<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Gitlab on CuraDevOps</title><link>https://curadevops.metacog.co.kr/tags/gitlab/</link><description>Recent content in Gitlab on CuraDevOps</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 20:52:16 +0000</lastBuildDate><atom:link href="https://curadevops.metacog.co.kr/tags/gitlab/index.xml" rel="self" type="application/rss+xml"/><item><title>GitLab argues Git needs a rebuild for AI-agent scale</title><link>https://curadevops.metacog.co.kr/insights/2026-08-27-git-was-built-for-humans-agents-need-an-upgrade/</link><pubDate>Thu, 27 Aug 2026 20:52:16 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-27-git-was-built-for-humans-agents-need-an-upgrade/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> GitLab&amp;rsquo;s own data — 40% more CI/CD pipelines, 50% more code pushes, 500% larger codebases over one year — frames why agent-scale SCM is a near-term architectural concern; worth tracking as a signal when evaluating long-term SCM platform direction, though no vendor-neutral decision is actionable yet.&lt;/li>
&lt;/ul></description></item><item><title>GitLab 19.3 adds bulk SAST false-positive dismissal and agentic remediation</title><link>https://curadevops.metacog.co.kr/insights/2026-08-21-when-your-backlog-outgrows-your-team-gitlab-scales-remediati/</link><pubDate>Fri, 21 Aug 2026 11:18:28 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-21-when-your-backlog-outgrows-your-team-gitlab-scales-remediati/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Teams self-hosting GitLab should note that 19.3 reaches EOL 2026-11-19 (~90 days); plan an upgrade to 19.4 or later before that date to stay on a supported version.&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> GitLab 19.3 GA adds bulk false-positive dismissal and agentic SAST remediation for existing vulnerability backlogs — worth evaluating if your pipelines already produce GitLab SAST findings, but no urgent action is required.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> GitLab 19.3 reaches EOL in 90d (2026-11-19)&lt;/li>
&lt;/ul></description></item><item><title>GitLab 19.3 Flow Creator agent: natural-language flow authoring</title><link>https://curadevops.metacog.co.kr/insights/2026-08-21-build-custom-flows-in-minutes-with-the-flow-creator-agent/</link><pubDate>Fri, 21 Aug 2026 11:18:28 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-21-build-custom-flows-in-minutes-with-the-flow-creator-agent/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Plan:&lt;/strong> New GA capability in GitLab 19.3 that lets domain experts author Custom Flows via natural language instead of learning the Flow Registry YAML schema; worth evaluating this quarter to reduce the bottleneck between process knowledge and automation authorship.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> GitLab 19.3 reaches EOL in 90d (2026-11-19)&lt;/li>
&lt;/ul></description></item><item><title>GitLab 19.3 released — EOL 2026-11-19</title><link>https://curadevops.metacog.co.kr/insights/2026-08-21-gitlab-19-3-released/</link><pubDate>Fri, 21 Aug 2026 11:18:28 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-21-gitlab-19-3-released/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Teams self-hosting GitLab should plan an upgrade to 19.3 and note that it reaches EOL on 2026-11-19, meaning another upgrade cycle must be scheduled within the quarter to stay on a supported version.&lt;/li>
&lt;li>&lt;strong>CI/CD — Plan:&lt;/strong> Review the 19.3 release notes for any pipeline syntax, runner, or artifact-handling changes; schedule adoption before the 2026-11-19 EOL to avoid running unsupported GitLab CI infrastructure.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> GitLab 19.3 reaches EOL in 90d (2026-11-19)&lt;/li>
&lt;/ul></description></item><item><title>GitLab Dedicated adds AI Gateway for in-tenant agentic workflows</title><link>https://curadevops.metacog.co.kr/insights/2026-08-21-run-agentic-software-delivery-inside-the-boundaries-you-alre/</link><pubDate>Fri, 21 Aug 2026 11:18:28 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-21-run-agentic-software-delivery-inside-the-boundaries-you-alre/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> If your org runs GitLab Dedicated, the AI Gateway for Duo Agent Platform is now deployable inside your single-tenant environment, keeping AI-processed data in your chosen AWS region. Evaluate this quarter whether to enable it as part of your agentic DevOps rollout.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Organizations using GitLab Dedicated for compliance or data-residency reasons can now extend that boundary to AI agent workloads — shapes thinking on how to pursue agentic DevOps without relaxing data-sovereignty requirements.&lt;/li>
&lt;/ul></description></item><item><title>GitLab as AWS control plane: OpenTofu + Argo CD tutorial</title><link>https://curadevops.metacog.co.kr/insights/2026-08-19-from-opentofu-to-argo-cd-gitlab-as-your-aws-control-plane/</link><pubDate>Wed, 19 Aug 2026 11:17:39 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-19-from-opentofu-to-argo-cd-gitlab-as-your-aws-control-plane/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Learn:&lt;/strong> A practical walkthrough integrating OpenTofu, GitLab CI/CD, and Argo CD into a unified IaC + GitOps platform pattern — useful design reference, but no GA capability change or deadline requiring action.&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> Illustrates how to wire GitLab pipelines to OpenTofu provisioning and Argo CD deployments end-to-end; worth reviewing as a pipeline design reference, but nothing here forces a pipeline change.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>GitLab critical patch release: 19.2.4, 19.1.6, 19.0.8, 18.11.11</title><link>https://curadevops.metacog.co.kr/insights/2026-08-18-gitlab-critical-patch-release-19-2-4-19-1-6-19-0-8-18-11-11/</link><pubDate>Tue, 18 Aug 2026 11:17:30 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-18-gitlab-critical-patch-release-19-2-4-19-1-6-19-0-8-18-11-11/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> If running a self-managed GitLab instance, upgrade to the patched version in your release line; no public PoC or KEV listing is confirmed from the title alone, so this is urgent-but-scheduled rather than emergency.&lt;/li>
&lt;li>&lt;strong>CI/CD — Act:&lt;/strong> GitLab CI users on self-managed instances should upgrade to 19.2.4, 19.1.6, 19.0.8, or 18.11.11 promptly — a critical patch to the CI/CD platform itself can directly break or compromise pipelines and should be treated as an outage-level priority.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> major release (19.0)&lt;/li>
&lt;/ul></description></item><item><title>GitLab improves vulnerability fingerprinting to survive refactors</title><link>https://curadevops.metacog.co.kr/insights/2026-08-13-how-gitlab-tracks-vulnerabilities-through-refactors-and-refo/</link><pubDate>Thu, 13 Aug 2026 11:41:08 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-13-how-gitlab-tracks-vulnerabilities-through-refactors-and-refo/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> GitLab&amp;rsquo;s improved Scope+Offset fingerprinting reduces duplicate vulnerability findings from reformats and comment additions; worth knowing when evaluating SAST signal quality in GitLab pipelines, but no pipeline change is needed today.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>GitLab Duo Self-Hosted gains Privatemode confidential-AI model provider</title><link>https://curadevops.metacog.co.kr/insights/2026-08-07-confidential-ai-for-gitlab-self-hosted/</link><pubDate>Fri, 07 Aug 2026 00:23:45 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-07-confidential-ai-for-gitlab-self-hosted/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Teams running GitLab Self-Hosted in regulated environments can now configure the Duo AI Gateway to proxy through Privatemode&amp;rsquo;s confidential-compute backend — worth scheduling this quarter to evaluate setup and network path requirements alongside any existing compliance review.&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> The prospect of GitLab Duo Agent Platform driving multi-step agentic flows as native CI jobs is a meaningful design shift to track, but there are no pipeline migrations or deprecations to act on today.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> For regulated orgs blocked from AI coding tools by IP or compliance constraints, this materially changes the vendor-risk calculus — evaluate Privatemode as a compliant model-provider path for GitLab Duo during the next planning cycle before competitors further compound their AI productivity lead.&lt;/li>
&lt;/ul></description></item><item><title>GitLab Secrets Manager adds ESO, Terraform, and API support via OpenBao</title><link>https://curadevops.metacog.co.kr/insights/2026-08-07-gitlab-secrets-manager-adds-eso-terraform-api-support/</link><pubDate>Fri, 07 Aug 2026 00:23:45 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-07-gitlab-secrets-manager-adds-eso-terraform-api-support/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> This GA expansion lets platform teams consolidate Kubernetes (ESO), Terraform/OpenTofu, and Vault CLI secrets into a single OpenBao-backed store — worth evaluating this quarter as a replacement for fragmented per-tool secret stores, with no forcing deadline yet.&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> GitLab CI/CD secret support landed in v19.0 already; the new ESO and Terraform integrations are primarily platform-side — no pipeline changes required today, but the unified API surface is worth noting for future supply-chain design.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The consolidated single-store model (one audit trail, one access model across Kubernetes, IaC, and pipelines) is worth tracking as a vendor-consolidation data point when revisiting secrets-toolchain standards, but no pricing or license forcing function exists yet.&lt;/li>
&lt;/ul></description></item><item><title>GitHub Enterprise Importer: GitLab-to-GitHub migration now GA</title><link>https://curadevops.metacog.co.kr/insights/2026-08-04-migrate-from-gitlab-to-github-with-github-enterprise-importe/</link><pubDate>Tue, 04 Aug 2026 12:54:10 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-04-migrate-from-gitlab-to-github-with-github-enterprise-importe/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Plan:&lt;/strong> If a GitLab-to-GitHub migration is on the roadmap, GEI reaching GA means self-serve tooling is now available for scoping the pipeline migration project.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your org is evaluating consolidating from GitLab to GitHub Enterprise Cloud, the GA of self-serve migration tooling removes a key friction point worth including in the next planning cycle.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> GA announcement&lt;/li>
&lt;/ul></description></item><item><title>GitLab + Claude: Securing the agentic coding pipeline to production</title><link>https://curadevops.metacog.co.kr/insights/2026-08-03-secure-every-commit-to-production-with-claude-and-gitlab/</link><pubDate>Mon, 03 Aug 2026 13:34:40 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-03-secure-every-commit-to-production-with-claude-and-gitlab/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> Describes an integration pattern where Claude flags issues at authoring time and GitLab enforces controls through merge, dependency update, and infra change stages; worth tracking as AI-assisted supply-chain governance matures, but no concrete pipeline change to make today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Outlines a governance model for agentic coding at scale — pairing Claude security guidance with GitLab policy enforcement — relevant for leaders setting standards around AI-assisted development, but no licensing or cost decision is triggered here.&lt;/li>
&lt;/ul></description></item><item><title>GitLab 19.2 Custom Flows reach GA: agentic multi-step delivery pipelines</title><link>https://curadevops.metacog.co.kr/insights/2026-07-17-turn-multi-step-software-delivery-into-agentic-flows-you-can/</link><pubDate>Fri, 17 Jul 2026 12:03:24 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-17-turn-multi-step-software-delivery-into-agentic-flows-you-can/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Plan:&lt;/strong> Custom Flows are now GA in GitLab 19.2, enabling event-triggered, AI-driven multi-step pipeline sequences (e.g., analyze failure → generate fix → commit → notify). Teams on GitLab should evaluate whether encoding trusted delivery sequences as Flows reduces manual handoffs and pipeline runbook debt.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> GitLab&amp;rsquo;s agentic flow model represents a meaningful shift in how AI is integrated into the delivery lifecycle — moving from single-turn chat to orchestrated, human-approved sequences. Worth tracking as input to dev-platform strategy and AI tooling evaluation, but no strategic decision is forced by this release.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> GA announcement&lt;/li>
&lt;/ul></description></item><item><title>GitLab 19.2 released</title><link>https://curadevops.metacog.co.kr/insights/2026-07-17-gitlab-19-2-released/</link><pubDate>Fri, 17 Jul 2026 12:03:24 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-17-gitlab-19-2-released/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Learn:&lt;/strong> GitLab 19.2 is a new minor release that may affect self-managed GitLab instances, but no summary or enrichment signals are available to identify breaking changes, security fixes, or upgrade urgency.&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> A new GitLab minor release typically includes CI/CD pipeline features worth evaluating, but no details are present in this item to determine whether any pipeline changes are warranted.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>GitLab Dependency Scanning Auto-Remediation now in beta</title><link>https://curadevops.metacog.co.kr/insights/2026-07-17-when-a-version-bump-breaks-your-build-gitlab-fixes-it/</link><pubDate>Fri, 17 Jul 2026 12:03:24 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-17-when-a-version-bump-breaks-your-build-gitlab-fixes-it/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> Beta feature that auto-opens MRs to patch vulnerable dependencies and iterates until the pipeline passes — worth evaluating once GA, but pre-GA status caps this at Learn for now.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Beta capability targeting the OWASP dependency backlog and compliance remediation windows (PCI-DSS/FedRAMP 30-day deadlines); monitor for GA before considering for the golden path.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> breaking-change flagged&lt;/li>
&lt;/ul></description></item><item><title>GitLab Duo CLI reaches GA in GitLab 19.2</title><link>https://curadevops.metacog.co.kr/insights/2026-07-17-bring-gitlab-duo-agent-platform-to-your-terminal/</link><pubDate>Fri, 17 Jul 2026 12:03:24 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-17-bring-gitlab-duo-agent-platform-to-your-terminal/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> The GA headless mode lets Duo run inside CI jobs and scripts, which could reshape how teams add AI-assisted triage or automation steps to pipelines — worth evaluating, but no migration or deadline attached.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> For orgs already on GitLab, this signals how AI assistance is extending across the full delivery lifecycle — useful context for AI toolchain strategy discussions, but no licensing, pricing, or vendor-risk forcing function yet.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> GA announcement&lt;/li>
&lt;/ul></description></item><item><title>GitLab Duo Security Review Flow (beta) targets logic-flaw blind spots</title><link>https://curadevops.metacog.co.kr/insights/2026-07-17-gitlab-duo-security-review-spots-logic-flaws-scanners-miss/</link><pubDate>Fri, 17 Jul 2026 12:03:24 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-17-gitlab-duo-security-review-spots-logic-flaws-scanners-miss/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> Public beta feature worth tracking for GitLab shops — it layers intent-based analysis over existing SAST to catch authorization and workflow flaws before merge, but it&amp;rsquo;s pre-GA so nothing to enable in production pipelines yet.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> AI-assisted logic-flaw detection is a meaningful gap-fill beyond signature-based scanners; worth monitoring as it approaches GA to assess whether it changes the org&amp;rsquo;s AppSec toolchain or reduces security-review cycle time.&lt;/li>
&lt;/ul></description></item></channel></rss>