May 2026 Summaries
21 posts from GitLab
Filter
Month:
Year:
Post Summaries
Back to Blog
Anthropic's Claude Opus 4.8 is a new model integrated into the GitLab Duo Agent Platform, designed to enhance the precision of complex, multi-step agentic tasks such as coding, document drafting, and data analysis. This model improves long-horizon agent execution by allowing agents to follow instructions autonomously over extended periods, resulting in more efficient and accurate outcomes with minimal intervention. It also supports mid-conversation system prompts, enabling updates without restarting the prompt cache, which is beneficial when asynchronous context changes occur during a session. Available now in GitLab Duo Agent Platform, Opus 4.8 requires GitLab Credits, and users can access it through a free trial or via existing GitLab Premium or Ultimate subscriptions.
May 28, 2026
338 words in the original blog post.
Coding agents have the potential to revolutionize software development by rapidly transforming prompts into merge requests, but their effectiveness hinges on the context they receive. Many demos highlight narrow use cases without addressing post-commit challenges such as CI/CD pipeline failures or security issues. When integrated with platforms like GitLab, coding agents can leverage full lifecycle context, including issues, pipelines, and security policies, to improve code quality, security assessments, and review cycles. Tutorials with GitLab illustrate how agents, when given progressively more platform context, can better align with project requirements and reduce review rounds. The use of AGENTS.md files standardizes instructions and improves agent output quality across projects. However, the utility of coding agents is constrained by their context window limits, necessitating efficient context delivery. Organizations must ensure their DevSecOps platforms provide the necessary context and controls to maximize the benefits of agentic coding while maintaining security and quality standards.
May 28, 2026
1,868 words in the original blog post.
GitLab 19.0 introduces SBOM-based dependency scanning to enhance application security by identifying vulnerabilities in third-party code dependencies, addressing the challenges posed by deep dependency trees and fast release cycles. This feature creates a software bill of materials (SBOM) that inventories every direct and transitive dependency in a project, allowing developers to trace vulnerable packages back to their source and focus on those actually used by their code. The SBOM-based analyzer, supporting over 24 package ecosystems, offers a more comprehensive approach than traditional scanners by parsing lockfiles and dependency graphs directly. The tool allows continuous scanning for new vulnerabilities and integrates seamlessly with GitLab's existing CI/CD workflows, presenting findings within merge requests and on vulnerability dashboards. GitLab 19.0 also introduces security configuration profiles that enable teams to enforce scanning standards across multiple projects easily. This feature is available for GitLab Ultimate customers and is designed to streamline the transition from Gemnasium-based analyzers, providing thorough documentation and support for a smooth migration.
May 26, 2026
845 words in the original blog post.
GitLab 19.0 introduces security configuration profiles, which offer a centralized approach to managing security scanners across multiple projects, addressing the scalability issues faced by CI/CD platforms as organizations grow. These profiles enable teams to apply static application security testing (SAST), dependency scanning, and secret detection uniformly across all projects from the outset, eliminating the need for manual configuration via individual .gitlab-ci.yml files. Default profiles come preconfigured, activating scan triggers such as merge request and branch pipelines, ensuring consistent security coverage and addressing vulnerabilities, compromised dependencies, and exposed secrets efficiently. This approach is particularly beneficial given the rapid code velocity driven by AI, reducing the drift between code development and security measures. The profiles are available on GitLab Ultimate and can coexist with existing scanner configurations, providing flexibility for users during transition periods.
May 26, 2026
1,449 words in the original blog post.
GitLab 19.0 introduces Components Analytics within its CI/CD Catalog, providing enhanced visibility into the usage and adoption of standardized pipeline components across organizations. This feature helps platform teams track which versions of components are being utilized in various projects, addressing a common issue where once components are deployed, it becomes difficult to monitor their usage, leading to potential security risks from outdated versions. The Components Analytics offers a high-level adoption view for all tiers, showing how widely components are used, and a detailed drill-down available on GitLab Ultimate that identifies specific projects and their component versions. This visibility is crucial as AI increasingly generates production pipelines, ensuring standards are maintained and security vulnerabilities can be managed efficiently. Unlike competitors like GitHub Actions and CircleCI, GitLab uniquely pairs a comprehensive CI component catalog with native analytics, allowing organizations to audit and manage their CI infrastructure effectively.
May 21, 2026
1,041 words in the original blog post.
GitLab 19.0 introduces Developer Flow, a new AI-driven tool that automates and streamlines the merge request (MR) lifecycle, addressing the manual tasks that occur between opening and merging an MR. This innovation includes features like an AI agent that handles reviewer feedback, resolves long-running branch conflicts, and researches unfamiliar codebases, effectively reducing the bottlenecks developers face. Developer Flow extends beyond initial code writing, enabling AI to participate actively throughout the MR process, thus allowing developers to focus on higher-level tasks like steering and decision-making. Additionally, the release features an autonomous merge conflict resolution tool and a one-click rebase and merge functionality, further minimizing manual interventions and enhancing delivery velocity. GitLab customers can access these capabilities through the GitLab Duo Agent Platform on Premium and Ultimate tiers, with the option to try a free trial for those interested in experiencing the benefits of this automation.
May 21, 2026
1,067 words in the original blog post.
GitLab 19.0 addresses the challenges faced by customers operating in highly regulated, air-gapped, or data-residency-constrained environments by expanding support for self-hosted open source models. These updates enable teams to select models that align with specific workflow requirements, even in isolated settings where external API calls and internet connectivity are restricted. The release includes models like Mistral Devstral 2 123B, GLM-5.1, Kimi-K2.6, and MiniMax-M2.7, which can be deployed on-premises to ensure data remains within the user's environment. The primary deployment pattern involves using vLLM, GitLab's suggested serving platform, on either local hardware or GPU-enabled virtual machines in private clouds. This approach provides on-demand capacity while maintaining data isolation. GitLab 19.0 also introduces hybrid deployment options, allowing for a mix of self-hosted and GitLab-managed models, and offers configurations tailored to both offline and online license holders.
May 21, 2026
486 words in the original blog post.
GitLab Secrets Manager, introduced in the public beta of GitLab 19.0, aims to enhance security by managing credentials within the GitLab platform itself, reducing the risk of leaks often caused by developers placing credentials in unsecured locations like CI/CD variables or config files. By integrating with GitLab’s existing project and group structures, Secrets Manager allows each secret to be scoped specifically to the jobs that need it, governed by the same access controls already in place, and limits the exposure of credentials. This approach contrasts with standalone vaults, which require maintaining separate systems and access models, potentially leading to security gaps. The GitLab Secrets Manager logs all secret-related events, enabling quick traceability when incidents occur, and it supports integration with other secret management tools, offering flexibility in adoption. Currently available for Premium and Ultimate users, the feature is free during the beta period, with future plans for it to become a paid feature.
May 21, 2026
1,088 words in the original blog post.
GitHub's recent announcement about Copilot CLI now supporting bring-your-own-key (BYOK) and locally running models highlights a shift in AI model flexibility and control for developers, enabling them to run models offline or through their own providers. However, this flexibility presents challenges in automated workflows across software delivery pipelines, as agentic AI can execute tasks without human intervention, raising significant security and governance concerns. GitLab's Duo CLI, built on the GitLab Duo Agent Platform, addresses these issues by providing governance controls applicable throughout pipeline execution, supporting headless mode for non-interactive tasks, and ensuring all AI-driven actions are auditable with composite identity and prompt injection detection. This approach emphasizes the importance of platform-level security models and governance architecture for deploying AI capabilities in production, offering both self-hosted and GitLab-hosted model options to maintain data sovereignty.
May 18, 2026
723 words in the original blog post.
GitLab Dedicated for Government has achieved GovRAMP Authorization, providing state and local agencies with an expedited path to modernizing and securing their software supply chains through a compliant DevSecOps platform. This single-tenant solution offers enhanced data residency, isolation, and private networking capabilities, allowing agencies to balance the operational ease of SaaS with necessary infrastructure-level control. GitLab's platform integrates foundational AI capabilities, including GitLab Duo, within a secure compliance boundary and addresses critical security challenges by uniting DevSecOps teams on a single platform. It incorporates comprehensive security and compliance features, such as native security scanning and policy automation, while supporting zero trust architecture implementation and offering centralized visibility through security dashboards and compliance management tools. With support for hybrid and multi-cloud strategies, GitLab Dedicated for Government is designed to help government agencies navigate budget constraints, workforce challenges, and sophisticated cybersecurity threats efficiently, enabling them to focus on mission-critical priorities without the burden of infrastructure management.
May 18, 2026
1,539 words in the original blog post.
Codex, a coding agent, enhances the developer experience by quickly addressing code-related tasks within the terminal, streamlining the transition from idea to implementation. This capability is particularly effective when integrated with GitLab, as demonstrated in a tutorial using the Tanuki IoT Platform project to address bugs in a Rust metrics backend. By leveraging Codex and GitLab Duo Agent Platform, the process of fixing bugs, improving code quality, and managing the software lifecycle becomes more efficient. The tutorial covers three use cases: starting with local bug fixes, incorporating GitLab MCP to align with issue requirements, and using Codex as an external agent to handle review feedback within merge requests. This integration not only speeds up coding but also ensures that code changes are well-documented, tested, and ready for deployment, aligning coding speed with the collaborative and verification processes crucial in software development. The synergy between Codex and GitLab allows for a comprehensive approach to software delivery that maintains the integrity of the merge request process, while also enabling the involvement of third-party coding tools.
May 18, 2026
3,118 words in the original blog post.
Enterprise vulnerability reports often contain numerous findings ranked using the Common Vulnerability Scoring System (CVSS), which may not accurately reflect the actual risk within a specific environment. GitLab's vulnerability management policies now allow for automatic overrides of these default CVSS severity levels based on user-defined conditions, ensuring that vulnerability reports align with an organization's unique risk model. Severity override policies can adjust vulnerability severity levels on every default-branch pipeline through rules that define match criteria and an override action, such as increasing, decreasing, or setting severity levels. For instance, internal service vulnerabilities can be downgraded due to lower exposure risk, while injection vulnerabilities in production code might be upgraded to Critical. Additionally, these policies can normalize severity across different scanners, align severity with exploitation intelligence, and apply organization-wide risk models at the group level. All automated changes are logged for audit purposes, and manual overrides by authorized users always take precedence, preserving a comprehensive record of changes and ensuring accurate risk assessment.
May 13, 2026
1,625 words in the original blog post.
AI-assisted development is progressing rapidly, often outpacing the security frameworks meant to govern it, leading to unnoticed vulnerabilities. GitLab Ultimate integrates application security as a fundamental part of its platform, addressing this issue by providing comprehensive security visibility, enforcement, and remediation within the software development lifecycle. It offers a Group Security Dashboard that consolidates security findings from various scanning tools and surfaces identity risks often overlooked by others. Policies are enforced automatically within the platform, ensuring that security measures are applied consistently across all projects and merge requests, regardless of whether changes are human or AI-driven. The platform also streamlines the remediation process by integrating security findings directly into the development workflow, using AI-generated recommendations to assist developers in addressing vulnerabilities efficiently. This approach helps close the gap between security policies and their implementation, supporting safe and secure AI-assisted development.
May 13, 2026
1,013 words in the original blog post.
GitLab is undergoing a significant restructuring to align with a strategic vision focused on the agentic era, where AI technologies play a central role in software development. The company is making structural changes, such as reducing its geographical footprint by 30% and flattening the organizational hierarchy to improve efficiency and speed. It plans to create smaller R&D teams with end-to-end ownership and integrate AI agents into its processes for automation. The restructuring is transparent, involving employee input, and aims to better position GitLab for future growth in the AI-driven software engineering landscape. The company reaffirms its commitment to customers, maintaining current support and service levels while focusing on innovation, as outlined in its strategic architectural bets and operating principles centered on speed, ownership, and customer outcomes. Amid these changes, GitLab emphasizes the importance of retaining talent and offers incentives like a new bonus program to enhance employee experience and engagement. The final scope and financial impact of this restructuring will be shared during GitLab's upcoming earnings call, with a commitment to reinvest savings into strategic initiatives to accelerate growth and maintain leadership in the evolving market.
May 11, 2026
3,767 words in the original blog post.
GitLab 18.11 introduced the general availability of Gitaly on Kubernetes, allowing teams to fully integrate their GitLab components within Kubernetes environments without relying on virtual machines for Gitaly. This advancement simplifies operations by eliminating the complexities of a hybrid architecture. However, transitioning Gitaly to Kubernetes required overcoming challenges related to Git operations' memory-intensive nature and the unpredictable usage patterns that could lead to out-of-memory events. To address these, Gitaly processes run in dedicated cgroups, and Kubernetes Pods are configured to handle cgroupfs writes and Pod restarts effectively. A key improvement involves configurable client retries, ensuring minimal downtime during Pod upgrades despite the abrupt nature of Kubernetes Pod restarts. Testing demonstrated nearly identical success rates for Git operations between virtual machines and Kubernetes environments. While high availability via Gitaly Cluster (Praefect) is not yet available for Kubernetes, its development is underway. This integration allows users to consolidate their GitLab infrastructure entirely within Kubernetes for a streamlined, Kubernetes-native deployment using the GitLab Helm chart.
May 07, 2026
659 words in the original blog post.
GitLab has introduced fine-grained personal access tokens (PATs) in beta, allowing users to restrict tokens to specific permissions required for particular tasks, enhancing security by limiting the potential damage if a token leaks. Unlike traditional PATs, which often have broad access across multiple projects, fine-grained PATs allow permissions to be assigned per resource, such as Issues, Merge Requests, and Pipelines, with distinct Create, Read, Update, and Delete permissions. This new approach means a token can be scoped to specific projects or groups and individual tasks, thereby reducing exposure and making it easier to audit token permissions. Although currently covering about 75% of REST API endpoints, the full rollout will extend support to all REST and GraphQL endpoints. During the beta phase, existing PATs remain functional, and users can experiment with both traditional and fine-grained tokens. Feedback is encouraged to refine the implementation and fully embrace the least-privilege token model.
May 07, 2026
541 words in the original blog post.
Onboarding a new microservice into an established GitOps workflow can be a complex and time-consuming task that involves generating manifests, updating pipelines, and ensuring correct configurations, which are prone to errors if done manually. The GitLab Duo Agent Platform offers a solution by enabling the creation of custom AI agents that automate this process, tailored to specific applications and workflows. In a tutorial example featuring a fictitious bank called TanukiBank, the platform facilitates the development and integration of a new microservice, thereby saving significant engineering time and effort. The process involves generating a system prompt using GitLab Duo, creating a custom agent to manage the onboarding, and executing the onboarding with minimal manual intervention. This approach not only accelerates deployment but also maintains governance and traceability by keeping all artifacts within GitLab, ensuring a balance between automation speed and enterprise control.
May 07, 2026
1,506 words in the original blog post.
Developers highly value Claude Code for its ability to aid in understanding unfamiliar code, proposing quick fixes, and scaffolding new features, akin to working with a senior engineer. However, the advancement of AI coding tools like Claude Code, which accelerates code writing, has highlighted challenges in the broader software lifecycle, such as increasing bug backlogs, pipeline failures, and security vulnerabilities. GitLab addresses these issues by streamlining the remaining stages of the software lifecycle, including CI/CD, security scanning, and code reviews, ensuring a comprehensive workflow from code writing to shipping. This tutorial demonstrates integrating Claude Code with GitLab Duo Agent Platform, showcasing scenarios where Claude Code efficiently fixes bugs and develops features, while GitLab manages CI/CD pipelines, security scans, and code reviews, ensuring that all actions align with organizational security policies and guardrails. The collaboration between these tools emphasizes the importance of balancing fast-paced code development with secure, certified software delivery, offering solutions for both new and existing GitLab users to enhance their development processes.
May 06, 2026
2,241 words in the original blog post.
As AI agents evolve to assist individuals in working more efficiently, understanding how to design AI for optimal team collaboration becomes crucial. A user experience researcher explored 17 agentic platforms to identify how these tools support human teams working alongside AI, discovering eight key capability patterns that consistently deliver three customer outcomes: moving faster, working smarter, and staying in control. These patterns encompass status updates, work routing, team communication, role-specific agents, conversational context, role-based access control, governed environments, and collaborative agent-building. The study highlights the importance of embedding AI within existing team tools, emphasizing governance and shared ownership in agent development. Successful platforms create a coherent team experience and tackle the coordination tax by integrating governance solutions, though few offer a unified experience. GitLab's DevSecOps lifecycle presents a structural advantage, as its platform inherently supports AI agents within the software delivery workflow, exemplified by the GitLab Duo Agent Platform, which ensures streamlined orchestration and execution within teams.
May 05, 2026
922 words in the original blog post.
Starting August 17, 2026, Atlassian will begin collecting customer metadata and in-app content from its cloud products like Jira and Confluence to train its AI offerings, a shift that follows industry trends towards opt-out-by-default data collection policies. This change affects approximately 300,000 organizations, with mandatory metadata collection for customers on the Free, Standard, and Premium tiers, and only Enterprise-tier customers having the option to opt out. The data collected, which includes operational signals and user-generated content, will be used for AI training, raising concerns about data governance and compliance, especially in regulated industries where documentation and risk reassessment obligations are triggered by such material changes. GitLab, in contrast, maintains a policy of not using customer data for AI training across all tiers, highlighting the importance of transparency and customer control over data in the evolving landscape of AI integration in software services. For organizations using Atlassian, especially those in sensitive sectors, the upcoming changes necessitate a reevaluation of data management practices and potential consideration of alternative platforms that align with specific compliance and security needs.
May 04, 2026
1,488 words in the original blog post.
GitLab's Threat Intelligence team, part of their Security Operations, has published an article detailing the tactics of North Korean state actors, specifically focusing on how they use Visual Studio Code (VS Code) tasks to distribute malware in a campaign known as Contagious Interview. This campaign exploits victims by posing as job interviews, leading them to download malicious code repositories which execute harmful tasks under the guise of legitimate developer processes. GitLab has developed custom controls to detect and prevent such attacks, particularly by identifying malicious subprocesses through the node-pty.spawn() library used in VS Code. Through extensive collaboration across various security disciplines, including Red and Purple Team exercises, GitLab has crafted preventive measures that avoid false positives by focusing on suspicious background subprocesses without user interaction. Additionally, they advocate for educational campaigns and proactive configurations to harden systems against similar threats. Their work aims to inspire others in the security community to adopt similar proactive and innovative measures to combat advanced persistent threats.
May 04, 2026
1,255 words in the original blog post.