GitLab Announces the Foundation for the Governed Software Factory
New capabilities help organizations move beyond fragmented shadow software factories to a governed system for
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.
![]()
All Remote– GitLab Inc., the intelligent orchestration platform for DevSecOps, today announced new capabilities for the governed software factory, a connected system for moving software from idea to production under an organization’s own policy and standards. These new innovations are designed to help organizations ship more AI-generated software to production without taking on more risk or cost.
More than 70 million developers and over 10,000 enterprises innovate on GitLab today. Over the last three months on GitLab, active users of agentic software development grew 200% year over year, while secure repositories grew 100%, user namespaces grew 80%, and CI/CD pipelines grew 40%.
Yet most organizations are running a shadow software factory built from separate tools for coding, issue tracking, source code management, CI/CD pipelines, security, artifact management, and deployment.
These systems have no shared identity, common policy, or a record of how a change was made. That fragmentation slows handoffs, breaks context between stages, and prevents engineering leaders from tracing changes from plan to production or measuring the true impact of their AI investments.
GitLab connects those steps so agents can work within an organization’s context, workflows, and guardrails, while creating an evidence chain that records how changes move from intent to production. Together, these capabilities form the foundation of a governed software factory, helping organizations move from intent to production with fewer handoffs, stronger safeguards, and clearer visibility into what AI delivers.
Orchestrating Agentic Workflows Across the Software Lifecycle
Agentic software development can stall after coding when reviews, tests, security checks, approvals, and deployments require handoffs between people, tools, and stages.
Goal-driven flows in GitLab Duo Agent Platform, powered by /goal in Duo CLI, in headless mode and in Duo Agentic Chat, and the GitLab for Slack app, eliminate waits between handoffs across the software lifecycle.
Custom Flows and flow triggers automate multi-step work under the same identity, policy, and evidence chain. Teams can start and follow the same flows from the tools and channels they already use, under the same identity and policy.
Assembling the Right Software at Agent Scale
Most software that organizations ship is assembled from open-source packages, base images, and libraries. Builds fail when pipelines assemble the wrong or missing components, and agents multiply that failure rate by publishing packages at machine speed across vendor and project registries that carry their own rules.
GitLab Artifact Central, now in beta on GitLab.com with availability on GitLab Self-Managed planned for later this month, lets platform teams assemble the right software the first time. It brings containers and packages into one control plane alongside source code management and CI pipelines. With GitLab Artifact Central, teams set policy once at the organization level, instantly answer what was published, and realize up to 50% lower total cost of ownership compared with alternative tooling.
Securing the Software Factory at Machine Speed
As organizations adopt agentic software development, more code, packages, and credentials move through the software supply chain than security teams can review. Agents can pull unvetted packages into a build or reuse credentials stored in local environments, and each vulnerability that stays open increases the risk of exploitation. At machine speed, agents need a foundation they can prove before they earn more autonomy.
To meet the challenge, GitLab is adding security controls to govern what enters a build, to protect credentials each job can reach, to harden the defensive posture for software delivery, and is providing the best practices engineering leaders can use to assess their risk posture for agentic software development.
GitLab Dependency Firewall, available in early access, checks every package against policy before it enters a build. It warns, blocks, or quarantines packages based on rules the organization sets for package age, vulnerability severity, malicious package detection, and license compliance. One control plane spans source, build, and registry, helping teams trace exposure to affected projects and prioritize remediation in minutes instead of weeks.
GitLab Secrets Manager, generally available on GitLab.com and on GitLab Self-Managed in the 19.5 release, secures build-time secrets in one place, and scopes each secret to the job that needs it. It applies existing group and project permissions, and records every event in the GitLab audit trail. With GitLab Secrets Manager, teams can revoke a leaked credential in one click, and realize up to 50% savings compared to hosting a separate vault.
Anthropic’s Claude Mythos 5 and 5.1 will be available within new GitLab Duo Agent Platform security flows next month, helping organizations with approved environments find and fix vulnerabilities faster than attackers can discover and exploit them.
The GitLab Security Standard, available today, gives security and engineering leaders a way to assess their security posture, build trust in autonomous agents through verifiable outcomes, and protect software already in production. The standard sets five controls for the agentic era and uses time from detection to verified remediation as its core metric.
Optimizing Agentic Workflows for Context and Cost
AI investment is difficult to manage when leaders cannot connect credits consumed to outcomes delivered. Without that evidence, prioritizing the next use case and setting spending limits becomes guesswork. Agentic workflows also incur unnecessary cost when they lack the lifecycle context needed to complete a task, leading to more retries and higher token consumption.
GitLab addresses these challenges by giving agents the lifecycle context they need to work more efficiently and leaders clear visibility into AI cost and impact.
Since its beta announcement in June, GitLab Orbit has been used by more than 3,500 organizations and supported over 280,000 queries from their coding agents. It maps the entire software lifecycle into real-time knowledge that agents can act on, enabling them to complete tasks with up to 45x fewer retries and 4.5x fewer tokens. Orbit will reach general availability next month across all GitLab deployment options.
Duo Agent Platform Impact Analytics, now in early access, shows cost and impact of AI investment by team, task, and model. Impact Analytics complements the recently introduced AI usage caps and controls, which allows platform admins to set spending ceilings at the subscription, group, or user level. Teams see their adoption metrics, results of agentic workflows, and credit consumption alongside the real work that reaches production. This level of visibility is made available even when using a mix of AI models with Duo Agent Platform: GitLab-managed frontier and open-weight models, or self-hosted.
To learn more, please read the what’s new page.
Supporting Quotes
- “GitLab Secrets Manager lets us centralize secrets across CI/CD, Kubernetes, and infrastructure as code without standing up multiple vaults or maintaining separate integration points,” said Jeremy Nauta, software architect, OneTrust. “It also strengthens our supply chain security by tightening which users and pipelines can access a given credential.”
- “When defenders have more context than attackers, advanced models change the math in their favor,” said Rajat Pandit, Head of Applied AI at Anthropic. “GitLab’s customers will be able to use Claude Mythos 5 and 5.1 to find vulnerabilities and verify fixes inside the workflows they already run.”
- “Every enterprise already runs a software factory, but few have intentionally designed the systems and controls that govern it,” said Manav Khurana, chief product and marketing officer at GitLab. “GitLab brings together the foundational building blocks for a governed software factory, connecting agentic workflows, security, and AI context and controls so organizations can move software from intent to production with greater speed, governance, and visibility.”
About GitLab
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 70 million registered users and approximately 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.
*Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.
Forward-Looking Statements
This press release contains “forward-looking statements” within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934. Although we believe that the expectations reflected in the forward-looking statements contained in this release are reasonable, they are subject to known and unknown risks, uncertainties, assumptions and other factors that may cause actual results or outcomes to be materially different from any future results or outcomes expressed or implied by the forward-looking statements.
Further information on risks, uncertainties, and other factors that could cause actual outcomes and results to differ materially from those included in or contemplated by the forward-looking statements contained in this release are included under the caption “Risk Factors” and elsewhere in the filings and reports we make with the Securities and Exchange Commission. We do not undertake any obligation to update or release any revisions to any forward-looking statement or to report any events or circumstances after the date of this press release or to reflect the occurrence of unanticipated events, except as required by law.
View source version on businesswire.com: https://www.businesswire.com/news/home/20261006057924/en/
Media gallery
