AI
GitLab 19.2 Brings Governed Agentic Automation to Clear the Backlog AI Coding Creates
SAN FRANCISCO, July 16, 2026--(All Remote)--GitLab Inc., the intelligent orchestration platform for DevSecOps, today released GitLab 19.2. As AI generates more code, dependencies, and change than developers can keep up with, GitLab 19.2 brings agentic automation to clear that load.
About this update from Gitlab Inc.
SAN FRANCISCO, July 16, 2026 --( BUSINESS WIRE )--(All Remote)-- GitLab Inc. , the intelligent orchestration platform for DevSecOps, today released GitLab 19.2. As AI generates more code, dependencies, and change than developers can keep up with, GitLab 19.2 brings agentic automation to clear that load. Developers can now use GitLab to fix vulnerable dependencies automatically, catch the logic flaws scanners miss, create custom agentic workflows, invoke agents from more surfaces they already use, and always do so under the organization's existing controls. A Forrester Consulting study commissioned by GitLab found organizations using GitLab Duo Agent Platform can achieve 400% return on investment with payback in under six months. Dependency Scanning Auto-Remediation, Now in Public Beta, Helps Fix Vulnerable Dependencies Automatically A growing share of application security risk now comes from dependencies teams never chose directly. A study of the Maven ecosystem found vulnerabilities reaching roughly 63% of latest releases through transitive dependencies, and roughly one in eight dependency updates introduces a breaking change, even as compliance deadlines under PCI DSS and FedRAMP keep running. Dependency Scanning Auto-Remediation , now in public beta, closes that gap. Security developers can now clear vulnerable dependencies without adding work for developers. When a scan finds a vulnerable package, GitLab opens a merge request with the suggested fix. If an upgrade breaks the build, agents iterate to fix the issue in the same merge request. New configuration controls let developers set the severity thresholds and version scope that remediation applies to. Every change stops at existing approval gates and leaves a full audit trail. Security Review Flow, Now in Public Beta, Brings Security Judgment to Every Merge Request