{"id":108740,"date":"2026-07-16T21:09:11","date_gmt":"2026-07-16T21:09:11","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/108740\/"},"modified":"2026-07-16T21:09:11","modified_gmt":"2026-07-16T21:09:11","slug":"gitlab-19-2-brings-governed-agentic-automation-to-clear-the-backlog-ai-coding-creates","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/108740\/","title":{"rendered":"GitLab 19.2 Brings Governed Agentic Automation to Clear the Backlog AI Coding Creates"},"content":{"rendered":"\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Dependency Scanning Auto-Remediation, now in public beta, shrinks the security backlog without diverting developers to upgrade vulnerable dependencies and fixing breaking changes in new code.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Security Review Flow, now in public beta, catches security flaws like business-logic errors and race conditions that pattern-based scanners cannot see.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">GitLab Duo CLI, now generally available, gives developers access to agents and multi-step agentic flows for all software lifecycle tasks right where they work.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Custom Flows, now generally available, let teams replace manual multi-step workflows with agentic automations for software development, triggered by GitLab events.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">SAN FRANCISCO, July 16, 2026&#8211;(<a href=\"https:\/\/www.businesswire.com\" data-ylk=\"slk:BUSINESS%20WIRE;elm:context_link;itc:0;sec:content-canvas;source:content-canvas%20default\" data-yga=\"{&quot;yLinkText&quot;:&quot;BUSINESS WIRE&quot;,&quot;yLinkElement&quot;:&quot;context_link&quot;,&quot;yModuleName&quot;:&quot;content-canvas&quot;,&quot;yTrafficOrigin&quot;:&quot;content-canvas default&quot;}\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">BUSINESS WIRE<\/a>)&#8211;(All Remote)&#8211;<a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fabout.gitlab.com%2F&amp;esheet=54571998&amp;newsitemid=20260716363399&amp;lan=en-US&amp;anchor=GitLab+Inc.&amp;index=1&amp;md5=5dc389ca0821ecfc07aeb63699b4f5ad\" data-ylk=\"slk:GitLab%20Inc.;elm:context_link;itc:0;sec:content-canvas;source:content-canvas%20default\" data-yga=\"{&quot;yLinkText&quot;:&quot;GitLab Inc.&quot;,&quot;yLinkElement&quot;:&quot;context_link&quot;,&quot;yModuleName&quot;:&quot;content-canvas&quot;,&quot;yTrafficOrigin&quot;:&quot;content-canvas default&quot;}\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">GitLab Inc.<\/a>, the intelligent orchestration platform for DevSecOps, today released GitLab 19.2. As AI generates more code, dependencies, and change than developers can keep up with, GitLab 19.2 brings agentic automation to clear that load.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Developers can now use GitLab to fix vulnerable dependencies automatically, catch the logic flaws scanners miss, create custom agentic workflows, invoke agents from more surfaces they already use, and always do so under the organization&#8217;s existing controls. A <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fabout.gitlab.com%2Fresources%2Fstudy-forrester-tei-gitlab-dap%2F&amp;esheet=54571998&amp;newsitemid=20260716363399&amp;lan=en-US&amp;anchor=Forrester+Consulting+study&amp;index=2&amp;md5=4a555327f6a69811337f9c3cfc83906c\" data-ylk=\"slk:Forrester%20Consulting%20study;elm:context_link;itc:0;sec:content-canvas;source:content-canvas%20default\" data-yga=\"{&quot;yLinkText&quot;:&quot;Forrester Consulting study&quot;,&quot;yLinkElement&quot;:&quot;context_link&quot;,&quot;yModuleName&quot;:&quot;content-canvas&quot;,&quot;yTrafficOrigin&quot;:&quot;content-canvas default&quot;}\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Forrester Consulting study<\/a> commissioned by GitLab found organizations using GitLab Duo Agent Platform can achieve 400% return on investment with payback in under six months.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Dependency Scanning Auto-Remediation, Now in Public Beta, Helps Fix Vulnerable Dependencies Automatically  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">A growing share of application security risk now comes from dependencies teams never chose directly. A study of the Maven ecosystem found vulnerabilities reaching roughly 63% of latest releases through transitive dependencies, and roughly one in eight dependency updates introduces a breaking change, even as compliance deadlines under PCI DSS and FedRAMP keep running.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\"><a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fabout.gitlab.com%2Fblog%2Fdependency-scanning-auto-remediation%2F&amp;esheet=54571998&amp;newsitemid=20260716363399&amp;lan=en-US&amp;anchor=Dependency+Scanning+Auto-Remediation&amp;index=3&amp;md5=3892f96c5a6116a3ff309a4e08e49947\" data-ylk=\"slk:Dependency%20Scanning%20Auto-Remediation;elm:context_link;itc:0;sec:content-canvas;source:content-canvas%20default\" data-yga=\"{&quot;yLinkText&quot;:&quot;Dependency Scanning Auto-Remediation&quot;,&quot;yLinkElement&quot;:&quot;context_link&quot;,&quot;yModuleName&quot;:&quot;content-canvas&quot;,&quot;yTrafficOrigin&quot;:&quot;content-canvas default&quot;}\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Dependency Scanning Auto-Remediation<\/a>, now in public beta, closes that gap. Security developers can now clear vulnerable dependencies without adding work for developers. When a scan finds a vulnerable package, GitLab opens a merge request with the suggested fix. If an upgrade breaks the build, agents iterate to fix the issue in the same merge request. New configuration controls let developers set the severity thresholds and version scope that remediation applies to. Every change stops at existing approval gates and leaves a full audit trail.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Security Review Flow, Now in Public Beta, Brings Security Judgment to Every Merge Request  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Developers can now catch a class of vulnerabilities that pattern-based scanners structurally cannot see, on every merge request, when a fix is cheapest. Static scanners are good at identifying flaws that match a known pattern, but application-logic flaws have needed manual review that cannot scale, or penetration testing that arrives too late.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\"><a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fabout.gitlab.com%2Fblog%2Fgitlab-duo-security-review-flow%2F&amp;esheet=54571998&amp;newsitemid=20260716363399&amp;lan=en-US&amp;anchor=Security+Review+Flow&amp;index=4&amp;md5=92805d189b74355f66ff03aa11b161fe\" data-ylk=\"slk:Security%20Review%20Flow;elm:context_link;itc:0;sec:content-canvas;source:content-canvas%20default\" data-yga=\"{&quot;yLinkText&quot;:&quot;Security Review Flow&quot;,&quot;yLinkElement&quot;:&quot;context_link&quot;,&quot;yModuleName&quot;:&quot;content-canvas&quot;,&quot;yTrafficOrigin&quot;:&quot;content-canvas default&quot;}\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Security Review Flow<\/a>, now in public beta, is a foundational flow in GitLab Duo Agent Platform. It reasons about what the code is meant to do rather than matching known patterns, and detects broken object-level and function-level authorization, missing authorization on state-changing operations, information disclosure, mass assignment, business logic errors, and race conditions. Findings include severity and a suggested fix where available. The flow never approves on its own; a person always makes the final call.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">GitLab Duo CLI, Now Generally Available, Puts Agents in Every Developer&#8217;s Terminal  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Developers do much of their work in the terminal, where AI assistance has usually meant reaching for tools that lack context on their GitLab projects, pipelines, and agent configurations. GitLab 19.2 closes that gap.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\"><a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fabout.gitlab.com%2Fblog%2Fgitlab-duo-cli-generally-available%2F&amp;esheet=54571998&amp;newsitemid=20260716363399&amp;lan=en-US&amp;anchor=GitLab+Duo+CLI&amp;index=5&amp;md5=350cde4a598b93c03ba41ab70a80b01c\" data-ylk=\"slk:GitLab%20Duo%20CLI;elm:context_link;itc:0;sec:content-canvas;source:content-canvas%20default\" data-yga=\"{&quot;yLinkText&quot;:&quot;GitLab Duo CLI&quot;,&quot;yLinkElement&quot;:&quot;context_link&quot;,&quot;yModuleName&quot;:&quot;content-canvas&quot;,&quot;yTrafficOrigin&quot;:&quot;content-canvas default&quot;}\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">GitLab Duo CLI<\/a>, now generally available across GitLab.com, Self-Managed, and Dedicated deployments, brings GitLab Duo Agent Platform&#8217;s agents to the terminal with full project context. A developer can get oriented in unfamiliar code, diagnose a failed pipeline, or propose a fix without leaving the command line. Administrators control rollout across the organization.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Agentic Flows Extend Automation From the Individual to the Whole Team  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">GitLab Duo Agent Platform&#8217;s <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fabout.gitlab.com%2Fblog%2Fmulti-step-software-delivery-with-agentic-flows%2F&amp;esheet=54571998&amp;newsitemid=20260716363399&amp;lan=en-US&amp;anchor=agentic+flows&amp;index=6&amp;md5=44b5ef4dced8867a63c6fdf10d5efe32\" data-ylk=\"slk:agentic%20flows;elm:context_link;itc:0;sec:content-canvas;source:content-canvas%20default\" data-yga=\"{&quot;yLinkText&quot;:&quot;agentic flows&quot;,&quot;yLinkElement&quot;:&quot;context_link&quot;,&quot;yModuleName&quot;:&quot;content-canvas&quot;,&quot;yTrafficOrigin&quot;:&quot;content-canvas default&quot;}\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">agentic flows<\/a> are sequences that chain agents to complete multi-step work, and in 19.2, they advance on two fronts.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Custom Flows, the flows teams build themselves, are now generally available. Build a flow once and it runs automatically on GitLab events. Custom Flows now authenticate to external services with short-lived, job-scoped tokens, so automation reaching cloud providers or internal APIs uses the same keyless pattern GitLab CI\/CD pipelines already trust.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">The upcoming Flow Creation Agent can turn a natural-language description into a custom flow. GitLab&#8217;s foundational flows, the ones GitLab ships ready to use, also get more capable. The Fix CI\/CD Pipeline Flow, now improved, classifies failures before acting and delivers targeted fixes as inline suggestions or a new merge request. GitLab Duo Agentic Chat can now delegate multi-step work to agents.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Controls That Keep the Automation Trustworthy  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">The point of automating this work is so that teams can trust it to run autonomously. GitLab 19.2 adds the controls that make that safe at scale. The AI Audit Event Report, now in beta, records AI-assisted actions as dedicated audit events, so compliance and security teams can include AI workflows in audit reporting, access reviews, and incident investigation.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Group-level custom instructions for GitLab Duo Code Review let administrators set review behavior across projects at once, and new MCP access controls govern which agents can run and what they can reach.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">To learn more, please read the <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fabout.gitlab.com%2Fwhats-new%2F&amp;esheet=54571998&amp;newsitemid=20260716363399&amp;lan=en-US&amp;anchor=what%27s+new+page&amp;index=7&amp;md5=504d345e85183a0bada556ba7e480174\" data-ylk=\"slk:what&#039;s%20new%20page;elm:context_link;itc:0;sec:content-canvas;source:content-canvas%20default\" data-yga=\"{&quot;yLinkText&quot;:&quot;what&#039;s new page&quot;,&quot;yLinkElement&quot;:&quot;context_link&quot;,&quot;yModuleName&quot;:&quot;content-canvas&quot;,&quot;yTrafficOrigin&quot;:&quot;content-canvas default&quot;}\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">what&#8217;s new page<\/a>.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Supporting Quote  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">&#8220;Coding agents made it possible to generate far more code and moved the bottleneck downstream to reviews and security,&#8221; said Manav Khurana, chief product and marketing officer at GitLab. &#8220;GitLab 19.2 puts agents to work on that bottleneck: fixing vulnerable dependencies, catching the flaws scanners miss, and automating the steps in between with a person still approving what ships.&#8221;  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">About GitLab  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and approximately 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">*Fortune 500\u00ae is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">View source version on businesswire.com: <a href=\"https:\/\/www.businesswire.com\/news\/home\/20260716363399\/en\/\" data-ylk=\"slk:https%3A%2F%2Fwww.businesswire.com%2Fnews%2Fhome%2F20260716363399%2Fen%2F;elm:context_link;itc:0;sec:content-canvas;source:content-canvas%20default\" data-yga=\"{&quot;yLinkText&quot;:&quot;https:\/\/www.businesswire.com\/news\/home\/20260716363399\/en\/&quot;,&quot;yLinkElement&quot;:&quot;context_link&quot;,&quot;yModuleName&quot;:&quot;content-canvas&quot;,&quot;yTrafficOrigin&quot;:&quot;content-canvas default&quot;}\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">https:\/\/www.businesswire.com\/news\/home\/20260716363399\/en\/<\/a>  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Contacts  <\/p>\n<p class=\"text text-block paragraph text-left neo-font-paragraph-xl-reg  yf-18d6y07\" style=\"text-decoration: none; font-style: normal; text-transform: none; text-align: inherit; font-variant-numeric: normal;\">Media Contact<br \/>GitLab<br \/><a href=\"https:\/\/finance.yahoo.com\/technology\/ai\/articles\/mailto:press@gitlab.com\" data-ylk=\"slk:press%40gitlab.com;elm:context_link;itc:0;sec:content-canvas;source:content-canvas%20default\" data-yga=\"{&quot;yLinkText&quot;:&quot;press@gitlab.com&quot;,&quot;yLinkElement&quot;:&quot;context_link&quot;,&quot;yModuleName&quot;:&quot;content-canvas&quot;,&quot;yTrafficOrigin&quot;:&quot;content-canvas default&quot;}\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">press@gitlab.com<\/a>  <\/p>\n","protected":false},"excerpt":{"rendered":"Dependency Scanning Auto-Remediation, now in public beta, shrinks the security backlog without diverting developers to upgrade vulnerable dependencies&hellip;\n","protected":false},"author":2,"featured_media":108741,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,7493,46811,14655],"class_list":["post-108740","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-agentic-artificial-intelligence","tag-dependencies","tag-gitlab"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/108740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=108740"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/108740\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/108741"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=108740"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=108740"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=108740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}