GitLab Inc., an intelligent orchestration platform for DevSecOps, has launched new features in its governed software factory platform. It is a platform that intends to unite software development processes in accordance with organizational policies and compliance standards in order to allow enterprise teams to scale AI-generated code deployments while keeping the system secure, governed, and cost-effective.
The company, which has more than 70 million developers and 10,000 enterprise organizations using their platform, has witnessed acceleration in the adoption of AI-based development approaches. The number of active users who engage in agentic software development on GitLab increased 200% year over year during the last quarter. Moreover, secure repository usage increased by 100%, namespaces increased by 80%, and CI/CD pipelines grew by 40% in the same period.
Nevertheless, there is still a lot of engineering organizations that have to deal with fragmented environment that uses various tools to manage source code, CI/CD process, vulnerabilities, artifacts, and issues. Such tools usually lack unified access, policies, and contextual traceability. GitLab solves these problems by integrating software assembly and deployment steps in one control plane and creating an auditable trace of all changes that take place from planning to production.
Streamlining Agentic AI Orchestration Across Development Pipelines
While AI coding agents can accelerate code generation, project timelines often stall during peer reviews, testing protocols, compliance checks, and approval handoffs.
Also Read: Cognizant Unveils Cognizant Activate to Bring Enterprise-Grade AI Transformation to High-Growth Companies
To mitigate these delays, GitLab has expanded the goal-driven automation capabilities within the GitLab Duo Agent Platform. Accessible via the Duo CLI /goal command, headless execution modes, Duo Agentic Chat, and the native GitLab for Slack application, these tools automate multi-step tasks across stages under a unified user identity and security framework. Teams can initiate, track, and manage complex cross-tool workflows within their existing communications platforms without losing context or bypassing corporate policies.
Unifying Package Management via GitLab Artifact Central
Modern applications rely heavily on open-source libraries, base container images, and external dependencies. As AI agents generate and package code at higher speeds, published artifacts across disparate vendor registries increase the risk of build failures and configuration drift.
In order to have package management centralized, GitLab has come up with GitLab Artifact Central which has gone live on GitLab.com in beta. This is expected to be available to GitLab Self-Managed this month. The solution aims to bring container and package management under one control plane with source code repositories and CI/CD pipelines. With the help of this solution, organization-wide policies will be standardized using a single interface, resulting in total cost of ownership being reduced by 50%.
Hardening Supply Chain Security for Automated Code Generation
The large-scale production of agentic software development leads to potential software supply chain threats such as unvetted dependencies and environment credential exposure. In order to mitigate these threats, GitLab will implement enhanced security measures that will ensure the safe ingestion of dependencies and safeguarding of runtime credentials:
GitLab Dependency Firewall: Available as early access, this control plane will inspect third-party software packages against the organization’s preset criteria prior to being integrated within a build. The dependency firewall automatically alerts, tags, and quarantines dependent packages based on package age, severity score of vulnerabilities, malicious code markers, and licensing criteria.
GitLab Secrets Manager: Generally available as of now on GitLab.com and set to be released on GitLab Self-Managed 19.5, this tool facilitates the handling of build-time secrets centrally. Secrets are only applicable to specific pipeline jobs, connected to current project permissions, and tracked via the GitLab audit log.
Anthropic Model Integration: Anthropic’s Claude Mythos 5 and 5.1 models will be integrated into the GitLab Duo Agent Platform security workflows next month, assisting authorized security teams in identifying and remediating code vulnerabilities.
By unifying identity, security policies, and package management across the DevSecOps ecosystem, GitLab provides a scalable framework for organizations to harness the speed of AI-driven development within a fully governed, traceable environment.























