At Transcend, we made over a dozen announcements across all four layers of our architecture for agentic software engineering: agent orchestration, data and context, DevOps workflows, and governance and security. Watch the replay, or read on for what shipped and how to turn on the new capabilities.
At a glanceWhat we launchedRelease statusWhat it doesGoal-driven flows (/goal)GA this monthCarry a change through review, tests, scans, and approvals without waiting between stages of the software lifecycle.Custom FlowsGAChain agents together to match the process your teams already follow for software delivery.GitLab for SlackGA this monthStart an agentic flow from the channels where your teams already work.MCP ServerGA this monthSecurely connect AI tools and applications into GitLab workflows under the same policy.Open weight modelsGAGet comparable performance on lower-cost workloads with GitLab-hosted GLM 5.3, Kimi K3, and MiniMax 3 models.GitLab OrbitGA next monthGive your agents the right knowledge requiring 45x fewer retries with a context graph of your software lifecycle.Duo Agent Platform Impact AnalyticsEarly accessMeasure the cost and impact of your AI investment, by team, task, and model.Credit and usage controlsGASet caps at the subscription, group, and user level and get alerts on AI spend.GitLab Artifact CentralBetaGive every package and container one governed home, next to source and CI.GitLab Dependency FirewallEarly accessSet rules that block, quarantine, or warn on risky packages before they reach your build.GitLab Secrets ManagerGA this monthScope build-time secrets to the job and revoke them with one click.GitLab Security StandardAvailable todayHarden your software factory in five stages and let your agents earn autonomy.New flows with Claude Mythos 5 and 5.1GA next monthFind and remediate vulnerabilities on GitLab Duo Agent Platform with new security flows.Agent orchestration across the software lifecycleToday, each step in your agentic workflow still waits for a person to approve it before the next one starts.
Goal-driven flows take a stated objective and run it end to end, through review, tests, security scans, and approvals from the Duo CLI, headless mode, or Agentic Chat. Custom Flows let you chain agents together to match the process your team already follows. GitLab for Slack starts a flow from the channel where the conversation is already happening. The MCP Server enables external AI applications and coding agents to securely access your GitLab instance under the same policy your own agents follow.
GitLab-hosted open-weight models, including GLM 5.3, Kimi K3, and MiniMax 3, give you a lower-cost option when a workload doesn't need a frontier model. At similar task-completion rates, some open weight pairings deliver up to 8x more model calls per GitLab Credit than their frontier counterparts.
Data and context to power human and agent reasoningEvery agent task starts by re-deriving the same context, which drives up retries and token use. And without coherent visibility into AI costs and ROI, there's no way to tell whether your investment is paying off.
GitLab Orbit, the context graph of your entire software lifecycle increases agent accuracy with up to 45x fewer retries, effectively reducing cost for agentic workflows with up to 4.5x fewer token use. During its beta period, Orbit has been used by more than 3,500 organizations, running over 280,000 queries.
Duo Agent Platform Impact Analytics shows the cost and impact of your AI investment by team, task, and model. Credit and usage controls let you set caps at the subscription, group, or user level, with alerts at 50%, 80%, and 100% of spend, and an automatic pause once you hit the cap you set.
DevOps infrastructure at agent scaleMost of what ships isn't code your team wrote, it's assembled from open source packages, base images, and libraries pulled in from everywhere. When every team runs its own registry, there's no single place to confirm what you actually published or shipped.
Back in June, during Transcend London, we introduced our next-gen source code management solution helping you achieve machine scale with your coding agents. The next machine-scale problem goes to the step after code, when you’re creating a build.
GitLab Artifact Central replaces a separate registry per team with one place to publish and pull from, built next to your source code and CI pipelines. It publishes and pulls Maven, npm, and Docker, and OCI packages directly from CI pipelines, with PyPI and NuGet coming at GA. Artifact Central uses the same identity and permissions as your source code, with virtual repos, native CI/CD authentication, and full build provenance. Early results show roughly 50% lower total cost of ownership compared to alternative tooling.
Governance and security with centralized enforcementAgents pull in package components to your build at machine speed, making it impossible to manually secure what you ship. When that gap exists, you risk shipping security vulnerabilities into production rather than catching them before they impact customers, and you have to answer for it.
GitLab Dependency Firewall, now in early access, sets rules on package age, vulnerability severity, malicious package detection, and license compliance, with actions to block, quarantine, or warn, enforced on the registries you already use. It works directly with GitLab Artifact Central, and is compatible with JFrog Artifactory and Sonatype Nexus Repository.
With a greater number of builds, another risk emerges: agents inheriting build-time secrets from local dev environments that nobody secured, and using them across CI pipelines. GitLab Secrets Manager gives each build-time secret one home, scoped to the job that needs it, with one-click revocation for a leaked credential and up to 50% savings compared to hosting a separate vault.
The same AI models that let agents write and ship code at machine speed also make existing weaknesses faster and cheaper to discover, connect, and exploit. The GitLab Security Standard lays out five stages for assessing and hardening your agentic software development: authorizing every actor's access, isolating workspaces and their inputs, verifying the checks that judge the work, releasing exactly what was verified, and responding fast when something looks wrong, all built on a foundation of policy, audit, and ownership. Read the full standard for the complete breakdown.
Coming soon, Anthropic’s Claude Mythos 5 and 5.1 will power new GitLab Duo Agent Platform security flows, helping organizations with approved environments find and fix vulnerabilities faster than attackers can discover and exploit them.
How to buy with GitLab FlexAgentic software engineering makes headcount, credit burn, and new capabilities hard to predict six months out. GitLab Flex is one annual commitment that covers new GitLab capabilities as they ship, without re-procurement. It lets teams reshape seat and AI spend via GitLab Credits on a monthly basis as their needs change.
Where to start- Turn on GitLab Duo Agent Platform: Existing customers start today with credits already in their subscription, and every new GitLab trial includes 30-day access. To increase the efficiency of your agents, turn on GitLab Orbit beta for GitLab.com.
- Adopt the GitLab Security Standard: GitLab Ultimate is available as a free trial. A Secrets Manager trial is available to Ultimate and Premium customers. GitLab Artifact Central is open in beta, and you can request early access to Dependency Firewall.
- Get more from every dollar with GitLab Flex: One annual commitment for new GitLab innovations without re-procurement - with the ability to reshape your spend for seats and GitLab Credits month to month.
- If you're migrating from GitHub, do it on your own terms with dedicated migration tools, custom migration services, and an exclusive offer to get one year of GitLab free when signing up for a three-year contract.
And if you're ready to start building, join "Life after code: the path to production at the speed of imagination," our three-week hackathon in partnership with Anthropic and Google Cloud.
Wherever you start, you're choosing the same destination: the foundation for a governed software factory where agents accelerate the work and every change stays trusted.
We can’t wait to see what you build next.