
3/19/2026 · Alisa Ho
What this post added
This post introduces and details three new AI-powered security capabilities: SAST false positive detection (now generally available), Agentic SAST vulnerability resolution (beta), and Secret false positive detection (beta). SAST false positive detection uses an LLM to assess the likelihood of a SAST finding being a false positive, providing a confidence score and explanation. Agentic SAST vulnerability resolution automatically creates merge requests with proposed fixes for verified SAST vulnerabilities. Secret false positive detection flags dummy and test secrets. These features leverage the GitLab Duo Agent Platform and aim to reduce manual triage effort and accelerate vulnerability remediation.