
6/18/2026 · Alisa Ho
What this post added
This post introduces AI audit event streaming (beta) for tracking AI agent actions and agent tool approval guardrails (beta) for controlling agent capabilities, enhancing governance and security. It also details the enforcement of third-party security scanners (SARIF output) at scale across all GitLab projects, integrating their findings into a unified vulnerability view and enabling automated remediation of detected vulnerabilities through the GitLab Duo Agent Platform. Additionally, secret detection now scans every commit on a new branch, and Secret False Positive Detection is now generally available with confidence scores and explanations.