February 2026 Summaries
16 posts from GitLab
Filter
Month:
Year:
Post Summaries
Back to Blog
Anthropic's introduction of Claude Code Security, an AI system designed to detect vulnerabilities and suggest fixes, has sparked debate about the future of traditional application security (AppSec) tools. While AI's ability to write and secure code raises questions about the potential obsolescence of AppSec, the complexity of enterprise security extends beyond mere detection. Organizations must consider whether their software is safe to deploy, how evolving environments and dependencies affect their risk posture, and how to govern increasingly AI-assembled codebases. GitLab positions itself as a comprehensive orchestration layer that governs the software lifecycle by embedding governance, policy enforcement, security scanning, and auditability into development workflows. This ensures that AI-assisted development is both rapid and trustworthy. As AI systems advance in identifying vulnerabilities, the critical challenge remains in establishing human-defined governance to set boundaries and maintain accountability. Effective security decisions require context, which large language models (LLMs) lack; thus, a robust governance framework is necessary to manage the dynamic risk associated with continuously evolving software. As AI reshapes software creation, the focus shifts from whether to use AI to how organizations can safely scale its integration, with strong governance being pivotal to leveraging AI's potential without compromising security.
Feb 27, 2026
729 words in the original blog post.
The GitLab MSP Partner Program is a new global initiative designed to enable managed service providers (MSPs) to deliver GitLab as a fully managed service, addressing the growing demand for modern DevSecOps platforms. This program offers a structured framework for MSPs, including financial benefits, technical enablement, and go-to-market support, allowing them to confidently invest in building a GitLab managed services practice. By handling operational aspects such as deployment, migration, and support, MSP partners allow development teams to focus on software creation while benefiting from a streamlined, documented DevSecOps experience. The program also positions MSPs to assist organizations in integrating AI into their workflows through the GitLab Duo Agent Platform, offering a governed environment for AI adoption. The program is suitable for MSPs already providing cloud, infrastructure, or application operations services and aims to foster long-term customer relationships. New partners can apply through the GitLab Partner Portal, with no minimum ARR or customer count required, and undergo a structured 90-day onboarding process to launch their managed offering.
Feb 26, 2026
732 words in the original blog post.
Deploying an AI agent built with Google's Agent Development Kit (ADK) to Google Cloud's Agent Engine using GitLab's native integration and CI/CD pipelines streamlines the complex process of AI deployment by automating infrastructure management, scaling, and security considerations. Agent Engine serves as a managed runtime environment that alleviates the need for manual server management, while GitLab enhances security through built-in vulnerability scanning and keyless authentication via Workload Identity Federation. The tutorial guides users through configuring IAM integration, setting up a CI/CD pipeline with GitLab, deploying the agent, and verifying its operation in the Google Cloud Console. By leveraging GitLab's DevSecOps platform and the integrated capabilities of Google Cloud, developers can efficiently deploy and manage AI agents with enhanced security and minimal manual intervention.
Feb 26, 2026
1,055 words in the original blog post.
Modern software development teams often struggle to balance speed with maintaining code quality, security, and consistency, particularly when AI coding assistants function independently from the broader development process. GitLab Duo Agent Platform addresses this by integrating external AI models, such as Anthropic's Claude and OpenAI's Codex, directly into the GitLab environment, allowing for customized AI capabilities that align with specific organizational needs and workflows. This integration allows AI agents to autonomously handle tasks like generating production-ready code from issue descriptions, conducting comprehensive code reviews, and automating deployment pipelines, thereby enhancing productivity and allowing developers to focus on more innovative tasks. The platform's seamless incorporation of AI into existing workflows ensures that development teams can accelerate delivery timelines, maintain consistent code quality, and minimize repetitive work, effectively transforming AI from an isolated tool into an integral part of the development lifecycle.
Feb 26, 2026
762 words in the original blog post.
Platform and DevOps engineers face challenges in managing fragmented tools and infrastructure, prompting GitLab to introduce two new beta features aimed at improving CI/CD infrastructure control without needing additional third-party tools. The CI/CD Job Performance Metrics feature provides job-level performance data directly on the CI/CD analytics page, allowing users to identify slow or failing jobs through sortable, searchable tables. Meanwhile, the Container Virtual Registry offers a unified GitLab endpoint for pulling container images from multiple registries with built-in caching, simplifying image management and reducing operational overhead. Both features are open for community feedback, aiming to enhance their utility based on user input, with more Core DevOps betas anticipated throughout the year.
Feb 25, 2026
792 words in the original blog post.
GitLab has introduced passkeys as a more secure and convenient method for accessing accounts, offering passwordless sign-in and serving as a phishing-resistant two-factor authentication (2FA) option. These passkeys utilize WebAuthn technology and public-key cryptography, where the private key remains on the user's device and the public key is stored on GitLab, ensuring that even if GitLab is compromised, credentials cannot be misused. Available across various desktop browsers, mobile devices, and FIDO2 hardware security keys, passkeys allow users to register multiple devices for easy access. With the implementation of passkeys, GitLab aligns with the CISA Secure by Design Pledge to enhance security and promote the use of multi-factor authentication across its products. This initiative aims to make signing into GitLab more secure and convenient for users, and the GitLab team invites feedback for potential improvements.
Feb 25, 2026
258 words in the original blog post.
GitLab uses a GPG key to sign the metadata of its apt and yum repositories to ensure the integrity of Linux and GitLab Runner packages, with the current key set to expire on February 6, 2028, after an extension from 2026. The extension of the key's expiration is part of GitLab's security policy to limit exposure risks without causing disruption to users, as rotating to a new key would necessitate all users to replace their trusted key. Existing users are advised to refer to official documentation to update their configurations, while new users simply need to follow standard installation guides. The public key can be refreshed from any GPG keyserver or downloaded directly from GitLab's package site, and additional support is available through the omnibus-gitlab issue tracker.
Feb 24, 2026
300 words in the original blog post.
GitLab and TCS have partnered to help enterprises enhance software innovation and delivery through a comprehensive DevSecOps platform that integrates AI-driven features. This collaboration aims to address challenges such as fragmented toolchains, inconsistent security, and manual compliance, which slow down the software delivery process. By leveraging GitLab's unified data model and TCS's industrialized adoption strategies, they provide a seamless transition from standardization to Intelligent Orchestration, enabling a cohesive development environment where AI agents automate tasks like coding, testing, and compliance. The GitLab Duo Agent Platform introduces AI agents that collaborate with developers to speed up releases and streamline workflows, ensuring security, compliance, and efficiency across the software development lifecycle. This partnership capitalizes on TCS's extensive industry experience to tailor GitLab's capabilities to meet enterprise-specific needs, allowing for scalable, secure, and compliant software delivery across diverse cloud environments.
Feb 24, 2026
842 words in the original blog post.
GitLab employs a GNU Privacy Guard (GPG) key to sign its Omnibus packages to ensure their integrity and security, separate from the keys used for repository metadata and GitLab Runner signing. The expiration of this package signing key, initially set for February 14, 2026, has been extended to February 16, 2028, as part of GitLab's security protocols to minimize risk in case of key compromise. This extension is chosen over key rotation to reduce user disruption, as rotation would necessitate all users to replace their trusted key. Users who verify package signatures need to update their copies of the signing key, though those who do not engage in such verification or have not configured their managers to do so need take no action to continue installing Omnibus packages. The updated key can be found on GPG keyservers or downloaded directly from GitLab’s package site, and additional help can be sought by opening an issue in the omnibus-gitlab issue tracker.
Feb 20, 2026
313 words in the original blog post.
Organizations in regulated industries face challenges in adopting AI-powered automation due to strict constraints on data residency, vendor control, and governance. GitLab addresses these challenges with the release of GitLab 18.9, enhancing the GitLab Duo Agent Platform to function as a governable AI control plane suitable for the most stringent regulatory environments. The new Self-Hosted for Online Cloud Licenses feature introduces a usage-based billing model, enhancing cost transparency and internal chargeback accuracy, while also allowing enterprises to run AI models on their own infrastructures. The "Bring Your Own Model" capability further extends flexibility by enabling integration of third-party or self-hosted models via GitLab's AI Gateway, allowing administrators to retain model choice and control. These advancements provide engineering leaders with a unified control plane for agentic AI, offering model freedom alongside robust governance, thus replacing fragmented AI solutions while maintaining compliance.
Feb 19, 2026
652 words in the original blog post.
Security and development teams often face challenges in prioritizing the remediation of numerous vulnerabilities due to a lack of contextual insights. The updated GitLab Security Dashboard addresses this by offering trend tracking, vulnerability age distribution, and risk scoring by project, providing a consolidated view of vulnerability data across projects, groups, and business units. Released in version 18.6 and further enhanced in 18.9, the dashboard includes new filtering options and visualizations that allow teams to slice data by severity, status, scanner, or project, making it possible to track open vulnerabilities, remediation velocity, vulnerability age distribution, and risk scores over time. These risk scores help prioritize which vulnerabilities pose the greatest threat, leveraging factors like vulnerability age, EPSS, and KEV scores. This update aims to make security efforts measurable and integrated into development workflows by converting raw data into actionable insights, enabling teams to focus on reducing risk effectively. The GitLab Security Dashboard also facilitates executive reporting by illustrating improvement in risk posture with clear trendlines, empowering developers to prioritize remediation efforts without relying on external tools.
Feb 19, 2026
486 words in the original blog post.
The report provides an in-depth analysis of North Korean nation-state threat actors using legitimate platforms, particularly GitLab, to conduct cyber operations and distribute malware under the guise of IT worker campaigns. Since 2022, these actors have posed as recruiters to manipulate software developers into executing malicious code, impacting thousands and enabling financial and identity theft. GitLab identified and banned accounts associated with these activities, offering insights into the infrastructure and techniques used, including the use of JavaScript-based malware and VPNs for concealment. The document also includes case studies that highlight the evolving tactics, such as synthetic identity creation, the use of automation for identity verification, and the cultivation of facilitators globally. Despite disruptions, the report anticipates continued cyber activities due to their effectiveness and the value of developer endpoints to North Korean actors, and it underscores the importance of vigilance and collaboration in mitigating these threats.
Feb 19, 2026
13,971 words in the original blog post.
GitLab has introduced a 99.9% availability service-level agreement (SLA) for its Ultimate customers on GitLab.com and GitLab Dedicated, offering service credits when this threshold is not met to ensure reliable DevSecOps workflows. This SLA covers essential platform services such as issues, merge requests, Git operations, and registry operations, with availability being monitored across multiple geographic locations to reflect actual customer experiences accurately. If availability drops below 99.9%, customers can claim credits by submitting a support request within 30 days of the affected month, and GitLab will review the claim and apply credits to future invoices if applicable. Additionally, GitLab is committed to addressing issues that might not be captured by automated monitoring, such as application bugs or performance degradation, by encouraging customers to submit claims for a holistic review. This initiative highlights GitLab's dedication to aligning its success with customer outcomes, ensuring that software delivery workflows remain uninterrupted and reliable.
Feb 18, 2026
524 words in the original blog post.
GitLab has integrated Claude Opus 4.6, Anthropic's most advanced AI model, into its Duo Agent Platform, providing users with enhanced capabilities for managing complex development workflows. This model, known for its proactive and agentic nature, can autonomously handle tasks and requires minimal oversight, making it suitable for challenging tasks. It features a 1 million token context window, significantly larger than its predecessor, allowing it to process extensive codebases and documentation in one interaction. The integration with GitLab's unified platform ensures seamless access to DevSecOps data, enhancing project context and facilitating high-quality outcomes without leaving the GitLab environment. Claude Opus 4.6 also supports multi-agent orchestration, enabling developers to delegate complex tasks to sub-agents, thereby optimizing the development process. Although the model is available for all agents and agentic chat on GitLab.com, it does not support GitLab Duo Classic features, and its integration with supported IDEs is forthcoming.
Feb 17, 2026
505 words in the original blog post.
GitLab's new managed service offering, DevSecOps-as-a-Service, in collaboration with Oracle Cloud Infrastructure (OCI) and Data Intensity, aims to ease the operational challenges of managing GitLab Self-Managed instances. This service provides the control and customization benefits of a self-managed platform while outsourcing the infrastructure management to Data Intensity's experts, leveraging OCI's high-performance and cost-effective cloud infrastructure. The service includes a standalone GitLab instance with features like 24x7 monitoring, automated backups, disaster recovery, and scalability to match organizational needs, all intended to reduce operational overhead for companies with strict compliance, security, or data residency requirements. OCI supports diverse deployment models, and the combination of GitLab's platform, OCI's infrastructure, and Data Intensity's management offers a comprehensive solution allowing teams to focus on software development. Organizations interested in this service can explore migration options and deployment planning through Data Intensity's website, reflecting GitLab's commitment to flexible deployment and management solutions.
Feb 10, 2026
631 words in the original blog post.
Git 2.53.0 introduces several key enhancements, including geometric repacking support that now works with partial clone repositories, addressing previous compatibility issues with promisor packfiles. This update allows the geometric strategy to handle promisor objects properly, moving it closer to becoming the default repacking strategy. Additionally, git-fast-import(1) has been improved with a new strip-if-invalid mode that preserves valid commit signatures while stripping invalid ones, aiding in maintaining signature integrity during history rewrites. The git-repo-structure command has been expanded to collect more data, such as the total size of reachable objects, providing a clearer view of repository performance characteristics. These updates, led by contributors like Patrick Steinhardt, Christian Couder, and Justin Tobler, reflect ongoing efforts to enhance Git's functionality and usability.
Feb 02, 2026
1,311 words in the original blog post.