GitLab Blog
Featured blog posts
Security
Track organization-wide security risk in one dashboard
For enterprises with many top-level groups, GitLab now aggregates vulnerabilities and a single risk score across your entire organization.
Security
Dependency Firewall: Block risky packages before the build
GitLab Dependency Firewall helps keep malicious and vulnerable packages out of your build automatically, so teams and their agents ship fast with trusted dependencies.
Product
Every artifact your teams ship, assembled right the first time
Bring your packages and container images into one governed home, right beside your code and pipelines. GitLab Artifact Central is now in free beta.
Recent posts

Two front doors: Module-level access in a Django GRC app
A technical deep-dive on restructuring a Django internal tool to support two distinct GitLab teams: Security Compliance and Internal Audit.
Browse by category

Agile planning gets a boost from new features in GitLab 18.10
Work items list and saved views reduce context switching, keeping your software development team aligned and their workflows efficient.
Ace your planning without the context-switching
Embedded views: The future of work tracking in GitLab

GitLab and Claude Code: Fast, compliant AI
Balance AI speed and compliance in government agencies. Discover how GitLab Duo Agent Platform governs Claude Code without slowing development.
Optimize your team's price-performance with hosted open weight models
New MCP tools help platform teams scale automation

curl removed from Omnibus-GitLab FIPS packages in 19.0
With the Omnibus-GitLab 19.0 release, GitLab will stop building curl for FIPS customers. Here’s what you need to know.
Claude Opus 4.7 is now available in GitLab Duo Agent Platform
Passkeys now available for passwordless sign-in and 2FA on GitLab

The Co-Create Program: How customers are collaborating to build GitLab
Learn how organizations like Thales, Scania, and Kitware are partnering with GitLab engineers to contribute meaningful features that benefit the entire community.
Kingfisher transforming the developer experience with GitLab
How Indeed transformed its CI platform with GitLab

How to design GitLab for enterprise scale
Plan an enterprise rollout with clear choices for deployment, runner capacity, availability, disaster recovery, and pipeline performance.
How to calculate DevOps platform total cost of ownership
Consolidate your GitLab stack with Gitaly on Kubernetes

Two front doors: Module-level access in a Django GRC app
A technical deep-dive on restructuring a Django internal tool to support two distinct GitLab teams: Security Compliance and Internal Audit.
How GitLab reduced code-per-agentic-flow ratio by 45%
Co-Create: Building GitLab with our users

When code is abundant
Producing code is getting cheap. Trusting it is not. Why enterprises need a durable layer of context, verification, and governance around AI agents.
GitLab named a Leader in the 2026 Gartner® Magic Quadrant™ for DevSecOps Platforms
GitLab and Capgemini accelerate DevSecOps transformation

What's new in Git 2.56.0?
Learn about the new features and changes in the latest Git release, including a new git-history(1) drop command, git-refs(1) getting new subcommands to modify refs, linearizing history with git-replay(1), and more.
How to recognize your team with GitLab Achievements
What's new in Git 2.55.0?

GitLab Transcend: Speed you can trust, all the way to production
Every new GitLab innovation announced at Transcend: what shipped, what's coming, and how to get started.
Every artifact your teams ship, assembled right the first time
GitLab Critical Patch Release: 19.4.1, 19.3.3, 19.2.7

Track organization-wide security risk in one dashboard
For enterprises with many top-level groups, GitLab now aggregates vulnerabilities and a single risk score across your entire organization.
Dependency Firewall: Block risky packages before the build
Securing the software factory at machine speed

DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent
GitLab's Threat Research Group found a flaw, ConfigPoisoning, that runs attacker code when a developer views a file's diff in DeepSeek-Reasonix.

