1. Image: GitLab Blog

    DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent

    GitLab BlogGitLab's Threat Research Group finds a command-execution vulnerability in DeepSeek-Reasonix Studio, a desktop Git client for developers using AI coding assistants. The ConfigPoisoning flaw can run attacker-supplied code when a developer views a file diff; the supplied account identifies it as GHSA-grg2-7gc6-36m6 and CVE-2026-102437.

  2. Image: GitLab Blog

    Dependency Firewall: Block risky packages before the build

    GitLab BlogGitLab introduces Dependency Firewall to block risky packages before builds, citing attacks involving malicious PyPI packages that run during installation and steal CI/CD credentials. GitLab says AI coding agents can also add unreviewed open-source dependencies, leaving developers less oversight of package risks.

  3. GitLab 19.4 released

    GitLab releases version 19.4. The supplied evidence contains no further release details.

  4. Optimize your team's price-performance with hosted open weight models

    GitLab BlogGitLab expands the model options managed by its Duo Agent Platform with hosted open-weight models Kimi K3, GLM 5.3, and MiniMax M3. The models are intended for different software tasks, including feature work, pipeline diagnosis, and resolving security vulnerabilities.

  5. Rate limits on GitLab.com are changing

    GitLab BlogGitLab plans to change rate limits on GitLab.com as demand and platform load grow, including from automation and agent workloads. The company says predictable limits are intended to keep the service fast as it scales.

  6. GitLab Duo CLI takes a task from goal to done

    GitLab BlogGitLab Duo CLI is presented as a way to carry complex tasks from a goal through completion, reducing the repeated handoffs that interrupt agent-driven work. The approach uses a predefined success criterion so the agent can proceed without stopping for step-by-step direction.

  7. How GitLab reduced code-per-agentic-flow ratio by 45%

    GitLab BlogGitLab describes how its Flow Registry uses reusable declarative configurations to compile YAML into LangGraph flows for the Duo Agent Platform. The company says this approach reduces its code-per-agentic-flow ratio by 45%.

  8. GitLab Dedicated: Compliance for a new regulatory era

    GitLab BlogGitLab discusses its Dedicated offering in the context of European cybersecurity oversight, including the NIS2 directive and ENISA’s NIS360 report. The focus is on compliance as authorities move toward active supervision and accountability in critical sectors.

  9. Image: GitLab Blog

    GitLab and Claude Code: Fast, compliant AI

    GitLab BlogGitLab presents GitLab Duo Agent Platform as a way for government agencies to govern use of Anthropic's Claude Code as they accelerate AI coding. The discussion responds to pressure from the U.S. Office of Management and Budget to deploy AI faster and from the U.S. Government Accountability Office to establish guardrails.

  10. Image: GitLab Blog

    Two front doors: Module-level access in a Django GRC app

    GitLab BlogGitLab's engineering team describes restructuring authorization in its internal Django governance, risk, and compliance tool, which serves Security Compliance and Internal Audit. The account focuses on module-level access for the two groups within one application.

  11. Securing the software factory at machine speed

    GitLab BlogGitLab’s CISO outlines an approach to securing software production as AI agents change how teams build and secure software. The argument centers on trust becoming a constraint as code production accelerates.

  12. When to use SAST versus an LLM security scanner

    GitLab BlogThe piece compares static application security testing with using a large language model to scan code changes. An LLM can find real issues in a merge request, including some that pattern-based scanners miss, but the supplied account does not detail a broader evaluation.

  13. Image: GitLab Blog

    See who spent your AI credits and set fair caps per team

    GitLab BlogA new AI-spending management capability lets organizations see usage by individual teams and set per-team caps. The added visibility is intended to help explain spending spikes and allocate budgets more fairly as teams scale AI use.

  14. How to design GitLab for enterprise scale

    GitLab BlogA guide outlines architecture decisions involved in deploying GitLab at enterprise scale, including deployment model and runner strategy. It emphasizes that choices made before rollout can affect organizations with thousands of developers, repositories, and pipelines.

  15. New MCP tools help platform teams scale automation

    GitLab BlogA guide for platform teams describes using Model Context Protocol tools to scale automation as agents take on pipeline operations, merge requests, and work triage. It highlights the risk of agents gaining access to software delivery tools beyond those selected and configured by platform teams.

  16. Image: GitLab Blog

    Every artifact your teams ship, assembled right the first time

    GitLab BlogA managed artifact service is presented as a way for teams to assemble software builds from open-source packages, base images, libraries, and their own code. It addresses build failures from missing or changed components and project-by-project registry sprawl, including retention, storage, and publishing controls.

  17. How to calculate DevOps platform total cost of ownership

    GitLab BlogA guide explains how to assess the total cost of ownership of a DevOps platform, beyond subscriptions and license fees. It includes CI/CD compute, AI usage, infrastructure, tools, and employee time among the costs to consider.