GitLab 18.11: AI fixes your security vulnerabilities on its own.
Automatic SAST fixes and two new agents: what’s new? On April 16, 2026, GitLab released version 18.11. GitLab 18.11 extends agent-based AI across the entire software lifecycle, with security remediation, pipeline configuration, and delivery analytics. This is a direct response to what GitLab itself calls the "AI Paradox": AI-generated code is outpacing the environment around it. As code volume grows, so does the backlog of pipelines to configure, security findings to address, and deployment questions. With 18.11, GitLab introduces three concrete tools to eliminate that backlog.
Wat doet Agentic SAST Vulnerability Resolution?
SAST stands for Static Application Security Testing: a technique that automatically scans source code for security issues without having to run the application. Until now, it has been up to the developer to review and resolve SAST findings, which is time-consuming.
Agentic SAST Vulnerability Resolution is now generally available for GitLab Ultimate customers using the Duo Agent Platform. GitLab’s 2025 DevSecOps Report shows that developers spend an average of 11 hours per month resolving vulnerabilities after a release. When a SAST scan is complete, the agent analyzes confirmed true positives, generates a code fix targeting the root cause, and opens a ready-to-merge pull request with a confidence score, allowing developers to take action without switching contexts.
That’s a real time-saver: instead of manually going through the findings, the developer simply reviews the proposed fix and merges it if the score is high enough.
Two new roles: CI Expert and Data Analyst.
In addition to the SAST agent, GitLab 18.11 also introduces two new agents to the Duo Agent Platform. The CI Expert Agent, currently in beta, scans a repository, identifies the language and framework being used, and suggests a build-and-test pipeline in plain language, with the goal of delivering a working pipeline in minutes, without the need to write YAML manually.
YAML is the configuration format typically used to describe CI/CD pipelines; for teams new to GitLab CI, writing a correct pipeline configuration is often a hurdle. The CI Expert Agent drastically lowers that hurdle. The Data Analyst Agent, now generally available, answers questions in plain language with quick visual responses about live software lifecycle data, including merge request durations, pipeline health, and deployment frequency. It is available for Free, Premium, and Ultimate tiers with the Duo Agent Platform enabled. This gives teams and IT decision-makers immediate insights without having to configure a dashboard or learn a query language.
Why this is relevant to Cube and its clients
Cube is a GitLab Channel Partner and advises on and implements GitLab as a DevSecOps platform for B2B clients. The features of GitLab 18.11 are immediately deployable: new spending limits at the subscription and user levels for GitLab Credits give organizations control over on-demand AI spending, enabling a broad rollout of the Duo Agent Platform with predictable cost management. This makes the move to agentic AI in CI/CD attractive even for organizations with strict budget controls. For Cube, 18.11 means in concrete terms: clients can deliver software more quickly and securely, because an agent resolves security issues before they reach production, and pipelines are automatically configured for new projects.
Get started with agent-based DevSecOps today.
Are you curious about how GitLab 18.11 can make your software delivery process more secure and faster? We’d be happy to help you implement and configure the GitLab Duo Agent Platform.
Worth reading next...
Having an MVP built: from software idea to working product.
Digitizing processes: 7 steps to start without chaos