December 2025 Summaries
8 posts from GitLab
Filter
Month:
Year:
Post Summaries
Back to Blog
GitLab 18.7 introduces enhancements in development, operations, and security to support teams as they integrate AI into their workflows, laying the groundwork for the upcoming GitLab Duo Agent Platform's general availability in January 2026. This release includes new automation features, advanced governance controls, and security improvements to streamline operations and prepare for a more reliable AI-driven experience. Notable updates include the introduction of Custom Flows for automating multistep workflows, AI-powered false positive detection for Static Application Security Testing (SAST), and Custom Agent Versioning to manage AI catalog agents and flows. The release also features the Data Analyst Agent for exploring GitLab data using natural language and dynamic input selection in pipelines to enhance user experience. These innovations aim to elevate software development by providing a unified platform for orchestrating AI across the software lifecycle while maintaining governance and security.
Dec 18, 2025
1,631 words in the original blog post.
In 2015, Dr. James Quilty faced disorganized course content delivery at Victoria University of Wellington, with learning materials scattered across various platforms, leading to confusion among students and faculty. By 2017, the university adopted GitLab Self-Managed Ultimate, consolidating these resources into a unified DevSecOps platform, significantly increasing student engagement and streamlining course management. This shift reflects broader challenges in higher education IT, where fragmented systems and outdated infrastructure hinder collaboration and efficiency. GitLab's platform offers a solution, allowing institutions to modernize incrementally while maintaining compliance with regulatory mandates. The platform's automation capabilities in compliance and governance enable significant time savings and operational improvements, as highlighted by a Forrester Consulting study. Additionally, the integration of AI tools through the GitLab Duo Agent Platform supports responsible AI adoption by enhancing software development processes without compromising security or governance standards. This approach allows educational institutions to simplify development workflows, reduce complexity, and focus on advancing education rather than managing disparate tools.
Dec 15, 2025
1,395 words in the original blog post.
GitLab has launched its product documentation in Japanese, addressing a significant language barrier that has impeded Japanese developers and DevSecOps teams from fully utilizing GitLab's capabilities. Recognizing Japan as a critical market with its vast developer community but limited English proficiency, GitLab has localized its documentation by building a robust infrastructure that integrates seamlessly with its existing docs-as-code principles. The process involves a strategic, AI-assisted translation workflow, where high-traffic pages are prioritized for AI translation, followed by professional human review to ensure linguistic accuracy and cultural appropriateness. This approach not only tackles the technical challenges of maintaining complex markdown syntax and automated testing but also streamlines content updates to keep the Japanese site synchronized with its English counterpart. The initiative reflects GitLab's commitment to supporting Japanese users and setting up a scalable foundation for future language expansions, with plans to enhance the search experience and expedite the localization workflow.
Dec 11, 2025
1,434 words in the original blog post.
Job seekers are being targeted by scammers posing as recruiters from tech companies like GitLab, using email, LinkedIn, and video conferencing platforms to create the illusion of legitimate hiring processes. These scams involve fake interview invitations, employment offers, and onboarding documents, often followed by requests for payment or personal information, and they misuse GitLab's branding without any affiliation with the company. Recent scams have become more sophisticated, using unauthorized domains, fake certifications, and impersonating GitLab HR staff on platforms like LinkedIn and Teams. Warning signs include [email protected] email domains, requests for payment, and communication that only happens through chat without verified GitLab calendar invites. GitLab's actual hiring process is transparent and verifiable, with all communications coming from official @gitlab.com email addresses, and interviews conducted via Zoom. The company is actively working to investigate and report fake recruiting domains and profiles, collaborating with legal and platform partners to remove fraudulent content, and advising candidates to verify email domains, confirm job postings on the official website, and avoid sending personal information to unverified recruiters.
Dec 10, 2025
399 words in the original blog post.
Leading academic institutions are increasingly challenged to provide comprehensive DevSecOps tools while maintaining control, a need addressed by the GitLab for Education program, which offers GitLab Ultimate to qualified institutions. This initiative has notably transformed operations at the Centre de Recherche en Informatique de Lens (CRIL), part of Artois University in France, by transitioning from GitLab Community Edition to Ultimate, thus enhancing their teaching and research capabilities. GitLab Ultimate's advanced features support nearly 3,000 users across 19,000 projects, enabling sophisticated project management, enhanced visibility, and a comprehensive curriculum that integrates DevSecOps principles. The program also facilitates open-source contributions using AI tools, as demonstrated by students who made impactful contributions to the GitLab product. The self-managed GitLab instance at Artois University ensures institutional control and data longevity, crucial for long-term research preservation, and underscores the importance of self-hosted solutions in higher education. The success at Artois University highlights the benefits of the GitLab for Education program in delivering a modern DevSecOps curriculum and supporting collaborative research.
Dec 10, 2025
901 words in the original blog post.
Enterprise teams are shifting from Azure DevOps to GitLab to enhance software delivery speed and security, particularly in regulated industries. GitLab offers integrated compliance frameworks and security testing, including SAST, DAST, and container scanning, embedded within the developer workflow. It also provides AI capabilities across the software delivery lifecycle and flexible deployment options, reducing integration complexity and security gaps. The migration process from Azure DevOps to GitLab involves several phases, including moving repositories, pipelines, and other assets like work items and container images, with tools like Congregate aiding the transition. Successful migration requires thorough planning, including inventory assessments, timeline determination, and pilot migrations to validate the process. GitLab's platform evolution offers a unified approach to managing projects, enhancing collaboration, and supporting enterprise-grade security and compliance, making it an appealing choice for organizations facing pressure to accelerate delivery while maintaining security and regulatory standards.
Dec 03, 2025
2,717 words in the original blog post.
Embedded systems development teams often struggle to balance development speed with meeting stringent functional safety and code quality requirements imposed by standards such as ISO 26262, IEC 62304, DO-178C, and IEC 61508. Manual verification processes create bottlenecks, forcing teams to choose between speed and safety. GitLab's integration with CodeSonar offers a solution by automating compliance workflows and enabling continuous verification, thus improving development velocity and compliance confidence. This integration uses a compliance-as-code approach within GitLab's CI/CD pipelines to enforce policies from the earliest stages of development, catching compliance issues early and automating security policy enforcement. CodeSonar performs deep analysis of C/C++ code, identifying vulnerabilities like buffer overruns and command injection, which are common in safety-critical systems. By automating evidence collection and embedding verification into every code change, this approach transforms compliance from a periodic checkpoint into an ongoing process, thereby reducing time-to-market and improving audit readiness. The integration supports customizable compliance frameworks for various standards and can be deployed in various environments, enhancing both security and efficiency in embedded systems development.
Dec 02, 2025
876 words in the original blog post.
GitLab's deployment pipeline enables up to 12 code changes daily to GitLab.com without downtime, using the platform's own CI/CD capabilities to manage these frequent updates. This rapid deployment strategy allows GitLab to quickly incorporate customer feedback, release security patches, and validate new features in a live environment, providing customers with immediate access to the latest capabilities. The process involves a multi-stage pipeline with environments such as staging, canary, and production, each equipped with rigorous quality assurance measures, including automated testing and canary deployments, to ensure reliability. GitLab's deployment model leverages a hybrid architecture that supports both containerized and traditional Linux services, showcasing a sophisticated balance between deployment speed and operational reliability. This model not only demonstrates GitLab's ability to manage complex large-scale deployments but also offers customers a proven framework they can adopt for their own applications, highlighting GitLab's commitment to continuous improvement and innovation in DevOps practices.
Dec 01, 2025
2,457 words in the original blog post.