GitLab is expanding agentic AI software development with new capabilities for secure software delivery. The company announced several updates focused on control, security, and automation.
GitLab Dedicated AI Gateway is now generally available for regulated and data-sensitive enterprises. The capability allows customers to run GitLab Duo Agent Platform within their single-tenant environment and region. Customers can also connect their own models for inference through the platform. Furthermore, AI-processed data remains within their existing security boundary.
GitLab also introduced new security and automation capabilities with GitLab 19.3. These include GitLab Secrets Manager, Flow Creator Agent, and Bulk SAST False Positive Detection.
Agentic SAST Vulnerability Resolution is also entering beta. These capabilities help teams manage security findings and automate secure software delivery.
Together, the updates give engineering and security teams greater control over agentic AI. They also help organizations increase development speed without changing established security controls.
Dedicated AI Gateway Strengthens AI Security
The AI Gateway for GitLab Duo Agent Platform now operates within GitLab Dedicated single-tenant SaaS infrastructure. Therefore, organizations can keep agentic workloads within the same residency and isolation model.
This approach supports enterprises with strict data residency requirements. It also addresses security requirements across sensitive software development environments.
Regulated organizations can now adopt agentic AI software development under a deployment model familiar to their auditors. As a result, teams can introduce AI-driven workflows without moving sensitive workloads outside established boundaries.
GitLab Dedicated customers already use the platform for secure software delivery workloads. The new capability extends those existing controls to agentic AI workloads.
Secrets Manager Extends Credential Protection
GitLab Secrets Manager is now available in limited availability as a paid add-on. GitLab.com customers can purchase the capability through GitLab Credits. The service manages credentials used inside and outside CI pipelines. Each CI secret receives permissions based on its environment, branch, and protection status.
In addition, Secrets Manager supports Kubernetes, Terraform, OpenTofu, and custom tools. This broader support allows teams to manage credentials across different development environments. Credentials remain within the platform that manages code and pipelines. Consequently, teams can avoid maintaining a separate permission model for these credentials.
This approach gives organizations more consistent control over secrets across their secure software delivery workflows.
Agentic SAST Resolution Targets Vulnerability Backlogs
GitLab is also introducing Bulk SAST False Positive Detection and Agentic SAST Vulnerability Resolution in beta. The capabilities allow security teams to review multiple vulnerabilities through a single action. Teams can select several findings from the Vulnerability Report.
GitLab then provides a confidence score for each selected finding. Confirmed risks receive a ready-to-merge fix for developer review. Therefore, developers can review and merge fixes without creating each remediation manually. The capability covers SAST vulnerabilities listed in the Vulnerability Report.
GitLab will also continue triaging new critical and high-severity findings automatically. The system can then support remediation as new risks enter the workflow.
Flow Creator Simplifies Custom Agentic Automation
Flow Creator Agent is now generally available through Agentic Chat. The capability removes the need for manual schema mapping when creating custom workflows. Users can describe an automation process using plain language. Flow Creator then produces a complete and runnable custom flow.
The finished flow can be registered through the AI Catalog. This approach allows process owners to create automation without learning the Flow Registry schema. However, GitLab maintains controls around how these flows operate. Each flow runs through a scoped service account with composite identity.
Users need the Maintainer role or higher to enable the capability. This requirement keeps custom automation within established administrative controls.
GitLab 19.3 Adds More AI Governance Controls
GitLab 19.3 also introduces secure software delivery additional controls for agentic AI usage. GitLab Credits usage caps are now generally available. Organizations can establish a monthly spending ceiling for agentic AI. Administrators can set a subscription-level cap through the Customers Portal. They can also configure a default per-user spending limit. Per-user overrides are available through the GraphQL API.
In addition, restricted visibility for custom agents and flows by GitLab group is now generally available. Members across multiple projects within the group can access these resources. The feature complements existing per-project and public visibility options. As a result, organizations gain more flexibility when managing custom AI agents and flows. These updates expand GitLab’s approach to agentic AI software development. The company combines AI-powered automation with security, governance, and deployment controls.
Explore IT Tech News for the latest advancements in Information Technology & insightful updates from industry experts!
News Source: Businesswire.com