GitLab 19.0 Embeds Agentic AI in Secrets, Merge Requests, and Supply Chain Security
GitLab just embedded agentic AI into secrets management, merge requests, and supply chain security. Not a pilot—GA today.

Why it matters
GitLab 19.0 moves agentic AI from code generation into infrastructure-critical workflows (credential management, dependency scanning, merge automation), signaling that AI agents are graduating from developer conveniences to security-adjacent production systems. For founders and CTOs, this means AI is now touching the SDLC stack where mistakes compound.
The key facts
5 to knowGitLab 19.0 release
Agentic AI extended to: Secrets Manager (public beta), Merge Request Developer Flow, dependency scanning
SBOM dependency scanning now GA
Usage-based GitLab Duo billing model introduced
AI agents now operating in supply chain security and credential management workflows
Go to the source
InfoQ AI/MLinfoq.com
Publisher excerpt: GitLab 19.0 extends agentic AI beyond code generation into securing credentials, reviewing and merging changes, and scanning dependencies, adding a public beta Secrets Manager, a full merge request Developer Flow, usage-based GitLab Duo billing, and generally available SBOM dependency scanning. By…