Skip to content

Rank #1 of 4 in Code Hosting

GitLab logo

GitLab Inc. · commercial

no public signals

Showcase

GitLab homepage screenshot
homepage · captured Sep 2026 · view live ↗
GitLab docs screenshot
docs · captured Sep 2026 · view live ↗

Verified integrations

Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.

By theme — the product's score on each story themeBy theme

Agenticness — how well agents can access and operate the productAgenticnessevidence →

How well agents can access and operate the product

63.8/100

Automation depth — how much of the product can run unattendedAutomation depthevidence →

How much of the product can run unattended

27.0/100

Ci cd — continuous integration and delivery — pipelines, runners, cachingCi cdevidence →

Continuous integration and delivery — pipelines, runners, caching

24.0/100

Ecosystem integrations — the surrounding ecosystem — integrations, marketplaces, community packagesEcosystem integrationsevidence →

The surrounding ecosystem — integrations, marketplaces, community packages

32.0/100

Governance — stories about governance in this arenaGovernanceevidence →

Stories about governance in this arena

60.0/100

Openness — open source, data portability, and self-hosting storiesOpennessevidence →

Open source, data portability, and self-hosting stories

44.4/100

Privacy posture — data-handling and privacy storiesPrivacy postureevidence →

Data-handling and privacy stories

4.0/100

Project planning — stories about project planning in this arenaProject planningevidence →

Stories about project planning in this arena

0.0/100

Repos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaborationevidence →

Working on repos together — pull requests, reviews, permissions

43.7/100

Security — security posture and hardening storiesSecurityevidence →

Security posture and hardening stories

41.7/100

Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hostingevidence →

Running it yourself — self-hosted servers, open-source clients

47.3/100

Story verdicts — every judged story with its evidenceStory verdicts

?

Sorted by importance (agentic first) (high → low) · 72/72 stories · click a row’s chevron for the rationale and evidence

Delegate tasks to a built-in AI assistant inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full9/10C

Drive the product through a documented public API G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full9/10C

Connect an agent via an official MCP server G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full8/10T

Plug MCP servers into this product so it can use their tools G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3none±0/10

Download a machine-readable API spec (OpenAPI or equivalent) G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10C

Point an agent at llms.txt or agent-oriented docs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Explore an interactive API reference with runnable examples G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10C

Get AI-generated insights and suggestions from my data inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10C

Rely on versioned APIs with a documented deprecation policy G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10C

Run the product headlessly / in CI for automation G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full±8/10C

Set up automations that run autonomously in the background G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10C

Use an official CLI G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10T

Operate the product with natural-language commands G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full7/10C

Issue scoped/least-privilege API credentials for an agent G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial6/10C

Build against official SDKs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial±4/10C

Subscribe to events via webhooks G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Test against a sandbox environment without touching production data G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness1none0/10

Consolidate static analysis, dependency, secret, and dynamic security scanning into one platform C

Vulnerability scanning

devops-leadSecurity — security posture and hardening storiesSecurity3full9/10C

Create and manage Git repositories and browse their commit history C

Repo management

developerRepos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration3full9/10X

Self-host the core product G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3full9/10X

Define rules that trigger actions automatically on events G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth3partial7/10C

Install a self-managed instance of the platform without laborious configuration G

Deployment options

devops-leadSelf hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting3full7/10C

Propose, discuss, and merge code changes using a pull or merge request workflow C

Repo management

developerRepos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration3full7/10X

Automatically receive pull requests that update vulnerable dependencies C

Vulnerability scanning

developerSecurity — security posture and hardening storiesSecurity3partial5/10C

Export all of my data in open formats and leave G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3partial5/10X

Review code changes online and respond to inline review comments C

Code review

developerRepos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration3partial5/10C

Define CI/CD pipelines as code using a YAML syntax C

Pipeline authoring

developerCi cd — continuous integration and delivery — pipelines, runners, cachingCi cd3partial3/10C

Run CI/CD jobs on runners hosted by the platform without managing infrastructure C

Runners

devops-leadCi cd — continuous integration and delivery — pipelines, runners, cachingCi cd3partial3/10X

Track requirements, features, and bugs using issues with milestones, time tracking, and dependencies C

Issue tracking

developerProject planning — stories about project planning in this arenaProject planning3none0/10

Prevent my data from being used to train AI models G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture3noneuntestednone yet

Secure my account with two-factor authentication G

Access security

developerSecurity — security posture and hardening storiesSecurity3noneuntestednone yet

Automate application deployments as part of my CI/CD pipeline C

Deployment

developerCi cd — continuous integration and delivery — pipelines, runners, cachingCi cd2full9/10C

Enforce coding standards and CI/CD policies across all teams and repositories C

Policy enforcement

devops-leadGovernance — stories about governance in this arenaGovernance2full8/10C

Extend my stack with third-party apps, actions, and AI models from a marketplace C

Marketplace extensions

developerEcosystem integrations — the surrounding ecosystem — integrations, marketplaces, community packagesEcosystem integrations2full8/10C

Generate and manage personal access tokens for authenticating to the platform G

Access security

developerSecurity — security posture and hardening storiesSecurity2full8/10C

Have an AI reviewer analyze code changes and suggest fixes during review C

Code review

ai-native userRepos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration2full8/10C

Do everything through the API that I can do in the UI G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial7/10T

Run my self-hosted instance on my choice of operating system and architecture, including containers G

Deployment options

devops-leadSelf hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting2partial7/10C

Set up SSH keys to authenticate and connect securely to the platform G

Access security

developerSecurity — security posture and hardening storiesSecurity2full7/10C

Assign the initial code review of a pull request to an AI reviewer for faster turnaround C

Code review

ai-native userRepos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration2partial6/10C

Have AI automatically generate and apply fixes for detected security vulnerabilities C

Vulnerability scanning

ai-native userSecurity — security posture and hardening storiesSecurity2partial6/10C

Scale my self-hosted installation using reference architectures supporting tens of thousands of users G

Deployment options

devops-leadSelf hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting2partial6/10X

Detect and remediate leaked secrets across the organization's repositories C

Vulnerability scanning

devops-leadSecurity — security posture and hardening storiesSecurity2partial5/10C

Enforce standardized, customizable merge checks before code can be merged C

Code review

devops-leadRepos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration2partial5/10C

Get centralized visibility into CI/CD workflow runs across the organization C

Runners

devops-leadCi cd — continuous integration and delivery — pipelines, runners, cachingCi cd2partial5/10C

Perform bulk operations across many items at once G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2partial5/10C

Reuse community-built CI/CD actions or plugins in my pipelines C

Pipeline authoring

developerCi cd — continuous integration and delivery — pipelines, runners, cachingCi cd2partial5/10C

Review large diffs and view third-party code quality reports directly in the review screen C

Code review

developerRepos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration2partial5/10C

Use migration tooling to move my code and users from another platform or from self-hosted to cloud C

Deployment options

devops-leadSelf hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting2partial5/10X

Search across repositories to find code, files, and commits C

Repo management

developerRepos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration2partial4/10C

Choose where my data is stored (region/residency) G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2partial3/10C

Control granular access permissions at the workspace, project, repository, and branch level C

Repo management

devops-leadRepos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration2partial3/10C

Organize work from high-level roadmaps to everyday tasks using project boards C

Issue tracking

developerProject planning — stories about project planning in this arenaProject planning2none0/10

Run CI/CD jobs on my own self-hosted or private runners C

Runners

devops-leadCi cd — continuous integration and delivery — pipelines, runners, cachingCi cd2none0/10

Automatically update linked issue tracker statuses by referencing issue keys in my commits C

External pm sync

developerProject planning — stories about project planning in this arenaProject planning2noneuntestednone yet

Control data retention and deletion G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Launch a ready-to-code cloud-based development environment in seconds C

Dev environments

developerCi cd — continuous integration and delivery — pipelines, runners, cachingCi cd2noneuntestednone yet

Opt out of telemetry and usage tracking G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Publish and consume software packages in multiple package formats from the same platform C

Package registry

open-source-maintainerRepos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration2noneuntestednone yet

Read the product's source under an open license G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2noneuntestednone yet

Restrict repository access to specific IP address ranges C

Access security

devops-leadSecurity — security posture and hardening storiesSecurity2noneuntestednone yet

Schedule recurring jobs or workflows G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2noneuntestednone yet

Access built-in resources to learn the Git version control system C

Onboarding

developerGovernance — stories about governance in this arenaGovernance1full8/10C

Make a single annual commitment and flexibly allocate spend across seat-based and usage-based licensing G

Licensing cost management

devops-leadGovernance — stories about governance in this arenaGovernance1partial6/10C

Version, review, and roll back my automations G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth1partial5/10C

Require automated change approval workflows before code reaches production C

Policy enforcement

devops-leadGovernance — stories about governance in this arenaGovernance1partial4/10C

Connect the platform to external CI/CD tools instead of using its native pipelines C

External ci cd integration

devops-leadEcosystem integrations — the surrounding ecosystem — integrations, marketplaces, community packagesEcosystem integrations1none0/10

Install third-party security scanning integrations directly from a security tab C

Security tool integrations

devops-leadEcosystem integrations — the surrounding ecosystem — integrations, marketplaces, community packagesEcosystem integrations1none0/10

Manage external issue tracker items directly within the code hosting UI C

External pm sync

developerProject planning — stories about project planning in this arenaProject planning1noneuntestednone yet

Manage projects and assign tasks from my mobile device C

Issue tracking

developerProject planning — stories about project planning in this arenaProject planning1noneuntestednone yet

Map incidents to deployments and require change approval before releases C

Deployment

devops-leadCi cd — continuous integration and delivery — pipelines, runners, cachingCi cd1noneuntestednone yet

Sync repository notifications and activity with chat tools C

Chat notifications

developerEcosystem integrations — the surrounding ecosystem — integrations, marketplaces, community packagesEcosystem integrations1noneuntestednone yet

Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 48 stories with headroom

What would move GitLab’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.

  1. Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their tools

    nonemoves agent-readyimpact 45

    Missing: documentation of adding/registering external MCP servers as tool sources for GitLab Duo agents, any UI/config for MCP server URLs within Agent Platform, and independent confirmation that GitLab agents can invoke tools from arbitrary MCP servers.

  2. Project planning — stories about project planning in this arenaTrack requirements, features, and bugs using issues with milestones, time tracking, and dependencies

    nonemoves PA Scoreimpact 30

    Missing: any docs or community evidence on issue creation, milestone planning, time tracking, or linking blocking/dependent issues.

  3. Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models

    nonemoves PA Scoreimpact 30

    No evidence pack item addresses opting out of AI model training on user data, data usage policies for Duo/AI features, or any privacy controls specific to training-data exclusion; the AI governance items ([gitlab-docs-44], [gitlab-docs-45]) cover tool permissions and monitoring, not training data usage.

  4. Security — security posture and hardening storiesSecure my account with two-factor authentication

    nonemoves PA Scoreimpact 30

    Missing: any documentation of 2FA/MFA enrollment, enforcement policies, or authenticator app support.

  5. Agenticness — how well agents can access and operate the productSubscribe to events via webhooks

    nonemoves agent-readyimpact 30

    The evidence pack covers REST API, personal access tokens, SSH keys, MCP server, and CLI, but contains no mention of webhooks or event subscription mechanisms anywhere.

  6. Ci cd — continuous integration and delivery — pipelines, runners, cachingRun CI/CD jobs on runners hosted by the platform without managing infrastructure

    partialq3/10moves PA Scoreimpact 21

    Missing: explicit documentation of GitLab.com shared/hosted runners, runner autoscaling, and infra-free operation, plus independent confirmation it works reliably.

  7. Ci cd — continuous integration and delivery — pipelines, runners, cachingDefine CI/CD pipelines as code using a YAML syntax

    partialq3/10moves PA Scoreimpact 21

    Missing: explicit mention of .gitlab-ci.yml YAML pipeline definition, pipeline syntax examples, and independent corroboration of YAML-as-code CI/CD authoring.

  8. Automation depth — how much of the product can run unattendedSchedule recurring jobs or workflows

    nonemoves PA Scoreimpact 20

    The evidence pack covers CI/CD, agent flows, and API automation broadly, but nothing explicitly documents recurring/scheduled job triggers (e.g., pipeline schedules, cron-based automation, or recurring agent flow runs) for AI-native users.

Showing the top 8 of 48 — every none/partial verdict in the story verdicts table is headroom.

Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.

Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map10 surfaces · 50 covered stories

Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.

User docs24 stories

about.gitlab.com21 stories

Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence

1 of 11 testable claims verified · 0 contradictedintegrity 9/100

13 distinct capability claims found in GitLab’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.

1

Verified

10

Unverified

0

Contradicted

39

Undersold

Verified (1)
Unverified (10)
Undersold (39)
Claims outside our story set (2)

Real capability claims found in GitLab’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.

  • Security findings are surfaced directly inside merge requests and IDEs

    source ↗
  • Provides tools to build and test applications as part of CI/CD

    source ↗
Suggest a story for these →

Business model

free-tiersubscription-per-seatusage-basedenterprise-custom

Free tier plus per-seat Premium/Ultimate subscriptions (Ultimate now custom-quoted), with usage-based CI/CD compute-minute overage billing.

pricing ↗

Score trend

How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.

PA Score33 (Sep 1 '26)56 (Sep 16 '26)
Agent-ready11 (Aug 28 '26)54 (Sep 16 '26)

Flag

⚑ Flag a verdict

Think a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.

Badge

Embed this product's score badge →

Hotlinked SVG — always shows the live current score.

For agents

Data

Agent surface uptime llms.txt 100% (30d, checked every 6h since Sep 8 '26)