Blogs›GitLab Feature Trails
See how major capabilities shipped, upgraded, and evolved across GitLab's engineering blog.
Publishing pulse
2012–2026 · peak 2020
1.5K posts mapped

GitLab is integrating AI/ML capabilities into its DevSecOps platform to enhance developer efficiency and security. This includes features like SAST, DAST, Container Scanning, Dependency Scanning, Auto Remediation, Security Dashboards, and Security Approvals, all integrated into the CI/CD workflow. The platform is also developing MLOps and DataOps capabilities to support AI/ML workloads. Customer data privacy is a key focus, with commitments that custom data is never used for training without explicit consent. The platform now supports prioritization of vulnerabilities using CVSS, KEV, and EPSS frameworks, providing actionable insights to focus remediation efforts on the most critical risks.
Timeline

GitLab Secrets Manager is evolving to provide a unified solution for secret retrieval across the software delivery chain. It now supports External Secrets Operator (ESO) for Kubernetes workloads, Terraform and OpenTofu runs, and direct API access for external automation. This builds upon its existing capabilities for CI/CD jobs and OpenBao/Vault CLI integration, aiming to reduce the complexity of managing multiple secret stores and ensure consistent auditing. This post details how GitLab Duo Workflow was used to implement a dynamic Helm chart limit configuration in the GitLab package registry, adding a new application setting and updating backend logic to use this setting instead of a hardcoded limit. This enhancement provides administrators with greater flexibility and control over package registry limits.
Timeline

GitLab is enhancing its code review process by integrating automated reviewer suggestions directly into merge requests using a machine learning algorithm that analyzes the changes in an MR and a project's contribution graph. This evolution moves away from a separate Slack-based tool, addressing workflow friction and availability issues. The goal is to ensure more even distribution of reviews, prevent knowledge silos, and improve the efficiency of the review process by making it an integral part of the MR workflow. This post argues that pre-commit and post-deploy code reviews are essential for maintaining code quality and team collaboration.
Timeline

GitLab is integrating AI/ML capabilities into its DevSecOps platform to enhance developer efficiency. This includes experiments like summarizing merge request review comments directly within the merge request interface using a new AI action, allowing users to edit or revise the summary before submitting their review. This helps authors quickly understand feedback and speeds up the review cycle. Future iterations will focus on refining the type of review feedback and better integrating these summ
Timeline

GitLab's Dynamic Application Security Testing (DAST) has evolved to a new browser-based analyzer (DAST 2). This new analyzer integrates passive checks by monitoring network traffic during website crawling, allowing for the identification of weaknesses without sending disruptive requests. The goal is to reduce alert fatigue by implementing fewer checks, reducing false positives, and aggregating true positives. The passive checks are primarily defined in YAML using a custom specification, with reu. Proxy-based DAST has been removed and replaced by this browser-based tool.
Timeline

GitLab CI/CD is continuously enhanced to improve pipeline efficiency and developer productivity. This includes leveraging Directed Acyclic Graphs (DAG) for concurrent job execution, utilizing parallel jobs and parallel matrix jobs for faster execution and manageable pipeline breakdown, and implementing parent/child pipelines for better dependency management in monorepos. Merge trains are employed to maintain target branch stability, and the ability to configure multiple caches in a single job has been improved. This thread also tracks the development and use of automation for deploying and managing elastic GitLab Runners on AWS, specifically leveraging AWS Autoscaling Groups (ASG) and Spot Instances for cost savings and efficient scaling. The "GitLab HA Scaling Runner Vending Machine for AWS" provides Infrastructure as Code (CloudFormation) to deploy and manage these runners, incorporating features like ARM architecture support, scheduled uptime, and tagging for Spot instance job management.
Timeline

GitLab Workhorse has evolved from a small Go program addressing Git clone timeouts into a critical component handling a significant portion of HTTP requests to GitLab. It now manages Git HTTP requests, download zip buttons, Git LFS, CI build artifacts, and acts as a smart proxy for all HTTP traffic, simplifying NGINX configurations and improving performance for various features. This includes replacing Gitolite with GitLab Shell for managing Git repositories and SSH authorized keys, reducing complexity. The integration of the GitLab CLI (`glab`) with AI agents via Model Context Protocol (MCP) further extends its capabilities by providing a direct, reliable interface for AI to interact with GitLab projects, enabling actions like reading issues, reviewing merge requests, and checking pipeline status programmatically. This enhances AI-driven development workflows by providing structured, real-time data and enabling programmatic actions through `glab api` for full REST and GraphQL access.
Timeline

GitLab is introducing Seat Link for self-managed customers to automate prorated charges for user growth throughout the year, eliminating the need for complex true-ups. Seat Link will send daily counts of users in connected instances to GitLab via secure HTTPS. This aims to provide more transparent and predictable billing for user growth.
Timeline

GitLab actively contributes to the core Git project, focusing on performance enhancements, new features, and improved reliability. This includes developing and upstreaming new commands like `git-replay` for efficient in-memory rebasing, optimizing commit-graph operations for faster history traversal, and preparing Git for a more robust and scalable ref backend with the 'reftable' format. The Gitaly team has also reworked the object database maintenance strategy to leverage new Git mechanisms like reftables. This release introduces tooling for migrating existing repositories to the reftable format, transactional symref updates for atomic reference operations, and subcommand-based UX improvements for `git-config`. Performance regressions related to attribute lookups in bare repositories have been addressed, and progress is being made on migrating end-to-end tests to a new C-based unit-testing framework. Bundle URI fixes have also been implemented.
Timeline

GitLab is now available as a fully managed platform on Google Cloud, delivered by GitLab-certified managed service providers (MSPs). This offering allows organizations to run GitLab on Google Cloud infrastructure while maintaining control over their code, pipelines, and security data, addressing country-specific sovereignty and data residency requirements. It integrates with Google's latest AI models, including Gemini and Gemma, through the GitLab Duo Agent Platform. Customers can leverage existing Google Cloud commitments for procurement and billing, with options for both managed and self-hosted AI models. This builds on previous collaborations to integrate Google AI models into GitLab Duo.
Timeline

GitLab has established a structured approach to handling bugs, differentiating between security, regression, and feature bugs. This system aims to prioritize fixes based on severity and impact, encouraging community contributions for identification and resolution. The process involves clear channels for reporting different bug types, from direct contact for security vulnerabilities to the issue tracker and feedback channels for other bugs. This framework is crucial for maintaining the stability and security of the platform. This post details how GitLab.com's Trust and Safety team actively detects and mitigates spam, including the definition of abuse, reporting mechanisms for GitLab.com users, and best practices for self-managed instances. It also outlines upcoming explorations in alternative captcha solutions and bot URL posting prevention, with the goal of incorporating successful automation into the product for all customers.
Timeline

GitLab's Dependency Proxy has evolved to be a robust, free feature available to all users, supporting private groups and subgroups for caching container images. It now includes authentication mechanisms for enhanced security and to prevent abuse. The Dependency Proxy helps mitigate Docker Hub rate limiting by caching image manifests and blobs, and can also provide support during Docker Hub outages by falling back to cached images. CI/CD integration has been improved with predefined environment variables. This post also highlights GitLab's integrated package management capabilities, including a Docker registry, Maven, and NPM support, and plans for further packaging features.
Timeline

GitLab Geo is evolving to support replication of all data types by introducing a new framework. This framework aims to reduce code duplication, improve maintainability, and enable non-Geo engineers to add support for new data types. The initial focus was on replicating new Package files, with subsequent work on replication of changes, deletions, backfills, and verification. The framework encapsulates common logic in `Replicator` classes and `Replicator strategies` for blobs and Git repositories. GitLab EE Premium introduces GitLab Geo for remote teams, offering read-only mirrors of GitLab instances to reduce clone/fetch times for large repos.
Timeline

GitLab has been enhancing its authentication and authorization capabilities, with a significant focus on integrating with enterprise identity management systems. This includes the introduction and ongoing development of SAML (Security Assertion Markup Language) support, enabling Single Sign-On (SSO) for enterprise customers. Recent efforts have focused on improving the security of OAuth Resource Owner Password Credentials (ROPC) by requiring client authentication for all requests, aligning with security best practices. This post introduces support for Universal 2nd Factor (U2F) authentication using hardware security keys like YubiKey, adding a robust layer against phishing and enhancing account security.
Timeline

GitLab differentiates itself by offering unconditional data commitments for AI training, ensuring customer data is never used without explicit consent, regardless of subscription tier. This contrasts with industry trends towards opt-out-by-default data collection. GitLab provides transparency through its AI Transparency Center and offers the Duo Agent Platform for self-managed deployments, allowing customers to keep data within their own infrastructure and use self-hosted AI models. This approach also includes plans to de-identify service usage data by limiting access to identifiable information and introducing a new system to de-identify users and other personal information from multi-user instances before the information lands in GitLab's analytics environment. This will allow GitLab to roll up more aggregated, de-identified user-level activity at the account level. However, there is a gap for single-user namespaces where de-identification may not be perfect.
Timeline

GitLab's Security Operations team has developed custom controls to detect and prevent malware campaigns that leverage IDE tasks for distribution, specifically addressing the 'Contagious Interview' threat campaign. This involves low-level detection mechanisms focusing on subprocess execution within IDEs like VS Code, aiming to protect GitLab workstations and customers from malicious code execution that can lead to infostealers, credential theft, and persistence establishment. This post details the technical implementation of these controls, including the use of tooling like gitrob and token hunter for secret discovery, and the emulation of endpoint exploitation and persistence scenarios. The team also leverages GitLab for managing TTPs and running custom attack tooling via CI jobs, outputting results to a secure GitLab Pages site. Collaboration with AppSec and infrastructure teams is emphasized, with shared chat channels for live operation monitoring. The team breaks down the stigma of red teaming by prioritizing transparency, documenting test plans, and involving stakeholders, framing findings as opportunities for improvement.
Timeline

GitLab's observability capability is completely open-sourced and relies on open APIs such as Prometheus and OpenTelemetry so users don't have to worry about vendor lock-in from instrumentation to alerting. It's built into the GitLab DevOps platform to help you use the capability right away within your native workflow. The vision is to make every GitLab project observable by default, with features that are easy to operate without specialized, expert skills. Teams can connect the dots between ever-present metrics, logs, and traces to gain deeper insights into application performance and user behavior. This post introduces Product Analytics capabilities, leveraging Snowplow, ClickHouse, Cube.dev, and ECharts to enable users to instrument their own applications, collect data, run experiments, and gain insights within GitLab. It emphasizes user privacy by allowing users to provide their own Kubernetes clusters for data processing and storage, ensuring data ownership. The initial focus is on web applications built with JavaScript and Ruby on Rails, with future plans for experiments and support for other frameworks and tech stacks. Configuration will be driven by files in the GitLab project, enabling collaboration via merge requests.
Timeline

GitLab is evolving its organizational hierarchy features to better model team structures and enable advanced permissions management. This includes enhancing the capabilities of groups, subgroups, and projects to support strategic planning, value stream management, and cascading configurations. The inheritance model allows settings and permissions defined at higher levels to apply to lower levels, providing visibility and control across the organization. Best practices are provided for setting up complex organizational structures, including the use of scoped labels for managing ownership and workflow states across multiple teams contributing to a single repository, and shared milestones for release cadence.
Timeline

GitLab CI/CD capabilities are enhanced with automated test result uploads from pipelines to external test management platforms like QMetry, enabling end-to-end traceability, faster feedback loops, and compliance adherence. This builds upon existing CI/CD features for running tests and generating reports. The integration of Hurl allows for continuous testing of web apps and APIs directly within GitLab CI/CD jobs, enabling automated HTTP request testing, response assertion, and integration with cu. This post emphasizes the importance of automated testing (unit, system, and compliance) within the DevOps pipeline as a verification mechanism to complement trust-based management, ensuring code quality, system stability, and adherence to requirements.
Timeline

GitLab has evolved its installation and update processes for security and user convenience. This includes managing the lifecycle of signing keys for Omnibus packages to ensure integrity and minimize disruption. The platform has also acquired Amazon's Service Ready Partner designation. A significant engineering effort has been the consolidation of GitLab Community Edition (CE) and Enterprise Edition (EE) into a single codebase. This involved separating proprietary code from free software, refactoring the Omnibus installer to support a unified codebase, and improving the user experience for initial setup and ongoing updates. This post details the process of deploying GitLab Community Edition on a DigitalOcean droplet using the GitLab One-Click Install Image and the Omnibus installer, including initial configuration of domain names, emails, and user accounts.
Timeline

GitLab has introduced and detailed its feature flags capability, allowing users to decouple deployment from release. This enables granular control over feature visibility through toggles in the GitLab UI. The integration leverages the Unleash SDK for Python, providing a robust and efficient way to manage feature flag evaluation locally within applications. This capability enhances release management by allowing gradual rollouts, quick rollbacks, and targeted feature delivery. The Remote Development capabilities are also being enhanced with feature flags.
Timeline

GitLab's issue and merge request workflows are enhanced with quick actions and description templates to streamline common tasks. This includes automating issue assignment, labeling, milestone setting, epic linking, and merge request draft status toggling, reviewer assignment, and rebasing. The integration of quick actions into description templates further automates these processes for issue creation and MRs. The GitLab VS Code extension is being developed to bring merge request review functions. The Issue Board feature allows for visual planning of issues with multiple intermediate steps, leveraging existing metadata like labels for sorting and filtering. Future iterations plan for multiple and cross-project boards, searching through all lists, and creating issues directly from the board view.
Timeline

GitLab's Container Registry has evolved to a next-generation architecture, now generally available for self-managed deployments. This new architecture includes zero-downtime garbage collection, improved API and UI performance, and enhanced features like better sorting/filtering and storage usage visibility. The transition involves an opt-in database enablement and a planned deprecation of the legacy registry. Future roadmap items include protected repositories, immutable tags, improved H. This initial release in 8.8 provided a secure and private registry for Docker images, fully integrated with GitLab, allowing for easy use of images in GitLab CI, creation of images specific to tags or branches, and no additional installation required. It offered seamless and secure workflows for building, storing, and deploying Docker container images, with user authentication from GitLab itself and a new 'Container Registry' tab per project.
Timeline

GitLab has undergone significant UI navigation and layout redesigns to improve usability and screen real estate. Early efforts focused on addressing specific navigation issues like limited space, stacked navigation levels, and the placement of navigation elements. Subsequent redesigns have aimed to create a more intuitive and efficient user experience, incorporating community feedback and evolving the visual presentation of the platform. This includes the development of a design system, starting with the creation of Slippers, a reusable library of design assets and code, to ensure consistency and scalability across the organization.
Timeline

GitLab is evolving its security posture with a Zero Trust model, implementing data zones based on data classification (RED, ORANGE, YELLOW, GREEN) and an authentication scoring system. This system augments access control by considering user identity, job description, device information, and geolocation. The data zones define boundaries for data access based on classification, ensuring that lower classification data is not accessible within higher classification zones without proper authorization. This post details how teams can mature their security practices by leveraging advanced access controls (organizational hierarchies, protected branches), robust review processes (multiple approvers, push rules), and compliance adherence tools (Audit Events, Code Quality Reports) within GitLab Premium.
Timeline

GitLab has built and automated a new Japanese GitLab Docs site, marking its first move toward making extensive documentation accessible worldwide. This involved creating localization infrastructure from the ground up, integrating with docs-as-code principles. The system uses AI-assisted translation with human post-editing, custom code to protect markdown syntax, an English fallback mechanism, dynamic anchor ID generation for consistent linking, and extended CI/CD pipelines to test localized cont
Timeline

GitLab has evolved its capabilities to address the challenge of versioning large binary files, which are problematic for traditional Git repositories. This includes integrating git-annex, supporting Git LFS, and developing tools like 'Git Much Faster' to optimize clone times and reduce repository size through techniques like disabling compression, increasing HTTP buffer sizes, shallow clones, partial clones, and sparse checkout. These optimizations significantly reduce clone times and impact on repositories. This post details the installation and usage of Git LFS, explaining how it stores lightweight pointers in the local repository and downloads the actual files on demand, thus keeping local repositories lean.
Timeline

GitLab is enhancing its deletion flow for groups and projects across all pricing tiers. This includes implementing a pending deletion state with self-service recovery, standardized status indicators, and an extended recovery window (now 30 days on GitLab.com). Future iterations will bring consistency to Admin area deletions, immediate namespace path reuse, a centralized 'Trash' interface, clear separation of delete actions (temporary vs. permanent), and bulk management capabilities for deleted items. This post details the default enablement of delayed deletion for Ultimate and Premium tiers, with a 7-day retention period on SaaS and configurable delays (1-90 days) for self-managed instances. The immediate deletion option from the Admin Area and group settings will be removed in GitLab 16.0.
Timeline

GitLab has improved its open source community growth and contribution milestones by developing and implementing a semi-automated onboarding solution. This solution leverages GitLab's own tools, including issue templates, scheduled pipelines, webhooks, GLQL, and project mirroring, to streamline the contributor journey. Key enhancements include personalized onboarding issues, standardized responses via comment templates, immediate pipeline triggers for access requests, automated nudges, and the introduction of workflow labels (`workflow::ready for review`, `workflow::in dev`, `workflow::blocked`) to better manage the state of merge requests. This has led to a significant reduction in the median time MRs spend in the 'ready for review' state and an increase in the number of merged community contributions.
Timeline

GitLab's platform performance is continuously optimized by diagnosing and resolving system-level bottlenecks. This includes implementing rate limitations for unauthenticated users of the Projects List API to ensure platform stability and reliability. The default limit for unauthenticated users on GitLab.com is 400 requests per 10 minutes per IP address, with self-managed instances allowing administrators to configure this limit. This change aims to mitigate server load caused by increased anonymous API requests.
Timeline
GitLab is adopting and adapting an open-source compliance framework (Adobe's CCF) to build an efficient and aggregated security control program. This approach aims to streamline interactions with internal teams by creating unified control statements that satisfy multiple industry frameworks (ISO, SOC, PCI) simultaneously, reducing redundant information requests and accelerating the establishment of a comprehensive compliance program. This post details the implementation of compliance as code, emphasizing the integration of compliance standards into the CI/CD pipeline, leveraging containers for compliant 'Golden Images', and establishing a System of Record (SOR) to track compliance. It also highlights the growing importance of software supply chain security as an overarching theme for compliance and security.
Timeline

GitLab has focused on simplifying user authentication and access management. This includes enhancing SSH key usage by providing screencasts to demonstrate ease of use and introducing an alternate `git+ssh` port (443) on GitLab.com to circumvent network restrictions. This post details a coordinated effort with Yubico to integrate hardware security keys (YubiKeys) for two-factor authentication, enhancing security beyond SMS or push notifications by leveraging the U2F protocol for phishing and Man-in-the-Middle attack protection. The integration aims to reduce friction and encourage wider adoption of strong authentication practices. GitLab also offers additional security capabilities like access control, workflow management, and audit trails.
Timeline

GitLab Pages has evolved its architecture to use API-based configuration, reducing daemon startup time from minutes to seconds. This change sources domain configuration via an internal API endpoint, caching it in memory. Future plans include transitioning from NFS to object storage and enabling Kubernetes deployment. For self-managed instances, API-based configuration can now be enabled via documentation guides. This post details how a user leveraged GitLab Pages and CI/CD to automate the download of SSG sites, providing examples for Ruby, Node.js, Python, and Go environments, and emphasizing the flexibility to build any SSG site.
Timeline

GitLab's issue and merge request workflows are enhanced with quick actions and description templates to streamline common tasks. This includes automating issue assignment, labeling, milestone setting, epic linking, and merge request draft status toggling, reviewer assignment, and rebasing. The integration of quick actions into description templates further automates these processes for issue creation and MRs. The GitLab VS Code extension is being developed to bring merge request review functions. The new Web IDE, built on VS Code, offers a more powerful and familiar interface for contributing, with features like collapsible panels, drag & drop support, find and replace, and an interactive terminal for remote development. It aims to reduce memory usage and improve reliability. Users can switch between the new beta and the previous Web IDE. Future plans include VS Code extension support and project-wide search.
Timeline

Vaadin migrated from a fragmented toolchain (Gitolite, Trac, etc.) to a self-managed GitLab instance to centralize projects, reduce administrative overhead, and improve developer experience. The migration was facilitated by GitLab Omnibus, and the team quickly adopted GitLab for its integrated issue tracking, code review, and project management capabilities. This move improved workflow, collaboration, and overall developer efficiency by providing a single entry point for all internal projects.
Timeline

GitLab is launching GitLab Serverless in version 11.6, enabling users to plan, build, and manage serverless workloads within the same GitLab UI. This feature leverages Knative for autoscaling serverless workloads on Kubernetes, supporting multi-cloud strategies. The integration with TriggerMesh and Sebastien Goasguen aims to provide a best-in-class serverless experience. The "Serverless" tab will be available as an alpha offering, allowing users to view and manage their defined functions, including secure sudo access for workspaces via Sysbox, Kata Containers, or user namespaces.
Timeline

GitLab webhooks are being enhanced with self-healing capabilities. Previously, webhooks that encountered 4xx errors would be permanently disabled after multiple failures. The new system will temporarily disable webhooks of any error type (4xx, 5xx, network, etc.) with an increasing backoff period, up to 1 day. Webhooks will be permanently disabled only after 40 successive failures. Existing permanently disabled webhooks will be migrated to this new temporary disablement state. This aims to reduce the impact of transient errors on webhook reliability. This post details how GitLab Webhooks can be used to automatically apply labels to merge requests based on commit messages and MR actions, by implementing a custom webhook server that interacts with the GitLab API.
Timeline

GitLab's DevOps platform is adopted by organizations to consolidate toolchains, improve version control, ensure accountability, boost collaboration, establish a single source of truth, and speed up production. This includes enabling teams to work in an Agile setting, accelerating the delivery of software while maintaining high quality, and incorporating feedback from all application stakeholders. The platform's integrated approach reduces the need for multiple tools, streamlines workflows, and enables organizations to adopt modern JavaScript frameworks like Vue.js to write simpler, more efficient code, reducing overall code volume and improving developer productivity.
Timeline

GitLab has consistently focused on enhancing the security of its platform, particularly concerning SSL/TLS configurations. This includes addressing critical vulnerabilities like Logjam by providing guidance and tools for users to strengthen their server's encryption. The evolution involves default secure configurations, user-configurable options for stronger encryption (like 2048-bit DH groups), and ongoing efforts to balance security with compatibility for older clients, especially for GitLab.com. This post announces the deprecation of TLS 1.0 and 1.1 by December 15, 2018, to improve security posture and comply with PCI DSS 3.1, and details identified client incompatibilities with TLS 1.2.
Timeline

The GitLab Wiki feature, previously available at the project level, has been expanded to support group-level wikis. This allows for centralized documentation across multiple projects within a group, ensuring consistent access permissions for all group members. This enhancement aims to improve knowledge management for teams managing complex project structures.
Timeline

GitLab's release management capabilities are enhanced with automated release note and changelog generation using commit trailers and the Changelog API. This allows for the creation of release artifacts, release notes, and comprehensive changelogs directly from CI/CD pipelines when a semantically versioned tag is pushed. The system leverages commit trailers like 'Changelog: added/changed/removed' to categorize changes, and the release-cli to create official releases with associated assets. The platform has also adopted a time-based release cadence, releasing new versions on the 22nd of every month regardless of feature completion. This philosophy prioritizes predictability, user trust, and developer motivation over feature-driven releases. This post discusses the challenges of releasing code before it's ready due to deadline pressure and unrealistic expectations, and suggests leveraging CI/CD and DevOps practices to ensure code is always tested and ready for deployment. It also highlights that releasing more often can help prevent premature releases.
Timeline

GitLab has enhanced its CI/CD variables management workflow by introducing a description field for variables to provide context on their usage. The creation and editing workflow has been streamlined for consecutive operations with improved notifications and contextual error messages. Error handling states have also been revisited and enhanced with new validations and help-texts. Previously, file type variables were expanded, which could expose sensitive data. This behavior has been removed to improve security. Additionally, a feature was introduced to generate pre-filled variables from the `.gitlab-ci.yml` file when running a pipeline manually, reducing user friction and errors.
Timeline

GitLab actively contributes to the core Git project, focusing on performance enhancements, new features, and improved reliability. This includes developing and upstreaming new commands like `git-replay` for efficient in-memory rebasing, optimizing commit-graph operations for faster history traversal, and preparing Git for a more robust and scalable ref backend with the 'reftable' format. Additionally, GitLab has developed its own solution, GitLab Shell, to replace Gitolite, addressing issues with synchronization, performance on large repositories, and setup complexity, leading to significant improvements in project creation time and overall stability.
Timeline

GitLab.com has evolved as a robust, open-source, community-driven alternative to centralized project hosting services like GitHub and Bitbucket. This thread tracks its value proposition, emphasizing its free tier for unlimited repositories and collaborators, beautiful design, advanced contributor statistics, flexible repository grouping, powerful source code search, fine-grained permission management, integrated CI/CD, and seamless import capabilities. The platform aims to provide a superior and cost-effective solution for project hosting and collaboration. This post details a customer's migration from GitHub to a self-managed GitLab instance, highlighting significant cost savings by comparing GitLab's self-hosted CI/CD capabilities (GitLab Runner) against paid third-party CI services like Travis-CI, and comparing GitLab's unlimited user/repository model against GitHub's evolving per-user pricing for private repositories. It also provides practical guidance on installing and configuring GitLab CE, including common gotchas and tips for importing large repositories.
Timeline

GitLab has integrated with AWS CodeStar Connections, enabling native integration with various AWS services like CodePipeline, CodeBuild, SageMaker MLOps Projects, and CodeDeploy. This integration acts as a utility layer, simplifying the process for other AWS services to connect with GitLab. This enhances the experience for co-customers using both GitLab and AWS together. This post introduces OIDC modules for secure authentication between GitLab CI and Google Cloud, leveraging Terraform and CI te
Timeline

GitLab's Auto DevOps feature, initially made generally available in 11.0, is now being enabled by default for all users in the 11.3 release. This aims to provide out-of-the-box benefits from Auto Build to Auto Monitoring. To ensure a smooth transition for specialized projects, Auto DevOps pipelines will be automatically disabled if they fail, with notifications sent to project owners. Gradual rollout on GitLab.com will precede the self-managed release. This post from 2017 discusses the critical role of a unified DevOps platform for SMBs, highlighting benefits such as multiplying tech muscle through automation, engaging the entire team by breaking down silos, eliminating the time and expense of complex toolchains, and improving security by integrating it into the entire software delivery lifecycle. This post emphasizes the strategic advantage of a single, end-to-end DevOps platform for SMBs to compete effectively.
Timeline

GitLab's integration capabilities are being expanded through a four-pronged approach: using GitLab to deploy to external platforms or host runners, hosting GitLab Server on external platforms, integrating with the development cycle via APIs and webhooks to display outputs in merge requests, and deep application integration requiring architectural understanding. The GitLab VS Code extension is being developed to bring merge request review functions. Sentry's integration with GitLab has been enhanced. This post details the integration with Koding, enabling one-click IDE environment creation for issues and merge requests, aiming to accelerate code contribution and collaboration.
Timeline

GitLab has introduced new default typefaces, GitLab Sans (Inter) and JetBrains Mono, to enhance UI consistency, readability, and brand continuity. This change aims to improve user experience by providing more control over typography, reducing inconsistencies across platforms and browsers, and enabling finer tuning of visual weight and hierarchy. The new typefaces are open source and packaged for easier consumption across GitLab properties and design tooling. This post details the specific iteration of improving product icons by changing the stroke weight from 2-pixel to 1.5-pixel, leading to better fidelity, balance with text, improved legibility for visually impaired users, better performance in dark UIs, and increased production efficiency through Figma's boolean unions and reusable components.
Timeline

GitLab has consistently focused on enhancing the security of its platform, particularly concerning TLS (Transport Layer Security) configurations. This has involved addressing vulnerabilities and providing guidance on upgrading encryption. A significant evolution has been the integration and simplification of obtaining and applying TLS certificates for custom domains, especially through the adoption of free, automated services like Let's Encrypt for GitLab Pages. This ensures data integrity, authentication, and confidentiality. This post details the process of securing GitLab Pages with free StartSSL Class 1 certificates, comparing them to Let's Encrypt and outlining the steps for domain verification and certificate installation, while also noting the recent distrust of StartCom certificates by major browsers and StartCom's efforts to resolve the issue.
Timeline

GitLab is adopted by organizations to consolidate toolchains, improve version control, ensure accountability, boost collaboration, establish a single source of truth, and speed up production. This includes enabling teams to work in an Agile setting, accelerating the delivery of software while maintaining high quality, and incorporating feedback from all application stakeholders. The platform's integrated approach reduces the need for multiple tools, streamlines workflows, and enables organizations to adopt microservices architecture. This involves identifying decomposable aspects of applications, determining key metrics to monitor (CPU, memory, API response time, error rate), implementing infrastructure automation, and utilizing consumer-driven contract tests to ensure API version compatibility. The goal is to enable teams to manage all aspects of a service independently, leading to faster feedback loops and reduced time to market.
Timeline

GitLab has evolved its database architecture by decomposing the monolithic Postgres database into independent databases, starting with the separation of CI-related data. This involved extensive planning, proof-of-concept work, and the development of tools and documentation to manage cross-database dependencies, such as cross-join detection, cross-database transaction detection, and loose foreign keys. The project leveraged Rails' multi-database support and addressed challenges like mirroring dat. This post details the successful upgrade to Rails 5, which involved a phased approach to manage the complexity of upgrading a large codebase. The strategy included enabling dual Rails 4/5 compatibility, splitting the upgrade into smaller, manageable issues, and rigorous CI testing to ensure stability. This approach allowed for a smooth transition without production issues.
Timeline

GitLab is evolving its open core development philosophy by open-sourcing eighteen features across various stages of the DevOps lifecycle. This move aims to empower the community, align the business model more accurately with the buyer-based open core model, and make it easier for individual contributors to access a wider range of functionalities. The open-sourced features span Plan, Create, Verify, Package, Release, Configure, and Protect stages, including functionalities like related issues, ex
Timeline

GitLab actively supports and contributes to the Ruby ecosystem, recognizing its importance for developers and companies using Ruby. This includes becoming a member of Ruby Together to fund critical infrastructure like Bundler and RubyGems.org, and exploring further contributions to community projects like RubyBench.org. This initiative aims to ensure the stability, performance, and continued development of essential Ruby tools and services, benefiting the entire community. The platform also leverages the Ruby on Rails framework for its core development, benefiting from its opinionated structure, extensive gem ecosystem, and best practices to maintain code consistency and enable rapid development of complex features. Challenges with Ruby's performance in production have led to strategic rewrites of performance-critical components in Go (e.g., Gitaly) and the use of Vue for frequently accessed pages to improve load times and reduce memory usage. Efforts are ongoing to enable multithreading in Ruby to further optimize memory usage.
Timeline

GitLab is enhancing its Infrastructure as Code (IaC) security capabilities by integrating with tools like Indeni Cloudrail. This integration shifts security checks left in the GitOps workflow, automating infrastructure compliance and reducing false positives. The goal is to prevent insecure infrastructure from being deployed by evaluating IaC for security impacts early in the development lifecycle, thereby accelerating delivery without compromising security. This post details the integration of GitLab's SSCS framework, which includes controls for Source, Build, Consumption, Management Process, and Tool Security, to provide a secure, end-to-end software supply chain. Near-term projects include enhancements to GitLab Runner Core.
Timeline

GitLab has developed Lingo, a micro language framework in Go for building Domain Specific Languages (DSLs). Lingo is designed to be simple, flexible, and composable, allowing developers to easily integrate custom types and functions without modifying the core parser or processor. It uses S-expressions as its foundation and is implemented in approximately 3K lines of pure Go code. Lingo aims to simplify the creation and evolution of embeddable DSLs for specific use cases, such as data generation for fuzzing.
Timeline

GitLab has evolved its database architecture by decomposing the monolithic Postgres database into independent databases, starting with the separation of CI-related data. This involved extensive planning, proof-of-concept work, and the development of tools and documentation to manage cross-database dependencies, such as cross-join detection, cross-database transaction detection, and loose foreign keys. The project leveraged Rails' multi-database support and addressed challenges like mirroring dat
Timeline

GitLab.com is extending CI/CD minute usage quotas to public projects not part of GitLab open source programs to prevent abuse, such as cryptocurrency mining, which negatively impacts performance and availability of shared runners. This change aims to ensure reliable service for all users by limiting excessive consumption of free pipeline minutes. Users will be notified upon reaching their quota and can upgrade their plan or purchase additional minutes. Self-managed users and members of GitLab's open source programs are exempt. Previously, unlimited CI minutes were offered for free.
Timeline

GitLab is establishing and iterating on a formal threat modeling process for its products, including the Kubernetes Agent. This process has evolved from initial security assessments to a dedicated activity with structured templates and dedicated repositories. The goal is to identify and mitigate security risks early in the development lifecycle, with plans for broader adoption across engineering teams and public sharing of threat models.
Timeline

GitLab's approach to rendering Markdown has evolved to align with established specifications, particularly concerning newline behavior. Initially, GitLab rendered all line breaks, but this was updated to conform to the Markdown specification, requiring two or more spaces at the end of a line for a newline. This change was applied consistently across various markdown-using areas like project files, issue descriptions, and comments to ensure a uniform user experience. The Web IDE and Web Editor now include a real-time, side-by-side preview panel for Markdown content, allowing users to see changes as they are made without context switching.
Timeline

GitLab has developed and adopted a modified PASTA framework for threat modeling, emphasizing its integration into existing development processes. The framework is designed to be easily understood, scalable, and to enhance DevSecOps with minimal overhead. A key aspect is that project teams, rather than solely the security department, run their own threat models using a markdown template, with the security team providing support and review. This approach aims to identify and fix security issues ea
Timeline

GitLab has addressed a bug in Usage Ping configuration for self-managed instances, ensuring that disabling Usage Ping via configuration files now functions correctly. This resolves an issue where Usage Ping events were unintentionally transmitted even when disabled through configuration. Users who suspect they were affected are advised to fill out a form for data purging. The SaaS product and UI-based disabling remain unaffected.
Timeline

This post introduces JSON linting as a method to improve code quality and accelerate development by identifying and fixing errors early. It details common JSON linting errors, how to fix them, and best practices for JSON formatting. It also touches upon using `curl` with the GitLab API and the benefits of parsing API responses in JSON format, with a brief mention of CI/CD workflows.
Timeline

GitLab has open-sourced the core protocol fuzz testing engine of Peach Fuzzer as GitLab Protocol Fuzzer Community Edition. This provides the engine to run and orchestrate fuzz tests and define custom protocols, making advanced protocol fuzz testing capabilities accessible to the open-source community, security researchers, and students. This complements existing API fuzz testing features within GitLab. The acquisition of Peach Tech and Fuzzit brings coverage-guided and behavioral fuzz testing in
Timeline

This feature thread tracks the evolution and standardization of proxy environment variables, specifically focusing on the inconsistencies and challenges associated with `http_proxy`, `https_proxy`, and `no_proxy` across different programming languages and tools. It aims to document the historical development, current implementations, and the impact of these variations on system behavior and troubleshooting.
Timeline

GitLab integrates with Google Kubernetes Engine (GKE) to simplify Kubernetes cluster creation and management. This integration allows for auto-creation of EKS clusters with a few clicks, enabling features like highly scalable CI/CD systems using GitLab Runner, shared clusters at instance, group, and project levels for isolation, dynamic environments for Review Apps, and leveraging Auto DevOps for automated build, test, and deployment pipelines. The process involves setting up AWS IAM roles (prov). Gravitational collaborated with GitLab to improve running PostgreSQL on Kubernetes and to build a terminal into GitLab for users to jump inside containers running on Kubernetes without leaving the GitLab environment. This collaboration also explored GitLab's path towards adopting Kubernetes for its internal SaaS.
Timeline

GitLab has successfully migrated its application servers from the single-threaded Unicorn to the multi-threaded Puma web server. This migration, which began with experimental use in 2015 and intensified with the formation of the Memory Team in 2019, aimed to address memory growth issues and improve scalability. The process involved extensive testing in pre-production environments, tuning of worker and thread configurations, and addressing thread-safety issues with libraries like ChronicDuration. The Memory team is also investigating memory and performance bottlenecks in Sidekiq, project import, and exports, and improving development practices around code complexity and memory usage.
Timeline

GitLab now sends notifications when a pipeline is fixed, in addition to when it fails. This feature aims to reduce the need for developers to constantly monitor pipeline statuses, allowing them to focus on other tasks. Users can customize these notifications at the project or global level.
Timeline

GitLab has adopted a time-based release cadence, releasing new versions on the 22nd of every month regardless of feature completion. This philosophy prioritizes predictability, user trust, and developer motivation over feature-driven releases. The approach aims to reduce stress, increase satisfaction by ensuring regular delivery, and foster a more active and engaged open-source community. This contrasts with traditional feature-driven releases which can lead to shifting deadlines, disappointment, and a less predictable development cycle. This post highlights the company's rapid iteration and shipping speed as a core tenet of its engineering culture, emphasizing small, focused changes and merging them quickly.
Timeline

GitLab has evolved its API security by deprecating and removing older API versions (v3) in favor of newer, more secure versions (v4). This ensures that integrations are using the latest security standards and features, reducing potential vulnerabilities and improving overall API robustness. The process involves clear communication and documentation for users to upgrade their integrations, minimizing downtime and ensuring a smooth transition to more secure API endpoints.
Timeline

GitLab has open-sourced the Gitter mobile apps (Android and iOS), detailing the technical process of removing secrets, managing configurations, and making the projects public. This effort aims to foster community contributions to the Gitter mobile platforms.
Timeline

GitLab is unifying its charting libraries to improve development velocity and onboarding. Initially considering D3.js, the team found it too low-level. After evaluating ECharts, Britecharts, and Plotly, ECharts was chosen for its robust and flexible chart types, good performance, and growing ecosystem. ECharts has been integrated into the Monitor, Secure, and Manage stages, increasing the rate of new chart type development.
Timeline

GitLab is evolving its approach to managing and disseminating UX research insights. Previously, insights were documented within individual GitLab issues or in separate, non-searchable reports. The introduction of a dedicated 'UXR Insights repository' utilizes GitLab issues as the primary mechanism for documenting key findings. This repository leverages improved issue formatting, search functionality, labels for organization, and epics/related issues for study grouping. This aims to create a single source of truth, eliminate research silos, make insights searchable and actionable, and ensure they remain up-to-date.
Timeline

GitLab's approach to rendering Markdown has evolved to align with established specifications, particularly concerning newline behavior. Initially, GitLab rendered all line breaks. The platform then proposed and implemented changes to conform to the Markdown specification, requiring two spaces at the end of a line for a line break, while paragraphs remain separated by blank lines. This change was applied consistently across all Markdown rendering within GitLab, including issue and merge request descriptions and comments, to ensure a uniform user experience. This post details the debate and technical considerations around line wrapping in documentation and user-generated content, highlighting the trade-offs between authoring ease and review readability, and proposing potential UI solutions to mitigate the challenges.
Timeline

GitLab Enterprise Edition offers a user-friendly interface for setting project-specific Git Hooks. This allows for custom rules on pushes, such as enforcing specific commit message formats (e.g., referencing JIRA issues) via regular expressions, and preventing the deletion of tags. The platform is looking to add more Git Hook functionalities based on customer requests. This post details a coordinated effort with Bitbucket and GitHub to educate users on secure best practices following a Git ransomware attack. Eko uses GitLab CE to allow professionals from different disciplines to collaborate on creating and publishing Interactive Video projects. Eko Studio acts as a Git client, translating user edits into Git commits. Developers use the standard Git interface. GitLab's API and webhooks are leveraged to connect Eko's infrastructure, enabling repository creation, initial commits, and real-time UI updates based on push events.
Timeline

The Donatinator is an open-source donation solution designed for small non-profits and charities. It aims to provide a free and accessible way to accept one-off donations and monthly subscriptions online. Key features include support for both single and recurring donations, basic Markdown page creation, and multi-user administration with reporting. The project is guided by principles of being open source, runnable on free hosting tiers, and minimizing costs to only credit card processing fees. It leverages GitLab for code hosting and aims to be a pragmatic solution for organizations with limited budgets.
Timeline

GitLab is making its ChatOps feature, which allows users to run commands from chat platforms like Slack and Mattermost, available to everyone. This feature is being open-sourced to encourage wider adoption and community contributions. The goal is to enhance ChatOps by integrating monitoring, queryability, permissions (RBAC), zero-config setup, and consistency, leveraging GitLab's single application for the DevOps lifecycle to provide out-of-the-box functionality for deployments and metrics. The acquisition of Gitter will also lead to improved GitLab integration, including 'Login with GitLab' and the ability to create chat rooms from GitLab groups and projects.
Timeline

GitLab has experienced and debugged filesystem corruption issues on NFS servers hosting Git repositories, leading to outages. The investigation involved analyzing kernel logs, understanding filesystem error messages, and considering recovery options. This led to the identification and resolution of a specific bug in the Linux v4.0 NFS client related to file handle staleness during renames, which was patched and backported to stable kernel versions. The experience highlights the collaborative nature of open-source debugging.
Timeline

Meltano is a product designed to be a complete solution for data teams, encompassing the data science lifecycle (model, extract, load, transform, analyze, notebook, orchestrate). It aims to bring software development best practices to data analytics, enabling version control, pipeline tracking, and making analytics accessible to a wider audience. Initially supporting Postgres and planning for Snowflake, Meltano focuses on managing data integrations and providing a more stable and process-driven approach. This post introduces two user personas (users with engineers on staff and users without), highlights the need for both CLI and GUI interfaces, and emphasizes the role of Meltano as the 'glue' between extractors and loaders based on Singer specifications. It also discusses the team's focus on building extractors and loaders, improving the CLI user experience with UX collaboration, and seeking frontend contributions. The team is also adopting a 'dogfooding' approach to better understand user pain points and has implemented embedded engineers to improve cross-functional understanding and problem-solving.
Timeline

GitLab has evolved its emoji rendering capabilities by switching from image-based emoji to native Unicode emoji. This transition involved developing a robust system for detecting Unicode emoji support across various operating systems and browsers, implementing fallbacks to image-based emoji for unsupported environments, and addressing platform-specific rendering inconsistencies. The goal is to reduce image loading, improve performance of the emoji reaction selector, and ensure a consistent emoji experience for users.
Timeline

GitLab has improved its search performance for PostgreSQL users by implementing trigram indexes. This enhancement allows for faster queries using LIKE conditions, significantly speeding up searches for issues, comments, commits, code, merge requests, and snippets. The implementation involved adapting Rails to support PostgreSQL-specific index types and ensuring compatibility with MySQL.
Timeline

GitLab Enterprise Edition allows for customization of the login page, including the company logo, title, and description, to provide a branded experience for users. This feature is accessible through the admin area's Appearance settings. Additionally, user preferences have been introduced to customize the UI layout (fluid or fixed width) and the default dashboard view (Projects, Starred Projects, Projects' Activity, or Starred Projects' Activity). Users can also choose between viewing the projec
Timeline

GitLab is expanding its integration capabilities to support diverse professional workflows, particularly within the research community. This initiative aims to connect GitLab with specialized platforms like the Open Science Framework (OSF) to enhance research efficiency, reproducibility, and collaboration. This post details the initial grant program to sponsor developers for building this integration.
Timeline

GitLab has established and refined its fully remote work culture, emphasizing asynchronous communication, flexible work hours, and robust social connection mechanisms. This includes daily morning meetings for coordination and team bonding, a preference for GitLab issues and Slack for communication, and regular individual check-ins with leadership to ensure employee happiness. The company also fosters in-person meetups and virtual social events, particularly around releases, to maintain team cohesion. This post details their lightweight, self-organizing workflow for incoming issues, working and prioritizing, and managing overflow, all while adhering to Agile principles and fostering openness, independence, and responsibility.
Timeline

GitLab has introduced a version check functionality to identify and alert users of outdated installations. This feature aims to improve security, user experience, and reduce the creation of duplicate issues by making users aware of available updates. The system works by loading a small image from a version check server, which indicates the update status (up-to-date, out-of-date, or critical security update). The request includes the GitLab version and server hostname (via HTTP referer) to gather usage insights, with an opt-out mechanism for users who wish to disable external connections. This initiative requires ongoing maintenance of the version check server.
Timeline

This feature thread tracks the evolution of GitLab's deployment options, specifically addressing the considerations and benefits of on-premises deployments in contrast to SaaS offerings. It covers aspects like security, integration capabilities, control, performance, flexibility, and data retrieval, highlighting why on-premises remains a viable and often preferred choice for certain organizations.
Timeline

GitLab has undergone significant UI navigation and layout redesigns to improve usability and screen real estate. Early efforts focused on addressing specific navigation issues like limited space, stacked navigation levels, and the placement of navigation elements. Subsequent redesigns have aimed to create a more intuitive and efficient user experience, incorporating community feedback and evolving the visual presentation of the platform.
Timeline

GitLab has established a structured approach to handling bugs, differentiating between security, regression, and feature bugs. This system aims to prioritize fixes based on severity and impact, encouraging community contributions for identification and resolution. The process involves clear channels for reporting different bug types, from direct contact for security vulnerabilities to the issue tracker and feedback channels for other bugs. This framework is crucial for maintaining the stability and reliability of the GitLab platform.
Timeline