SAN FRANCISCO — GitLab Inc., the clever orchestration platform for DevSecOps, has introduced updates that give enterprises extra management as they scale agentic software program improvement. GitLab Devoted prospects, who already run their most delicate software program supply workloads on GitLab, can now run GitLab Duo Agent Platform inside that very same single tenant setting and area, join their very own fashions for inference, and hold AI-processed knowledge inside their current safety boundary.
GitLab 19.3 additionally ships at present with help for Secrets and techniques Supervisor, Circulate Creator Agent, and Bulk SAST False Optimistic Detection and Agentic SAST Vulnerability Decision. Each secret, whether or not it’s used inside a pipeline or by the infrastructure exterior the pipeline, now runs underneath the identical permission mannequin. Moreover, builders who personal a course of can now create customized agentic flows throughout the software program improvement lifecycle, and safety groups can ship ready-to-merge fixes in opposition to their backlog at scale. Collectively, these updates give engineering groups, course of house owners, and safety groups the pace of agentic AI, with out giving up the management they have already got in place.
The AI Gateway for GitLab Duo Agent Platform now runs inside GitLab Devoted single-tenant SaaS infrastructure, enabling agentic workloads to comply with the identical residency and isolation mannequin as the remainder of the software program improvement lifecycle inside GitLab. Regulated and residency-sensitive groups can unlock the usage of agentic AI for software program supply underneath the identical deployment mannequin their auditors already perceive.
Secrets and techniques Supervisor Extends Management Past the Pipeline
GitLab Secrets and techniques Supervisor is now in restricted availability as a paid add-on billed by way of GitLab Credit for GitLab.com prospects. Each CI secret is scoped to the setting, department, and safety standing of the job that wants it. Secrets and techniques Supervisor additionally now helps Kubernetes, Terraform, OpenTofu, and customized instruments. Credentials stay in the identical platform that runs code and pipelines, so groups don’t keep a separate permission mannequin.
Bulk SAST Remediation Helps Take away Years of Gathered Threat in a Single Motion
SAST False Optimistic Detection and Agentic SAST Vulnerability Decision allow groups to clear a complete vulnerability backlog as a substitute of 1 discovering at a time. Groups choose a number of findings within the Vulnerability Report, and GitLab returns a confidence rating for every. Confirmed dangers get a ready-to-merge repair, so a developer evaluations and merges as a substitute of writing the repair from scratch. This covers each SAST vulnerability within the Vulnerability Report, and GitLab continues to triage and remediate new important and excessive severity findings robotically as they arrive.
Circulate Creator Agent Removes the Schema Barrier to Customized Automation
Circulate Creator Agent removes the necessity for guide schema mapping that retains course of house owners from automating their work. With Circulate Creator, obtainable by way of Agentic Chat as a foundational agent in GitLab Duo Agent Platform, a consumer describes the automation in plain language and will get again a whole, runnable circulate, able to register from the AI Catalog. Each circulate nonetheless runs underneath a scoped service account with composite id, requiring the Maintainer position or increased to allow it.
Further Capabilities Shipped in GitLab 19.3
GitLab Credit utilization caps at the moment are typically obtainable, permitting organizations to set a month-to-month ceiling on agentic AI spend earlier than it turns into an overage. Directors can set a subscription stage cap within the Prospects Portal, together with choices for a default per consumer cap or per consumer overrides by way of the GraphQL API.
Restricted visibility for customized brokers and flows per GitLab group is now typically obtainable, making them accessible to members throughout a number of initiatives inside that group. That is along with per-project and public visibility choices which have already been obtainable.
“These updates lengthen the pace and management enterprises want deeper into the regulated and data-sensitive phase of the enterprise market,” stated Manav Khurana, chief product and advertising officer at GitLab. “Each functionality we shipped this month, from the place an agent runs to which secret it will probably contact, extends that very same management into the trusted software program supply workflows enterprises already depend upon.”
