One vulnerability view: From s... Note
GitLab

One vulnerability view: From scanner coverage to AI governance

Enterprises often struggle with inconsistent security scanner coverage across projects, leading to undetected blind spots. GitLab 19.1 addresses this by enabling the integration and enforcement of existing third-party security scanners at scale. This new functionality provides a unified view of scanner coverage, ensuring all projects are scanned according to defined policies. Vulnerabilities detected by these integrated scanners flow directly into GitLab's central vulnerability view for consistent management. Furthermore, these third-party findings can now be automatically remediated using GitLab Duo Agent Platform workflows.The release also enhances secret detection by scanning every commit on a new branch, preventing secrets committed earlier from being missed. Secret False Positive Detection is now generally available, providing confidence scores and explanations to reduce developer noise. On the AI governance front, AI audit event streaming, currently in beta, records every action taken by AI agents. This allows organizations to monitor and prove agent behavior. Agent tool approval guardrails, also in beta, empower administrators to define agent actions, requiring human approval for sensitive operations. This combination of comprehensive scanner coverage, automated remediation, and robust AI agent governance offers improved security and accountability.