GitLab 18.10 release notes
GitLab 18.10 transitions SAST false positive detection from beta to general availability. The feature utilizes the GitLab Duo Agent Platform to analyze critical and high-severity vulnerabilities for false positive likelihood.
Verified State Diff
Impact & Verification Analysis
Security engineers, DevSecOps teams, and enterprise users with Duo add-ons.
Reduces alert fatigue and manual triage overhead by providing automated confidence assessments for high-severity security findings.
Full Fact Overview
The release of GitLab 18.10 marks the production-ready status of AI-driven SAST triage. By integrating the GitLab Duo Agent Platform, the system now automatically assesses the probability of false positives in security scans, providing contextual metadata directly within the vulnerability report. This functionality requires Duo Core, Pro, or Enterprise add-ons and is available across GitLab.com, Self-Managed, and Dedicated tiers. Additionally, the release includes community-driven updates to triage-ops automation and Value Stream Analytics, specifically removing the 180-day default limit on AI impact reporting.