how default and explicit repository property values interact, see [AUTOTITLE](/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization#adding-custom-properties).
1. The configuration file will be automatically detected and merged with the configuration default setup generates the next time {% data variables.product.prodname_code_scanning %} runs on each repository in the organization. Repositories that already have an explicit value set for the `github-codeql-config-file` property continue to use that value instead of the organization-wide default. For more information about how default and explicit repository property values interact, see [AUTOTITLE](/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization#adding-custom-properties-on-github).

### Applying a configuration file to a repository

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ For more information, see [AUTOTITLE](/code-security/concepts/supply-chain-secur

### Configuring the runner type for {% data variables.product.prodname_dependabot %}

You can configure which type of runner {% data variables.product.prodname_dependabot %} uses to scan for version and security updates. By default, {% data variables.product.prodname_dependabot %} uses standard **{% data variables.product.company_short %}-hosted runners**. You can configure {% data variables.product.prodname_dependabot %} to use **self-hosted runners** with custom labels, which allows you to integrate with existing runner infrastructure such as {% data variables.product.prodname_actions_runner_controller %} (ARC).
You can configure which type of runner {% data variables.product.prodname_dependabot %} uses to scan for version and security updates. By default, {% data variables.product.prodname_dependabot %} uses standard **{% data variables.product.company_short %}-hosted runners**. You can configure {% data variables.product.prodname_dependabot %} to use **labeled runners**, which allows you to integrate with existing runner infrastructure such as {% data variables.product.prodname_actions_runner_controller %} (ARC).

> [!NOTE]
> * For security reasons, {% data variables.product.prodname_dependabot %} uses {% data variables.product.company_short %}-hosted runners for public repositories, even when you configure labeled runners.
Expand All @@ -71,9 +71,9 @@ To configure the runner type:
1. Under "{% data variables.product.prodname_dependabot %}", next to "Runner type", select {% octicon "pencil" aria-label="Edit runner type" %}.
1. In the "Edit runner type for {% data variables.product.prodname_dependabot %}" dialog, select the runner type you want {% data variables.product.prodname_dependabot %} to use:
* **Standard {% data variables.product.company_short %} runner**.
* **Labeled runner**: If you select this option, {% data variables.product.prodname_dependabot %} will use self-hosted runners that match the label you specify.
* **Labeled runner**: If you select this option, {% data variables.product.prodname_dependabot %} will use {% ifversion fpt or ghec %}self-hosted or {% data variables.actions.hosted_runners %}{% else %}self-hosted runners{% endif %} that match the label you specify.
1. If you selected **Labeled runner**:
* In "Runner label", enter the label assigned to your self-hosted runners. {% data variables.product.prodname_dependabot %} will use runners with this label. By default, the `dependabot` label is used, but you can specify a custom label to match your existing runner infrastructure.
* In "Runner label", enter the label assigned to your runners. {% data variables.product.prodname_dependabot %} will use runners with this label. By default, the `dependabot` label is used, but you can specify a custom label to match your existing runner infrastructure.
* Optionally, in "Runner group name", enter the name of a runner group if you want to target a specific group of runners.
1. Click **Save runner selection**.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,13 @@ If you restrict access to your organization's or repository's private resources,
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
{% data reusables.repositories.navigate-to-code-security-and-analysis %}
{% ifversion dependabot-repository-runner-settings %}
1. Under "Dependency scanning", in the "{% data variables.product.prodname_dependabot %} version updates" section, next to "Runner type", click {% octicon "pencil" aria-label="Edit runner type" %}.
1. From the "Runner type" dropdown menu, select **Standard {% data variables.product.github %} runner**.
1. Click **Save runner selection**.
{% else %}
1. Under "Dependabot", to the right of "{% data variables.product.prodname_dependabot %} on Actions runners", click **Enable** to enable the feature or **Disable** to disable it.
{% endif %}

{% data reusables.dependabot.no-ubuntu-latest-label-self-hosted %}

Expand Down
Loading
Loading