2026-10-11 16:38 UTC

GitLab claims version 19.4 lets third-party MCP agents operate repository, merge-request, and CI/CD workflows under configurable per-tool governance, bringing external coding agents into the same approval controls as internal Duo tools.

state: watchingheat: lowuncertainty: lowconvergesscott: highagent-governance mcp coding-agents agent-harnessesGitLab

What is this?

GitLab 19.4 (released September 17, 2026) introduces configurable per-tool governance for Model Context Protocol (MCP) server tools in public beta, expanding MCP access to repositories, merge requests, CI/CD pipelines, work items, and vulnerabilities. Governance defaults are read-only tools allowed by default, write/delete tools defaulting to 'Always Ask' for human approval. These external MCP agents operate under the same tool-level rules that govern GitLab's internal Duo Agent Platform. The press release frames this as the foundation for a 'Governed Software Factory.' All evidence comes from GitLab's own documentation, press release, and secondary coverage; no independent adoption reports or third-party integration confirmations appear in the search results.

Why it matters to Scott

GitLab 19.4's per-tool governance for external MCP agents (read-only allow, write/delete ask) independently implements a runtime-governance pattern Scott has argued for — configurable approvals at the tool boundary, shared between first-party Duo and third-party agents — but stops at platform-enforced policy without the independent deterministic verification boundary, fixed authority separation, or proof-carrying Decision Attestation Packages that define his Decision Authority Infrastructure. This is a concrete enterprise instance of the 'compliance cosplay' gap: governance configured in-path but not architecturally separated from the agent runtime.
ip:framework.decision-authority-infrastructureip:concept.runtime-governanceip:source.compliance-cosplayip:framework.agent-addressabilityip:concept.zero-trust-for-decisionsip:framework.the-governance-stackdev:concept.bounded-cognitive-worker-ladderdev:concept.attributable-named-agent-runswork:project.leverageairadar:agentconnect-permissioned-shared-agentsradar:agenticos-self-hosted-governanceradar:archer-os-agent-authority-specradar:alibaba-anolisa-agent-osradar:agent-substrate-sandbox-runtime
queries asked of Scott's wikis
  • runtime governance configurable approvals per-tool decision authority
  • MCP server tools agent harness integration patterns
  • coding agents external agent governance enterprise adoption
  • decision authority infrastructure vs runtime-dependent enforcement
  • agent-governance sovereignty local inference control

Measured heat

now 0 pts/hpeak 2 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 602h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-16 14:00⭐ origin echo-reconstructedGitLab 19.4 adds configurable governance for MCP server tools alongside expanded repository, merge-request, and CI/CD tools; read-only tools
GitLab on blog (echo) · attributed from hn.story.49752221
—
09-18 10:08first on hacker news · published · +44.1hGitLab 19.4: MCP server tools and agent governance
joshcsimmons
—
09-18 10:08amplified on hacker newshn.story.49752221
joshcsimmons
peak 1 · 0 comments · 35% of case engagement
10-08 11:41amplified on hacker news 👑hn.story.50004639
codebastard
peak 2 · 0 comments · 65% of case engagement
09-18 10:20our radar first saw it · +44.4hdiscovery anchor: hn.story.49752221—
pace: p9 vs 1032 stories at the 336h mark (now 602h old) — behind addom-local-coding-harness (0.5x)

Evidence (3) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnGitLab 19.4: MCP server tools and agent governance
Retrieved article excerpt

Open article · Retrieved 2026-09-18T10:21:31.795185+00:00

---

# GitLab 19.4 release notes

On September 17, 2026, GitLab 19.4 was released with the following features.

We are excited to recognize [Jimmy](https://gitlab.com/jspagnola), a Level 4 contributor,
as this month’s [Notable Contributor](https://contributors.gitlab.com/notable-contributors)!

Jimmy contributed across the GitLab codebase, `client-go`, and the Terraform
provider to ensure that tokens, service accounts, and push mirrors can be
managed end to end through infrastructure as code.

## Primary features

### Governance for GitLab MCP server tools

- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated, GitLab Dedicated for Government
- Links: [Documentation](https://docs.gitlab.com/user/ai_governance/tool-governance) · [Related Issue](https://gitlab.com/gitlab-org/gitlab/-/work_items/628391)

Previously, you could only apply [AI agent tool governance](https://docs.gitlab.com/user/ai-governance/tool-governance/)
rules to internal GitLab Duo Agent Platform tools. Tools available to both GitLab Duo Agent Platform and
third-party agents through the GitLab MCP server followed fixed rules that could not be changed.

You can now govern GitLab MCP server tools from the same place as internal GitLab Duo Agent Platform
tools. They appear alongside internal tools in your group and project **GitLab Duo** settings, where
you can set a mode for each tool:

- Read-only tools default to **Always Allow**, so routine lookups run without interrupting your team.
- Write and delete tools default to **Always Ask**, giving reviewers a checkpoint before an agent
  changes anything.

### Advanced SAST includes Kotlin, Dart, and Scala language support

- Tier: Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated, GitLab Dedicated for Government
- Links: [Documentation](https://docs.gitlab.com/user/application_security/sast/gitlab_advanced_sast/#supported-languages) · [Related Issue](https://gitlab.com/groups/gitlab-org/-/work_items/23383)

Advanced SAST now scans Kotlin, Dart, and Scala codebases with the same deep taint
analysis that covers Java, Python, and other supported languages, all delivered through
the Software Factory architecture with per-language front-ends and framework-aware rule gating.

- Kotlin detection targets Android APIs for SQL injection, unsafe WebView usage, OS command
  injection, hardcoded credentials, and weak cryptography.
- Dart detection includes a Flutter and Dio framework detector covering SSRF, path traversal,
  command injection, and cleartext HTTP.
- Scala detection covers Play, Slick, and Akka frameworks for SQL injection, SSRF, open redirect,
  path traversal, command injection, and XSS.

All three additions are verified using deliberately vulnerable real-code repositories,
with findings reported as code flows from source to sink.

### SPDX license expression support in dependency and license scanning

- Tier: Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/compliance/license_scanning_of_cyclonedx_files/) · [Related Issue](https://gitlab.com/groups/gitlab-org/-/work_items/16801)

GitLab license data now carries SPDX license expressions, including compound declarations
such as `MIT OR Apache-2.0` or `GPL-2.0-only WITH Classpath-exception-2.0`.
Previously these were reported as `unknown` in the dependency list and were invisible to
license approval policies.

Composite licenses now appear in the dependency list with their operator (`AND`, `OR`,
`WITH`), and license approval policies can allow or deny them the same way they handle
single-license dependencies.

Expressions declared in a CycloneDX SBOM have been supported since GitLab 19.3.
This release adds them to the license data GitLab synchronizes.
Offline instances receive expressions only after
[downloading the v3 license data](https://docs.gitlab.com/topics/offline/quick_start_guide/#download-v3-license-data).

## Agentic Core

### /goal command in GitLab Duo CLI

- Tier: Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/gitlab_duo_cli/use/#slash-commands) · [Related Issue](https://gitlab.com/groups/gitlab-org/ai-powered/-/work_items/10)

GitLab Duo CLI now includes a `/goal` slash command that delegates open-ended objectives to a
governed, goal-driven flow that runs locally.

You describe a goal and GitLab Duo handles implementation and verification, using an
independent judge to decide when you have achieved your goal or reached the iteration limit. You
stay in control the whole time: pause, update the goal, or redirect the agent at any time.

The `/goal` slash command requires GitLab 19.3 and later, and GitLab Duo CLI 9.17.0 and later.

To get started, run `/goal <task>`.

For example:

```
/goal Fix the failing tests in spec/models/user_spec.rb
```

### GitLab Duo Slack integration (Experimental)

- Tier: Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/project/integrations/gitlab_slack_application/#gitlab-duo) · [Related Issue](https://gitlab.com/groups/gitlab-org/-/work_items/22438)

You can now invoke GitLab Duo agent flows directly from Slack, without switching to the GitLab UI.

With the GitLab Duo Slack integration, you can mention GitLab with `@GitLab` in any Slack channel or thread. Mention GitLab to trigger agent flows, get answers from your codebase, and create GitLab issues from conversations. GitLab Duo streams its progress back into the Slack thread in real time, and includes thumbs-up and thumbs-down feedback buttons so you can rate responses without leaving Slack.

This integration is available as an experiment. To share your feedback, add a comment to [issue 624364](https://gitlab.com/gitlab-org/gitlab/-/work_items/624364).

### GitLab flow builder for custom flows (Beta)

- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/duo_agent_platform/flows/custom/#create-a-flow) · [Related Issue](https://gitlab.com/groups/gitlab-org/editor-extensions/-/work_items/236)

Build custom flows for your GitLab projects with the GitLab flow builder, a new visual
editor for AI-native workflows in the GitLab for VS Code extension.
Compose a flow visually from components (Agent, Custom tool, and AI task), or edit the
underlying YAML directly.

To start, open your flow’s YAML file in VS Code and select **Open GitLab Flow Builder**.
Test your flow with the **Run** button, which opens an execution console.
When your flow is ready, select **Publish** to publish it to the AI Catalog.

The flow builder is available as a beta feature in GitLab for VS Code 6.87.0 and later. To get started, enable the `gitlab.featureFlags.flowBuilder` setting in VS Code.

### MCP server CI/CD tools

- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/model_context_protocol/mcp_server_tools) · [Related Issue](https://gitlab.com/gitlab-org/gitlab/-/work_items/627598)

New CI/CD tools let agents trigger, inspect, and control CI/CD from any MCP
client:

- `save_pipeline` runs, retries, or cancels a pipeline without switching tools.
- `get_job` returns job metadata together with the job trace, so an agent can
  read the log of a failed build and diagnose the problem on its own.

Previously, agents had no way to trigger or inspect pipelines through MCP.

### MCP server merge request tools

- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/model_context_protocol/mcp_server_tools) · [Related Issue](https://gitlab.com/gitlab-org/gitlab/-/work_items/627598)

Merge request tools let agents run the full merge request loop through the
GitLab MCP server:

- `save_merge_request` opens and updates an MR.
- `get_merge_request` inspects an MR in depth, with new diffs, conflicts, and
  approvals facets.
- `list_merge_requests` now works at group scope.
- `save_merge_request_review` leaves line-level review comments, with batched
  diff comments and a summary in a single call.
- `accept_merge_request` merges an MR once checks pass, and can also approve
  or unapprove it.

### MCP server project and user tools

- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/model_context_protocol/mcp_server_tools) · [Related Issue](https://gitlab.com/gitlab-org/gitlab/-/work_items/627598)

New project and user tools give agents the context they need to target work
correctly through the GitLab MCP server:

- `get_project` and `list_projects` find and read project details.
- `list_project_members` enumerates members and their roles.
- `get_user` looks up user details for assignment and mentions.

Previously, agents had no way to discover project membership or user
information through the GitLab MCP server.

### MCP server repository tools

- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/model_context_protocol/mcp_server_tools) · [Related Issue](https://gitlab.com/gitlab-org/gitlab/-/work_items/627598)

New repository tools let agents browse a project’s structure, read its commit
history, and propose changes through the GitLab MCP server:

- `list_repository_tree` explores the file tree.
- `list_branches` and `list_tags` enumerate refs.
- `list_releases` inspects published releases.
- `get_commit` retrieves a commit’s metadata, diff, or notes.
- `list_commits` pages through a branch’s history.
- `add_commit` commits one or more file actions in a single call, optionally to a
  new branch from a specific starting ref or source project.
- `fork_repository` forks a project, so an agent can go from exploring an
  upstream repository to proposing changes without leaving its client.

### MCP server semantic search tool

- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/model_context_protocol/mcp_server_tools) · [Related Issue](https://gitlab.com/gitlab-org/gitlab/-/work_items/627598)

`semantic_code_search` is now `semantic_search`. The tool finds code by meaning
rather than by exact symbol or filename, which is unchanged from earlier
releases. The rename adds a `scope` parameter so that additional indexed content
types can fold into the same tool in future releases. Today `scope` accepts
`code` only.

### MCP server work item tools

- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/model_context_protocol/mcp_server_tools) · [Related Issue](https://gitlab.com/gitlab-org/gitlab/-/work_items/627598)

The GitLab MCP server now exposes work item tools, so agents and MCP clients can search, read, create, and update issues, epics, tasks, incidents, objectives, and key results.

Use `get_work_item` to read a single item in depth, `list_work_items` to search across a group or project, and `save_work_item` to create or update any work item type.

Because issues and epics are work item types, `get_work_item` and `save_work_item` cover what `get_issue` and `create_issue` do today.

`save_note` lets an agent comment on a work item or merge request and reply inside an existing discussion thread. The introduction of this tool renames existing `create_merge_request_note` and `create_workitem_note`.

### Merge request created event trigger

- Tier: Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Links: [Documentation](https://docs.gitlab.com/user/duo_agent_platform/triggers/) · [
joshcsimmons10
🟧 echo.blog ⭐GitLab 19.4 adds configurable governance for MCP server tools alongside expanded repository, merge-request, and CI/CD tools; read-only toolsGitLab——
🟧 hnGitLab Announces the Foundation for the Governed Software Factorycodebastard20

Interpretation history

Decision trace