GitLab 19.3 Agentic DevSecOps Guide
On this page
Quick answer
GitLab 19.3 combines features with different lifecycle and control boundaries: Dedicated AI Gateway and Flow Creator are announced as generally available; bulk SAST false-positive detection and agentic vulnerability resolution are beta; Secrets Manager is Limited Availability on GitLab.com with a separate Self-Managed beta path.
Do not approve them as one bundle. Build an adoption record per feature covering deployment, plan, identity, permissions, data path, billing, audit, human review, failure behavior, and rollback.
Release matrix
| Surface | Lifecycle to verify | Primary boundary |
|---|---|---|
| Dedicated AI Gateway | GA for GitLab Dedicated | Single-tenant deployment and inference/data path |
| Flow Creator | GA | Generated runnable flow, service account, Maintainer enablement, review |
| Agentic SAST bulk workflows | Beta | Ultimate/prerequisites, runners, scale, security validation |
| Secrets Manager | Limited Availability on GitLab.com; beta Self-Managed | Credits, scoped access, audit, irreversible disable behavior |
Pilot each feature separately. Preserve merge request review, branch protection, security ownership, secrets recovery planning, Credits caps, and an exit path.
Use the readiness checklist and the feature-specific guides below.
Official sources
Source check: August 23, 2026. Verify live lifecycle, plan, deployment, prerequisites, permissions, billing, and data boundaries.