Securing the software factory at machine speed

From the source: GitLab Blog

I joined GitLab at a moment when the way teams build and secure software has been changing rapidly. GitLab CEO Bill Staples recently framed that shift in When Code Is Abundant . When code is no longer the bottleneck, trust becomes scarce, and that constraint shows up first in what reaches production. As a CISO accountable for the same decisions as my peers, my operating thesis is simple: Agentic…

Read the full story on GitLab Blog
Originally published by GitLab Blog on 18 Sept 2026. Techarda links to the original rather than republishing it. Read the full article →

Have you worked with this?

The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.

Start the discussion

More from GitLab

Recent updates from GitLab, so you can tell whether this is a one-off or part of a pattern.

All GitLab news →
DevOps & Platform Engineering

GitLab Critical Patch Release: 19.4.1, 19.3.3, 19.2.7

GitLab·via GitLab Blog
DevOps & Platform EngineeringHow-to

How to design GitLab for enterprise scale

At enterprise scale, even small architecture choices can have outsized consequences. A deployment that works for a handful of teams can become a constraint once thousands of developers, repositories, and pipelines depend on it. That makes each decision made before rollout especially consequential. For example, your: Deployment model defines what your team must operate Runner strategy shapes how…

GitLab·via GitLab Blog
DevOps & Platform EngineeringCase study

How GitLab reduced code-per-agentic-flow ratio by 45%

GitLab Duo Agent Platform orchestrates and automates complex tasks through agentic flows. A key part of the platform is the Flow Registry, a declarative configuration framework, built from reusable components, that compiles YAML into fully functional LangGraph flows. By using Flow Registry, agent builders — both our GitLab engineers and our customers can use declarative YAML configurations…

GitLab·via GitLab Blog

More in DevOps & Platform Engineering

What other companies in DevOps & Platform Engineering are doing. The category page shows who’s active, side by side.

Compare companies in DevOps & Platform Engineering →
DevOps & Platform EngineeringNewWhy it matters

Secure AI agents with HashiCorp Boundary

Enable AI agents to securely access your resources while operating within enterprise identity, access, and audit controls.

HashiCorp·via HashiCorp Blog
DevOps & Platform EngineeringWhy it matters

AI agents need continuity, not just context

Pulumi Neo works on infrastructure the way an engineer does: it clones repositories, edits files, installs dependencies, runs previews, and produces intermediate work along the way. A task is not only a conversation with a model. It is also a working directory that has to survive long enough for the agent to keep making progress. Imagine asking an agent to upgrade a Pulumi provider version across…

Pulumi·via Pulumi Blog
DevOps & Platform EngineeringHow-to

CI/CD Security Best Practices: A 2026 Pipeline Checklist

CI/CD security best practices for 2026: secrets management, scoped access, dependency scanning, signed artifacts, and audit logging in one checklist. | Blog

Harness·via Harness Blog
DevOps & Platform Engineering

AI Writes Code Fast. Can You Trust What Gets Deployed?

AI has solved writing code fast. The new bottleneck is trusting what actually reaches production. Here's what that requires. | Blog

Harness·via Harness Blog