News

GitLab 19.2: Governed Agentic Automation for DevSecOps in 2026

News | 27.07.2026

As AI generates more code than developers can review, security backlogs and dependency risk are piling up faster than teams can respond. GitLab 19.2 answers this challenge with governed agentic automation that fixes vulnerable dependencies, catches logic flaws that pattern-based scanners miss, and lets teams build custom multi-step agent workflows, all under existing organizational controls.

What was announced

On July 16, 2026, GitLab Inc. released GitLab 19.2, the intelligent orchestration platform for DevSecOps. The release introduces four major capabilities designed to clear the backlog that AI-assisted coding creates.

Dependency Scanning Auto-Remediation is now in public beta. When a scan finds a vulnerable package, GitLab opens a merge request with the suggested fix, and if an upgrade breaks the build, agents iterate to fix the issue in the same merge request. A study of the Maven ecosystem cited by GitLab found vulnerabilities reaching roughly 63% of latest releases through transitive dependencies, while roughly one in eight dependency updates introduces a breaking change.

Security Review Flow, also in public beta, catches vulnerabilities that pattern-based scanners cannot see: broken object-level and function-level authorization, missing authorization on state-changing operations, information disclosure, mass assignment, business logic errors and race conditions. A person always makes the final call.

GitLab Duo CLI is now generally available across GitLab.com, Self-Managed and Dedicated deployments, bringing agents to the terminal with full project context. Custom Flows are also generally available, letting teams replace manual multi-step workflows with agentic automations triggered by GitLab events.

Why this matters

For CIOs, CISOs and IT directors, the shift to agentic automation is a governance question as much as a productivity one. A Forrester Consulting study commissioned by GitLab found organizations using GitLab Duo Agent Platform can achieve 400% ROI with payback in under six months.

Compliance deadlines under PCI DSS and FedRAMP continue to run regardless of AI adoption. GitLab 19.2 keeps every automated change inside existing approval gates and leaves a full audit trail. The new AI Audit Event Report, in beta, records AI-assisted actions as dedicated audit events, so compliance and security teams can include AI workflows in audit reporting, access reviews and incident investigation.

Coding agents made it possible to generate far more code and moved the bottleneck downstream to reviews and security. GitLab 19.2 puts agents to work on that bottleneck: fixing vulnerable dependencies, catching the flaws scanners miss, and automating the steps in between with a person still approving what ships

Manav Khurana, Chief Product and Marketing Officer at GitLab

Technical details

  • Dependency Scanning Auto-Remediation: public beta; automated merge requests with iterative fixes, configurable severity thresholds and version scope.
  • Security Review Flow: public beta; detects authorization, business logic and race-condition flaws with severity ratings and suggested fixes.
  • GitLab Duo CLI: generally available on GitLab.com, Self-Managed and Dedicated; agents in the terminal with full project context.
  • Custom Flows: generally available; event-triggered agentic workflows with short-lived, job-scoped tokens for external services.
  • Fix CI/CD Pipeline Flow: improved failure classification with inline suggestions or new merge requests.
  • Governance controls: AI Audit Event Report (beta), group-level custom instructions for GitLab Duo Code Review, MCP access controls.

Softprom and GitLab

Softprom is the official partner of GitLab. Organizations planning to adopt governed agentic automation can rely on Softprom for licensing, deployment guidance and enablement across GitLab.com, Self-Managed and Dedicated environments.

This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.