GitLab 19.3 Agentic DevSecOps Guide

On this page

Quick answer

GitLab 19.3 combines features with different lifecycle and control boundaries: Dedicated AI Gateway and Flow Creator are announced as generally available; bulk SAST false-positive detection and agentic vulnerability resolution are beta; Secrets Manager is Limited Availability on GitLab.com with a separate Self-Managed beta path.

Do not approve them as one bundle. Build an adoption record per feature covering deployment, plan, identity, permissions, data path, billing, audit, human review, failure behavior, and rollback.

Release matrix

SurfaceLifecycle to verifyPrimary boundary
Dedicated AI GatewayGA for GitLab DedicatedSingle-tenant deployment and inference/data path
Flow CreatorGAGenerated runnable flow, service account, Maintainer enablement, review
Agentic SAST bulk workflowsBetaUltimate/prerequisites, runners, scale, security validation
Secrets ManagerLimited Availability on GitLab.com; beta Self-ManagedCredits, scoped access, audit, irreversible disable behavior

Pilot each feature separately. Preserve merge request review, branch protection, security ownership, secrets recovery planning, Credits caps, and an exit path.

Use the readiness checklist and the feature-specific guides below.

Official sources

Source check: August 23, 2026. Verify live lifecycle, plan, deployment, prerequisites, permissions, billing, and data boundaries.