GitLab Announces the Foundation for the Governed Software Factory

GitLab Inc. announced new capabilities for the governed software factory, a connected system for moving software from idea to production under an organisation’s own policy and standards. These new innovations are designed to help organisations ship more AI-generated software to production without taking on more risk or cost.

More than 70 million developers and over 10,000 enterprises innovate on GitLab today. Over the last three months on GitLab, active users of agentic software development grew 200% year over year, while secure repositories grew 100%, user namespaces grew 80%, and CI/CD pipelines grew 40%.

Yet most organisations are running a shadow software factory built from separate tools for coding, issue tracking, source code management, CI/CD pipelines, security, artifact management, and deployment.

These systems have no shared identity, common policy, or a record of how a change was made. That fragmentation slows handoffs, breaks context between stages, and prevents engineering leaders from tracing changes from plan to production or measuring the true impact of their AI investments.

GitLab connects those steps so agents can work within an organisation’s context, workflows, and guardrails, while creating an evidence chain that records how changes move from intent to production. Together, these capabilities form the foundation of a governed software factory, helping organisations move from intent to production with fewer handoffs, stronger safeguards, and clearer visibility into what AI delivers.

Orchestrating Agentic Workflows Across the Software Lifecycle

Agentic software development can stall after coding when reviews, tests, security checks, approvals, and deployments require handoffs between people, tools, and stages.

Goal-driven flows in GitLab Duo Agent Platform, powered by /goal in Duo CLI, in headless mode and in Duo Agentic Chat, and the GitLab for Slack app, eliminate waits between handoffs across the software lifecycle.

Custom Flows and flow triggers automate multi-step work under the same identity, policy, and evidence chain. Teams can start and follow the same flows from the tools and channels they already use, under the same identity and policy.

Assembling the Right Software at Agent Scale

Most software that organisations ship is assembled from open-source packages, base images, and libraries. Builds fail when pipelines assemble the wrong or missing components, and agents multiply that failure rate by publishing packages at machine speed across vendor and project registries that carry their own rules.

Securing the Software Factory at Machine Speed

As organisations adopt agentic software development, more code, packages, and credentials move through the software supply chain than security teams can review. Agents can pull unvetted packages into a build or reuse credentials stored in local environments, and each vulnerability that stays open increases the risk of exploitation. At machine speed, agents need a foundation they can prove before they earn more autonomy.

To meet the challenge, GitLab is adding security controls to govern what enters a build, to protect credentials each job can reach, to harden the defensive posture for software delivery, and is providing the best practices engineering leaders can use to assess their risk posture for agentic software development.

GitLab Dependency Firewall, available in early access, checks every package against policy before it enters a build. It warns, blocks, or quarantines packages based on rules the organisation sets for package age, vulnerability severity, malicious package detection, and license compliance. One control plane spans source, build, and registry, helping teams trace exposure to affected projects and prioritize remediation in minutes instead of weeks.

GitLab Secrets Manager, generally available on GitLab.com and on GitLab Self-Managed in the 19.5 release, secures build-time secrets in one place, and scopes each secret to the job that needs it. It applies existing group and project permissions, and records every event in the GitLab audit trail. With GitLab Secrets Manager, teams can revoke a leaked credential in one click, and realise up to 50% savings compared to hosting a separate vault.

Anthropic’s Claude Mythos 5 and 5.1 will be available within new GitLab Duo Agent Platform security flows next month, helping organisations with approved environments find and fix vulnerabilities faster than attackers can discover and exploit them.

The GitLab Security Standard, gives security and engineering leaders a way to assess their security posture, build trust in autonomous agents through verifiable outcomes, and protect software already in production. The standard sets five controls for the agentic era and uses time from detection to verified remediation as its core metric.

Optimising Agentic Workflows for Context and Cost

AI investment is difficult to manage when leaders cannot connect credits consumed to outcomes delivered. Without that evidence, prioritising the next use case and setting spending limits becomes guesswork. Agentic workflows also incur unnecessary cost when they lack the lifecycle context needed to complete a task, leading to more retries and higher token consumption.

GitLab addresses these challenges by giving agents the lifecycle context they need to work more efficiently and leaders clear visibility into AI cost and impact.

Since its beta announcement in June, GitLab Orbit has been used by more than 3,500 organisations and supported over 280,000 queries from their coding agents. It maps the entire software lifecycle into real-time knowledge that agents can act on, enabling them to complete tasks with up to 45x fewer retries and 4.5x fewer tokens. Orbit will reach general availability next month across all GitLab deployment options.

Duo Agent Platform Impact Analytics, now in early access, shows cost and impact of AI investment by team, task, and model. Impact Analytics complements the recently introduced AI usage caps and controls, which allows platform admins to set spending ceilings at the subscription, group, or user level. Teams see their adoption metrics, results of agentic workflows, and credit consumption alongside the real work that reaches production. This level of visibility is made available even when using a mix of AI models with Duo Agent Platform: GitLab-managed frontier and open-weight models, or self-hosted.

AgenticAIGitLab
Comments (0)
Add Comment