Articles from Source: GitLab-Blog

GitLab Duo Security Review spots logic flaws scanners miss

2026-07-16 00:00
GitLab's new Security Review Flow, currently in public beta, addresses a critical gap in identifying application logic flaws that traditional static scanners often miss. πŸ” This tool analyzes code changes like a security expert, focusing on intent rather than patterns. It detects flaws such as broken authorization and business logic errors early in the development process, reducing overall costs and risks. πŸ’» Security Review Flow complements existing scanners, providing context-rich findings...
Source: GitLab Blog
Mark Settle

Turn multi-step software delivery into agentic flows you can trust

2026-07-16 00:00
πŸš€ GitLab 19.2 introduces Custom Flows for smoother software delivery. These AI-powered workflows allow teams to automate multi-step tasks triggered by GitLab events. No more manual handoffs for common actions like reviewing merge requests or fixing pipelines! Agentic Chat enhances collaboration by recommending specialist flows, making it easier to approve and track progress. Discover how to transform your delivery processes with these new features! #GitLab #SoftwareDevelopment #Automation...
Source: GitLab Blog
Ozer Dondurmacioglu

When a version bump breaks your build, GitLab fixes it

2026-07-16 00:00
πŸš€ GitLab introduces Dependency Scanning Auto-Remediation, now in beta, to enhance security by automatically addressing vulnerable dependencies. When a vulnerable package is detected, it opens a merge request to update it and uses AI to fix any build-breaking changes. This process helps shrink security backlogs without diverting developers' attention. High-severity vulnerabilities can be resolved within compliance deadlines, and each change is tracked for accountability. Learn more about this...
Source: GitLab Blog
Mark Settle

Green DevOps: Why carbon measurement belongs in your CI/CD pipeline

2026-07-09 00:00
πŸ’»πŸŒ± Software teams run hundreds of CI/CD jobs daily, each consuming energy and contributing to carbon emissions without visibility in logs. To tackle this, Eco CI and Carmen are open-source tools that integrate carbon measurement into your existing GitLab pipelines. Eco CI tracks emissions at the pipeline level, while Carmen provides deeper insights from infrastructure and application layers. Both tools help identify resource-intensive jobs and inform better engineering decisions. Starting is...
Source: GitLab Blog
Lysanne Pinto

GitLab Patch Release: 19.1.2, 19.0.4, 18.11.7

2026-07-08 00:00
πŸš€ GitLab has announced patch releases for its software versions 19.1.2, 19.0.4, and 18.11.7. These updates include important security fixes and improvements aimed at enhancing system stability. Users are encouraged to upgrade to benefit from these enhancements. πŸ”’ Stay informed about the latest updates to keep your projects secure. #GitLab #SoftwareUpdate #Cybersecurity #TechNews
Source: GitLab Blog

How we used AI agents to migrate GitLab rate limiting

2026-07-08 00:00
A GitLab team recently experimented with AI agents to migrate their legacy rate-limiting system. They successfully unified two paths using a structured process involving human oversight and AI support. The project highlighted the importance of careful planning, strong observability, and human judgment. While AI agents facilitated mechanical tasks, human engineers ensured quality and addressed unforeseen issues during rollouts. The team completed six cohorts, refining the migration process to...
Source: GitLab Blog
Sam Wiskow

Keep your GitLab seats in check with restricted access

2026-07-06 00:00
GitLab has enhanced its restricted access feature for instance admins, group owners, and billing managers. This update helps manage seat costs more effectively by preventing new billable users from being added when all licensed seats are in use. Key improvements include better integration with identity providers, automatic deactivation of dormant users, and clearer operational notifications. Existing billable members remain unaffected, while new users can be assigned a non-billable Minimal...
Source: GitLab Blog
Priyanka Palanikumar

GitLab Patch Release: 18.8.11

2026-07-01 00:00
πŸš€ GitLab has announced the patch release of version 18.8.11. This update addresses several important bug fixes and security improvements. Users are encouraged to update to enhance their experience and maintain security standards. For more details, check the official release notes. #GitLab #SoftwareUpdate #TechNews #Cybersecurity #DevOps
Source: GitLab Blog

Claude Sonnet 5 on GitLab: More reliable, more efficient

2026-06-30 00:00
πŸš€ Anthropic's Claude Sonnet 5 is now live on GitLab Duo Agent Platform, enhancing software team efficiency. This model excels in multi-step tasks, generating high-quality code, and completing all benchmark tasksβ€”an improvement over its predecessor. πŸ” Teams can expect fewer interruptions and better usability, allowing for smoother workflows. Explore the different models available to optimize your project costs. #GitLab #AI #SoftwareDevelopment #ClaudeSonnet5 #TechNews
Source: GitLab Blog
Talia Armato-Helle

What's new in Git 2.55.0?

2026-06-29 00:00
πŸš€ Git 2.55.0 has been released, featuring several key updates! πŸ”§ The new `git-history(1) fixup` command simplifies the process of amending changes to existing commits by automatically updating related branches. 🐧 Linux users can now benefit from the `fsmonitor` daemon, enhancing the performance of `git-status(1)` for large monorepos. πŸ“¦ Additionally, `git push` now supports remote groups, allowing efficient updates across multiple remotes in one command. πŸ“Š The `git log --graph` feature has...
Source: GitLab Blog
Toon Claes

Google Antigravity agents get full context with GitLab Orbit

2026-06-25 00:00
πŸš€ Exciting news for developers! Google Antigravity now integrates with GitLab Orbit, allowing agents to access structured project data directly from the Antigravity MCP Store. With this integration, agents can query relationships between projects, pipelines, merge requests, and vulnerabilities, enhancing their ability to understand the software lifecycle. πŸ› οΈ Discover how this improves workflows, from blast radius analyses to onboarding, enabling faster responses and accurate insights....
Source: GitLab Blog
Regnard Raquedan

GitLab Patch Release: 19.0.2, 18.11.5, 18.10.8

2026-06-11 00:00
πŸš€ GitLab has announced patch releases for versions 19.0.2, 18.11.5, and 18.10.8. These updates address various security vulnerabilities and improve overall system performance. Users are encouraged to upgrade to benefit from these enhancements. Stay informed and keep your systems secure! πŸ”’πŸ’» #GitLab #SoftwareUpdate #CyberSecurity #TechNews #DevOps
Source: GitLab Blog

GitLab Flex: Commit once, reshape your seats and AI spend

2026-06-10 00:00
🌐 GitLab Flex addresses the unpredictable needs of software procurement in the agentic era. With a single annual commitment, you can adjust seats, AI usage, and new capabilities monthlyβ€”without re-procurement. This flexibility helps avoid overpayment and streamlines project transitions. Explore how this model can benefit your organization! #GitLabFlex #SoftwareInnovation #Agile #AI #TechSolutions
Source: GitLab Blog
Talia Armato-Helle

GitLab on Google Cloud: Fully managed, compliant, and AI-ready

2026-06-10 00:00
πŸš€ GitLab is now available as a fully managed platform on Google Cloud! With GitLab-certified managed service providers like Beyond and Digital Future, teams can enjoy a scalable DevSecOps architecture while retaining control over their code and data. The integration of Google's latest AI models, including Gemini 3.5 Flash, enhances development capabilities. Compliance and governance are built-in, ensuring visibility and auditability for all actions. Explore this advanced setup today! #GitLab...
Source: GitLab Blog
Rajesh Agadi

GitLab: Built for the agentic engineering era

2026-06-10 00:00
πŸš€ GitLab Transcend recently highlighted key innovations for the agentic engineering era. πŸ” Announcements included a next-gen source code management system in private beta, and GitLab Orbit, a public beta context graph for the software lifecycle. πŸ›‘οΈ New agents for security and governance are also in private beta, enhancing oversight for every action. πŸ€– The GitLab Duo Agent Platform is now available, streamlining issue handling and code reviews. πŸ’‘ With 91% of organizations using multiple AI...
Source: GitLab Blog
Manav Khurana

Introducing GitLab Orbit: Full code and lifecycle context, in one query

2026-06-10 00:00
πŸš€ GitLab has introduced Orbit, now in public beta, to enhance code navigation and lifecycle understanding. This tool offers a live, queryable graph of code, merge requests, pipelines, and more, allowing teams to work more efficiently. In tests, Orbit outperformed other AI code review methods, achieving better accuracy in comments and summaries. Engineers can now ask complex questions and receive quick answers, improving productivity and reducing manual work. πŸ”— Try GitLab Orbit today:...
Source: GitLab Blog
Rebecca Carter

Mythos-class Claude Fable 5 arrives on GitLab Duo Agent Platform

2026-06-09 00:00
πŸš€ Claude Fable 5, a robust Mythos-class model, is now live on the GitLab Duo Agent Platform! This model enhances multi-step, goal-directed tasks with improved first-shot accuracy. Early testers report significant reductions in iteration time for complex problems. Key features include long-horizon autonomy, allowing workflows to run without manual checkpoints, and better bug detection in code reviews. Explore its capabilities with GitLab Duo Agent today! 🌟 #GitLab #AI #ClaudeFable5...
Source: GitLab Blog
Talia Armato-Helle

Shai-Hulud copycat campaign targets Python developers through PyPI typosquatting

2026-06-09 00:00
🚨 A recent report by GitLab's Vulnerability Research team revealed a supply chain attack on PyPI involving the Shai-Hulud malware. Five malicious packages were identified, including typosquats of popular libraries like Flask, Requests, and NumPy. These packages execute harmful code at installation without user action. The attack showcases how attackers exploit Python's .pth file mechanism for self-propagating credential theft, targeting major cloud providers and CI/CD environments. For those...
Source: GitLab Blog
Daniel Abeles

Agentic coding is only as good as its context

2026-05-28 00:00
πŸš€ Coding agents can enhance development efficiency, but their effectiveness relies on context. The article discusses how GitLab's coding agents perform better when they have access to more lifecycle information. It highlights three scenarios showing the progression from a repository-only view to full platform visibility. Incorporating issues, pipelines, and security policies allows agents to produce code that aligns with team requirements, improving quality and reducing rework. Learn how to...
Source: GitLab Blog
Jessica Taylor

Claude Opus 4.8 on GitLab: Complex agentic work, less disruption

2026-05-28 00:00
πŸš€ Anthropic has launched Claude Opus 4.8 on GitLab, designed for precise execution in complex multi-step tasks. This model enhances agent performance, ensuring tasks transition smoothly from intent to production. Opus 4.8 improves long-horizon execution, making teams' workflows more efficient. Additionally, it supports mid-conversation system prompts, allowing for real-time updates without losing context. Get started with GitLab Duo Agent Platform today! #GitLab #AI #ClaudeOpus...
Source: GitLab Blog
Talia Armato-Helle

GitLab Patch Release: 19.0.1, 18.11.4, 18.10.7

2026-05-28 00:00
πŸš€ GitLab has announced patch releases for versions 19.0.1, 18.11.4, and 18.10.7. These updates focus on fixing security vulnerabilities and improving performance. Users are encouraged to upgrade to these latest versions to enhance their experience and security. Stay safe and updated! πŸ”’ #GitLab #SoftwareUpdate #Cybersecurity #TechNews
Source: GitLab Blog

GitLab Patch Release: 18.9.8, 18.8.10, 18.7.7, 18.6.8, 18.5.7

2026-05-27 00:00
πŸ”§ GitLab has announced patch releases for several versions: 18.9.8, 18.8.10, 18.7.7, 18.6.8, and 18.5.7. These updates address important security fixes and bug improvements to enhance performance and reliability. Users are encouraged to upgrade to benefit from these enhancements. #GitLab #SoftwareUpdate #SecurityFixes #TechNews
Source: GitLab Blog

Full security scanner coverage of your codebase in minutes

2026-05-26 00:00
πŸ” Security teams face challenges in scaling scanner configurations as organizations grow. GitLab 19.0 introduces security configuration profiles, allowing teams to centrally manage how and when security scanners run across projects. πŸš€ This feature streamlines the process, enabling static application security testing (SAST), dependency scanning, and secret detection with minimal manual setup. πŸ’‘ With default profiles, teams can easily ensure consistent security coverage across all projects. For...
Source: GitLab Blog
Michael Omokoh

Reduce supply chain risk with SBOM-based dependency scanning

2026-05-26 00:00
πŸ” Third-party code poses risks in software development, with recent incidents showing how compromised packages can impact multiple projects. GitLab 19.0 introduces SBOM-based dependency scanning, which tracks both direct and transitive dependencies. This tool helps developers identify vulnerable packages and their sources, ensuring better project security. With continuous scanning and integration into merge requests, teams can address vulnerabilities effectively. #SupplyChainSecurity #GitLab...
Source: GitLab Blog
Joel Patterson

GitLab 19.0 released

2026-05-21 00:00
πŸš€ GitLab has officially launched version 19.0, introducing several new features aimed at enhancing user experience. Key updates include improved performance enhancements, new security features, and streamlined workflows to help teams collaborate more efficiently. This release reflects GitLab's commitment to continuous improvement and innovation. #GitLab #SoftwareUpdate #TechNews #Collaboration #DevOps
Source: GitLab Blog

GitLab 19.0: Transform MRs from manual tasks to an automated workflow

2026-05-21 00:00
πŸš€ GitLab 19.0 introduces Developer Flow, streamlining the merge request (MR) process. This update includes an AI agent that automates tasks like addressing reviewer feedback, resolving conflicts, and even splitting large MRs. Developers can now focus on reviewing while the agent handles execution. Key features include: - Automatic conflict resolution - One-click rebase and merge - Enhanced project setup for accuracy Experience the benefits of Developer Flow with GitLab Duo Agent Platform....
Source: GitLab Blog
Corinne Dent

Manage CI/CD credentials with GitLab Secrets Manager

2026-05-21 00:00
πŸš€ GitLab Secrets Manager is now in public beta! It helps manage CI/CD credentials securely within your existing GitLab environment. By scoping secrets to specific jobs, it reduces the risk of leaks and improves access management using familiar controls. This eliminates the need for standalone vaults, simplifying operations. πŸ” Developers can easily integrate it into projects by declaring secrets in the .gitlab-ci.yml file. Join the beta and streamline your credential management today! πŸ’»...
Source: GitLab Blog
Mark Settle

More AI models for GitLab Duo Agent Platform Self-Hosted

2026-05-21 00:00
πŸš€ GitLab 19.0 enhances the Duo Agent Platform for self-hosted environments, addressing challenges like data residency and compliance. 🌐 New support for open source models enables teams in air-gapped networks to optimize workflows without external API reliance. πŸ” Options include deploying on-premises or using GPU-enabled virtual machines for flexibility. For more details, check the supported models and deployment options. #GitLab #AI #OpenSource #DataCompliance #TechUpdates
Source: GitLab Blog
Jordan Janes

Track CI component usage across your organization

2026-05-21 00:00
πŸš€ GitLab 19.0 introduces Components Analytics, enhancing visibility of CI/CD component usage across organizations. πŸ“Š This feature allows teams to track adoption data and usage counts, helping to identify outdated versions that may pose security risks. πŸ” The high-level view shows how widely components are used, while GitLab Ultimate offers detailed insights into which projects are using specific versions. Access these insights today via Explore > CI/CD Catalog > Analytics. #GitLab #CICD...
Source: GitLab Blog
Corinne Dent

Beyond BYOK: Why governance matters for AI agents

2026-05-18 00:00
GitHub's Copilot CLI now supports BYOK and local models for developers, but it lacks organization-wide control for auditing actions taken by AI agents in automated workflows. πŸ€– In contrast, GitLab Duo CLI integrates governance at the platform level, ensuring actions are approved and auditable, even in CI/CD pipelines. πŸ’» Key questions for leaders: Does the AI implementation require enterprise-level control? How does the security model hold without human oversight? πŸ” Explore GitLab Duo CLI for...
Source: GitLab Blog
Jessica Hurwitz

Fix bugs with Codex and GitLab

2026-05-18 00:00
πŸš€ Codex is a coding agent that streamlines coding tasks directly in the terminal. It efficiently reads code, proposes fixes, and executes commands to enhance developer productivity. πŸ› οΈ This tutorial explores three use cases with Codex and GitLab Duo Agent Platform, focusing on fixing bugs in the Tanuki IoT Platform project. From local bug fixes to integrating issue context with GitLab MCP, Codex enhances the coding experience. πŸ” Learn how Codex can also aid in addressing review feedback...
Source: GitLab Blog
Michael Friedrich

GitLab Dedicated for Government now GovRAMP-authorized

2026-05-18 00:00
πŸš€ GitLab Dedicated for Government has achieved GovRAMP Authorization, streamlining secure DevSecOps adoption for state and local agencies. This single-tenant solution enhances data residency and compliance, enabling agencies to modernize their software supply chains effectively. Key benefits include toolchain consolidation, robust security features, and the integration of AI capabilities via GitLab Duo. Discover how this can support your agency's modernization efforts! #GovRAMP #DevSecOps...
Source: GitLab Blog
Deepa Mahalingam

5 ways to fix misleading vulnerability severities with policy

2026-05-13 00:00
GitLab introduces new vulnerability management policies to enhance enterprise security. πŸ“Š These policies allow automatic adjustments to CVSS severity levels based on defined criteria, making vulnerability reports more relevant to your specific environment. Key features include the ability to set, increase, or decrease severity levels, ensuring that vulnerabilities are prioritized correctly. πŸ”’ Ready-to-use configurations help organizations address common scenarios, such as downgrading low-risk...
Source: GitLab Blog
Grant Hickman

GitLab Patch Release: 18.11.3, 18.10.6, 18.9.7

2026-05-13 00:00
πŸš€ GitLab has announced patch releases for versions 18.11.3, 18.10.6, and 18.9.7. These updates address several important fixes and improvements to enhance user experience and security. Users are encouraged to update to the latest versions to benefit from these enhancements. πŸ”’ Stay informed and keep your systems secure! #GitLab #SoftwareUpdate #Cybersecurity
Source: GitLab Blog

Harden your pipeline perimeter for the era of AI-assisted coding

2026-05-13 00:00
AI-assisted development is advancing rapidly, often outpacing existing security measures. GitLab Ultimate addresses this by integrating security directly into the development workflow. Key features include a comprehensive Group Security Dashboard that consolidates security findings, enhancing visibility across projects. The platform automates policy enforcement, ensuring security protocols are consistently applied. Additionally, GitLab Ultimate streamlines remediation with tools that...
Source: GitLab Blog
Vishal Thenge

GitLab Act 2

2026-05-11 00:00
πŸš€ Big changes are underway at GitLab! The company is initiating a transparent restructuring to adapt to the evolving software landscape. This includes reducing its operational footprint by 30% in certain countries and flattening management layers to enhance efficiency. GitLab is also focusing on empowering smaller R&D teams and integrating AI to optimize processes. For customers and investors, commitments remain unchanged while innovation is set to accelerate. Key updates on financial impacts...
Source: GitLab Blog
Bill Staples

Automate deployment processes using a custom agent in GitLab Duo Agent Platform

2026-05-07 00:00
πŸ› οΈ Onboarding new microservices can be complex and time-consuming. GitLab Duo Agent Platform offers a solution by creating custom agents that automate this process. In a recent tutorial, the onboarding for a fictitious bank, TanukiBank, was demonstrated. The custom agent understands specific application workflows and performs the necessary steps efficiently, saving time and reducing errors. Learn how to build your own agent and streamline deployment processes! πŸš€ #GitLab #DevOps #Automation...
Source: GitLab Blog
Cesar Saavedra

Consolidate your GitLab stack with Gitaly on Kubernetes

2026-05-07 00:00
πŸš€ Great news for GitLab users on Kubernetes! Gitaly is now officially available on Kubernetes, simplifying your setup by eliminating the need for a hybrid architecture. πŸ“Š With this release, teams can run Gitaly's memory-intensive operations within Kubernetes, enhancing stability and reducing downtime. πŸ”§ Gitaly can be deployed via the GitLab Helm chart, making it easier for new users to adopt a fully Kubernetes-native environment. For detailed configuration guidance, check the Gitaly on...
Source: GitLab Blog
Olivier Campeau

Limit credential exposure with fine-grained personal access tokens

2026-05-07 00:00
πŸš€ GitLab is introducing fine-grained personal access tokens (PATs) in beta, enhancing security by limiting token permissions. These tokens can be scoped to specific tasks, reducing risk if they are exposed. You can define their reach and permissions, ensuring a token is only as powerful as needed. πŸ” The updated tokens table allows for easier auditing of permissions. It's advised to avoid using fine-grained PATs in production until they are fully available. Learn how to create and manage these...
Source: GitLab Blog
Nelly Vahab

GitLab Patch Release: 18.11.2, 18.10.5

2026-04-29 00:00
πŸš€ GitLab has announced patch releases 18.11.2 and 18.10.5 for both the Community and Enterprise Editions. These updates aim to improve functionality and address previous issues. Users are encouraged to review the release notes for detailed information on changes and enhancements. Stay updated and ensure your systems are running smoothly! πŸ”§ #GitLab #SoftwareUpdate #TechNews #DevOps #ReleaseNotes
Source: GitLab Blog