GitLab Inc., the intelligent orchestration platform for DevSecOps, is introducing updates that give enterprises more control as they scale agentic software development.
GitLab Dedicated customers, who already run their most sensitive software delivery workloads on GitLab, can now run GitLab Duo Agent Platform inside that same single tenant environment and region, connect their own models for inference, and keep AI-processed data inside their existing security boundary, according to the company.
GitLab 19.3 is also shipping now with support for Secrets Manager, Flow Creator Agent, and Bulk SAST False Positive Detection and Agentic SAST Vulnerability Resolution.
Every secret, whether it's used inside a pipeline or by the infrastructure outside the pipeline, now runs under the same permission model. Additionally, developers who own a process can now create custom agentic flows across the software development lifecycle, and security teams can ship ready-to-merge fixes against their backlog at scale. Together, these updates give engineering teams, process owners, and security teams the speed of agentic AI, without giving up the control they already have in place, said the company.
The AI Gateway for GitLab Duo Agent Platform now runs inside GitLab Dedicated single-tenant SaaS infrastructure, enabling agentic workloads to follow the same residency and isolation model as the rest of the software development lifecycle within GitLab.
GitLab Secrets Manager is now live in limited availability as a paid add-on billed through GitLab Credits for GitLab.com customers. Every CI secret is scoped to the environment, branch, and protection status of the job that needs it. Secrets Manager also now supports Kubernetes, Terraform, OpenTofu, and custom tools.
SAST False Positive Detection and Agentic SAST Vulnerability Resolution enable teams to clear an entire vulnerability backlog instead of one finding at a time.
Flow Creator Agent removes the need for manual schema mapping that keeps process owners from automating their work. With Flow Creator, available through Agentic Chat as a foundational agent in GitLab Duo Agent Platform, a user describes the automation in plain language and gets back a complete, runnable flow, ready to register from the AI Catalog.
Additional capabilities available in GitLab 19.3 include:
GitLab Credits usage caps are now generally available, allowing organizations to set a monthly ceiling on agentic AI spend before it becomes an overage.
Restricted visibility for custom agents and flows per GitLab group is now generally available, making them accessible to members across multiple projects within that group. This is in addition to per-project and public visibility options that have already been available.
"These updates extend the speed and control enterprises need deeper into the regulated and data-sensitive segment of the enterprise market," said Manav Khurana, chief product and marketing officer at GitLab. "Every capability we shipped this month, from where an agent runs to which secret it can touch, extends that same control into the trusted software delivery workflows enterprises already depend on."
For more information about this news, visit https://about.gitlab.com.