What's new in GitLab 18.2

Jul 17, 2025
Past release

GitLab Duo Agent Platform public beta, custom workflow statuses, enhanced compliance dashboards, and expansive improvements to the core platform.

Reimagining the future of software development

We're delivering critical enterprise capabilities from workflow customization to security governance that will establish the standards for modern software delivery at scale.

Read CEO's blog

Developers can go beyond basic tracking of projects with configurable statuses that reflect actual workflows:

  • Define workflows for accurate reporting and replace label workarounds with real visibility.

  • Update the status of multiple items with bulk operations across portfolios simultaneously.

  • Board automations can be configured with precise workflow transitions to improve accuracy in workflow stages.

Improved layout makes it possible to juggle dozens of MRs across multiple projects for developers:

  • Role-based views separate author vs. reviewer responsibilities so developers can focus on specific tasks.

  • Workflow view organizes group flows by the review state of MRs for clear next actions.

  • Expanded visibility combines authored and assigned MRs to ensure nothing is missed across projects.

  • The Active merge requests tab makes it easy to find what needs attention now.

Protect production stability and maintain compliance with tags that cannot be modified after creation:

  • Deployment integrity enforces production tags that remain unchanged in order to prevent accidental modifications.

  • Audit trails provide a complete view into container modifications for compliance reporting and security reviews.

  • Pattern-based rules support up to 5 RE2 regex patterns per project to help automatically protect semantic versions and critical tags.

  • Automated exclusions respect immutable tags in cleanup policies to prevent accidental deletion of critical images.

Major enhancements to vulnerability detection help development teams identify and fix security issues faster:

  • Multi-architecture support provides native Linux Arm64 scanning to eliminate emulation and speeds up scans.

  • Enhanced archive scanning delivers better vulnerability attribution across images to understand where the issues exist.

  • JavaScript reachability analysis identifies actually-used vulnerable code to reduce false positives and focus remediation efforts.

  • Reachability filtering highlights the most critical vulnerabilities.

Native AWS integration with GitLab CI/CD streamlines enterprise secret management and strengthens security controls:

  • Native AWS support enables direct Secrets Manager and Parameter Store access to eliminate the need for custom scripting.

  • Removes third-party tools to simplify architecture and reduce attack surface.

  • OIDC authentication provides keyless access so teams can manage secrets without storing credentials.

  • Centralized management consolidates secret handling to enable comprehensive security auditing.

Single point of control for organization-wide security policies, eliminating fragmentation across projects:

  • Define once in the CSP, apply everywhere with instance-wide policy enforcement.

  • Business unit flexibility allows teams to inherit and extend organizational policies from the CSP group.

  • Least privilege ensures centralized control with delegated execution.

  • Complete coverage supports all existing security policy types.

Comprehensive improvements to security visibility and reporting help developers quickly demonstrate compliance adherence:

  • PDF Security Reports enable dashboard export for board reporting.

  • Audit Stream controls allow updates to streaming without reconfiguration, preventing manual maintenance.

  • Enhanced filtering by event type, groups, or projects are now available.

  • Vulnerability GraphQL API tracks introduction and resolution pipelines.

  • Credentials Inventory now includes service accounts to show complete token visibility.

The new aggregated compliance view gives stakeholders instant visibility into organizational compliance standards, along with dashboards for:

  • Framework coverage, which shows the percentage of projects with compliance frameworks.

  • Requirement status, which tracks pass/fail rates across the organization.

  • Control effectiveness, which measures aggregate performance data to provide actionable compliance insights.

  • Risk prioritization, which identifies frameworks to focus on the highest-impact improvements.

Comprehensive planning improvements give developers the ability to coordinate complex projects more effectively:

  • Epic assignments provide clear ownership for strategic initiatives.

  • Milestone-to-epic linking connects quarterly objectives to daily work.

  • Unified references introduce new work_item:123 syntax across GitLab, making it easier to cross-reference items.

  • Display preferences offer customizable metadata visibility for teams to find relevant information.

  • Drawer/full-page toggle lets users choose how to view epic details for their specific needs and preferences.

Enterprise administration capabilities for managing GitLab at scale:

  • Custom Admin Role (Beta) provides granular permissions for Admin Area.

  • Workspace Kubernetes Agents enable instance-wide agent mapping.

Bringing intelligent assistance directly into VS Code and JetBrains IDEs as an enhancement layer so developers can stay in flow:

  • Natural workflow integration gives full context in the IDE to eliminate context switching.

  • Comprehensive access provides Issues, MRs, pipelines, and security data to enable better-informed code decisions.

  • MCP support connects to external tools and data sources to expand capabilities.

  • Pattern-based search enables advanced grep and file discovery to help developers find code quickly.

Fine-grained control over AI features helps organizations balance innovation with governance in GitLab Premium and Ultimate:

  • Hierarchical controls cascade from instance to project to simplify policy management.

  • Feature-specific toggles separate Code Suggestions and Chat controls to enable a controlled rollout.

  • Compliance alignment meets diverse regulatory requirements to ensure responsible AI usage.

  • User flexibility balances innovation with control to support varying team needs.