SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
GitLab unveils governed software factory tools for AI

GitLab unveils governed software factory tools for AI

Wed, 7th Oct 2026 (Today)
Raphael Veloso
RAPHAEL VELOSO News Editor

GitLab has introduced new products and features for what it calls a governed software factory, focused on software orchestration, security, artifact management and AI oversight.

The additions are intended to help organisations move software from idea to production under internal policies and standards, while addressing the growth of AI-generated code and agent-led development workflows.

Key additions include new workflow tools in GitLab Duo Agent Platform and GitLab for Slack, the new GitLab Artifact Central service, GitLab Dependency Firewall, expanded security flows using Anthropic models, a GitLab Security Standard, and Duo Agent Platform Impact Analytics.

GitLab said many organisations still rely on disconnected systems for coding, issue tracking, source code management, CI and CD, security, artifact management and deployment. According to the company, that fragmentation can make it harder to track how software changes move from planning to production and to measure the effect of AI spending.

Manav Khurana, Chief Product and Marketing Officer at GitLab, said the company sees a gap between the scale of software development inside large organisations and the controls governing those systems.

"Every enterprise already runs a software factory, but few have intentionally designed the systems and controls that govern it," said Manav Khurana, Chief Product and Marketing Officer at GitLab.

"GitLab brings together the foundational building blocks for a governed software factory, connecting agentic workflows, security, and AI context and controls so organisations can move software from intent to production with greater speed, governance, and visibility," Khurana said.

Workflow automation

A central part of the launch is the expansion of agent-led workflow tools across the software lifecycle. GitLab said its goal-driven flows in Duo Agent Platform, supported by /goal in Duo CLI, headless mode, Duo Agentic Chat and the GitLab for Slack app, are designed to reduce delays between coding, review, testing, security checks, approvals and deployment.

Custom Flows and flow triggers let teams automate multi-step work under one identity, policy framework and evidence chain, GitLab said. Teams can also start and follow the same flows from the tools and communication channels they already use.

Artifact control

GitLab is also introducing GitLab Artifact Central, now in beta on GitLab.com. The product is designed to place containers and packages in one control plane alongside source code management and CI pipelines.

GitLab said platform teams can set policy once at organisation level and track what has been published. The service is intended to address problems that arise when software builds pull the wrong or missing components from open-source packages, base images and libraries.

Security measures

Security features are another major part of the release. GitLab Dependency Firewall, available in early access, checks packages against policy before they enter a build. Organisations can configure rules covering package age, vulnerability severity, malicious package detection and licence compliance, with the option to warn, block or quarantine software packages, GitLab said.

GitLab Secrets Manager is also becoming generally available on GitLab.com and on GitLab Self-Managed in the 19.5 release. GitLab said the service stores build-time secrets in one place, limits access to the specific job that requires each secret, applies existing group and project permissions, and logs activity in the audit trail.

OneTrust is among the users GitLab cited in support of the secrets product.

"GitLab Secrets Manager lets us centralise secrets across CI/CD, Kubernetes, and infrastructure as code without standing up multiple vaults or maintaining separate integration points," said Jeremy Nauta, Software Architect at OneTrust.

"It also strengthens our supply chain security by tightening which users and pipelines can access a given credential," Nauta said.

GitLab is also adding security flows using Anthropic's Claude Mythos 5 and 5.1 models. GitLab said the models will be available within new Duo Agent Platform security flows and are aimed at helping approved environments identify and address vulnerabilities.

"When defenders have more context than attackers, advanced models change the math in their favour," said Rajat Pandit, Head of Applied AI at Anthropic.

"GitLab's customers will be able to use Claude Mythos 5 and 5.1 to find vulnerabilities and verify fixes inside the workflows they already run," Pandit said.

Alongside those additions, GitLab has published its GitLab Security Standard, which sets out five controls for agentic software development. GitLab said the framework uses time from detection to verified remediation as its main measure.

AI oversight

GitLab also used the announcement to highlight the challenge of accounting for AI costs and outcomes. It said leaders often struggle to connect consumed credits with work delivered, making it harder to prioritise use cases or set spending limits.

Duo Agent Platform Impact Analytics, now in early access, is intended to provide that view by showing the cost and impact of AI investment by team, task and model. GitLab said the tool sits alongside AI usage caps and controls that let administrators set spending ceilings at subscription, group or user level.

GitLab also gave an update on GitLab Orbit, saying it has been used by more than 3,500 organisations since its beta announcement and has supported more than 280,000 queries from coding agents. According to GitLab, Orbit maps the software lifecycle into real-time knowledge for agents and can reduce retries and token usage during task completion.

GitLab said it now serves more than 70 million developers and over 10,000 enterprises. Over the past three months, active users of agentic software development on the platform rose 200% year on year, while secure repositories grew 100%, user namespaces 80% and CI/CD pipelines 40%, according to the company.