You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: content/admin/managing-accounts-and-repositories/managing-organizations-in-your-enterprise/custom-properties.md
+14-9Lines changed: 14 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,7 +1,6 @@
1
1
---
2
2
title: Custom properties
3
3
intro: 'Custom properties allow you to add structured metadata to repositories and organizations, enabling better organization, governance, and automation across your {% data variables.product.github %} environment.'
4
-
permissions: 'Repository custom properties can be managed by organization owners and users with admin permissions to the repository. Organization custom properties can be managed by enterprise owners and users with the "Manage the Enterprise''s custom properties definitions" permission.'
5
4
versions:
6
5
ghec: '*'
7
6
ghes: '>= 3.21'
@@ -15,15 +14,11 @@ category:
15
14
16
15
Custom properties are structured metadata fields that you can attach to repositories or organizations in {% data variables.location.product_location %}. They allow you to decorate your repositories or organizations with information such as compliance frameworks, data sensitivity, or project details.
17
16
18
-
An enterprise can have up to 100 property definitions. An allowed value list can have up to 200 items.
19
-
20
17
There are two types of custom properties:
21
18
22
19
***Repository custom properties**: Metadata attached to individual repositories.
23
20
***Organization custom properties**: Metadata attached to organizations within an enterprise.
24
21
25
-
{% data reusables.enterprise-accounts.org-custom-properties-public-preview %}
26
-
27
22
## What are the benefits of using custom properties?
28
23
29
24
As well as providing improved discovery, automated workflows, compliance tracking, targeted policy enforcement, and better reporting capabilities, custom properties enable powerful governance through **ruleset integration**.
@@ -35,10 +30,20 @@ Both repository and organization custom properties can be used as targeting crit
35
30
36
31
## How do I add and manage custom properties?
37
32
38
-
{% ifversion ghec %}
33
+
There are multiple ways to manage custom properties. To manage properties within {% data variables.product.github %}, you can use:
39
34
40
-
Custom properties are fully supported through {% data variables.product.github %}'s REST API, enabling programmatic management and integration with external systems. See [AUTOTITLE](/rest/enterprise-admin/custom-properties).
35
+
* Your organization or enterprise settings. See [AUTOTITLE](/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization) and [AUTOTITLE](/admin/managing-accounts-and-repositories/managing-organizations-in-your-enterprise/managing-custom-properties-for-organizations).
36
+
* {% data variables.product.github %}'s [AUTOTITLE](/rest/enterprise-admin/custom-properties).
41
37
42
-
{% endif %}
38
+
{% ifversion external-custom-properties %}
39
+
40
+
You can also set up an integration to automatically update custom properties with metadata from an external system, such as a software catalog or internal developer portal. External properties can be used in the same places as standard repository custom properties. See [AUTOTITLE](/organizations/managing-organization-settings/sync-external-custom-properties)
43
41
44
-
You can add custom properties through {% data variables.product.github %}'s UI. See [AUTOTITLE](/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization) and [AUTOTITLE](/admin/managing-accounts-and-repositories/managing-organizations-in-your-enterprise/managing-custom-properties-for-organizations).
42
+
Both standard custom properties and external properties can be managed at scale with the REST API and {% data variables.product.prodname_github_apps %}. External properties are more suitable when the external system should be the source of truth, because they are:
43
+
44
+
* Namespaced (`external_system.property_name`), so their provenance is clear and they don't conflict with other custom properties in the organization.
45
+
* Read-only on {% data variables.product.github %}, so users cannot edit them and bring them out of line with the external system.
46
+
47
+
External properties are **not** available for organization custom properties (metadata attached to organizations).
Copy file name to clipboardExpand all lines: content/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/managing-custom-properties-for-repositories-in-your-enterprise.md
+13-1Lines changed: 13 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -42,7 +42,19 @@ When you create a single-select or multi-select property, {% data variables.prod
42
42
This feature is available with {% data variables.copilot.copilot_business_short %} or {% data variables.copilot.copilot_enterprise_short %}. By default, suggestions are enabled for enterprise-level properties and each organization can decide whether to enable suggestions. Enterprise owners can instead enable or disable suggestions everywhere with the **Repository custom property suggestions** policy. See [AUTOTITLE](/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-enterprise-policies).
43
43
{% endif %}
44
44
45
-
## Adding custom properties
45
+
{% ifversion external-custom-properties %}
46
+
47
+
## Syncing custom properties with an external system
48
+
49
+
> [!NOTE] {% data reusables.organizations.external-properties-preview %}
50
+
51
+
{% data reusables.organizations.external-properties-intro %}
52
+
53
+
External custom properties are configured separately for each organization. For setup instructions, see [AUTOTITLE](/organizations/managing-organization-settings/sync-external-custom-properties).
54
+
55
+
{% endif %}
56
+
57
+
## Adding custom properties on {% data variables.product.github %}
46
58
47
59
You can add custom properties to your enterprise to make those properties available in all of your organizations.
Copy file name to clipboardExpand all lines: content/code-security/concepts/supply-chain-security/dependabot-on-actions.md
+17-1Lines changed: 17 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -39,14 +39,28 @@ You may see workflow runs named `dynamic/dependabot/dependabot-updates` or check
39
39
You can run {% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} using:
40
40
***Standard {% data variables.product.prodname_dotcom %}-hosted runners.** These are the default runners used by {% data variables.product.github %} to execute {% data variables.product.prodname_actions %} jobs.
41
41
***{% data variables.actions.hosted_runners_caps %}.** These are {% data variables.product.prodname_dotcom %}-hosted runners with advanced features like more RAM, CPU, and disk space. For more information, see [AUTOTITLE](/actions/how-tos/manage-runners/larger-runners).
42
-
***Self-hosted runners.** These runners grant you greater control over {% data variables.product.prodname_dependabot %} access to your private registries and internal network resources. Be aware that for security reasons, {% data variables.product.prodname_dependabot_updates %} on self-hosted runners will not run on public repositories. For more information on assigning a `dependabot` label on self-hosted runners, see [AUTOTITLE](/code-security/how-tos/secure-your-supply-chain/manage-your-dependency-security/configure-on-self-hosted-runners).
42
+
***Self-hosted runners.** These runners grant you greater control over {% data variables.product.prodname_dependabot %} access to your private registries and internal network resources. Be aware that for security reasons, {% data variables.product.prodname_dependabot_updates %} on self-hosted runners will not run on public repositories. For more information on assigning labels to self-hosted runners, see [AUTOTITLE](/code-security/how-tos/secure-your-supply-chain/manage-your-dependency-security/configure-on-self-hosted-runners).
43
43
44
44
Running {% data variables.product.prodname_dependabot %} on standard {% data variables.product.prodname_dotcom %}-hosted or self-hosted runners **does not** count towards your included {% data variables.product.prodname_actions %} minutes. For {% data variables.product.prodname_dependabot %} on {% data variables.actions.hosted_runners %}, {% data variables.product.prodname_dotcom %} will bill your organization at the regular rate. See [AUTOTITLE](/billing/reference/actions-runner-pricing).
You can select a runner type for {% data variables.product.prodname_dependabot %} at the organization or repository level:
53
+
54
+
***Standard {% data variables.product.company_short %} runner** uses the default {% data variables.product.company_short %}-hosted environment.
55
+
***Labeled runner** sends jobs to self-hosted or {% data variables.actions.hosted_runners %} that match the configured label. If you do not specify a label, {% data variables.product.prodname_dependabot %} uses the `dependabot` label. You can also specify a runner group to limit jobs to matching runners in that group.
56
+
57
+
> [!WARNING]
58
+
> If the specified runner group does not exist, {% data variables.product.prodname_dependabot %} reports an error immediately. If the group exists but no online runner in the group matches the configured label, the job remains queued until a matching runner is available. Make sure the repository can access the specified runner group.
59
+
60
+
Labeled runners are not available for public repositories. These repositories use standard {% data variables.product.company_short %}-hosted runners.
61
+
62
+
{% else %}
63
+
50
64
The {% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} runners and {% data variables.product.prodname_dependabot %} on self-hosted runners settings are interdependent:
51
65
52
66
* Enabling "{% data variables.product.prodname_dependabot %} on self-hosted runners" automatically enables "{% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} runners". Disabling "{% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} runners" automatically disables "{% data variables.product.prodname_dependabot %} on self-hosted runners".
@@ -55,6 +69,8 @@ The {% data variables.product.prodname_dependabot %} on {% data variables.produc
55
69
> [!WARNING]
56
70
> If both settings are enabled but no self-hosted runners or {% data variables.actions.hosted_runners %} with a `dependabot` label are available, {% data variables.product.prodname_dependabot %} jobs will remain queued indefinitely. Ensure runners with this label are configured before enabling "{% data variables.product.prodname_dependabot %} on self-hosted runners".
57
71
72
+
{% endif %}
73
+
58
74
## Access and permissions
59
75
60
76
If you are transitioning to using {% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} runners and you restrict access to your organization's or repository's private resources, you may need to update your list of allowed IP addresses. For example, if you currently limit access to your private resources to the IP addresses that {% data variables.product.prodname_dependabot %} uses, you should update your allowlist to use the {% data variables.product.prodname_dotcom %}-hosted runners IP addresses sourced from the meta API endpoint. For more information, see [AUTOTITLE](/rest/meta).
Copy file name to clipboardExpand all lines: content/code-security/how-tos/find-and-fix-code-vulnerabilities/manage-your-configuration/edit-default-setup.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -101,7 +101,7 @@ The recommended way to customize default setup at scale is to set an organizatio
101
101
102
102
We recommend testing the configuration file on a single repository before setting the organization-wide default. See [AUTOTITLE](/code-security/concepts/code-scanning/repository-properties#testing-changes-before-applying-them).
103
103
104
-
1. The configuration file will be automatically detected and merged with the configuration default setup generates the next time {% data variables.product.prodname_code_scanning %} runs on each repository in the organization. Repositories that already have an explicit value set for the `github-codeql-config-file` property continue to use that value instead of the organization-wide default. For more information about how default and explicit repository property values interact, see [AUTOTITLE](/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization#adding-custom-properties).
104
+
1. The configuration file will be automatically detected and merged with the configuration default setup generates the next time {% data variables.product.prodname_code_scanning %} runs on each repository in the organization. Repositories that already have an explicit value set for the `github-codeql-config-file` property continue to use that value instead of the organization-wide default. For more information about how default and explicit repository property values interact, see [AUTOTITLE](/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization#adding-custom-properties-on-github).
Copy file name to clipboardExpand all lines: content/code-security/how-tos/secure-at-scale/configure-organization-security/establish-complete-coverage/configure-global-settings.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -60,7 +60,7 @@ For more information, see [AUTOTITLE](/code-security/concepts/supply-chain-secur
60
60
61
61
### Configuring the runner type for {% data variables.product.prodname_dependabot %}
62
62
63
-
You can configure which type of runner {% data variables.product.prodname_dependabot %} uses to scan for version and security updates. By default, {% data variables.product.prodname_dependabot %} uses standard **{% data variables.product.company_short %}-hosted runners**. You can configure {% data variables.product.prodname_dependabot %} to use **self-hosted runners** with custom labels, which allows you to integrate with existing runner infrastructure such as {% data variables.product.prodname_actions_runner_controller %} (ARC).
63
+
You can configure which type of runner {% data variables.product.prodname_dependabot %} uses to scan for version and security updates. By default, {% data variables.product.prodname_dependabot %} uses standard **{% data variables.product.company_short %}-hosted runners**. You can configure {% data variables.product.prodname_dependabot %} to use **labeled runners**, which allows you to integrate with existing runner infrastructure such as {% data variables.product.prodname_actions_runner_controller %} (ARC).
64
64
65
65
> [!NOTE]
66
66
> * For security reasons, {% data variables.product.prodname_dependabot %} uses {% data variables.product.company_short %}-hosted runners for public repositories, even when you configure labeled runners.
@@ -71,9 +71,9 @@ To configure the runner type:
71
71
1. Under "{% data variables.product.prodname_dependabot %}", next to "Runner type", select {% octicon "pencil" aria-label="Edit runner type" %}.
72
72
1. In the "Edit runner type for {% data variables.product.prodname_dependabot %}" dialog, select the runner type you want {% data variables.product.prodname_dependabot %} to use:
73
73
***Standard {% data variables.product.company_short %} runner**.
74
-
***Labeled runner**: If you select this option, {% data variables.product.prodname_dependabot %} will use self-hosted runners that match the label you specify.
74
+
***Labeled runner**: If you select this option, {% data variables.product.prodname_dependabot %} will use {% ifversion fpt or ghec %}self-hosted or {% data variables.actions.hosted_runners %}{% else %}self-hosted runners{% endif %} that match the label you specify.
75
75
1. If you selected **Labeled runner**:
76
-
* In "Runner label", enter the label assigned to your self-hosted runners. {% data variables.product.prodname_dependabot %} will use runners with this label. By default, the `dependabot` label is used, but you can specify a custom label to match your existing runner infrastructure.
76
+
* In "Runner label", enter the label assigned to your runners. {% data variables.product.prodname_dependabot %} will use runners with this label. By default, the `dependabot` label is used, but you can specify a custom label to match your existing runner infrastructure.
77
77
* Optionally, in "Runner group name", enter the name of a runner group if you want to target a specific group of runners.
Copy file name to clipboardExpand all lines: content/code-security/how-tos/secure-your-supply-chain/manage-your-dependency-security/configure-on-github-hosted-runners.md
+6Lines changed: 6 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -25,7 +25,13 @@ If you restrict access to your organization's or repository's private resources,
25
25
{% data reusables.repositories.navigate-to-repo %}
26
26
{% data reusables.repositories.sidebar-settings %}
27
27
{% data reusables.repositories.navigate-to-code-security-and-analysis %}
1. Under "Dependency scanning", in the "{% data variables.product.prodname_dependabot %} version updates" section, next to "Runner type", click {% octicon "pencil" aria-label="Edit runner type" %}.
30
+
1. From the "Runner type" dropdown menu, select **Standard {% data variables.product.github %} runner**.
31
+
1. Click **Save runner selection**.
32
+
{% else %}
28
33
1. Under "Dependabot", to the right of "{% data variables.product.prodname_dependabot %} on Actions runners", click **Enable** to enable the feature or **Disable** to disable it.
34
+
{% endif %}
29
35
30
36
{% data reusables.dependabot.no-ubuntu-latest-label-self-hosted %}
0 commit comments