GitLab Announces New Capabilities for the Governed Software Factory
To help organizations move AI-generated code into production, GitLab today announced new capabilities that connect the steps that allow agents to work within set policies and standards. These capabilities, GitLab said, help create a governed system “for orchestrating, securing and optimizing software development” and move organizations beyond shadow software factories.
Those shadow factories cobble together tools for coding, issue tracking, source code management, CI/CD pipelines and more, with no common policy or share identity — or even a record of how and why a change was made. Fragmentation such as this leads to show handoffs, broken context between stages, and an inability for leaders to trace changes from plan to production, the company wrote in its announcement.
The new
The most comprehensive AI-powered DevSecOps platform
DevOps Platform Compare pricing & 2 other DevOps Platform →-
/goal in GitLab Duo Agent Platform and GitLab for Slack automate work progression and eliminate the wait between handoffs across the software lifecycle.
-
GitLab Artifact Central , now in beta, gives teams one governed home next to source code and CI to assemble the right software, every time.
-
GitLab Dependency Firewall blocks malicious, vulnerable, and non-compliant packages before they reach the build.
-
Claude Mythos 5 and 5.1 by Anthropic will power new GitLab Duo Agent Platform flows that identify and remediate security findings on the path to production.
-
GitLab Security Standard defines five controls to reduce the time from detection to verified remediation for agentic software development.
-
Duo Agent Platform Impact Analytics shows cost and impact of investment into AI-powered software delivery by team, task, and model.
Securing the Software Factory
GitLab has added security controls for the supply chain, to prevent agents from pulling in unvetted packages or reusing old credentials, noting that each vulnerability that remains open increases risk of exploitation. This, GitLab said, “hardens the defense posture for software delivery.”
Meanwhile, GitLab Secrets Manager, generally available on GitLab.com and on GitLab Self-Managed in the 19.5 release, “secures build-time secrets in one place, and scopes each secret to the job that needs it. It applies existing group and project permissions, and records every event in the GitLab audit trail,” the company wrote in its announcement.
Optimizing Agentic Workflows for Context and Cost
GitLab Orbit, announced in June as a beta, maps the oftware life cycle into real-time knowledge that agents can act on, enabling them to complete tasks with up to 45x fewer retries and 4.5x fewer tokens. To learn more, please read the what’s new page.
SD Times Q&A
What is GitLab Dependency Firewall and what does it block?
GitLab Dependency Firewall is a supply chain security feature that blocks malicious, vulnerable, and non-compliant packages before they reach the build. It is designed to prevent AI agents from pulling in unvetted packages during automated software development workflows.
How does GitLab Secrets Manager work with CI/CD pipelines?
GitLab Secrets Manager, generally available on GitLab.com and in GitLab Self-Managed 19.5, stores build-time secrets in a single governed location and scopes each secret to the specific job that requires it. It leverages existing group and project permissions and logs every access event in the GitLab audit trail.
What is GitLab Orbit and how does it reduce AI agent token usage?
GitLab Orbit is a feature, announced in June as a beta, that maps the software lifecycle into real-time knowledge that AI agents can act on. According to GitLab, it enables agents to complete tasks with up to 45x fewer retries and 4.5x fewer tokens compared to without it.
What is GitLab Artifact Central and is it generally available?
GitLab Artifact Central is a centralized, governed repository for software artifacts, positioned alongside source code and CI pipelines. As of this announcement, it is in beta and not yet generally available.
The post GitLab Announces New Capabilities for the Governed Software Factory appeared first on SD Times.
Tech Developers
No comments