G

GitLab

G
GitLab DevOps

DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent

GitLab's Threat Research Group discovered a command execution vulnerability (GHSA-grg2-7gc6-36m6, CVE-2026-102437) in DeepSeek-Reasonix Studio, a desktop git client designed for developers pairing with AI coding assistants. The flaw, called ConfigPoisoning, could allow attacker-supplied code to execute when a developer views a file's diff. To address this vulnerability, you should update to DeepSe…

G
GitLab DevOps

GitLab and Claude Code: Fast, compliant AI

Government agencies are feeling twin pressures: While the U.S. Office of Management and Budget (OMB) is urging you to deploy AI faster, the U.S. Government Accountability Office (GAO) wants guardrails in place before that happens.To accelerate AI coding, many agencies are turning to AI coding assistants like Anthropic's Claude Code. But what about guardrails? GitLab Duo Agent Platform can govern y…

G
GitLab DevOps v2.56.0

What's new in Git 2.56.0?

The Git project recently released Git 2.56.0. Let's look at some of the highlights of the release, including contributions from the Git team at GitLab.What's covered:Git Merge 2026 and schedule for Git 3.0git-history(1) learns dropgit-branch(1) learns to delete merged branchesgit-refs(1) learns to modify refsGoogle Summer of Code 2026Linearizing history with git-replay(1)Making the object database…

G
GitLab DevOps

How to design GitLab for enterprise scale

At enterprise scale, even small architecture choices can have outsized consequences. A deployment that works for a handful of teams can become a constraint once thousands of developers, repositories, and pipelines depend on it.That makes each decision made before rollout especially consequential. For example, your:Deployment model defines what your team must operateRunner strategy shapes how CI/CD…

G
GitLab DevOps

How GitLab reduced code-per-agentic-flow ratio by 45%

GitLab Duo Agent Platform orchestrates and automates complex tasks through agentic flows. A key part of the platform is the Flow Registry, a declarative configuration framework, built from reusable components, that compiles YAML into fully functional LangGraph flows. By using Flow Registry, agent builders — both our GitLab engineers and our customers can use declarative YAML configurations instead…

G
GitLab DevOps

Securing the software factory at machine speed

I joined GitLab at a moment when the way teams build and secure software has been changing rapidly. GitLab CEO Bill Staples recently framed that shift in When Code Is Abundant. When code is no longer the bottleneck, trust becomes scarce, and that constraint shows up first in what reaches production.As a CISO accountable for the same decisions as my peers, my operating thesis is simple: Detection i…

G
GitLab DevOps

GitLab Duo CLI takes a task from goal to done

Complex tasks hit a wall at the end of every chat turn. Developers already know what they're trying to accomplish. What stalls the work is the handoff back and forth between each step. Without a pre-defined definition of success, the agent stops and waits for direction or clarification, so you end up re-prompting it step by step, effectively acting as its continue button until the task is done.Dep…

G
GitLab DevOps

New MCP tools help platform teams scale automation

Agentic tools are moving fast past code completion into running pipelines, opening merge requests, and triaging work on a team's behalf. The Model Context Protocol (MCP) has become the common way these agents reach into a team's existing tools, which means the agents touching an organization's software delivery pipeline are no longer only the ones a platform team chose and configured themselves.Th…

G
GitLab DevOps

See who spent your AI credits and set fair caps per team

Scaling AI across your organization depends on knowing where the budget is going and who’s using it. While a subscription cap keeps your total spend within budget, it can’t tell you how much AI was used by individual teams. And predicting future budget needs ahead of business needs gets more challenging as teams grow. Without per-user data you can’t set a fair cap on AI spend, explain a spike, or…

G
GitLab DevOps

Optimize your team's price-performance with hosted open weight models

There’s no single best model for every software development task. Implementing a new feature, diagnosing a failed pipeline, and resolving security vulnerabilities all place different demands on the model handling them. GitLab Duo Agent Platform is expanding GitLab-managed model choice with three hosted open weight models: Kimi K3, GLM 5.3, and MiniMax M3.Together with the frontier models already a…

G
GitLab DevOps

Rate limits on GitLab.com are changing

GitLab.com hosts millions of projects for teams of every size that need a platform they can rely on. Demand is climbing quickly, and we expect platform load to grow several times over this year. Predictable limits are what keep GitLab.com fast for everyone on it, including the automation and agent workloads teams are building on the platform.To hold that as we scale, we're updating how rate limits…

G
GitLab DevOps

When to use SAST versus an LLM security scanner

You're probably running some version of this experiment already: Point a frontier model at a merge request and ask it to double as a vulnerability scanner. On a single merge request, it often works well. The model reads the code, reasons about what it's supposed to do, and catches real issues, sometimes ones a pattern-based scanner misses entirely.So the next thought is reasonable: If a model revi…

G
GitLab DevOps

GitLab Dedicated: Compliance for a new regulatory era

Enforcements such as NIS2 are no longer a future planning consideration. The European Union Agency for Cybersecurity's (ENISA) NIS360 report confirms that supervisory authorities are actively assessing cybersecurity maturity across critical sectors. The agency is moving from guidance and consultation into active oversight, scrutiny, and accountability. This is the regulatory environment European e…

G
GitLab DevOps

How to calculate DevOps platform total cost of ownership

There’s nothing like budget pressure to put your DevOps platform under a microscope. But subscription fees and license costs only tell one part of the story. The total cost of ownership (TCO) for a DevOps platform also includes variable costs like CI/CD compute and AI usage, along with the infrastructure, tools, and employee time required to keep software delivery moving.That wider view matters wh…

G
GitLab DevOps

Prepare for the Cyber Resilience Act's 24-hour reporting deadline

Starting on September 11, 2026, many businesses that place software on the European Union (EU) market will have 24 hours to file a report once they learn that a vulnerability in one of their products is being actively exploited. This is a new requirement under the Cyber Resilience Act (CRA), the EU law that sets cybersecurity requirements for products with digital elements sold in Europe, put in p…

G
GitLab DevOps

Co-Create: Building GitLab with our users

GitLab users bring firsthand experience of the workflows they want to improve. Through our Co-Create program, they collaborate directly with us to design, build, and deliver product improvements that benefit more teams.In the first half of 2026, our users helped us extend APIs, add CI/CD capabilities, expand language support for AI-powered code understanding, strengthen security controls, increase…

G
GitLab DevOps

GPT-6 Astra on GitLab: Faster runs, fewer tokens used

OpenAI's newest frontier model GPT-6 Astra is now on GitLab Duo Agent Platform, delivering faster runs and lower token usage.In GitLab's internal evaluation, GPT-6 Astra finished a typical run 43.4% faster than GPT-5.6 Sol and used 42.7% fewer tokens per run, while completing every task in the benchmark. For your team, that means agentic tasks such as dependency updates, build fixes, and small mul…

G
GitLab DevOps

Bring your own model to GitLab Duo Self-Hosted with Microsoft Foundry

For many organizations, the question about AI coding tools isn't whether they help, but where the code goes. Teams under data sovereignty, residency, or regulatory constraints need to know which network handles their source code before they can adopt anything. GitLab Duo Self-Hosted answers that by letting administrators connect GitLab Duo features to models running on infrastructure they choose,…

G
GitLab DevOps

Critical remote code execution in vm2, a widely used Node.js sandbox library

GitLab's Threat Research Group found a critical sandbox escape vulnerability in vm2, one of the most widely adopted Node.js sandboxing libraries. The vulnerability uses a configuration copied straight from vm2's own README. We found the flaw, rated CVSS 3.1: 10.0, critical, using our own AI automated tools. Anyone running vm2 Version 3.11.6 or earlier with require.external turned on should treat t…

G
GitLab DevOps

GitLab’s internal playbook to foster AI-fluent technical teams

Give two engineering teams the same AI tool and you can end up with two very different outcomes. One team ships faster with fewer bugs, while the other gets burned by an agent that confidently generates the wrong output.At GitLab, our team had AI tools at their fingertips and some found real value fast, working faster and catching issues earlier. Meanwhile, others hadn't quite found an entry point…

G
GitLab DevOps

How to recognize your team with GitLab Achievements

Every team runs on people who go above and beyond. The engineer who fixes the flaky test nobody else will touch. The reviewer who turns your merge request around in an hour. The teammate who finishes their certification. Or the community member who shows up release after release. Whether your team is a company, an open source project, or a community, GitLab had no built-in way to say "we see you."…

G
GitLab DevOps

GitLab compliance frameworks: Adhere to SOC 2 in minutes

Compliance is the part of software delivery that everyone agrees is important, yet nobody enjoys. It often lives in spreadsheets, screenshots, and the quiet dread of an upcoming audit. GitLab's custom compliance frameworks work differently. Instead of documenting what should be true about your projects, you define the controls once and let the platform continuously verify what is true.In this arti…

G
GitLab DevOps

Git was built for humans — agents need an upgrade

The industry is now racing to rebuild source code management for agents. We showed our answer at GitLab Transcend, but let’s reiterate why rebuilding the Git backend is only half the problem.Three things break when agents become the primary users of a Git server. Every developer running hundreds of agents hits the same wall, regardless of tools:The clone tax. An agent clones an entire repository t…

G
GitLab DevOps

Making room for what's next in the GitLab UI

Throughout this year, the product interface has been in a season of reduction. On the heels of dark mode, the tide has been moving out with a quieter application chrome, overall color reduction, and neutral controls. It can feel like loss, low tide always does. But low tide is also when you can see the shape of the shoreline clearly enough to build something new on it.What’s coming in is a user in…

G
GitLab DevOps

Scale software delivery pipelines in isolation without owning the runner fleet

Many enterprises choose GitLab Dedicated for a clear reason: a secure and compliant, single-tenant GitLab instance, managed by GitLab. As agentic workflows drive more pipeline volume, full data isolation and runner infrastructure operational burden become a challenge. This leads to the question, “Does owning the runner fleet still make sense?”With GitLab Dedicated, there is no more need to provisi…

G
GitLab DevOps

When code is abundant

I returned from the holiday break in January convinced that something fundamental had changed.Large language models had reached the point where they could produce useful code reliably enough, and cheaply enough, to change the economics of software development. Engineers everywhere seemed to be experimenting with the same thing: not just asking an AI assistant for suggestions, but giving agents rea…