AI-Assisted Features in DevSecOps
One vulnerability view: From scanner coverage to AI governance

One vulnerability view: From scanner coverage to AI governance

6/18/2026 · Alisa Ho

What this post added

This post introduces AI audit event streaming (beta) for tracking AI agent actions and agent tool approval guardrails (beta) for controlling agent capabilities, enhancing governance and security. It also details the enforcement of third-party security scanners (SARIF output) at scale across all GitLab projects, integrating their findings into a unified vulnerability view and enabling automated remediation of detected vulnerabilities through the GitLab Duo Agent Platform. Additionally, secret detection now scans every commit on a new branch, and Secret False Positive Detection is now generally available with confidence scores and explanations.

Read the original post ↗