GitLab Expands Governed Software Factory as AI-Generated Code Scales
The company said the new capabilities are part of its “governed software factory,” which connects software development, security, CI/CD, artifact management and deployment under a common set of policies and controls.
GitLab has introduced a new set of capabilities designed to help enterprises manage the growing volume of AI-generated software moving from development into production, while maintaining security, governance and cost controls.
The company said the new capabilities are part of its “governed software factory,” which connects software development, security, CI/CD, artifact management and deployment under a common set of policies and controls.
GitLab said the approach is intended to address the growing fragmentation across enterprise software development environments, where separate tools often make it difficult to trace changes from initial planning through production.

The push comes as adoption of agentic software development grows on the platform. GitLab said active users of agentic software development increased 200% year over year during the past three months, while secure repositories grew 100%, user namespaces increased 80% and CI/CD pipelines rose 40%. More than 70 million developers and over 10,000 enterprises currently use GitLab, according to the company.
The company is expanding its Duo Agent Platform with goal-driven workflows that can automate tasks across coding, reviews, testing, security checks, approvals and deployment. Custom flows and triggers allow teams to automate multi-step processes while maintaining a common identity, policy framework and evidence trail.
"Every enterprise already runs a software factory, but few have intentionally designed the systems and controls that govern it. GitLab brings together the foundational building blocks for a governed software factory, connecting agentic workflows, security, and AI context and controls so organisations can move software from intent to production with greater speed, governance, and visibility,” said Manav Khurana, GitLab Chief Product and Marketing Officer.
GitLab is also introducing Artifact Central in beta on GitLab.com, bringing containers and software packages into a single control plane alongside source-code management and CI pipelines. The company said the service allows organisations to establish package policies centrally and track what has been published.
On the security side, GitLab Dependency Firewall, now in early access, checks packages against organisational policies before they enter a build. GitLab Secrets Manager, generally available on GitLab.com and in the 19.5 release for Self-Managed customers, secures build-time credentials and records access through the GitLab audit trail.
Anthropic’s Claude Mythos 5 and 5.1 will also become available within GitLab Duo Agent Platform security workflows next month, allowing approved environments to use the models to identify vulnerabilities and verify fixes.
“When defenders have more context than attackers, advanced models change the math in their favour. GitLab’s customers will be able to use Claude Mythos 5 and 5.1 to find vulnerabilities and verify fixes inside the workflows they already run,” said Rajat Pandit, Anthropic Head, Applied AI.
GitLab also said its Orbit platform has been used by more than 3,500 organisations since its June beta launch, supporting more than 280,000 queries from coding agents. The company claims Orbit can help agents complete tasks with up to 45x fewer retries and 4.5x fewer tokens, while its new Impact Analytics provides visibility into AI costs and outcomes by team, task and model.






