January 2026 Summaries
18 posts from GitLab
Filter
Month:
Year:
Post Summaries
Back to Blog
Single sign-on (SSO) enhances user authentication and security by enabling access to multiple applications with a single set of credentials. This guide details the integration of SAML-based SSO between Google Workspace and GitLab.com to streamline access management, automate group synchronization, and ensure seamless collaboration. By configuring SAML authentication, users can log into GitLab using Google credentials, with their permissions reflecting Google group memberships. The guide outlines the steps for setting up SAML, including obtaining necessary configuration values from GitLab, creating a SAML application in Google Workspace, and mapping Google groups to GitLab roles for automatic provisioning and dynamic permissions management. It emphasizes security best practices, such as maintaining emergency access and enforcing SAML authentication, while also highlighting the benefits of reduced administrative overhead and enhanced security. The process concludes with testing the configuration to ensure successful synchronization and proper role assignments, providing a scalable and efficient solution for centralized access control.
Jan 27, 2026
4,115 words in the original blog post.
GitLab's HackerOne Bug Bounty program, initially launched in 2018, has been updated to enhance transparency, improve testing guidance, and refine the scope of vulnerabilities in response to feedback from the security research community. These updates emphasize the use of local testing environments through the GitLab Development Kit (GDK) to protect both researchers and production infrastructure, with specific recommendations for testing denial-of-service (DoS) impacts and vulnerabilities requiring production architecture. The scope has been clarified to exclude standalone prompt injection and general information gathering, while still including privacy breaches and certain application layer DoS vulnerabilities. A transition period with a 7-day grace period is provided for researchers with active investigations under the previous policy. GitLab remains committed to transparency, safety, and fairness by setting clearer boundaries, protecting systems, and ensuring consistent evaluation standards, which supports program sustainability and focuses resources on high-impact security issues. New researchers are encouraged to visit the HackerOne program page, set up local testing, and review the full policy for detailed guidelines, while the security research community is thanked for their ongoing contributions to maintaining GitLab's security.
Jan 20, 2026
564 words in the original blog post.
GitLab has announced the general availability of its GitLab Duo Agent Platform, which aims to integrate agentic AI into the entire software development lifecycle, addressing the AI paradox in software delivery. This platform seeks to enhance productivity by automating tasks across the development process, offering features such as intelligent orchestration and agentic AI automation. GitLab credits are introduced, providing users with virtual currency to access the platform's features, with credits refreshing monthly for Premium and Ultimate subscribers. The platform's capabilities include Agentic Chat for context-aware assistance, specialized agents for task delegation, and flows to automate complex tasks, all designed to improve collaboration and streamline workflows. Additionally, GitLab provides governance, visibility, and flexible deployment options to ensure responsible AI adoption, allowing teams to customize the platform according to privacy, security, and compliance requirements.
Jan 15, 2026
1,906 words in the original blog post.
GitLab introduced GitLab Credits as a new virtual currency for usage-based pricing in its Duo Agent Platform, aiming to address the limitations of seat-based pricing models that create disparities in AI access among engineering teams. This approach allows every team member with a GitLab account to access agentic AI capabilities without needing individual seat purchases, as credits are pooled across the organization and used based on AI requests. The system promotes cost efficiency by offsetting usage among power and light users and provides detailed usage visibility through dashboards, with controls to manage access and notifications to track credit consumption. GitLab Credits start at $1 per credit, with volume discounts available for annual commitments, and are designed to be drawn down based on the number of agentic requests, with different rates for various language models. Existing Premium and Ultimate customers receive promotional credits for a limited time, allowing them to explore Duo Agent Platform features without extra cost, while new customers can start with a GitLab Ultimate trial to experience the platform's capabilities.
Jan 15, 2026
2,013 words in the original blog post.
The final installment of the "Getting Started with GitLab Duo Agent Platform" series focuses on mastering the customization of AI agents and workflows within the development lifecycle, emphasizing the importance of tailoring tools to meet specific team needs. Detailed guidance is provided on creating custom rules, which set preferences for coding styles and workflow behaviors, applicable at user and project levels. It introduces AGENTS.md as a method for providing project-specific context to agents, ensuring consistent adherence to coding standards and project conventions, while also extending the utility across other AI tools. Custom review instructions are highlighted for maintaining consistent code review standards, and Agent Skills are discussed as a way to integrate specialized knowledge and workflows. The Model Context Protocol (MCP) is explored as a means for agents to connect with external systems. The series concludes with insights into developing custom agents and flows, using system prompts to define agent behaviors, and leveraging the AI Catalog for discovering and sharing solutions, thus empowering teams to optimize their software development lifecycle (SDLC) with tailored AI-driven solutions.
Jan 14, 2026
2,171 words in the original blog post.
GitLab Duo Agent Platform is a comprehensive tool for integrating AI agents and workflows into the development lifecycle, offering foundational, custom, and external agents to enhance various tasks. Foundational agents, maintained by GitLab, provide ready-to-use solutions for development, planning, security, data analysis, and CI/CD optimization. Custom agents allow users to tailor functionalities to specific team workflows by configuring system prompts and behaviors. External agents, such as those powered by Anthropic Claude and OpenAI Codex, offer specialized AI capabilities and operate asynchronously, triggered by mentions or assignments in issues and merge requests. These external agents are ideal for those requiring specific AI behavior, compliance with data residency requirements, or integration with provider-specific tools. The platform encourages starting with foundational agents, evolving to custom agents for tailored needs, and employing external agents for advanced automation and integration with third-party AI services.
Jan 14, 2026
1,608 words in the original blog post.
GitLab Duo Agent Platform is an AI-powered solution designed to enhance software development workflows by embedding intelligent assistants, or "agents," throughout the development lifecycle, promoting asynchronous collaboration across DevSecOps. This platform transforms traditional linear workflows into dynamic, parallel processes by allowing developers to delegate routine tasks, such as code refactoring and security scans, to specialized AI agents, thus enabling them to focus on complex problem-solving and innovation. Leveraging GitLab's comprehensive DevSecOps capabilities, these agents are informed by complete project context, ensuring they operate effectively while maintaining adherence to team standards. The platform evolves from the previous GitLab Duo Pro and Enterprise offerings by expanding from individual developer-AI interactions to a many-to-many team-agent collaborative model, which allows agents to autonomously manage routine tasks across the entire software lifecycle. This eight-part guide covers everything from the introduction to the platform, accessing and customizing agents, to creating and managing AI workflows and integrating external tools, providing a thorough understanding of how to implement and maximize the benefits of GitLab Duo Agent Platform within a team.
Jan 14, 2026
1,006 words in the original blog post.
This section of the guide on the GitLab Duo Agent Platform focuses on managing AI agents and workflows within development projects, offering insights into AI management capabilities, agent and flow management, event-driven triggers, and activity monitoring through sessions. It highlights the central role of the AI management capabilities as a hub for overseeing AI workflows, providing visibility into agent and flow activities, and enabling event-driven automation. Users can manage agents and flows by navigating through the AI menu, which offers options to view, create, and manage these components, as well as configure event-based automation through triggers. The section also explains how sessions monitor execution status, step-by-step progress, and the decision-making process of agents and flows, ensuring transparency in operations.
Jan 14, 2026
596 words in the original blog post.
GitLab Duo Agentic Chat is a dynamic AI collaboration tool designed to enhance development workflows by acting as an autonomous partner capable of executing various tasks such as creating and modifying code, managing merge requests, and triaging issues within the GitLab environment. It offers a range of specialized agents tailored for specific functions, including product management, security analysis, data analysis, and CI/CD pipeline optimization, allowing users to switch between them based on their needs. With capabilities that include code operations, project insights, actionable tasks, and context awareness, GitLab Duo Agentic Chat integrates into different development environments like IDEs and the terminal, providing a seamless interface for users. It also supports extensibility through the Model Context Protocol and offers multi-agent support for diverse tasks. The platform facilitates an interactive experience with tutorials guiding users from initial interactions to production-ready workflows, ensuring full customization and integration into the software development lifecycle.
Jan 14, 2026
1,331 words in the original blog post.
GitLab Duo Agent Platform is a transformative AI orchestration tool designed to integrate AI agents into the software development lifecycle, enhancing productivity while maintaining enterprise governance and security. It allows developers to build and deploy AI-driven workflows, enabling asynchronous collaboration with specialized agents across various stages of development, such as code, issues, merge requests, and CI/CD pipelines. By operating within the GitLab environment, it provides visibility and control over AI-generated code, addressing challenges like increased code review durations and security vulnerabilities. The platform offers a centralized AI management hub where teams can interact with agents via chat or command-line interface, create custom workflows, and utilize foundational flows for common development tasks. It supports both GitLab-managed and external AI agents, with capabilities to automate complex, multi-agent tasks while ensuring compliance with organizational standards. The platform's architecture facilitates seamless integration with external data sources and third-party services, enabling developers to accelerate innovation without compromising control or security.
Jan 14, 2026
2,049 words in the original blog post.
The GitLab Duo Agent Platform enables users to build and deploy AI agents and workflows within their development lifecycle by orchestrating multi-step processes called flows. These flows, which can be foundational or custom, consist of multiple agents that work autonomously to complete complex tasks, such as software development, CI/CD pipeline fixes, and code reviews, without requiring user intervention. Foundational flows offer pre-built, production-ready workflows for common development tasks, while custom flows allow teams to tailor automation to their specific needs, leveraging GitLab's platform compute and GitLab Runner infrastructure. Custom flows can be triggered through various GitLab events, such as mentions or assignments, and are defined through a YAML configuration that specifies components, agents, and execution logic. The platform helps streamline development processes by allowing users to focus on higher-level tasks while flows handle background operations, ultimately enhancing project efficiency and consistency.
Jan 14, 2026
2,472 words in the original blog post.
Part 5 of the guide "Getting Started with GitLab Duo Agent Platform" delves into the AI Catalog, a central repository for discovering, creating, and sharing AI agents and workflows within an organization. The AI Catalog facilitates consistency and collaboration by enabling teams to leverage pre-built solutions, and it provides access to foundational, custom, and external agents, as well as flows and Model Context Protocol (MCP) servers. Users can browse, enable, and customize agents and flows, setting them as either private or public based on their project's needs. The platform also supports versioning for custom agents and flows, allowing users to manage changes and updates while ensuring consistent behavior across projects. This part of the guide emphasizes the importance of thorough documentation, testing, and visibility management when publishing agents and flows, and it sets the stage for learning about monitoring and automating AI workflows in the subsequent section.
Jan 14, 2026
1,367 words in the original blog post.
GitLab is enhancing security on GitLab.com by mandating multi-factor authentication (MFA) for all users and API endpoints that authenticate using a username and password, as part of its Secure by Design commitment to combat credential stuffing and account takeover attacks. This requirement applies to users who sign in with a username and password, but not to those using social sign-on or single sign-on, unless they also have a password for direct login. The MFA rollout will occur gradually over the coming months, with notifications provided via email and in-product reminders, allowing users to prepare and minimize disruptions. Users are advised to set up MFA methods like passkeys, authenticator apps, or WebAuthn devices, and to securely save recovery codes. For API authentication, switching to personal access tokens is recommended. Failure to enable MFA by the deadline will prevent account access, and password-based CI/CD pipelines or automations will require adjustments unless using personal access or deploy tokens.
Jan 09, 2026
499 words in the original blog post.
AI is revolutionizing software development by accelerating coding processes, yet paradoxically, it introduces challenges to compliance and security, creating workflow bottlenecks within DevSecOps teams. Despite AI-generated code constituting a significant portion of development work, traditional manual tasks in the DevSecOps lifecycle consume substantial time, leading to inefficiencies. Many teams face collaboration barriers due to fragmented toolchains and a multitude of tools, underscoring the need for intelligent orchestration that integrates AI and human efforts seamlessly. While AI is not seen as a replacement for human developers, it is expected to reshape roles, emphasizing the value of creativity, innovation, and strategic vision that humans uniquely bring. GitLab's upcoming Transcend event will address these challenges by showcasing how intelligent orchestration can enhance AI-powered software development, helping organizations achieve a balance between AI adoption and essential aspects like security and compliance.
Jan 08, 2026
531 words in the original blog post.
The GitLab team participated as judges in the iHack Hackathon at IIT Bombay's E-Summit, where they were impressed by the determination and ingenuity of students tackling real-world problems using GitLab's platform. The event highlighted the students' ability to overcome significant challenges and use GitLab tools such as Issue Boards and CI/CD pipelines to enhance their projects. Noteworthy projects included Team Decode's FIRE, a rapid data processing tool; Team BichdeHueDost's RFID-based cashless payment system for schools; and Team ZenYukti's RepoInsight AI, which aids in codebase comprehension. Beyond the technical achievements, the event underscored the importance of inclusion, as GitLab committed to reimbursing travel expenses for students who faced logistical barriers, emphasizing that while talent is widespread, access to opportunities is not. GitLab's commitment to education was further demonstrated by their support for students' learning and collaboration through their GitLab for Education program.
Jan 08, 2026
850 words in the original blog post.
The OWASP Foundation's 2025 "Top 10 Security Risks" list introduces major updates reflecting the changing landscape of application security, emphasizing new and emerging threats. The list is based on analysis of over 175,000 CVE records and global feedback from security experts, highlighting the inclusion of two new categories: "Software Supply Chain Failures," which addresses the security of dependencies and distribution systems, and "Mishandling of Exceptional Conditions," focusing on improper error handling and system responses. Notable changes include the rise of "Security Misconfiguration" to the second spot, driven by configuration vulnerabilities, while traditional threats like "Injection" and "Cryptographic Failures" have dropped in ranking but remain significant. The list stresses the importance of evolving testing strategies to encompass a broader range of CWEs, now totaling 589, and the critical role of comprehensive security scanning tools like GitLab Ultimate, which provides extensive detection and management capabilities across all listed categories. The update underscores the growing complexity of software systems and the necessity for robust security measures to address both longstanding and novel risks.
Jan 07, 2026
2,195 words in the original blog post.
Modern applications frequently encounter security vulnerabilities, and development teams often face the challenge of sifting through numerous findings from security scanners to prioritize the most critical threats. Effective vulnerability triaging is crucial in addressing these challenges, and GitLab offers a solution by integrating security scanning capabilities and leveraging the GitLab Duo Security Analyst Agent. This AI-powered tool transforms vulnerability management from a labor-intensive manual process into an intelligent, efficient workflow by analyzing vulnerabilities within the context of the specific codebase, evaluating risk, providing actionable recommendations, and reducing false positives. GitLab's built-in security scanners, such as Static Application Security Testing (SAST), Dependency Scanning, and Container Scanning, automatically run during CI/CD pipeline execution, contributing to a comprehensive Vulnerability Report. The Security Analyst Agent further enhances this process by prioritizing vulnerabilities based on risk and offering clear guidance for remediation, ultimately enabling teams to focus on the vulnerabilities that pose genuine threats to their applications.
Jan 06, 2026
1,844 words in the original blog post.
As AI agents increasingly contribute to software development, building trust between humans and these autonomous systems becomes vital, according to GitLab's UX Research team. Their study reveals that trust isn't formed through singular breakthroughs but through numerous "micro-inflection points"—subtle design choices and interaction patterns that gradually build confidence in AI agents over time. The research identifies four pillars essential for trust: safeguarding actions, providing transparency, remembering context, and anticipating needs. Safeguards like confirmation dialogs and rollback capabilities ensure security, while transparency transforms AI agents into comprehensible partners. Remembering user preferences and adapting to feedback further enhances trust, and anticipatory capabilities allow agents to proactively support workflows. Organizations are advised to implement AI agents in low-risk environments initially, gradually increasing reliance as trust grows. The study emphasizes that trust compounds through consistent positive micro-interactions, transforming AI agents into indispensable partners, while a single failure can significantly undermine accumulated confidence.
Jan 05, 2026
1,034 words in the original blog post.