Surprisingly Useful AI Article Enhancements
GitLab has released version 19.0 of its DevSecOps platform, expanding secrets management, agentic merge request workflows, CI pipeline visibility, self-hosted open source model support and supply chain visibility.
The release targets what GitLab describes as the “AI Paradox,” where engineering organisations shipping more code than ever find that surrounding workflows for securing credentials, reviewing and merging changes, enforcing pipeline standards and running AI in regulated environments have not kept pace.
Manav Khurana, Chief Product and Marketing Officer at GitLab, framed the update as closing the gap between code generation and code governance.
“AI made it faster to generate code, but it didn’t make it easier to trust or secure it at scale,” Khurana observed. “When security, automation and governance share the same platform as the code, teams can move fast on AI without losing control of what ships, and that’s exactly what GitLab 19.0 delivers.”
Secrets Manager enters public beta
GitLab Secrets Manager, now in public beta for GitLab Premium and Ultimate users, stores credentials inside the same platform that runs code and pipelines. Each secret is scoped to only the jobs authorised to use it.
Access control and audit logging use the same group and project structure already in GitLab, with no separate permission model to maintain. If a credential is compromised, responders can trace every job that used it from the GitLab audit trail, linked to the originating pipeline, without correlating logs across separate systems.
The feature works alongside existing integrations with HashiCorp Vault, AWS Secrets Manager, Azure Key Vault and Google Cloud Secret Manager.
Developer Flow handles full merge request lifecycle
GitLab 19.0 extends Developer Flow across the full merge request lifecycle, addressing reviewer feedback, resolving conflicts, splitting oversized merge requests and implementing features at any stage. The flow reads project-specific standards from AGENTS.md before committing, so output reflects team context and guardrails rather than generic defaults.
Two new capabilities are now in beta: a Resolve with Duo button that evaluates both branches, commits a proposed fix and leaves a summary comment for the next reviewer, and one-click rebase-and-merge for teams using semi-linear or fast-forward merge methods. Both are available for Free, Premium and Ultimate tier users.
Components Analytics for CI/CD visibility
A new Components Analytics feature gives platform engineering teams visibility into which CI/CD Catalog components and versions are running across their organisation. Adoption data is available for Free, Premium and Ultimate tier users, with per-component drill-down available for Ultimate tier users.
Self-hosted open source model expansion
GitLab Duo Agent Platform Self-Hosted now supports four additional open source models: Mistral Devstral 2 123B, GLM-5.1, Kimi-K2.6 and MiniMax-M2.7. The additions are aimed at teams in air-gapped or regulated environments that cannot send source code to external APIs.
Each model was evaluated against GitLab Duo Agent Platform task requirements including multi-step tool use, code generation quality and reasoning across large code differences. Both on-premises and private cloud deployment options are supported, including deployment via vLLM on GPU-enabled infrastructure and hybrid configurations that mix self-hosted and GitLab-managed models.
Supply chain security additions
GitLab 19.0 introduces dependency scanning with a software bill of materials (SBOM) that produces an auditable inventory of third-party components matched against GitLab security advisories. The feature is available to Ultimate tier users.
New security configuration profiles allow teams to enable Secret Detection, SAST and Dependency Scanning across projects through policies rather than per-project CI configuration changes.
Last Updated on May 22, 2026 by Nick Ross
Related: Best Business Laptops for work & school
Related: Best Gaming Laptops
Related: Best Portable Laptop



