GitLab Agentic SAST Bulk Triage and Remediation Guide
On this page
Quick answer
GitLab announced bulk SAST false-positive detection and agentic vulnerability resolution as beta in the 19.3 release. The documented resolution flow focuses on high and critical SAST findings and requires Agent Platform prerequisites, foundational-flow settings, and runners.
AI triage and proposed fixes are review inputs. GitLab’s documentation says security professionals must review results; service-account mentions cannot invoke the foundational SAST resolution flow.
Safe bulk workflow
Freeze the finding cohort and baseline severity, scanner, branch, code, ownership, and existing exceptions. Run a small sample first. For every result, preserve the original finding, reasoning evidence, changed files, tests, residual risk, reviewer, and final disposition.
Do not auto-dismiss a finding or merge a fix solely from an agent label. Test false-positive error, incomplete patch, vulnerable dependency, generated-test weakness, runner failure, duplicated batch, stale branch, permission denial, Credits cap, and rollback.
Continue with the 19.3 overview and readiness checklist.
Official sources
Source check: August 23, 2026. Verify beta lifecycle, plan, prerequisites, runner, invocation, finding scope, Credits, and review requirements.