<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/gitlab-19-0-embeds-agentic-ai-in-secrets-merge-requests-and-supply-chain-security-ecao3bucp" -->

---
title: GitLab 19.0 Embeds Agentic AI in Secrets, Merge...
description: GitLab 19.0 extends agentic AI beyond code generation into secrets management, merge request automation, and supply chain security. Key additions include a...
canonical: https://daily.dev/posts/gitlab-19-0-embeds-agentic-ai-in-secrets-merge-requests-and-supply-chain-security-ecao3bucp
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: GitLab 19.0 Embeds Agentic AI in Secrets, Merge Requests, and Supply Chain Security | daily.dev
og:description: GitLab 19.0 extends agentic AI beyond code generation into secrets management, merge request automation, and supply chain security. Key additions include a...
og:url: https://daily.dev/posts/gitlab-19-0-embeds-agentic-ai-in-secrets-merge-requests-and-supply-chain-security-ecao3bucp
og:image: https://api.daily.dev/og/posts/ecaO3bucP.png
og:image:alt: GitLab 19.0 Embeds Agentic AI in Secrets, Merge Requests, and Supply Chain Security
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# GitLab 19.0 Embeds Agentic AI in Secrets, Merge Requests, and Supply Chain Security

**[InfoQ](https://daily.dev/sources/infoq)** · 3 min read · 8 upvotes · 0 comments

## Summary

GitLab 19.0 extends agentic AI beyond code generation into secrets management, merge request automation, and supply chain security. Key additions include a public beta GitLab Secrets Manager that integrates with HashiCorp Vault, AWS, Azure, and GCP secret stores; an expanded Developer Flow agent that handles reviewer feedback, MR splitting, conflict resolution, and one-click rebase-and-merge; and generally available SBOM-based dependency scanning covering Maven, npm, NuGet, PyPI, Go, and Cargo. GitLab Duo Core moves to usage-based billing via GitLab Credits, and Duo Chat becomes agent-based on the GitLab Duo Agent Platform. Self-hosted teams gain four new open-source models for air-gapped environments plus Claude Opus 4.7 and Gemini support. The release also raises minimum platform requirements to PostgreSQL 17 and drops Redis 6 and several Linux package targets.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.infoq.com/news/2026/06/gitlab-19-agentic-ai>

## Questions this post answers

### What are the new minimum platform requirements for GitLab 19.0?

GitLab 19.0 requires PostgreSQL 17 as the minimum supported version, ends support for Redis 6, and drops Linux packages for Ubuntu 20.04 and SUSE distributions. Teams planning to upgrade need to verify their infrastructure meets these raised minimums before moving to this release.

_Track platform requirement changes like these on daily.dev before planning a GitLab upgrade._

### What is GitLab Secrets Manager and how does it work with existing secret stores like HashiCorp Vault?

GitLab Secrets Manager is a public beta feature for Premium and Ultimate users that stores credentials within the same platform running code and pipelines, restricting each secret to authorized jobs. It works alongside HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, and Google Cloud Secret Manager rather than replacing them, using GitLab's existing group and project hierarchy for access control and audit logging.

_Developers weighing secrets management options can follow tooling comparisons like this on daily.dev._

### Which ecosystems does GitLab's SBOM-based dependency scanning support now that it's generally available?

GitLab's SBOM-based dependency scanner is generally available and covers Maven, npm, NuGet, PyPI, Go, and Cargo ecosystems. Automatic dependency resolution, which generates required lockfiles or dependency graph exports when a project hasn't committed them, is enabled by default for Maven, Gradle, and Python, with manifest scanning as a fallback.

_daily.dev helps engineers keep up with supply chain security features as scanning tools mature._

## Similar posts on daily.dev

- [GitLab 19.0](https://daily.dev/posts/gitlab-19-0-3itkgipag) · GitLab · 10 upvotes · 0 comments
- [GitLab 19.0 trades its string section for a full DevSecOps orchestra](https://daily.dev/posts/gitlab-19-0-trades-its-string-section-for-a-full-devsecops-orchestra-jczm46v34) · The New Stack · 2 upvotes · 0 comments
- [GitLab 19.0 targets the gap between writing code and shipping it](https://daily.dev/posts/gitlab-19-0-targets-the-gap-between-writing-code-and-shipping-it-jmuidkvw4) · The Next Web · 2 upvotes · 0 comments

---

Tags: [#gitlab](https://daily.dev/tags/gitlab), [#devsecops](https://daily.dev/tags/devsecops), [#agentic-ai](https://daily.dev/tags/agentic-ai), [#secrets-management](https://daily.dev/tags/secrets-management), [#sbom](https://daily.dev/tags/sbom)

[View this post on daily.dev](https://daily.dev/posts/gitlab-19-0-embeds-agentic-ai-in-secrets-merge-requests-and-supply-chain-security-ecao3bucp)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"GitLab 19.0 Embeds Agentic AI in Secrets, Merge Requests, and Supply Chain Security","url":"https://daily.dev/posts/gitlab-19-0-embeds-agentic-ai-in-secrets-merge-requests-and-supply-chain-security-ecao3bucp","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/gitlab-19-0-embeds-agentic-ai-in-secrets-merge-requests-and-supply-chain-security-ecao3bucp"},"datePublished":"2026-06-19T08:02:12.766Z","dateModified":"2026-09-13T20:01:01.927Z","description":"GitLab 19.0 extends agentic AI beyond code generation into secrets management, merge request automation, and supply chain security. Key additions include a...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/adfec35719646bc839497ae257986154?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/adfec35719646bc839497ae257986154?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"InfoQ","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"InfoQ","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/afc3bced3e1e4b188dd9127017a60e0c","url":"https://daily.dev/sources/infoq"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/gitlab-19-0-embeds-agentic-ai-in-secrets-merge-requests-and-supply-chain-security-ecao3bucp","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":8},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"gitlab,devsecops,agentic-ai,secrets-management,sbom","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"InfoQ","item":"https://daily.dev/sources/infoq"},{"@type":"ListItem","position":3,"name":"GitLab 19.0 Embeds Agentic AI in Secrets, Merge Requests, and Supply Chain Security"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/gitlab-19-0-embeds-agentic-ai-in-secrets-merge-requests-and-supply-chain-security-ecao3bucp#faq","mainEntity":[{"@type":"Question","name":"What are the new minimum platform requirements for GitLab 19.0?","acceptedAnswer":{"@type":"Answer","text":"GitLab 19.0 requires PostgreSQL 17 as the minimum supported version, ends support for Redis 6, and drops Linux packages for Ubuntu 20.04 and SUSE distributions. Teams planning to upgrade need to verify their infrastructure meets these raised minimums before moving to this release. Track platform requirement changes like these on daily.dev before planning a GitLab upgrade."}},{"@type":"Question","name":"What is GitLab Secrets Manager and how does it work with existing secret stores like HashiCorp Vault?","acceptedAnswer":{"@type":"Answer","text":"GitLab Secrets Manager is a public beta feature for Premium and Ultimate users that stores credentials within the same platform running code and pipelines, restricting each secret to authorized jobs. It works alongside HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, and Google Cloud Secret Manager rather than replacing them, using GitLab's existing group and project hierarchy for access control and audit logging. Developers weighing secrets management options can follow tooling comparisons like this on daily.dev."}},{"@type":"Question","name":"Which ecosystems does GitLab's SBOM-based dependency scanning support now that it's generally available?","acceptedAnswer":{"@type":"Answer","text":"GitLab's SBOM-based dependency scanner is generally available and covers Maven, npm, NuGet, PyPI, Go, and Cargo ecosystems. Automatic dependency resolution, which generates required lockfiles or dependency graph exports when a project hasn't committed them, is enabled by default for Maven, Gradle, and Python, with manifest scanning as a fallback. daily.dev helps engineers keep up with supply chain security features as scanning tools mature."}}]}
```

