GitLab is a DevSecOps platform for software teams that puts Git hosting, merge requests, CI/CD pipelines and security scanning in one application.
GitLab is a DevSecOps platform for software teams that keeps source code, code review, CI/CD pipelines and application security testing in one application. It removes the chain of separate tools a team assembles around a Git host, so a change is planned, built, tested, scanned and deployed in the same place under one login. GitLab Inc. makes it, an independent public company traded on the NASDAQ as GTLB; the product started as an open source project in 2011 and the company was incorporated in 2014. Source Code Management holds the repositories, with merge requests for review and discussion, protected branches with approval rules, and Git LFS for large binary files. Issues track the work, and Team Project Management and SLA Management extend that on the Premium tier. CI/CD pipelines run build and test jobs from the repository, with Advanced CI/CD on Premium, and the Container Registry and package registry keep images and packages next to the code. GitLab Pages publishes static sites and project wikis hold documentation. The Web IDE edits in the browser and Workspaces, on Premium and Ultimate, open a hosted development sandbox for a project. Static Application Security Testing runs on the Free tier; the Ultimate tier adds Dependency Scanning, Secret Push Protection, Vulnerability Management, Software Supply Chain Security, Compliance and Governance, Value Stream Management and Strategic Portfolio Management. The GitLab Duo Agent Platform reviews code and fixes pipelines, and is paid for with GitLab Credits. Individual developers and open source contributors start on the Free tier, which is sized for small groups. Scaling organizations that want unlimited licensed users and priority support move to Premium, and enterprises with security, supply chain and compliance mandates buy Ultimate. Teams that cannot use a hosted service install GitLab themselves on a Linux distribution, a cloud provider or a Kubernetes cluster. GitLab is bought per user, with the Premium tier priced per user per month and billed annually, on GitLab.com or self-managed, with add-ons for credits, compute minutes, storage and Enterprise Agile Planning seats, and GitLab Flex puts seats and credits under one annual commitment. In daily use GitLab is the place a developer opens a merge request, watches its pipeline pass or fail, reads the vulnerability report it produced and merges. Teams arriving from GitHub, Bitbucket or Gitea bring their repositories over with the importer. A group on Premium or Ultimate signs its members in through a SAML identity provider and exports audit events to CSV or reads them over the API. Product managers and other stakeholders join the same projects through Enterprise Agile Planning seats, and containers built in a pipeline are stored in the project's private Container Registry.
Features
- Included: Pull or merge request workflow
- Included: Protected branches with required approvals
- Not included: Code owners for automatic reviewer requests
- Included: Built-in CI/CD pipelines
- Included: Git LFS for large binary files
- Included: Built-in issue tracker per repository
- Included: Repository wiki and hosted static pages
- Included: Package and container registry
- Included: Repository import from other hosts
- Included: Dependency vulnerability alerts
- Included: Secret scanning on push
- Included: Hosted cloud development environments
- Included: Fine-grained repository permissions
- Included: SAML single sign-on for the organization
- Included: Organization audit log
- Included: Self-managed installation option
- Included: Free tier with private repositories
Additional Features
- Per-project and per-group roles from Guest to Owner
- Git repository hosting with Source Code Management
- Merge requests with inline discussion
- Protected branches with approval rules
- Git LFS for large binary files
- Issues for planning and tracking work
- Team Project Management (Premium)
- CI/CD pipelines with included compute minutes
Best for
- Software teams that want source control, code review, CI/CD and security scanning in one application
- Individuals and open source contributors working within the Free tier's group size
- Scaling organizations that need unlimited licensed users and priority support
- Enterprises with application security, supply chain and compliance requirements
- Organizations that must run the platform on their own servers or Kubernetes clusters
- Teams moving repositories over from GitHub, Bitbucket or Gitea
- Product managers and stakeholders who plan work in GitLab without a developer licence
Use cases
- Hosting Git repositories and reviewing changes through merge requests
- Running build and test pipelines on every push
- Scanning code for vulnerabilities with Static Application Security Testing
- Finding known-vulnerable dependencies with Dependency Scanning
- Blocking keys and API tokens before they reach a repository
- Storing container images and packages beside the code
- Publishing documentation and static sites with GitLab Pages and wikis
- Enforcing SAML sign-in and reviewing audit events for a group
- Developing in hosted Workspaces instead of a local machine
- Importing repositories from another Git host
- Tracking delivery with Value Stream Management
- Reviewing code and fixing failing pipelines with GitLab Duo agents
Screenshots & Videos
Explore GitLab in action