Home / Companies / GitLab / Blog / July 2025

July 2025 Summaries

15 posts from GitLab

Filter
Month: Year:
Post Summaries Back to Blog
GitLab's Senior Director of Application Security emphasizes the importance of safeguarding customers from software vulnerabilities, especially as AI transforms software development. The integration of AI into platforms like the GitLab Duo Agent Platform introduces new security challenges, such as prompt injection attacks, necessitating robust security measures. GitLab collaborates closely with external security researchers, like Persistent Security, to address these threats and ensure a secure platform. The company's AI Transparency Center highlights its commitment to ethics and transparency in AI development, showcasing its proactive approach in responding to potential vulnerabilities. External researchers play a critical role in identifying emerging threats, conducting real-world testing, and contributing diverse expertise to strengthen GitLab's security posture. GitLab values this collaboration and remains dedicated to rapid responses, clear guidance, and sharing insights with the broader community to foster innovation while protecting users.
Jul 31, 2025 577 words in the original blog post.
Migrating GitLab groups and projects by direct transfer, now generally available from GitLab 18.3, simplifies the process of moving resources between GitLab instances using either a user-friendly UI or flexible API. This new method eliminates the need for manual file exports and imports, allowing users with the Owner role to directly migrate top-level groups, including sub-groups and projects, while offering enhancements such as post-import user contribution mapping and reliable handling of large projects through resource batching and concurrent execution. The feature, enabled by default on GitLab.com and requiring administrator activation on GitLab Self-Managed and Dedicated, provides better migration insights and is optimized for recent GitLab versions, though it still requires network connectivity between instances, limiting its use in air-gapped networks. Users are encouraged to familiarize themselves with the migration process, including user contribution mapping, and can review migration results via the group import history page or API endpoints. Feedback on further improvements is welcomed as GitLab continues to iterate on this feature.
Jul 31, 2025 752 words in the original blog post.
Observations in security compliance are identified gaps or deficiencies in security controls, arising from design flaws, ineffective operations, or missing documentation, and are crucial as they represent real security risks needing prompt remediation. GitLab's Security Team handles these observations through a structured lifecycle using their DevSecOps platform, integrating them into development and operations workflows to enhance transparency and accountability. This lifecycle involves stages from identification to resolution, ensuring real-time status reporting and clear ownership. GitLab utilizes labels and issue boards to organize and track these observations by various criteria such as workflow stage, department, risk severity, and system, allowing for effective prioritization and monitoring. Automation plays a significant role in managing observations, with tools like the triage bot helping streamline the process by enforcing policies for issue management. By transforming observations into actionable work items, GitLab facilitates collaboration, speeds up remediation, and shifts compliance from a reactive burden to a proactive, strategic process, ultimately enhancing security culture and organizational resilience.
Jul 24, 2025 1,504 words in the original blog post.
Supply chain security transcends traditional focuses like vulnerability scanning or dependency management, encompassing the entire process from code creation to production deployment. Key aspects include source, build, artifact, deployment, and tool security, with any weakness potentially compromising the entire software delivery chain, as demonstrated by the 2020 SolarWinds attack. Despite heightened awareness, organizations remain vulnerable due to misconceptions and barriers such as cost-focused mindsets, skills shortages, misaligned incentives, and tool complexity. Additionally, AI introduces new and amplified threats, such as model supply chain attacks and insecure AI-generated code. Organizations struggle to translate awareness into effective action due to overwhelming security alerts and a lack of integrated processes, often confusing activity with impactful security measures. The path forward involves rethinking how security integrates with development workflows, focusing on collaboration, reducing tool complexity, and employing platforms like GitLab's DevSecOps to embed security seamlessly into the development process.
Jul 24, 2025 1,266 words in the original blog post.
GitLab has launched the Healthy Backlog Initiative to manage its growing issue backlog, which has resulted from increased community contributions over the years. By refining their approach to issue management, GitLab's Product and Engineering teams aim to focus on issues with ongoing community engagement, recent activity, or strategic alignment, while closing those that lack relevance or community interest. The initiative seeks to enhance innovation, set clearer expectations, and accelerate development cycles by conducting weekly assessments to prioritize issues aligning with the product strategy. This streamlined approach promises faster delivery, improved feedback loops, and clearer communication about the roadmap, ensuring that community feedback remains significant and well-considered. GitLab remains committed to transparency and community involvement, encouraging contributions and rewarding active participants through various programs.
Jul 23, 2025 573 words in the original blog post.
GitLab 18.2 introduces two key features, Security Inventory and Dependency Path visualization, to enhance software supply chain security. Security Inventory provides Application Security teams with a centralized overview of risks and scan coverage across GitLab groups and projects, allowing them to identify vulnerabilities and prioritize mitigation efforts. Dependency Path visualization offers developers insight into how open-source vulnerabilities are introduced through the dependency chain, facilitating precise fixes. These features are integrated into the GitLab platform, enabling seamless collaboration between development and security teams without requiring additional tools or integrations. The reliance on open-source software in modern applications increases security risks due to outdated or vulnerable components, making Software Composition Analysis (SCA) essential. Dependency Path visualization helps address the challenge of managing transitive dependency risk, which accounts for a significant portion of known vulnerabilities. As security teams manage numerous repositories, these tools provide the necessary visibility and context to transition from reactive to strategic security governance, aligning with GitLab's DevSecOps approach to embed security within the development workflow.
Jul 21, 2025 805 words in the original blog post.
GitLab is advancing software development with its GitLab Duo Agent Platform, an innovative DevSecOps orchestration platform that fosters collaboration between developers and AI agents. This platform is designed to transform software engineering by allowing AI agents to manage repetitive tasks, freeing developers to focus on complex problem-solving and innovation. The GitLab Duo Agent Platform, currently in public beta, provides a range of specialized AI agents capable of performing roles like code development, security analysis, and deployment management within the development lifecycle. It supports integration with popular IDEs and enables the creation and customization of workflows called "Flows" to automate complex tasks. GitLab's platform leverages its comprehensive toolkit and knowledge graph to offer AI agents rich context, ensuring they can make informed recommendations and actions. As the platform evolves, GitLab plans to enhance agent capabilities, increase customization, and foster community-driven innovation through an AI Catalog, ultimately aiming to amplify productivity and efficiency for its users.
Jul 17, 2025 3,453 words in the original blog post.
GitLab's Contributor Success team addressed challenges faced by first-time open source contributors by conducting research studies and implementing a personalized onboarding process that integrated GitLab tools like issue templates, webhooks, and the GitLab Query Language (GLQL). Initial research in 2023 revealed that contributors found the documentation confusing and the process overwhelming, leading to only one successful code merge out of six participants. By 2025, after refining the onboarding process with features such as immediate pipeline triggering and automated follow-ups, all ten new participants successfully merged their contributions, demonstrating a 100% success rate. These improvements not only doubled the number of contributors within nine months but also reduced response and approval times, and facilitated better recognition and engagement through a central hub for contributors. GitLab's efforts have been shared with the wider open source community to help other projects overcome similar barriers and foster a more inclusive environment.
Jul 15, 2025 1,392 words in the original blog post.
GitLab has announced significant improvements to its group and project deletion flow, aimed at enhancing data protection, simplifying recovery, and creating a more intuitive user experience across all pricing tiers. Responding to user feedback, GitLab has addressed inconsistencies in the deletion process, such as limited recovery options for free-tier users and locked namespace paths after deletion. Key changes already implemented include a "pending deletion" state for all deleted content, self-service recovery, standardized deletion status indicators, and an extended recovery period of 30 days. Future enhancements will ensure admin area consistency, immediate path reuse, a centralized "Trash" interface, clear separation between temporary and permanent deletions, and bulk management capabilities. These improvements are designed to protect against data loss, provide a consistent and efficient workflow, and offer a user-friendly interface that enhances control and visibility over deleted content.
Jul 14, 2025 629 words in the original blog post.
AI has become integral to modern software development, significantly boosting coding speed and automating tasks such as writing test cases and summarizing documentation, with 81% of developers either using AI or planning to incorporate it soon. While AI tools enhance productivity, they also introduce potential security risks due to increased reliance on AI-generated code, which developers might trust without sufficient scrutiny. To mitigate these risks, developers are encouraged to adopt a zero-trust mindset toward AI-generated code, treating it as input from a junior developer that requires thorough review. Successful developers will combine AI's efficiency with a focus on security, and initiatives like GitLab's code review feature aim to enhance human judgment rather than replace it. Prompt engineering is vital for generating secure code, emphasizing the need for clear, security-aware instructions to AI models. Additionally, automated scanning for vulnerabilities throughout the development process is crucial, as AI-generated code can increase the attack surface, necessitating fast, accurate, and scalable security measures integrated into the developer's workflow. Platforms like GitLab provide native security scanning and AI-powered insights to help developers maintain speed without compromising security, making scanning an indispensable part of the development lifecycle.
Jul 10, 2025 1,085 words in the original blog post.
GitLab's CI/CD inputs offer a modern solution to the challenges posed by traditional variable-based parameter passing in pipelines, providing a more reliable, secure, and maintainable method for handling parameters. Unlike variables, which lack type validation and can be modified at runtime leading to unpredictable behavior, inputs enforce type safety and immutability, ensuring consistent pipeline execution. This new approach eliminates common issues such as variable collisions and security risks by creating clear contracts that define expected values and their types. Inputs also enhance pipeline configuration flexibility, allowing for dynamic interpolation and unique naming to prevent job name collisions. With features like expand_vars for proper variable expansion and the ability to seamlessly integrate with existing variable-based workflows, inputs enable a gradual transition while maintaining backward compatibility. The shift to inputs not only improves error detection and automation reliability but also lays the groundwork for leveraging GitLab's CI/CD Catalog, facilitating the use of reusable components with typed interfaces. As GitLab continues to expand inputs functionality, teams can expect further enhancements in pipeline customization and job-level parameter management, ultimately leading to more efficient and predictable CI/CD processes.
Jul 07, 2025 2,735 words in the original blog post.
Agentic AI is revolutionizing the development of intelligent applications by enabling AI agents to operate autonomously, making decisions and executing tasks without constant human intervention. This tutorial guides users through deploying an AI agent, specifically the Canada City Advisor, using Google's Agent Development Kit (ADK) on Cloud Run with GitLab's CI/CD tools. The Canada City Advisor agent uses a multi-agent architecture to provide personalized city recommendations based on user preferences, leveraging sub-agents for budget analysis and lifestyle matching. The deployment process involves setting up secure, keyless authentication between GitLab and Google Cloud using Workload Identity Federation, integrating with Google Artifact Registry, and creating a CI/CD pipeline in GitLab. This approach offers enhanced security through automated vulnerability scanning, an audit trail, and fine-grained access control, simplifying the deployment of scalable and secure AI agents.
Jul 07, 2025 1,022 words in the original blog post.
GitLab's Duo Agent Platform is designed to streamline complex programming tasks, such as understanding system architecture and gRPC communication flows, by automating routine tasks and enabling developers to focus on strategic work. The platform assists in generating comprehensive documentation, as demonstrated with a Golang project's gRPC communication flow, transforming hours of manual code analysis into minutes through guided interaction. By intelligently gathering context and creating execution plans, it provides detailed outputs like mermaid diagrams that elucidate communication patterns and payload structures. Duo Agent Platform's effectiveness lies in its collaborative refinement process, allowing developers to guide its actions and ensure deliverables meet specific requirements. This capability extends beyond documentation, offering potential applications in code reviews, testing, debugging, security scanning, and CI/CD optimization. With its public beta upcoming, the platform represents a significant advancement in intelligent DevSecOps, promising further developments through specialized agents and community-driven extensions.
Jul 07, 2025 1,277 words in the original blog post.
Ensuring high application quality can be challenging due to time constraints, inconsistent test coverage, and issues slipping through manual quality assurance processes. GitLab Duo with Amazon Q introduces an AI-powered solution tailored for AWS customers, which automates the generation of comprehensive unit tests, significantly speeding up the quality assurance workflow. By analyzing code for structure, logic, and potential edge cases, Amazon Q automatically creates unit tests that ensure optimal coverage, addressing both expected outcomes and overlooked error conditions. This automation not only maintains consistent testing quality across teams but also detects issues before deployment, helping developers maintain application reliability while accelerating development velocity.
Jul 03, 2025 514 words in the original blog post.
Embedded systems teams are increasingly adopting DevSecOps, a practice traditionally associated with SaaS applications, to meet modern market demands that emphasize software as a primary differentiator in hardware products. This shift, termed "embedded DevSecOps," incorporates collaborative engineering practices, integrated toolchains, and automation tailored for embedded systems development, including adaptations for hardware integration. The convergence of three major market forces is driving this transition: the software-defined product revolution, which has drastically increased the software complexity in products like vehicles; hardware virtualization technologies that enable efficient testing and continuous integration; and competitive pressures exacerbated by a talent war favoring modern tool proficiency over legacy systems. Companies that embrace embedded DevSecOps are better equipped to address challenges like hardware-testing bottlenecks and compliance governance, ultimately reducing costs, accelerating time-to-market, and fostering innovation. This strategic transformation is crucial for organizations aiming to maintain a competitive edge as software becomes an increasingly crucial aspect of embedded products.
Jul 01, 2025 1,059 words in the original blog post.