June 2026 Summaries
16 posts from GitLab
Filter
Month:
Year:
Post Summaries
Back to Blog
Claude Sonnet 5, now accessible on the GitLab Duo Agent Platform via GitLab's AI Gateway, enhances the efficiency and reliability of software development tasks by completing all benchmark tasks in GitLab's evaluation suite and improving issue resolution by 8.8% compared to its predecessor. This model facilitates multi-step tasks, code generation, and scalable workflows, ensuring higher-quality code and reducing the costs associated with incomplete runs. It offers a cost-effective solution for everyday development work by balancing quality, speed, and cost, while allowing for model selection based on the complexity of tasks. Available to all tiers and deployment models, Claude Sonnet 5 uses GitLab Credits, with options for free trials and integration for existing GitLab subscribers.
Jun 30, 2026
590 words in the original blog post.
Git 2.55.0 introduces several notable features and improvements, including contributions from the Git team at GitLab. Key updates include the addition of the git-history(1) fixup command, which simplifies the process of amending changes into an existing commit by automatically rebasing related branches. The fsmonitor daemon now supports GNU/Linux, using inotify(7) to enhance git-status(1) performance in large repositories. Git-push(1) can now push to remote groups, a feature previously limited to git-fetch(1). A new option for limiting the git log --graph lane width improves readability by truncating excessive lanes with a tilde mark. Rust continues to evolve in the Git codebase, with the Rust compiler now required unless explicitly disabled, reflecting an ongoing community effort to integrate Rust into Git's infrastructure. Additionally, git-grep(1) and git-cherry(1) commands benefit from improved performance through batched blob downloads in partial clones.
Jun 29, 2026
2,133 words in the original blog post.
GitLab continues to evolve and expand its offerings with a focus on AI integration, security enhancements, and improved governance. Recent updates include the release of GitLab 19.1 and multiple patch releases addressing security vulnerabilities. The company has been recognized as a leader in the 2026 Gartner Magic Quadrant for DevSecOps Platforms and is actively working with partners like Capgemini to accelerate DevSecOps transformation. GitLab's innovations, such as the GitLab Duo Agent Platform and GitLab Orbit, aim to enhance code management and lifecycle context. The platform also emphasizes security with features like full security scanner coverage, SBOM-based dependency scanning to reduce supply chain risks, and managing CI/CD credentials with the GitLab Secrets Manager. Additionally, GitLab offers solutions tailored for government use with GovRAMP authorization and is committed to refining AI governance and operations through updates like the AI Catalog.
Jun 25, 2026
604 words in the original blog post.
Integrating security testing directly into the software delivery workflow can significantly enhance the speed and quality of software development by consolidating various security tools like SAST, SCA, Secret Detection, and DAST into one platform, reducing costs and integration complexities. This approach allows security findings to appear directly in developers' environments, such as merge requests and IDEs, which minimizes context switching and keeps the workflow seamless. With compliance controls for standards like SOC 2, ISO 27001, and PCI DSS, audit-ready evidence can be automatically collected across pipelines. GitLab exemplifies this model by reducing incident resolution times and providing comprehensive security coverage across the software development lifecycle. Early detection of vulnerabilities is facilitated by built-in scans running on every push, and AI-driven tools like GitLab Duo offer explanations and automatic remediation of security issues, thereby improving the overall security posture and efficiency in addressing vulnerabilities. This integrated approach not only accelerates vulnerability detection and management but also empowers teams to produce secure software more rapidly, supported by a maturity framework that guides them through different stages of security advancement.
Jun 25, 2026
495 words in the original blog post.
Google Antigravity users can now enhance their development workflows by installing the GitLab Orbit lifecycle context graph from the Antigravity MCP Store, providing structured access to projects, pipelines, and more within their GitLab instances. The integration enriches Google's agent-first development platform by indexing GitLab data into a knowledge graph, enabling precise and complex software lifecycle queries without the need for manual context-switching. This allows agents to efficiently analyze project dependencies, identify unresolved vulnerabilities, and determine appropriate reviewers for merge requests, significantly improving response times and reducing errors in coding agents. Users benefit from enhanced onboarding, dependency mapping, and blast radius analysis, with tools like architecture diagram generation and Walkthrough Artifacts providing up-to-date, actionable insights. GitLab Orbit is accessible to GitLab Premium and Ultimate subscribers, integrating seamlessly with the Duo Agent Platform, and consumes GitLab Credits for queries, while its schema retrieval is free.
Jun 25, 2026
926 words in the original blog post.
GitLab 19.1 introduces enhanced security and governance features aimed at improving application security and providing comprehensive oversight of AI agent activities. The update allows for the integration of third-party security scanners across all projects, ensuring consistent and provable scanner coverage, with automatic remediation of vulnerabilities through the GitLab Duo Agent Platform. Secret detection now scans all commits on a new branch, reducing the risk of missed secrets and minimizing false positives by adding a confidence score to each finding. Additionally, the release includes AI audit event streaming in beta, which records all actions performed by AI agents as audit events, allowing for greater transparency and control over agent activities. Administrators can set approval guardrails for agent tools, ensuring sensitive actions require human review before execution, thereby maintaining accountability and governance within the codebase.
Jun 18, 2026
800 words in the original blog post.
GitLab 19.1 introduces event-driven triggers for Duo Flows, enhancing enterprise AI adoption by allowing workflows to run continuously and automatically without manual intervention. This update addresses the challenge of admins needing to know what is running in their environment by offering new governance controls and configuration validation to ensure safe operation of AI workflows. The release includes four new triggers that automate processes such as conflict detection, compliance checks, and post-approval steps, which were previously manually initiated. New security settings enable admins to restrict unapproved AI agents and flows, ensuring compliance and preventing unauthorized content from disrupting enterprise operations. Additionally, GitLab 19.1 moves validation to the point of flow creation to catch configuration errors early, thus improving reliability and reducing the impact of misconfigurations. A public beta feature also allows admins to create an allowlist of approved AI models, providing governance over AI usage while maintaining flexibility. These enhancements aim to streamline production automation, improve developer experience, and provide admins with greater control over their environments.
Jun 18, 2026
1,045 words in the original blog post.
GitLab and Capgemini have entered a global alliance partnership to enhance software development processes for clients worldwide by leveraging GitLab's portfolio, including the GitLab Duo Agent Platform, which integrates AI throughout the software development lifecycle. As a GitLab Select Partner, Capgemini will offer specialized implementation services aimed at accelerating client transformation, with a focus on cloud-native development, application modernization, and compliance with regulatory and data-residency requirements. This collaboration combines GitLab's DevSecOps orchestration capabilities with Capgemini's expertise in digital and business transformation, aiming to modernize software delivery, secure supply chains, and incorporate AI into development workflows, ultimately enabling organizations to streamline their software delivery lifecycle and expedite product deployment.
Jun 17, 2026
204 words in the original blog post.
GitLab has been recognized as a Leader in the 2026 Gartner® Magic Quadrant™ for DevSecOps Platforms for the fourth consecutive year, highlighting its role in balancing speed and control in software development. As enterprises face challenges in managing the proliferation of AI coding assistants and agentic AI, GitLab provides a unified platform for planning, building, securing, and deploying software, integrating source code management, CI/CD, security, and deployment capabilities. The platform supports enterprise-grade uptime with a 99.9% availability commitment and has been noted for its parity between SaaS and on-premises options, offering comprehensive governance without sacrificing deployment control. Recent innovations include next-gen source code management, a context graph called GitLab Orbit, and agentic triggers for task automation, positioning GitLab as a control layer in the agentic era. With a commitment to continuous innovation, GitLab has shipped new capabilities monthly for over 175 consecutive months, supporting organizations like Ericsson, Southwest, and Barclays PLC in meeting their operational and regulatory requirements.
Jun 17, 2026
981 words in the original blog post.
The GitLab Partner Program in the EMEA region continues to strengthen its network of DevSecOps professionals by recognizing partners who excelled in helping customers modernize their software development. The 2026 GitLab Partner Award Winners were celebrated for their outstanding performance and strategic collaboration. Among the honorees, cc cloud GmbH was recognized for its cloud-based application expertise in Central Europe, while Eficode, a leader in AI and software development lifecycle services, stood out in Northern Europe. Kiratech was noted for modernizing infrastructures in Southern Europe, and Bynet was acknowledged for its role in digital modernization in Eastern Europe and Israel. Capgemini | Sogeti, Devoteam, ITDOTCOM, Linux Polska, and Conoa also received awards for their innovative solutions, technical certifications, early success, customer acquisition, and co-marketing efforts, respectively, highlighting the diverse strengths and contributions of GitLab's partners in advancing DevSecOps and AI adoption across various regions.
Jun 17, 2026
631 words in the original blog post.
GitLab Orbit, now in public beta, addresses the challenges faced by AI-assisted engineering, particularly in navigating the complex systems surrounding code, such as related codebases, pipelines, deployments, and team ownership. By creating a live, queryable graph of an organization's code and its associated elements, Orbit allows for more efficient and accurate navigation and analysis. It enhances the capabilities of coding agents like Claude Code by providing precise answers through queries rather than extensive crawling, significantly improving speed and reducing errors. Orbit has demonstrated its effectiveness in real-world applications, such as at Compare the Market, where it outperformed other approaches in accurately placing comments and summarizing code changes. The tool integrates seamlessly with GitLab's existing data infrastructure, offering engineers a powerful resource for tracing changes, investigating incidents, and answering complex cross-system questions quickly, thus streamlining workflows and improving overall productivity in software development and maintenance.
Jun 10, 2026
1,248 words in the original blog post.
GitLab has partnered with Google Cloud to offer a fully managed platform that integrates Google's latest AI models, such as Gemini and Gemma, within GitLab’s DevSecOps architecture through managed service providers (MSPs) like Beyond and Digital Future. This collaboration allows teams to maintain control over their code, pipelines, and security data while benefiting from advanced AI capabilities, eliminating the need to compromise between governance and modern AI tools. By utilizing the Google Cloud Marketplace, organizations can leverage their existing commitments to simplify billing and procurement processes, ensuring a seamless integration of platform, inference, and infrastructure expenses. Additionally, GitLab's built-in audit and policy controls provide visibility and governance, allowing compliance teams to oversee agent actions and security findings. The platform's model lineup, which includes Gemini 3.5 Flash for high-throughput tasks and Gemma 4 for self-hosted environments, offers flexibility for various software tasks, ensuring that the deployment, model choice, and expenditure remain aligned within a single governed platform.
Jun 10, 2026
847 words in the original blog post.
GitLab Flex is an adaptable annual commitment model designed to address the unpredictable nature of software and AI usage in the agentic era, allowing businesses to adjust their needs without waiting for contract renewal. Unlike traditional fixed contracts, GitLab Flex offers the flexibility to reshape allocations monthly across platform seats, AI usage, and new capabilities, all within a single agreement that covers GitLab.com, Self-Managed, Dedicated, and air-gapped deployments. This approach allows companies to optimize costs by reallocating resources as projects and team requirements evolve, avoiding unnecessary expenditures on idle seats or the need for re-procurement when adopting new features. GitLab Flex incorporates volume discounts and predictable economics, with larger commitments unlocking better pricing while maintaining GitLab Premium and Ultimate features. Existing customers can continue their current contracts until renewal, while new agreements are encouraged to adopt the flexible model to better manage dynamic needs and budgetary shifts in line with the evolving software engineering landscape.
Jun 10, 2026
965 words in the original blog post.
GitLab's recent Transcend event highlighted several key announcements, including the introduction of next-generation source code management designed for agent-scale concurrency, GitLab Orbit for full software lifecycle context, and enhanced security and governance capabilities for coding agents. The event emphasized GitLab's commitment to transforming the software development process by integrating features that support efficient, context-aware, and secure coding practices. The platform's new offerings include the GitLab Duo Agent Platform, which facilitates seamless orchestration of development tasks, and GitLab Flex, a flexible buying model that adapts to the variable needs of AI adoption and usage. With these innovations, GitLab aims to streamline software delivery by addressing the challenges of agentic coding, ensuring that code generation and deployment are efficient, secure, and aligned with enterprise-scale operations.
Jun 10, 2026
1,941 words in the original blog post.
GitLab's Vulnerability Research team uncovered a coordinated supply chain attack on PyPI, which involved deploying a copy of the Shai-Hulud malware through five malicious packages, including typosquats of popular Python libraries and a compromised legitimate project. The malware executed automatically upon installation, stealing credentials from CI/CD environments across major cloud providers and propagating itself using stolen credentials. The attack utilized Python's .pth file mechanism for execution, bypassing the need for explicit imports, and involved complex payload obfuscation techniques, including ROT-N ciphers and AES encryption. GitLab was not directly affected but shared their findings to aid the broader security community, highlighting the need for vigilance as independent actors continue to exploit the Shai-Hulud toolkit across various ecosystems.
Jun 09, 2026
1,465 words in the original blog post.
Claude Fable 5, a Mythos-class model from Anthropic, was initially announced as available on the GitLab Duo Agent Platform, offering significant advancements over previous models, including improved first-shot correctness, long-horizon autonomy, and higher accuracy in interpreting technical content. It was designed to complete complex, multi-step tasks with fewer iterations and greater reliability, reducing the need for human oversight in AI agent workflows. Notably, Claude Fable 5 excelled in tasks such as multi-file refactors, incident investigations, and infrastructure-as-code definitions, showing enhanced bug-finding capabilities and faster incident resolution. However, as of June 12, 2026, access to Claude Fable 5 has been suspended on the platform due to a U.S. government directive, although other Claude models remain available.
Jun 09, 2026
694 words in the original blog post.