GitLab 19.2: AI Agents Tackle Security Backlog
Summary
GitLab has released version 19.2 of its DevSecOps platform, introducing new agentic automation. This update aims to address the growing backlog in security and review work, which has increased as AI coding tools generate more code than developers can manually check. Four key features are now out of beta or in public beta. Dependency Scanning Auto-Remediation, now in public beta, automatically proposes safe versions for vulnerable dependencies. If an update breaks the build, an agent iterates on the merge request until the pipeline passes. This capability is called Agentic Breaking Change Resolution. The Security Review Flow, also in public beta, identifies logic flaws that typical scanners often miss. It posts findings as threaded comments with severity ratings and suggested fixes, but a person still makes the final approval. GitLab Duo CLI is now generally available, bringing agents into the terminal with project awareness. Custom Flows has also reached general availability, allowing teams to build their own automations in YAML. The bottom line is that these new features help manage the increased code volume from AI-assisted coding, making the review and security process more efficient.
This is an AI-generated audio summary. Always check the original source for complete reporting.