AI-Assisted Features in DevSecOps
Automate remediation with ready-to-merge AI code fixes

Automate remediation with ready-to-merge AI code fixes

4/16/2026 · Alisa Ho

What this post added

This post introduces Agentic SAST Vulnerability Resolution, a new capability within the GitLab Duo Agent Platform, which automatically generates ready-to-merge code fixes for SAST vulnerabilities. It analyzes vulnerabilities, generates fixes, and validates them through automated testing. The post also details enhancements in GitLab 18.11, including faster SAST scanning with incremental scanning for Advanced SAST, improved vulnerability scoring using CVSS 4.0, policy-based severity overrides, risk-based enforcement for merge approvals (KEV/EPSS), and a Top CWEs security dashboard chart. Additionally, it introduces the Security Manager role and SAST configuration profiles to enhance security controls and reduce operational overhead.

Read the original post ↗