[{"data":1,"prerenderedAt":1198},["ShallowReactive",2],{"/blog/claude-security-and-gitlab":3,"navigation-en-us":419,"banner-en-us":846,"footer-en-us":856,"blog-post-authors-en-us-Alisa Ho":1101,"blog-related-posts-en-us-claude-security-and-gitlab":1115,"blog-promotions-en-us":1136,"next-steps-en-us":1188},{"id":4,"title":5,"authors":6,"body":8,"category":399,"date":400,"description":401,"extension":402,"externalUrl":403,"faq":403,"featured":404,"heroImage":405,"meta":406,"navigation":404,"path":407,"seo":408,"slug":411,"stem":412,"tags":413,"template":417,"updatedDate":403,"__hash__":418},"blogPosts/en-us/blog/claude-security-and-gitlab.md","Secure every commit to production with Claude and GitLab",[7],"Alisa Ho",{"type":9,"value":10,"toc":388},"minimark",[11,28,31,40,45,48,51,102,109,113,116,119,171,177,181,184,187,223,229,233,248,251,254,305,311,315,323,326,332,336,339,342,361,365],[12,13,14,15,21,22,27],"p",{},"Agentic coding is moving faster than many enterprise governance programs can keep up with. Coding assistants, like the ",[16,17,20],"a",{"href":18,"rel":19},"https://code.claude.com/docs/en/security-guidance",[],"Claude security guidance plugin"," and ",[16,23,26],{"href":24,"rel":25},"https://code.claude.com/docs/en/claude-security",[],"Claude Security",", can flag and fix common vulnerabilities in code as it's written, in the same session. This is valuable for writing more secure code, but security doesn't stop there. A commit is one stage in the path to production: Merges, dependency updates, infrastructure changes, and audits happen after the session ends.",[12,29,30],{},"GitLab covers securing the remainder of the path to production. There are five handoffs in the typical Anthropic Claude-to-GitLab security workflow. This article walks through each one to illustrate how to govern agentic coding at scale.",[12,32,33,34,39],{},"Teams already using Claude security guidance and Claude Security can plug that context directly into GitLab through the ",[16,35,38],{"href":36,"rel":37},"https://docs.gitlab.com/user/model_context_protocol/mcp_server/",[],"GitLab MCP server"," and keep their existing workflow. Claude handles the moment of authoring; GitLab handles everything from there through production, on one platform.",[41,42,44],"h2",{"id":43},"from-flagged-to-enforced-controls","From flagged to enforced controls",[12,46,47],{},"The Claude security guidance plugin reviews code within a single developer's session, catching issues fast enough to keep an agent moving. Once that code leaves a session, security teams need a record of what happened inside it and controls over what happens next.",[12,49,50],{},"GitLab gives teams the visibility and the control to define guardrails for secure coding, before code reaches production, no matter where the code originated.",[52,53,54,68,79,85],"ul",{},[55,56,57,61,62,67],"li",{},[58,59,60],"strong",{},"Define controls once, enforce scale."," ",[16,63,66],{"href":64,"rel":65},"https://docs.gitlab.com/user/application_security/configuration/security_configuration_profiles/",[],"Security configuration profiles"," apply the scans you require across every project and pipeline from outside the repository, so coverage is consistent and can't be bypassed.",[55,69,70,61,73,78],{},[58,71,72],{},"Enforce separation of duties, even for agents.",[16,74,77],{"href":75,"rel":76},"https://docs.gitlab.com/user/application_security/policies/merge_request_approval_policies/",[],"Merge request approval policies"," ensure that the agent that wrote a change can't approve it. An agent, or the developer who prompted it, can't merge its own work without a designated approver.",[55,80,81,84],{},[58,82,83],{},"Block critical vulnerabilities before they ship."," Merge request approval policies hold any merge with unresolved critical findings until a named approver signs off, so dismissed or missed vulnerabilities can't reach production quietly.",[55,86,87,90,91,21,96,101],{},[58,88,89],{},"Track every finding's status, permanently."," The ",[16,92,95],{"href":93,"rel":94},"https://docs.gitlab.com/user/application_security/vulnerability_report/",[],"Vulnerability report",[16,97,100],{"href":98,"rel":99},"https://docs.gitlab.com/user/application_security/security_dashboard/",[],"Security dashboard"," show whether each finding was detected, dismissed with a reason, or resolved.",[12,103,104],{},[105,106],"img",{"alt":107,"src":108,"title":107},"Enable scanners across every in-scope project at scale, with no way to bypass them","https://res.cloudinary.com/about-gitlab-com/image/upload/v1785525382/b29bi5eu71wuowipzskr.png",[41,110,112],{"id":111},"from-scanned-in-session-to-audit-evidence","From scanned in session to audit evidence",[12,114,115],{},"Change management audit requirements are expanding to include agents. Compliance frameworks such as SOC 2, PCI DSS, and FedRAMP require documented evidence that every change was tested, reviewed, and approved before it shipped.",[12,117,118],{},"GitLab makes compliance controls enforceable and evidence collection automatic for auditors:",[52,120,121,132,155],{},[55,122,123,61,126,131],{},[58,124,125],{},"Prove the scan ran and review.",[16,127,130],{"href":128,"rel":129},"https://docs.gitlab.com/user/compliance/compliance_frameworks/#gitlab-compliance-controls",[],"Compliance controls"," guarantee a scan runs on every merge request, and every finding surfaces in the merge request and vulnerability report, visible to a human.",[55,133,134,61,137,142,143,148,149,154],{},[58,135,136],{},"Answer auditors in minutes.",[16,138,141],{"href":139,"rel":140},"https://docs.gitlab.com/ci/jobs/job_logs/",[],"Pipeline logs",", ",[16,144,147],{"href":145,"rel":146},"https://docs.gitlab.com/user/project/merge_requests/approvals/",[],"approval records",", and ",[16,150,153],{"href":151,"rel":152},"https://docs.gitlab.com/user/compliance/audit_events/",[],"audit events"," give you reproducible history of what was scanned and who approved it, change by change, tied to the people and agents involved.",[55,156,157,61,160,164,165,170],{},[58,158,159],{},"Map evidence to the framework your auditor requests.",[16,161,163],{"href":128,"rel":162},[],"Compliance frameworks"," group evidence into named requirements, such as SOC 2 or a custom framework, each built from specific controls, and the ",[16,166,169],{"href":167,"rel":168},"https://docs.gitlab.com/user/compliance/compliance_center/compliance_status_report/",[],"compliance status report"," shows which controls passed, are pending, or failed, per framework.",[12,172,173],{},[105,174],{"alt":175,"src":176,"title":175},"Audit log of agent activity, showing session-level events and start times","https://res.cloudinary.com/about-gitlab-com/image/upload/v1785525382/xehdn27jhyv1tb0agrjt.png",[41,178,180],{"id":179},"control-what-sensitive-data-is-sent","Control what sensitive data is sent",[12,182,183],{},"You probably send more of your code, and the business context around it, to a model for review than you do a person. Regulated, government, and IP-sensitive teams need to decide what leaves their environment, such as credentials, proprietary logic, and regulated data. That decision has to happen before any scan runs, and across every tool that touches their code.",[12,185,186],{},"With GitLab, you decide what data reaches a model before it ever leaves your environment:",[52,188,189,200,212],{},[55,190,191,61,194,199],{},[58,192,193],{},"Keep secrets and sensitive code out of what you send to a model.",[16,195,198],{"href":196,"rel":197},"https://docs.gitlab.com/user/duo_agent_platform/context/",[],"Context exclusions"," hold secrets and sensitive files back from everything an agent sends to models.",[55,201,202,205,206,211],{},[58,203,204],{},"Keep code and inference inside your boundary, on models you approve."," Run a self-managed environment with self-hosted models so nothing leaves your environment. ",[16,207,210],{"href":208,"rel":209},"https://docs.gitlab.com/user/duo_agent_platform/model_selection/",[],"Select the model per flow",", restrict which models are permitted, and keep your code out of training.",[55,213,214,61,217,222],{},[58,215,216],{},"Filter what gets sent.",[16,218,221],{"href":219,"rel":220},"https://docs.gitlab.com/user/gitlab_duo/prompt_guardrails/",[],"GitLab Duo's prompt guardrails"," scan code suggestions for secrets before they reach a model, and isolate the content a prompt can act on to reduce prompt injection risk, on top of whatever you've already excluded.",[12,224,225],{},[105,226],{"alt":227,"src":228,"title":227},"Define what files or directories should be excluded from being sent to AI models","https://res.cloudinary.com/about-gitlab-com/image/upload/v1785525382/uvgikegtzsabqdqahg04.png",[41,230,232],{"id":231},"from-one-scan-to-full-scanning-coverage-across-the-development-lifecycle","From one scan to full scanning coverage across the development lifecycle",[12,234,235,236,241,242,247],{},"Anthropic's ",[16,237,240],{"href":238,"rel":239},"https://github.com/anthropics/claude-plugins-official/tree/main/plugins/security-guidance",[],"documentation"," is explicit that the Claude security guidance plugin is a best-effort assistive tool, meant to sit alongside human code review and various security scanners, not replace them. That scoping is important to pay attention to, because some vulnerabilities don't exist at the moment code ships. A dependency you ship today can have a critical vulnerability disclosed against it next year, with no change to your own code. ",[16,243,246],{"href":244,"rel":245},"https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-356a",[],"Log4Shell"," is the clearest example; applications that shipped years earlier were suddenly exploitable the moment the vulnerability became public knowledge in December 2021.",[12,249,250],{},"Dependencies, container images, infrastructure configuration, and secrets already sitting in your commit history need scanning that runs independently of any single session.",[12,252,253],{},"GitLab secures the entire software delivery lifecycle:",[52,255,256,287,299],{},[55,257,258,61,261,142,266,142,271,142,276,148,281,286],{},[58,259,260],{},"Cover the whole attack surface.",[16,262,265],{"href":263,"rel":264},"https://docs.gitlab.com/user/application_security/dependency_scanning/",[],"Dependency",[16,267,270],{"href":268,"rel":269},"https://docs.gitlab.com/user/application_security/container_scanning/",[],"container",[16,272,275],{"href":273,"rel":274},"https://docs.gitlab.com/user/application_security/iac_scanning/",[],"infrastructure-as-code",[16,277,280],{"href":278,"rel":279},"https://docs.gitlab.com/user/application_security/secret_detection/",[],"secret",[16,282,285],{"href":283,"rel":284},"https://docs.gitlab.com/user/application_security/dast/",[],"dynamic application security testing (DAST)"," scanning check the parts of an application a session-based review never reaches: the dependencies you pull in, the images you ship, the infrastructure you provision, the secrets that leak into commits, and the running app.",[55,288,289,292,293,298],{},[58,290,291],{},"Catch the flaws that scanners might miss."," Deterministic scanners cannot catch business logic errors, broken authorization, or race conditions. ",[16,294,297],{"href":295,"rel":296},"https://docs.gitlab.com/user/duo_agent_platform/flows/foundational_flows/security_review/",[],"Security Review Flow"," reasons about intent to catch that category directly, posted as comments on the affected code for a human to act on.",[55,300,301,304],{},[58,302,303],{},"Have a deterministic scan the results don't drift on."," LLM-based review could return different findings on the same code from one run to the next. A deterministic scan, such as advanced SAST, traces tainted data across function boundaries using a fixed algorithm and returns reproducible, CWE-mapped results — the consistent evidence a compliance audit needs.",[12,306,307],{},[105,308],{"alt":309,"src":310,"title":309},"SAST, DAST, dependency, container, and secret scanning enforced to be run on the pipeline","https://res.cloudinary.com/about-gitlab-com/image/upload/v1785525382/tmmgtxgnlivwhjmx6uz7.png",[41,312,314],{"id":313},"one-set-of-guardrails-for-every-agent-and-every-developer","One set of guardrails, for every agent and every developer",[12,316,317,318,322],{},"The Claude security guidance plugin reviews the code Claude writes and commits inside a session. Commits made from a developer's own shell, including the \"!\" shell escape inside a session, ",[16,319,321],{"href":18,"rel":320},[],"fall outside what the plug-in reviews",". Claude Security extends that to a full codebase or human-written code, on demand, when a developer or admin runs it.",[12,324,325],{},"GitLab’s scan execution and merge request approval policies run on the pipeline for every change, so coverage doesn't depend on whether a human or an agent wrote the code, or whether they remembered to initiate a scan.",[12,327,328],{},[105,329],{"alt":330,"src":331,"title":330},"Configure security scans to be run on every default branch","https://res.cloudinary.com/about-gitlab-com/image/upload/v1785525383/hs2u66vp2c7fbxemwvbt.png",[41,333,335],{"id":334},"govern-what-ships","Govern what ships",[12,337,338],{},"Claude security guidance and Claude Security help developers catch and fix issues the moment code is written. Once that code leaves the session, enterprise security and platform teams are accountable for shipping it securely to production. They need visibility into what an agent did, proof that security procedures were followed, and the ability to stop a problematic change before it ships.",[12,340,341],{},"GitLab bridges your Claude workflow. Set guardrails once in GitLab, and every agent and every developer ships faster and more securely inside them. Claude helps write secure code. GitLab governs everything from there to production, without slowing teams down.",[343,344,345,352],"blockquote",{},[12,346,347],{},[16,348,351],{"href":349,"rel":350},"https://about.gitlab.com/free-trial/?utm_medium=native&utm_source=integrate-market&utm_campaign=eg_global_cmp_content-syndication_security_en_",[],"Start a free trial of GitLab Ultimate!",[12,353,354,355,360],{},"Already on Ultimate? ",[16,356,359],{"href":357,"rel":358},"https://docs.gitlab.com/user/application_security/policies/",[],"Set up scan execution and merge request approval policies"," to start enforcing guardrails today.",[41,362,364],{"id":363},"learn-more","Learn more",[52,366,367,374,381],{},[55,368,369],{},[16,370,373],{"href":371,"rel":372},"https://about.gitlab.com/blog/claude-code-and-gitlab/",[],"Claude Code and GitLab: Three workflows that ship",[55,375,376],{},[16,377,380],{"href":378,"rel":379},"https://about.gitlab.com/blog/gitlab-duo-agent-platform-with-claude-accelerates-development/",[],"GitLab Duo Agent Platform with Claude accelerates development",[55,382,383],{},[16,384,387],{"href":385,"rel":386},"https://about.gitlab.com/blog/how-to-use-gitlabs-custom-compliance-frameworks-in-your-devsecops/",[],"How to use GitLab's Custom Compliance Frameworks in your DevSecOps environment",{"title":389,"searchDepth":390,"depth":390,"links":391},"",2,[392,393,394,395,396,397,398],{"id":43,"depth":390,"text":44},{"id":111,"depth":390,"text":112},{"id":179,"depth":390,"text":180},{"id":231,"depth":390,"text":232},{"id":313,"depth":390,"text":314},{"id":334,"depth":390,"text":335},{"id":363,"depth":390,"text":364},"security","2026-08-03","Claude Security catches vulnerabilities inside a coding session. GitLab picks up from there, scanning, enforcing policy, and producing audit evidence for the software lifecycle. ","md",null,true,"https://res.cloudinary.com/about-gitlab-com/image/upload/v1756122536/akivvcnafog9c4dhhzkp.png",{},"/en-us/blog/claude-security-and-gitlab",{"config":409,"title":5,"description":401},{"noIndex":410},false,"claude-security-and-gitlab","en-us/blog/claude-security-and-gitlab",[399,414,415,416],"AI","features","product","BlogPost","V8xYSbERuR3oef9BFJVYmIbD73GNfNn1k4gdH2WTysA",{"logo":420,"freeTrial":425,"sales":430,"login":435,"items":440,"search":766,"minimal":797,"duo":816,"switchNav":825,"pricingDeployment":836},{"config":421},{"href":422,"dataGaName":423,"dataGaLocation":424},"/","gitlab logo","header",{"text":426,"config":427},"Get free trial",{"href":428,"dataGaName":429,"dataGaLocation":424},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com&glm_content=default-saas-trial/","free trial",{"text":431,"config":432},"Request a demo",{"href":433,"dataGaName":434,"dataGaLocation":424},"/sales/?contact-topic=request-demo","sales",{"text":436,"config":437},"Sign in",{"href":438,"dataGaName":439,"dataGaLocation":424},"https://gitlab.com/users/sign_in/","sign in",[441,469,569,574,688,744],{"text":442,"config":443,"menu":445},"Platform",{"dataNavLevelOne":444},"platform",{"type":446,"columns":447},"cards",[448,454,462],{"title":442,"description":449,"link":450},"The intelligent orchestration platform for DevSecOps",{"text":451,"config":452},"Explore our Platform",{"href":453,"dataGaName":444,"dataGaLocation":424},"/platform/",{"title":455,"description":456,"link":457},"GitLab Duo Agent Platform","Agentic AI for the entire software lifecycle",{"text":458,"config":459},"Meet GitLab Duo",{"href":460,"dataGaName":461,"dataGaLocation":424},"/gitlab-duo-agent-platform/","gitlab duo agent platform",{"title":463,"description":464,"link":465},"Why GitLab","See the top reasons enterprises choose GitLab",{"text":364,"config":466},{"href":467,"dataGaName":468,"dataGaLocation":424},"/why-gitlab/","why gitlab",{"text":470,"left":404,"config":471,"menu":473},"Product",{"dataNavLevelOne":472},"solutions",{"type":474,"link":475,"columns":479,"feature":548},"lists",{"text":476,"config":477},"View all Solutions",{"href":478,"dataGaName":472,"dataGaLocation":424},"/solutions/",[480,504,527],{"title":481,"description":482,"link":483,"items":488},"Automation","CI/CD and automation to accelerate deployment",{"config":484},{"icon":485,"href":486,"dataGaName":487,"dataGaLocation":424},"AutomatedCodeAlt","/solutions/delivery-automation/","automated software delivery",[489,493,496,500],{"text":490,"config":491},"CI/CD",{"href":492,"dataGaLocation":424,"dataGaName":490},"/solutions/continuous-integration/",{"text":455,"config":494},{"href":460,"dataGaLocation":424,"dataGaName":495},"gitlab duo agent platform - product menu",{"text":497,"config":498},"Source Code Management",{"href":499,"dataGaLocation":424,"dataGaName":497},"/solutions/source-code-management/",{"text":501,"config":502},"Automated Software Delivery",{"href":486,"dataGaLocation":424,"dataGaName":503},"Automated software delivery",{"title":505,"description":506,"link":507,"items":512},"Security","Deliver code faster without compromising security",{"config":508},{"href":509,"dataGaName":510,"dataGaLocation":424,"icon":511},"/solutions/application-security-testing/","security and compliance","ShieldCheckLight",[513,517,522],{"text":514,"config":515},"Application Security Testing",{"href":509,"dataGaName":516,"dataGaLocation":424},"Application security testing",{"text":518,"config":519},"Software Supply Chain Security",{"href":520,"dataGaLocation":424,"dataGaName":521},"/solutions/supply-chain/","Software supply chain security",{"text":523,"config":524},"Software Compliance",{"href":525,"dataGaName":526,"dataGaLocation":424},"/solutions/software-compliance/","software compliance",{"title":528,"link":529,"items":534},"Measurement",{"config":530},{"icon":531,"href":532,"dataGaName":533,"dataGaLocation":424},"DigitalTransformation","/solutions/visibility-measurement/","visibility and measurement",[535,539,543],{"text":536,"config":537},"Visibility & Measurement",{"href":532,"dataGaLocation":424,"dataGaName":538},"Visibility and Measurement",{"text":540,"config":541},"Value Stream Management",{"href":542,"dataGaLocation":424,"dataGaName":540},"/solutions/value-stream-management/",{"text":544,"config":545},"Analytics & Insights",{"href":546,"dataGaLocation":424,"dataGaName":547},"/solutions/analytics-and-insights/","Analytics and insights",{"title":549,"type":474,"items":550},"GitLab for",[551,557,563],{"text":552,"config":553},"Enterprise",{"icon":554,"href":555,"dataGaLocation":424,"dataGaName":556},"Building","/enterprise/","enterprise",{"text":558,"config":559},"Small Business",{"icon":560,"href":561,"dataGaLocation":424,"dataGaName":562},"Work","/small-business/","small business",{"text":564,"config":565},"Public Sector",{"icon":566,"href":567,"dataGaLocation":424,"dataGaName":568},"Organization","/solutions/public-sector/","public sector",{"text":570,"config":571},"Pricing",{"href":572,"dataGaName":573,"dataGaLocation":424,"dataNavLevelOne":573},"/pricing/","pricing",{"text":575,"config":576,"menu":578},"Resources",{"dataNavLevelOne":577},"resources",{"type":474,"link":579,"columns":583,"feature":677},{"text":580,"config":581},"View all resources",{"href":582,"dataGaName":577,"dataGaLocation":424},"/resources/",[584,617,644],{"title":585,"items":586},"Getting started",[587,592,597,602,607,612],{"text":588,"config":589},"Install",{"href":590,"dataGaName":591,"dataGaLocation":424},"/install/","install",{"text":593,"config":594},"Quick start guides",{"href":595,"dataGaName":596,"dataGaLocation":424},"/get-started/","quick setup checklists",{"text":598,"config":599},"Learn",{"href":600,"dataGaLocation":424,"dataGaName":601},"https://university.gitlab.com/","learn",{"text":603,"config":604},"Product documentation",{"href":605,"dataGaName":606,"dataGaLocation":424},"https://docs.gitlab.com/","product documentation",{"text":608,"config":609},"Best practice videos",{"href":610,"dataGaName":611,"dataGaLocation":424},"/getting-started-videos/","best practice videos",{"text":613,"config":614},"Integrations",{"href":615,"dataGaName":616,"dataGaLocation":424},"/integrations/","integrations",{"title":618,"items":619},"Discover",[620,625,630,635,639],{"text":621,"config":622},"Customer success stories",{"href":623,"dataGaName":624,"dataGaLocation":424},"/customers/","customer success stories",{"text":626,"config":627},"Blog",{"href":628,"dataGaName":629,"dataGaLocation":424},"/blog/","blog",{"text":631,"config":632},"Demo Hub",{"href":633,"dataGaName":634,"dataGaLocation":424},"/demo-hub/","demo hub",{"text":636,"config":637},"The Source",{"href":638,"dataGaName":629,"dataGaLocation":424},"/the-source/",{"text":640,"config":641},"Remote",{"href":642,"dataGaName":643,"dataGaLocation":424},"https://handbook.gitlab.com/handbook/company/culture/all-remote/","remote",{"title":645,"items":646},"Connect",[647,652,657,662,667,672],{"text":648,"config":649},"GitLab Services",{"href":650,"dataGaName":651,"dataGaLocation":424},"/services/","services",{"text":653,"config":654},"Contribute",{"href":655,"dataGaName":656,"dataGaLocation":424},"https://contributors.gitlab.com","contribute",{"text":658,"config":659},"Community",{"href":660,"dataGaName":661,"dataGaLocation":424},"/community/","community",{"text":663,"config":664},"Forum",{"href":665,"dataGaName":666,"dataGaLocation":424},"https://forum.gitlab.com/","forum",{"text":668,"config":669},"Events",{"href":670,"dataGaName":671,"dataGaLocation":424},"/events/","events",{"text":673,"config":674},"Partners",{"href":675,"dataGaName":676,"dataGaLocation":424},"/partners/","partners",{"config":678,"title":681,"text":682,"link":683},{"background":679,"textColor":680},"url('https://res.cloudinary.com/about-gitlab-com/image/upload/v1777322348/qpq8yrgn8knii57omj0c.png')","#000","What’s new in GitLab","Stay updated with our latest features and improvements.",{"text":684,"config":685},"Read the latest",{"href":686,"dataGaName":687,"dataGaLocation":424},"/whats-new/","whats new",{"text":689,"config":690,"menu":692},"Company",{"dataNavLevelOne":691},"company",{"type":474,"columns":693},[694],{"items":695},[696,701,707,709,714,719,724,729,734,739],{"text":697,"config":698},"About",{"href":699,"dataGaName":700,"dataGaLocation":424},"/company/","about",{"text":702,"config":703,"footerGa":706},"Jobs",{"href":704,"dataGaName":705,"dataGaLocation":424},"/jobs/","jobs",{"dataGaName":705},{"text":668,"config":708},{"href":670,"dataGaName":671,"dataGaLocation":424},{"text":710,"config":711},"Leadership",{"href":712,"dataGaName":713,"dataGaLocation":424},"/company/team/e-group/","leadership",{"text":715,"config":716},"Handbook",{"href":717,"dataGaName":718,"dataGaLocation":424},"https://handbook.gitlab.com/","handbook",{"text":720,"config":721},"Investor relations",{"href":722,"dataGaName":723,"dataGaLocation":424},"https://ir.gitlab.com/overview/default.aspx","investor relations",{"text":725,"config":726},"Trust Center",{"href":727,"dataGaName":728,"dataGaLocation":424},"/security/","trust center",{"text":730,"config":731},"AI Transparency Center",{"href":732,"dataGaName":733,"dataGaLocation":424},"/ai-transparency-center/","ai transparency center",{"text":735,"config":736},"Newsletter",{"href":737,"dataGaName":738,"dataGaLocation":424},"/company/contact/#contact-forms","newsletter",{"text":740,"config":741},"Press",{"href":742,"dataGaName":743,"dataGaLocation":424},"/press/","press",{"text":745,"config":746,"menu":747},"Contact us",{"dataNavLevelOne":691},{"type":474,"columns":748},[749],{"items":750},[751,756,761],{"text":752,"config":753},"Talk to sales",{"href":754,"dataGaName":755,"dataGaLocation":424},"/sales/","talk to sales",{"text":757,"config":758},"Support portal",{"href":759,"dataGaName":760,"dataGaLocation":424},"https://support.gitlab.com/hc/en-us","support portal",{"text":762,"config":763},"Customer portal",{"href":764,"dataGaName":765,"dataGaLocation":424},"https://customers.gitlab.com/customers/sign_in/","customer portal",{"close":767,"login":768,"suggestions":775},"Close",{"text":769,"link":770},"To search repositories and projects, login to",{"text":771,"config":772},"gitlab.com",{"href":438,"dataGaName":773,"dataGaLocation":774},"search login","search",{"text":776,"default":777},"Suggestions",[778,780,784,786,790,794],{"text":455,"config":779},{"href":460,"dataGaName":455,"dataGaLocation":774},{"text":781,"config":782},"Code Suggestions (AI)",{"href":783,"dataGaName":781,"dataGaLocation":774},"/solutions/code-suggestions/",{"text":490,"config":785},{"href":492,"dataGaName":490,"dataGaLocation":774},{"text":787,"config":788},"GitLab on AWS",{"href":789,"dataGaName":787,"dataGaLocation":774},"/partners/technology-partners/aws/",{"text":791,"config":792},"GitLab on Google Cloud",{"href":793,"dataGaName":791,"dataGaLocation":774},"/partners/technology-partners/google-cloud-platform/",{"text":795,"config":796},"Why GitLab?",{"href":467,"dataGaName":795,"dataGaLocation":774},{"freeTrial":798,"mobileIcon":803,"desktopIcon":808,"secondaryButton":811},{"text":799,"config":800},"Start free trial",{"href":801,"dataGaName":429,"dataGaLocation":802},"https://gitlab.com/-/trials/new/","nav",{"altText":804,"config":805},"Gitlab Icon",{"src":806,"dataGaName":807,"dataGaLocation":802},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203874/jypbw1jx72aexsoohd7x.svg","gitlab icon",{"altText":804,"config":809},{"src":810,"dataGaName":807,"dataGaLocation":802},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203875/gs4c8p8opsgvflgkswz9.svg",{"text":812,"config":813},"Get Started",{"href":814,"dataGaName":815,"dataGaLocation":802},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com/get-started/","get started",{"freeTrial":817,"mobileIcon":821,"desktopIcon":823},{"text":818,"config":819},"Learn more about GitLab Duo",{"href":460,"dataGaName":820,"dataGaLocation":802},"gitlab duo",{"altText":804,"config":822},{"src":806,"dataGaName":807,"dataGaLocation":802},{"altText":804,"config":824},{"src":810,"dataGaName":807,"dataGaLocation":802},{"button":826,"mobileIcon":831,"desktopIcon":833},{"text":827,"config":828},"/switch",{"href":829,"dataGaName":830,"dataGaLocation":802},"#contact","switch",{"altText":804,"config":832},{"src":806,"dataGaName":807,"dataGaLocation":802},{"altText":804,"config":834},{"src":835,"dataGaName":807,"dataGaLocation":802},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1773335277/ohhpiuoxoldryzrnhfrh.png",{"freeTrial":837,"mobileIcon":842,"desktopIcon":844},{"text":838,"config":839},"Back to pricing",{"href":572,"dataGaName":840,"dataGaLocation":802,"icon":841},"back to pricing","GoBack",{"altText":804,"config":843},{"src":806,"dataGaName":807,"dataGaLocation":802},{"altText":804,"config":845},{"src":810,"dataGaName":807,"dataGaLocation":802},{"title":847,"titleMobile":848,"button":849,"config":854},"Duo Agent Platform delivers 400% ROI, per new Forrester Consulting study.","400% ROI: Forrester TEI for GitLab Duo",{"text":364,"config":850},{"href":851,"dataGaName":852,"dataGaLocation":853},"https://about.gitlab.com/blog/gitlab-duo-agent-platform-delivers-400-percent-roi/","forrester-tei-dap-banner","global-banner",{"layout":855,"disabled":410},"release",{"data":857},{"text":858,"source":859,"edit":865,"contribute":870,"config":875,"items":880,"minimal":1090},"Git is a trademark of Software Freedom Conservancy and our use of 'GitLab' is under license",{"text":860,"config":861},"View page source",{"href":862,"dataGaName":863,"dataGaLocation":864},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/","page source","footer",{"text":866,"config":867},"Edit this page",{"href":868,"dataGaName":869,"dataGaLocation":864},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/content/","web ide",{"text":871,"config":872},"Please contribute",{"href":873,"dataGaName":874,"dataGaLocation":864},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/CONTRIBUTING.md/","please contribute",{"twitter":876,"facebook":877,"youtube":878,"linkedin":879},"https://twitter.com/gitlab","https://www.facebook.com/gitlab","https://www.youtube.com/channel/UCnMGQ8QHMAnVIsI3xJrihhg","https://www.linkedin.com/company/gitlab-com",[881,928,982,1026,1058],{"title":570,"links":882,"subMenu":897},[883,887,892],{"text":884,"config":885},"View plans",{"href":572,"dataGaName":886,"dataGaLocation":864},"view plans",{"text":888,"config":889},"Why Premium?",{"href":890,"dataGaName":891,"dataGaLocation":864},"/pricing/premium/","why premium",{"text":893,"config":894},"Why Ultimate?",{"href":895,"dataGaName":896,"dataGaLocation":864},"/pricing/ultimate/","why ultimate",[898],{"title":899,"links":900},"Contact Us",[901,904,906,908,913,918,923],{"text":902,"config":903},"Contact sales",{"href":754,"dataGaName":434,"dataGaLocation":864},{"text":757,"config":905},{"href":759,"dataGaName":760,"dataGaLocation":864},{"text":762,"config":907},{"href":764,"dataGaName":765,"dataGaLocation":864},{"text":909,"config":910},"Status",{"href":911,"dataGaName":912,"dataGaLocation":864},"https://status.gitlab.com/","status",{"text":914,"config":915},"Terms of use",{"href":916,"dataGaName":917,"dataGaLocation":864},"/terms/","terms of use",{"text":919,"config":920},"Privacy statement",{"href":921,"dataGaName":922,"dataGaLocation":864},"/privacy/","privacy statement",{"text":924,"config":925},"Cookie preferences",{"dataGaName":926,"dataGaLocation":864,"id":927,"isOneTrustButton":404},"cookie preferences","ot-sdk-btn",{"title":470,"links":929,"subMenu":938},[930,934],{"text":931,"config":932},"DevSecOps platform",{"href":453,"dataGaName":933,"dataGaLocation":864},"devsecops platform",{"text":935,"config":936},"AI-Assisted Development",{"href":460,"dataGaName":937,"dataGaLocation":864},"ai-assisted development",[939],{"title":940,"links":941},"Topics",[942,947,952,957,962,967,972,977],{"text":943,"config":944},"CICD",{"href":945,"dataGaName":946,"dataGaLocation":864},"/topics/ci-cd/","cicd",{"text":948,"config":949},"GitOps",{"href":950,"dataGaName":951,"dataGaLocation":864},"/topics/gitops/","gitops",{"text":953,"config":954},"DevOps",{"href":955,"dataGaName":956,"dataGaLocation":864},"/topics/devops/","devops",{"text":958,"config":959},"Version Control",{"href":960,"dataGaName":961,"dataGaLocation":864},"/topics/version-control/","version control",{"text":963,"config":964},"DevSecOps",{"href":965,"dataGaName":966,"dataGaLocation":864},"/topics/devsecops/","devsecops",{"text":968,"config":969},"Cloud Native",{"href":970,"dataGaName":971,"dataGaLocation":864},"/topics/cloud-native/","cloud native",{"text":973,"config":974},"AI for Coding",{"href":975,"dataGaName":976,"dataGaLocation":864},"/topics/devops/ai-for-coding/","ai for coding",{"text":978,"config":979},"Agentic AI",{"href":980,"dataGaName":981,"dataGaLocation":864},"/topics/agentic-ai/","agentic ai",{"title":983,"links":984},"Solutions",[985,987,989,994,998,1001,1005,1008,1010,1013,1016,1021],{"text":514,"config":986},{"href":509,"dataGaName":514,"dataGaLocation":864},{"text":503,"config":988},{"href":486,"dataGaName":487,"dataGaLocation":864},{"text":990,"config":991},"Agile development",{"href":992,"dataGaName":993,"dataGaLocation":864},"/solutions/agile-delivery/","agile delivery",{"text":995,"config":996},"SCM",{"href":499,"dataGaName":997,"dataGaLocation":864},"source code management",{"text":943,"config":999},{"href":492,"dataGaName":1000,"dataGaLocation":864},"continuous integration & delivery",{"text":1002,"config":1003},"Value stream management",{"href":542,"dataGaName":1004,"dataGaLocation":864},"value stream management",{"text":948,"config":1006},{"href":1007,"dataGaName":951,"dataGaLocation":864},"/solutions/gitops/",{"text":552,"config":1009},{"href":555,"dataGaName":556,"dataGaLocation":864},{"text":1011,"config":1012},"Small business",{"href":561,"dataGaName":562,"dataGaLocation":864},{"text":1014,"config":1015},"Public sector",{"href":567,"dataGaName":568,"dataGaLocation":864},{"text":1017,"config":1018},"Education",{"href":1019,"dataGaName":1020,"dataGaLocation":864},"/solutions/education/","education",{"text":1022,"config":1023},"Financial services",{"href":1024,"dataGaName":1025,"dataGaLocation":864},"/solutions/finance/","financial services",{"title":575,"links":1027},[1028,1030,1032,1034,1037,1039,1042,1044,1046,1048,1050,1052,1054,1056],{"text":588,"config":1029},{"href":590,"dataGaName":591,"dataGaLocation":864},{"text":593,"config":1031},{"href":595,"dataGaName":596,"dataGaLocation":864},{"text":598,"config":1033},{"href":600,"dataGaName":601,"dataGaLocation":864},{"text":603,"config":1035},{"href":605,"dataGaName":1036,"dataGaLocation":864},"docs",{"text":626,"config":1038},{"href":628,"dataGaName":629,"dataGaLocation":864},{"text":1040,"config":1041},"What's new",{"href":686,"dataGaName":687,"dataGaLocation":864},{"text":621,"config":1043},{"href":623,"dataGaName":624,"dataGaLocation":864},{"text":640,"config":1045},{"href":642,"dataGaName":643,"dataGaLocation":864},{"text":648,"config":1047},{"href":650,"dataGaName":651,"dataGaLocation":864},{"text":653,"config":1049},{"href":655,"dataGaName":656,"dataGaLocation":864},{"text":658,"config":1051},{"href":660,"dataGaName":661,"dataGaLocation":864},{"text":663,"config":1053},{"href":665,"dataGaName":666,"dataGaLocation":864},{"text":668,"config":1055},{"href":670,"dataGaName":671,"dataGaLocation":864},{"text":673,"config":1057},{"href":675,"dataGaName":676,"dataGaLocation":864},{"title":689,"links":1059},[1060,1062,1064,1066,1068,1070,1074,1079,1081,1083,1085],{"text":697,"config":1061},{"href":699,"dataGaName":691,"dataGaLocation":864},{"text":702,"config":1063},{"href":704,"dataGaName":705,"dataGaLocation":864},{"text":710,"config":1065},{"href":712,"dataGaName":713,"dataGaLocation":864},{"text":715,"config":1067},{"href":717,"dataGaName":718,"dataGaLocation":864},{"text":720,"config":1069},{"href":722,"dataGaName":723,"dataGaLocation":864},{"text":1071,"config":1072},"Sustainability",{"href":1073,"dataGaName":1071,"dataGaLocation":864},"/sustainability/",{"text":1075,"config":1076},"Diversity, inclusion and belonging (DIB)",{"href":1077,"dataGaName":1078,"dataGaLocation":864},"/diversity-inclusion-belonging/","Diversity, inclusion and belonging",{"text":725,"config":1080},{"href":727,"dataGaName":728,"dataGaLocation":864},{"text":735,"config":1082},{"href":737,"dataGaName":738,"dataGaLocation":864},{"text":740,"config":1084},{"href":742,"dataGaName":743,"dataGaLocation":864},{"text":1086,"config":1087},"Modern Slavery Transparency Statement",{"href":1088,"dataGaName":1089,"dataGaLocation":864},"https://handbook.gitlab.com/handbook/legal/modern-slavery-act-transparency-statement/","modern slavery transparency statement",{"items":1091},[1092,1095,1098],{"text":1093,"config":1094},"Terms",{"href":916,"dataGaName":917,"dataGaLocation":864},{"text":1096,"config":1097},"Cookies",{"dataGaName":926,"dataGaLocation":864,"id":927,"isOneTrustButton":404},{"text":1099,"config":1100},"Privacy",{"href":921,"dataGaName":922,"dataGaLocation":864},[1102],{"id":1103,"title":7,"body":403,"config":1104,"content":1106,"description":403,"extension":1109,"meta":1110,"navigation":404,"path":1111,"seo":1112,"stem":1113,"__hash__":1114},"blogAuthors/en-us/blog/authors/alisa-ho.yml",{"template":1105},"BlogAuthor",{"name":7,"config":1107},{"headshot":1108},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1771440109/xcnydlisb91u4qiwdyw2.jpg","yml",{},"/en-us/blog/authors/alisa-ho",{},"en-us/blog/authors/alisa-ho","WU4QiU5Np9PQ8aLtvZXnH41_rF4JeUvaD9lOvDqkzYw",[1116,1124,1129],{"title":1117,"description":1118,"heroImage":1119,"category":399,"date":1120,"authors":1121,"slug":1123,"externalUrl":403},"GitLab Duo Security Review spots logic flaws scanners miss","Use AI-driven security reasoning to detect authorization gaps, business-logic errors, and race conditions while code is still under review.","https://res.cloudinary.com/about-gitlab-com/image/upload/v1783980535/t3gez0gpayfndrhncunf.png","2026-07-16",[1122],"Mark Settle","gitlab-duo-security-review-flow",{"title":1125,"description":1126,"heroImage":1119,"category":399,"date":1120,"authors":1127,"slug":1128,"externalUrl":403},"When a version bump breaks your build, GitLab fixes it","Automatically upgrade dependencies, adapt code for breaking changes, and route changes for approval — only GitLab does it natively, with full context.",[1122],"dependency-scanning-auto-remediation",{"title":1130,"description":1131,"heroImage":1132,"category":399,"date":1133,"authors":1134,"slug":1135,"externalUrl":403},"One vulnerability view: From scanner coverage to AI governance","As AI writes more code, security must keep pace. GitLab is one platform for all scanner coverage, detection, and remediation, with AI governance over agents.","https://res.cloudinary.com/about-gitlab-com/image/upload/v1781621337/mtjqzed2cqtef0frmor2.png","2026-06-18",[7],"one-vulnerability-view",{"promotions":1137},[1138,1152,1163,1174],{"id":1139,"categories":1140,"header":1142,"text":1143,"button":1144,"image":1149},"ai-modernization",[1141],"ai","Is AI achieving its promise at scale?","Quiz will take 5 minutes or less",{"text":1145,"config":1146},"Get your AI maturity score",{"href":1147,"dataGaName":1148,"dataGaLocation":629},"/assessments/ai-modernization-assessment/","modernization assessment",{"config":1150},{"src":1151},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138786/qix0m7kwnd8x2fh1zq49.png",{"id":1153,"categories":1154,"header":1155,"text":1143,"button":1156,"image":1160},"devops-modernization",[416,966],"Are you just managing tools or shipping innovation?",{"text":1157,"config":1158},"Get your DevOps maturity score",{"href":1159,"dataGaName":1148,"dataGaLocation":629},"/assessments/devops-modernization-assessment/",{"config":1161},{"src":1162},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138785/eg818fmakweyuznttgid.png",{"id":1164,"categories":1165,"header":1166,"text":1143,"button":1167,"image":1171},"security-modernization",[399],"Are you trading speed for security?",{"text":1168,"config":1169},"Get your security maturity score",{"href":1170,"dataGaName":1148,"dataGaLocation":629},"/assessments/security-modernization-assessment/",{"config":1172},{"src":1173},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138786/p4pbqd9nnjejg5ds6mdk.png",{"id":1175,"paths":1176,"header":1179,"text":1180,"button":1181,"image":1186},"github-azure-migration",[1177,1178],"migration-from-azure-devops-to-gitlab","integrating-azure-devops-scm-and-gitlab","Is your team ready for GitHub's Azure move?","GitHub is already rebuilding around Azure. Find out what it means for you.",{"text":1182,"config":1183},"See how GitLab compares to GitHub",{"href":1184,"dataGaName":1185,"dataGaLocation":629},"/compare/gitlab-vs-github/github-azure-migration/","github azure migration",{"config":1187},{"src":1162},{"header":1189,"blurb":1190,"button":1191,"secondaryButton":1196},"Start building faster today","See what your team can do with the intelligent orchestration platform for DevSecOps.\n",{"text":1192,"config":1193},"Get your free trial",{"href":1194,"dataGaName":429,"dataGaLocation":1195},"https://gitlab.com/-/trial_registrations/new?glm_content=default-saas-trial&glm_source=about.gitlab.com/","feature",{"text":902,"config":1197},{"href":754,"dataGaName":434,"dataGaLocation":1195},1785880525357]