Retrieved article excerpt
Open article · Retrieved 2026-09-18T10:21:31.795185+00:00
---
# GitLab 19.4 release notes
On September 17, 2026, GitLab 19.4 was released with the following features.
We are excited to recognize [Jimmy](https://gitlab.com/jspagnola), a Level 4 contributor,
as this month’s [Notable Contributor](https://contributors.gitlab.com/notable-contributors)!
Jimmy contributed across the GitLab codebase, `client-go`, and the Terraform
provider to ensure that tokens, service accounts, and push mirrors can be
managed end to end through infrastructure as code.
## Primary features
### Governance for GitLab MCP server tools
- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated, GitLab Dedicated for Government
- Links: [Documentation](https://docs.gitlab.com/user/ai_governance/tool-governance) · [Related Issue](https://gitlab.com/gitlab-org/gitlab/-/work_items/628391)
Previously, you could only apply [AI agent tool governance](https://docs.gitlab.com/user/ai-governance/tool-governance/)
rules to internal GitLab Duo Agent Platform tools. Tools available to both GitLab Duo Agent Platform and
third-party agents through the GitLab MCP server followed fixed rules that could not be changed.
You can now govern GitLab MCP server tools from the same place as internal GitLab Duo Agent Platform
tools. They appear alongside internal tools in your group and project **GitLab Duo** settings, where
you can set a mode for each tool:
- Read-only tools default to **Always Allow**, so routine lookups run without interrupting your team.
- Write and delete tools default to **Always Ask**, giving reviewers a checkpoint before an agent
changes anything.
### Advanced SAST includes Kotlin, Dart, and Scala language support
- Tier: Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated, GitLab Dedicated for Government
- Links: [Documentation](https://docs.gitlab.com/user/application_security/sast/gitlab_advanced_sast/#supported-languages) · [Related Issue](https://gitlab.com/groups/gitlab-org/-/work_items/23383)
Advanced SAST now scans Kotlin, Dart, and Scala codebases with the same deep taint
analysis that covers Java, Python, and other supported languages, all delivered through
the Software Factory architecture with per-language front-ends and framework-aware rule gating.
- Kotlin detection targets Android APIs for SQL injection, unsafe WebView usage, OS command
injection, hardcoded credentials, and weak cryptography.
- Dart detection includes a Flutter and Dio framework detector covering SSRF, path traversal,
command injection, and cleartext HTTP.
- Scala detection covers Play, Slick, and Akka frameworks for SQL injection, SSRF, open redirect,
path traversal, command injection, and XSS.
All three additions are verified using deliberately vulnerable real-code repositories,
with findings reported as code flows from source to sink.
### SPDX license expression support in dependency and license scanning
- Tier: Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/compliance/license_scanning_of_cyclonedx_files/) · [Related Issue](https://gitlab.com/groups/gitlab-org/-/work_items/16801)
GitLab license data now carries SPDX license expressions, including compound declarations
such as `MIT OR Apache-2.0` or `GPL-2.0-only WITH Classpath-exception-2.0`.
Previously these were reported as `unknown` in the dependency list and were invisible to
license approval policies.
Composite licenses now appear in the dependency list with their operator (`AND`, `OR`,
`WITH`), and license approval policies can allow or deny them the same way they handle
single-license dependencies.
Expressions declared in a CycloneDX SBOM have been supported since GitLab 19.3.
This release adds them to the license data GitLab synchronizes.
Offline instances receive expressions only after
[downloading the v3 license data](https://docs.gitlab.com/topics/offline/quick_start_guide/#download-v3-license-data).
## Agentic Core
### /goal command in GitLab Duo CLI
- Tier: Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/gitlab_duo_cli/use/#slash-commands) · [Related Issue](https://gitlab.com/groups/gitlab-org/ai-powered/-/work_items/10)
GitLab Duo CLI now includes a `/goal` slash command that delegates open-ended objectives to a
governed, goal-driven flow that runs locally.
You describe a goal and GitLab Duo handles implementation and verification, using an
independent judge to decide when you have achieved your goal or reached the iteration limit. You
stay in control the whole time: pause, update the goal, or redirect the agent at any time.
The `/goal` slash command requires GitLab 19.3 and later, and GitLab Duo CLI 9.17.0 and later.
To get started, run `/goal <task>`.
For example:
```
/goal Fix the failing tests in spec/models/user_spec.rb
```
### GitLab Duo Slack integration (Experimental)
- Tier: Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/project/integrations/gitlab_slack_application/#gitlab-duo) · [Related Issue](https://gitlab.com/groups/gitlab-org/-/work_items/22438)
You can now invoke GitLab Duo agent flows directly from Slack, without switching to the GitLab UI.
With the GitLab Duo Slack integration, you can mention GitLab with `@GitLab` in any Slack channel or thread. Mention GitLab to trigger agent flows, get answers from your codebase, and create GitLab issues from conversations. GitLab Duo streams its progress back into the Slack thread in real time, and includes thumbs-up and thumbs-down feedback buttons so you can rate responses without leaving Slack.
This integration is available as an experiment. To share your feedback, add a comment to [issue 624364](https://gitlab.com/gitlab-org/gitlab/-/work_items/624364).
### GitLab flow builder for custom flows (Beta)
- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/duo_agent_platform/flows/custom/#create-a-flow) · [Related Issue](https://gitlab.com/groups/gitlab-org/editor-extensions/-/work_items/236)
Build custom flows for your GitLab projects with the GitLab flow builder, a new visual
editor for AI-native workflows in the GitLab for VS Code extension.
Compose a flow visually from components (Agent, Custom tool, and AI task), or edit the
underlying YAML directly.
To start, open your flow’s YAML file in VS Code and select **Open GitLab Flow Builder**.
Test your flow with the **Run** button, which opens an execution console.
When your flow is ready, select **Publish** to publish it to the AI Catalog.
The flow builder is available as a beta feature in GitLab for VS Code 6.87.0 and later. To get started, enable the `gitlab.featureFlags.flowBuilder` setting in VS Code.
### MCP server CI/CD tools
- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/model_context_protocol/mcp_server_tools) · [Related Issue](https://gitlab.com/gitlab-org/gitlab/-/work_items/627598)
New CI/CD tools let agents trigger, inspect, and control CI/CD from any MCP
client:
- `save_pipeline` runs, retries, or cancels a pipeline without switching tools.
- `get_job` returns job metadata together with the job trace, so an agent can
read the log of a failed build and diagnose the problem on its own.
Previously, agents had no way to trigger or inspect pipelines through MCP.
### MCP server merge request tools
- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/model_context_protocol/mcp_server_tools) · [Related Issue](https://gitlab.com/gitlab-org/gitlab/-/work_items/627598)
Merge request tools let agents run the full merge request loop through the
GitLab MCP server:
- `save_merge_request` opens and updates an MR.
- `get_merge_request` inspects an MR in depth, with new diffs, conflicts, and
approvals facets.
- `list_merge_requests` now works at group scope.
- `save_merge_request_review` leaves line-level review comments, with batched
diff comments and a summary in a single call.
- `accept_merge_request` merges an MR once checks pass, and can also approve
or unapprove it.
### MCP server project and user tools
- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/model_context_protocol/mcp_server_tools) · [Related Issue](https://gitlab.com/gitlab-org/gitlab/-/work_items/627598)
New project and user tools give agents the context they need to target work
correctly through the GitLab MCP server:
- `get_project` and `list_projects` find and read project details.
- `list_project_members` enumerates members and their roles.
- `get_user` looks up user details for assignment and mentions.
Previously, agents had no way to discover project membership or user
information through the GitLab MCP server.
### MCP server repository tools
- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/model_context_protocol/mcp_server_tools) · [Related Issue](https://gitlab.com/gitlab-org/gitlab/-/work_items/627598)
New repository tools let agents browse a project’s structure, read its commit
history, and propose changes through the GitLab MCP server:
- `list_repository_tree` explores the file tree.
- `list_branches` and `list_tags` enumerate refs.
- `list_releases` inspects published releases.
- `get_commit` retrieves a commit’s metadata, diff, or notes.
- `list_commits` pages through a branch’s history.
- `add_commit` commits one or more file actions in a single call, optionally to a
new branch from a specific starting ref or source project.
- `fork_repository` forks a project, so an agent can go from exploring an
upstream repository to proposing changes without leaving its client.
### MCP server semantic search tool
- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/model_context_protocol/mcp_server_tools) · [Related Issue](https://gitlab.com/gitlab-org/gitlab/-/work_items/627598)
`semantic_code_search` is now `semantic_search`. The tool finds code by meaning
rather than by exact symbol or filename, which is unchanged from earlier
releases. The rename adds a `scope` parameter so that additional indexed content
types can fold into the same tool in future releases. Today `scope` accepts
`code` only.
### MCP server work item tools
- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/model_context_protocol/mcp_server_tools) · [Related Issue](https://gitlab.com/gitlab-org/gitlab/-/work_items/627598)
The GitLab MCP server now exposes work item tools, so agents and MCP clients can search, read, create, and update issues, epics, tasks, incidents, objectives, and key results.
Use `get_work_item` to read a single item in depth, `list_work_items` to search across a group or project, and `save_work_item` to create or update any work item type.
Because issues and epics are work item types, `get_work_item` and `save_work_item` cover what `get_issue` and `create_issue` do today.
`save_note` lets an agent comment on a work item or merge request and reply inside an existing discussion thread. The introduction of this tool renames existing `create_merge_request_note` and `create_workitem_note`.
### Merge request created event trigger
- Tier: Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/duo_agent_platform/triggers/) · [