GitLab is expanding its DevSecOps platform with capabilities designed to govern how AI-generated software moves from intent to production. Spanning workflow automation, artefact management, software supply chain security and the monitoring of AI costs and usage, the additions underpin what the company describes as a “governed software factory”, where development work operates under shared organisational policies, identities and records of how changes progress through the software lifecycle. Through this approach, GitLab is targeting the fragmentation that can occur when coding, issue tracking, source management, CI/CD, security, artefact management and deployment are handled by separate tools.

According to GitLab, active users of agentic software development on its platform grew 200% year over year during the preceding three months. Over the same period, secure repositories grew 100%, user namespaces increased 80% and CI/CD pipelines rose 40%. GitLab also says more than 70 million developers and over 10,000 enterprises use its platform.

Agentic workflows extend across the software lifecycle

GitLab is extending the Duo Agent Platform so automated workflows can continue across stages such as reviews, testing, security checks, approvals and deployment. Goal-driven flows use /goal in Duo CLI and are available in headless mode and in Duo Agentic Chat, while the GitLab for Slack app lets teams start and follow the same workflows from Slack. In addition, Custom Flows and flow triggers can automate multi-step work under the same identity, policy and evidence chain, with the aim of reducing delays and lost context as work moves between people, tools and different stages of software delivery.

GitLab Artifact Central brings containers and packages into the same control plane as source code management and CI pipelines. It is in beta on GitLab.com, with GitLab Self-Managed availability planned for later in the same month as the announcement. Platform teams can use Artifact Central to apply policy at organisation level, track what has been published and manage containers and packages alongside the development pipeline, while GitLab claims the service can deliver up to 50% lower total cost of ownership compared with alternative tooling.

Security controls cover packages and credentials

GitLab Dependency Firewall, available in early access, checks packages against organisation-defined policies before they enter a build. Rules can cover package age, vulnerability severity, malicious package detection and licence compliance, with packages warned about, blocked or quarantined according to the configured policy. The company says the same control plane spans source, build and registry activity, allowing teams to trace exposure to affected projects and prioritise remediation.

For credential protection, GitLab Secrets Manager is generally available on GitLab.com and is set to be available on GitLab Self-Managed in the 19.5 release. It centralises build-time secrets, applies existing group and project permissions, restricts each secret to the job that needs it and records events in the GitLab audit trail. Teams can also revoke a leaked credential in one click, while GitLab claims organisations can realise up to 50% savings compared with hosting a separate vault.

Jeremy Nauta, software architect at OneTrust, described the appeal of consolidating these controls within existing development systems. “GitLab Secrets Manager lets us centralise secrets across CI/CD, Kubernetes, and infrastructure as code without standing up multiple vaults or maintaining separate integration points,” he said. “It also strengthens our supply chain security by tightening which users and pipelines can access a given credential.”

Anthropic’s Claude Mythos 5 and 5.1 are due to become available in new GitLab Duo Agent Platform security flows in the month following the announcement, with GitLab noting that the models will support workflows for identifying vulnerabilities and verifying fixes in approved environments. The GitLab Security Standard is also available, setting five controls for agentic software development. It uses time from detection to verified remediation as its core metric, giving security and engineering teams a way to assess their security posture and measure how quickly issues progress from discovery to confirmed remediation.

GitLab adds AI context and spending controls

GitLab Orbit maps information from across the software lifecycle into real-time knowledge that coding agents can use while completing tasks. Since its beta announcement in June, GitLab says Orbit has been used by more than 3,500 organisations and supported over 280,000 queries from coding agents. The company claims that this lifecycle context can reduce retries by up to 45x and token use by up to 4.5x. Orbit is scheduled to reach general availability in the month following the announcement across all GitLab deployment options.

Duo Agent Platform Impact Analytics, now in early access, is designed to show the cost and impact of AI investment by team, task and model. It works alongside AI usage caps and controls that allow platform administrators to set spending ceilings at subscription, group or user level. Teams can view adoption metrics, agentic workflow results and credit consumption alongside work that reaches production, with GitLab confirming that this visibility remains available when organisations use a mixture of GitLab-managed frontier models, open-weight models or self-hosted models through Duo Agent Platform.

Share