
I built a self-hosted AI agent for GitLab. It has reviewed 1,000+ merge requests.
Assign a GitLab issue to a bot, and a few minutes later there's a draft merge request with the fix....
Tag archive

Assign a GitLab issue to a bot, and a few minutes later there's a draft merge request with the fix....
Measured HTTP exposure of GitLab deployments and why source control measurement deserves a different reading than web-server counting.
Post-patch hardening guide for self-managed GitLab, covering detection review, credential rotation and reachability reduction.
CVE-2026-85706 is an unauthenticated arbitrary file read in GitLab's repository commits API. On a DevSecOps platform, that read is a credential incident, not just a confidentiality bug.
Prioritisation framework for CVE-2026-85706 remediation, explaining the value of a file read on a GitLab host and how to sequence the work.
Sentinel mr-report 0.2.0 URL adress:...
What Discloses From GitLab EE CVE-2026-87719: Advanced Search Configuration and...
"Follows our coding standards" is the phrase teams use when they mean "does not post the same generic...
GitLab published a cross-branch security patch on 23 September covering 19.4.1, 19.3.3 and 19.2.7, with fixes rated up to Critical and self-managed operators asked to upgrade as soon as possible.
GitLab Self-Managed now runs two different AI code review features, and which one fires depends on...

rm -rf on the wrong host: in 2017 a GitLab engineer wiped the production PostgreSQL database, and none of the five backups worked. The full postmortem.
CVE-2026-89078: What the Advisory Says and What It Does Not