GitLab
Follow
When your backlog outgrows your team, GitLab scales remediation
Development speed, accelerated by AI, now outpaces security teams’ ability to manage vulnerabilities. Attackers are also leveraging AI to exploit vulnerabilities faster, making them the leading method for data breaches. Many exploited vulnerabilities remain unpatched in production. GitLab 19.3 introduces automated solutions for tackling this growing problem. Teams can now perform Static Application Security Testing (SAST) False Positive Detection and Agentic SAST Vulnerability Resolution in bulk on their existing vulnerability backlogs. This process helps dismiss false positives and automatically generates ready-to-merge fixes for confirmed vulnerabilities. These new capabilities apply to any SAST vulnerability, regardless of scanner or severity, and can even ingest findings from third-party scanners. By automating these tasks, accumulated risk can be significantly reduced in a single action. Furthermore, new vulnerabilities identified in pipelines can be automatically triaged and remediated. This allows developers to focus on shipping secure code rather than manual vulnerability management. GitLab Duo Agent Platform credits are used for these features, with bulk operations not costing extra credits per execution. These bulk jobs are designed to not overwhelm pipelines and can be canceled if needed.