« Blog Home

What’s New in GitLab 19.4 ?

GitLab 19.4 Release Overview

GitLab 19.4, released on September 17, 2026, expands agentic automation across the software development lifecycle, adds stronger governance for MCP tools, improves AI cost visibility, and introduces new security capabilities such as malicious-package detection and broader SAST language coverage.

GitLab 19.4

We recommend planning an upgrade to the appropriate supported release after checking the upgrade path, deployment requirements, and applicable feature flags. See the Geo deployment action below before upgrading an affected environment.

We help many customers upgrade their GitLab environments and get the most out of them, including CI/CD, DevSecOps, AI governance, and secrets-management best practices!

Contact me with any questions or concerns.

The overview below covers all 35 feature entries in the published GitLab 19.4 release notes, together with the release’s community-contributed enhancements. Beta, experimental, tier, and deployment restrictions are noted where relevant.

AI and Agentic Workflows

GitLab 19.4 expands the development tasks that teams can delegate to AI agents, with configurable governance and approval controls. AI access depends on the subscription, enabled features, supported models, and GitLab Credits.

  1. /goal Command in GitLab Duo CLI (Public Beta): Developers describe an open-ended objective, such as fixing failing tests. The local workflow implements changes and uses an independent judge to check progress until the objective is met or the iteration limit is reached. Developers can pause or redirect it. Requires Premium or Ultimate, GitLab 19.3 or later, and GitLab Duo CLI 9.17.0 or later. Local workflow execution does not mean the AI model runs locally.
  2. Governance for GitLab MCP Server Tools: MCP tools appear alongside internal tools in GitLab Duo settings. Read-only MCP tools default to Always Allow; write and delete tools default to Always Ask. Rules can also deny tools. Availability follows the applicable entitlement and governance settings; background-flow enforcement has a separate feature flag.
  3. Restrict Access to External MCP Servers (Beta): Premium and Ultimate customers can allow or deny access to entire external MCP servers or individual tools across Agentic Chat, flows, IDEs, and CLI environments. Check the governance configuration and applicable feature flags for the execution environment.
  4. Expanded MCP Tools (Public Beta): The release expands CI/CD, merge request, repository, project, user, work-item, and vulnerability automation. Tool availability still depends on permissions, licensing, and enabled features. Vulnerability tools require Ultimate.
  5. CI/CD Tools: save_pipeline starts, retries, or cancels pipelines; get_job provides job metadata and traces for build diagnostics.
  6. Merge Request Tools: Agents can open and update merge requests, inspect diffs, conflicts, and approvals, list merge requests across a group, submit batched line comments with a summary, and approve, unapprove, or merge when checks permit.
  7. Project and User Tools: Agents can discover projects, read project details, list members and roles, and look up users for assignments or mentions.
  8. Repository Tools: Agents can browse trees, branches, tags, releases, and commits, create commits containing multiple file changes, and fork repositories.
  9. Work Item and Discussion Tools: get_work_item, list_work_items, and save_work_item cover issues, epics, tasks, incidents, objectives, and key results. The consolidated save_note tool creates comments and discussion replies, replacing the earlier separate note-creation tools.
  10. Semantic Search Tool: semantic_code_search becomes semantic_search. Its new scope parameter currently accepts only code; this change does not add other searchable content types.
  11. Duo Session Lookup: get_duo_session retrieves a session’s status and available results so agents can inspect earlier work.
  12. GitLab Duo Slack Integration (Experimental): Users can mention @GitLab in a Slack channel or thread to ask questions about a codebase, trigger an agent flow, or create a GitLab issue. GitLab Duo streams its progress back into the Slack conversation.
  13. Visual Flow Builder (Beta): The GitLab for VS Code extension provides a visual editor for custom flows, with agents, tools, and AI tasks. Users can test flows locally and publish them to the AI Catalog. Requires extension version 6.87.0 or later and the gitlab.featureFlags.flowBuilder setting. Running flows also requires the appropriate project permissions and Agent Platform configuration.
  14. Merge Request Created Trigger: AI flows and external agents can now be triggered as soon as a merge request is opened and GitLab generates its diff. This enables automatic first-pass reviews and contextual analysis before a developer manually begins reviewing the merge request. This includes both draft and ready merge requests.
  15. Redesigned Agent Session Details: The panel groups session status, timestamps, triggering user, and execution details. Linked items distinguish the initiating item from outputs such as merge requests, jobs, work items, and comments.
  16. Additional Model Choices: GitLab-hosted GLM 5.3, Kimi K3, and MiniMax M3 are available for Agentic Chat and supported agents and flows. Users can choose a chat model; group Owners and administrators can set defaults. The model matrix excludes these three from Code Review Flow and Security Review Flow. These are hosted-model choices, not an announcement of air-gapped inference support.
  17. Model Availability Update on September 22: GitLab’s current model documentation also lists GPT-6 Sol and GPT-6 Luna for Agentic Chat and other supported agents. This is a post-release model-catalog update, separate from the September 17 launch.
  18. Independent Developer Flow Model Selection (GA): Administrators can select the Developer Flow model independently of the models used by other Agent Platform features.
  19. Disable Flow Triggers Without Deleting Them: Flow triggers can now be disabled while retaining their filters and configuration, making it easier to pause and resume automations. Manage them under AI > Triggers.

2. Security and Compliance

GitLab 19.4 adds new supply-chain protections, expands application-security coverage, and gives security teams more automation and visibility. The security features in this section require Ultimate; configuration and deployment restrictions also apply.

  1. Malicious Package Detection (Beta): Dependency Scanning now checks dependencies against GitLab malware advisories, helping identify typosquatting, compromised maintainer accounts, and packages containing malicious code. Findings appear in the Dependency List and Vulnerability Report with a Malware badge, Critical severity, and a GLAM- identifier rather than a CVE. Supported ecosystems include npm, PyPI, Maven, Go, NuGet, Cargo, and RubyGems. A malware rule in merge request approval policies can require approval for malicious dependencies. Continuous vulnerability scanning uses the same advisories; offline instances must import them manually.
  2. Advanced SAST for Kotlin, Dart, and Scala (Beta): Advanced SAST adds taint analysis for these languages, with coverage for Android APIs, Flutter and Dio, and Scala frameworks such as Play, Slick, and Akka. Findings show source-to-sink code flows.
  3. Vulnerability Context Flow (Experimental): The Vulnerability Context Analysis agent produces authentication, authorization, and sensitive-data context to support triage. When enabled, it analyzes default-branch changes in the background and provides context to downstream security features. The analysis sends project source code to LLMs.
  4. Vulnerability Tools for the GitLab MCP Server: AI agents can now list and inspect vulnerabilities, dismiss or confirm findings, return findings to the detected state, override severity with a comment, and create linked issues. Write operations remain subject to configured approval rules.
  5. Organization Security Dashboards (Beta, GitLab.com Only): Organization Owners can view vulnerability severity, trends, top CWEs, risk scores, and vulnerability age across top-level groups. Advanced search and advanced vulnerability management are prerequisites. Availability remains subject to the organization_security_dashboard feature flag, which the documentation lists as disabled by default.
  6. Aggregated Scanner Coverage: Security Inventory now shows SAST, DAST, Dependency Scanning, and other scanner coverage across an entire group hierarchy. It reports project counts and percentages by scanner status, supports filtering to coverage gaps, and lets users choose visible inventory columns.
  7. Automated Triage and Remediation Profiles: Ultimate customers can configure automated security handling for groups or projects through a single GraphQL profile, with Conservative, Standard, and Proactive presets. Configuration is GraphQL-only and requires Agent Platform with foundational flows enabled for the top-level group. Most included flows consume GitLab Credits; each preset’s thresholds and limits vary by flow.
  8. Automatic Revocation of Routable Personal Access Tokens: With automatic response enabled, leaked GitLab personal access tokens detected in public projects can now be revoked for legacy, routable, and versioned-routable formats. Coverage includes both GitLab Secret Scanning for Source Code and the Gitleaks-based analyzer.
  9. SPDX License Expressions: GitLab 19.4 adds compound SPDX expressions to synchronized license data and their evaluation in license approval policies. Expressions supplied directly in CycloneDX SBOMs were already supported in 19.3. Offline installations need the v3 license dataset to receive the new synchronized expression data.
  10. Bulk Vulnerability Due Dates: Security teams can assign, update, or remove due dates for up to 1,000 vulnerability findings at once through the GraphQL API. The mutation is bulkSetVulnerabilityFindingsDueDates and returns update counts and structured errors.
  11. Filtered Vulnerability CSV Exports: CSV exports from the Vulnerability Report now respect the filters applied in the interface.
  12. Dependency Resolution Timeouts: Two inputs in the Dependency-Scanning.v2 template allow users to increase dependency-resolution time limits.

3. DevOps and Platform Updates

This release also improves credit management, deployment operations, CI/CD infrastructure, and day-to-day usability.

  1. GitLab Credits Usage Visibility (GA): Platform owners can inspect usage by user. The new export adds a billable-event CSV to the daily summary in one ZIP file, including project, user, session, credits, and token data. Billing account managers request exports through Customers Portal; the export runs in the background and the download link arrives by email.
  2. Credit Caps in the User Interface: GitLab.com group Owners and Self-Managed administrators can set a default user cap and individual overrides through the Credit caps page. This Premium/Ultimate feature depends on credit_caps_ui, documented as disabled by default. The GraphQL API remains available.
  3. Early Warnings for Flex Spend Caps: Billing account managers receive email notifications when on-demand usage reaches 50% or 80% of a monthly spend cap. Notifications are sent at most once per capability per billing period, for the highest threshold crossed; caps below $10 are excluded.
  4. Improved Credit Consumption Order: Each user’s included monthly credits are consumed before shared temporary evaluation credits. The ordering of monthly commitment, one-time-charge, and on-demand credits is unchanged.
  5. GitLab Runner 19.4: Fastzip becomes the default cache and artifact archiver. The Kubernetes executor gains suspend/resume support, and Docker service containers gain services_cap_add and services_cap_drop settings. Job Router observability improves through new runner/system_id metric labels and dedicated SLI/SLO/alerting integration. Completion requests include an environment key, and an option hides cache-transfer URLs in job logs. Secret-resolution failures are classified by cause.
  6. Runner Reliability Fixes: The release also addresses Job Router 409 handling, shared-label mutation panics, Windows cancellation and graceful shutdown, excessive metric cardinality, configuration validation warnings, intermittent source-fetch failures, adaptive-concurrency warnings, and Kubernetes pause-pod startup failures.
  7. Geo SSH Proxying Enabled by Default: On Premium/Ultimate Self-Managed deployments, SSH fetches and pushes through a secondary can be proxied to the primary using the now-enabled geo_proxy_fetch_ssh_to_primary and geo_proxy_push_ssh_to_primary flags.
  8. Geo Deployment Action: Cloud Native deployments using the bundled NGINX Ingress can experience stalled or timed-out SSH operations through secondaries. The release notes require migrating to Gateway API with Envoy Gateway before rollout, or disabling both Geo SSH proxy flags after rollout.
  9. Upcoming GitLab.com Rate-Limit Changes: GitLab announced tier-based limits starting October 19, 2026 for Free accounts and unauthenticated requests, followed by Premium and Ultimate in January 2027. These are scheduled service changes, not limits already enforced by the 19.4 release. The rate-limit reference still describes the new limits as proposed.
  10. Improved Artifact API Access and Transfers: The Job Artifacts API adds file_type to download an eligible report directly, subject to its authorization check. For example, file_type=junit requests JUnit results. Administrators can also allow clients to choose a direct redirect or a proxied transfer for job artifact and package downloads.
  11. Pipeline Editor Validation: The editor recognizes additional CI/CD keywords already accepted by the backend.

4. Developer Experience

GitLab 19.4 includes several improvements that make everyday development, review, and administration more transparent.

  1. Preview New Markdown and AsciiDoc Files: The new-file editor now includes Write and Preview tabs, allowing users to preview Markdown or AsciiDoc content before committing the file. The renderer also follows changes to the filename extension.
  2. Markdown Preview in Snippets: The snippet editor adds live Markdown preview through its context menu.
  3. More Specific Merge Request Statuses: The merge request widget now distinguishes between states such as checking for merge conflicts and an actual conflict. When a rebase is refused, it also gives a specific reason, such as source-branch force-push protection.
  4. See Who Locked a File or Directory: The blob viewer now displays the user who locked a file and explains whether the current user can unlock it. Requires Premium or Ultimate.
  5. Improved Issue-Date Filtering: Filtering issues by created, closed, due, or updated date is now generally available.
  6. Merge Request Description Copying: When creating a merge request after cherry-picking a commit, users can choose to copy the source merge request’s description instead of automatically applying the project template.
  7. Internal Notes in Comment Templates: The /internal_note command can now be used when creating comments, allowing internal notes to be included in comment templates and saved replies.
  8. Promote an Issue to an Epic: The /type Epic quick action now also promotes an issue, like /promote_to Epic.
  9. Improved Mermaid Diagrams: Links in Mermaid flowcharts are now clickable, and diagrams render correctly without clipping in Chrome on iOS.
  10. Improved Table Pasting: The rich text editor lets users merge copied cells into a table or insert a nested table within a cell. A keyboard shortcut supports nested pasting; clipboard access requires HTTPS or localhost.
  11. LDAP Group-Sync Diagnostics and Filtering: Group-sync errors now surface on the group page, identifying up to five affected members. More specific audit events distinguish link creation, link removal, and users blocked by LDAP sync. The group_filter setting restricts which LDAP entries are treated as groups. LDAP group-sync configuration requires Premium or Ultimate on Self-Managed.
  12. Service Desk Empty-Subject Emails: Emails with an empty subject now create Service Desk tickets instead of being rejected.
  13. Achievement Visibility: Administrators can configure achievements to appear on profiles without requiring each recipient to accept an emailed link.

We help many customers upgrade their GitLab environments and get the most out of them, including CI/CD, DevSecOps, AI governance, and secret-management best practices.

Read the full release notes and the official community-contribution summary: GitLab 19.4 release notes GitLab 19.4 What’s New

    * Full Name

    * Work Email

    * Are you using any AI tools today? What tools?

      * Full Name

      * Work Email

      Are you using any SCA solution? Which one?

        * Full Name

        * Work Email

        * Are you using OpenProject?

        Do you have any questions you'd like to ask before the webinar?

          * Full Name

          * Work Email

          * Are you using any Secrets Management solution? Which one?