GitLab 19.3 rolls out enterprise-focused updates for scaling agentic software development, including running GitLab Duo Agent Platform inside GitLab Dedicated single-tenant environments, a new Secrets Manager add-on covering CI and infrastructure secrets, Flow Creator Agent for building custom automation flows via plain language, and Bulk SAST False Positive Detection with Agentic SAST Vulnerability Resolution for clearing vulnerability backlogs at scale. Additional features include GitLab Credits usage caps for controlling agentic AI spend and restricted visibility for custom agents and flows at the group level.

4m read timeFrom sdtimes.com
Post cover image
Table of contents
About SD Times Newswire

Questions this post answers

What new features does GitLab 19.3 include for AI agents and security?

GitLab 19.3 ships Secrets Manager in limited availability as a paid add-on, Flow Creator Agent for building custom automation flows from plain language descriptions, and Bulk SAST False Positive Detection with Agentic SAST Vulnerability Resolution that lets teams clear multiple vulnerability findings at once with confidence scores and ready-to-merge fixes. daily.dev helps engineering teams track GitLab release updates like these for their DevSecOps pipelines.

Can GitLab Duo Agent Platform run inside GitLab Dedicated single-tenant infrastructure?

Yes, as of GitLab 19.3, the AI Gateway for GitLab Duo Agent Platform runs inside GitLab Dedicated single-tenant SaaS infrastructure, letting agentic workloads follow the same residency and isolation model as the rest of the software development lifecycle, and customers can connect their own models for inference while keeping AI-processed data inside their existing security boundary. Teams evaluating agentic AI deployment options for regulated environments follow changes like this on daily.dev.

How does GitLab Secrets Manager scope CI secrets differently from a standard CI variable setup?

GitLab Secrets Manager scopes every secret to the environment, branch, and protection status of the job requesting it, applying the same permission model whether the secret is used inside a pipeline or by infrastructure outside it. It also supports Kubernetes, Terraform, OpenTofu, and custom tools, and is available in limited availability as a paid add-on billed through GitLab Credits. daily.dev keeps developers managing pipeline secrets current on tooling changes like this.

2 Impressions