GitLab 19.4 release notes GitLab released version 19.4 on September 17, 2026, adding governance controls for GitLab MCP server tools so administrators can allow or deny third-party agent access from the same group and project GitLab Duo settings used for internal Duo Agent Platform tools. The release also extends Advanced SAST to Kotlin, Dart, and Scala, adds SPDX license expressions such as 'MIT OR Apache-2.0' to license data and approval policies, and introduces a /goal slash command in GitLab Duo CLI 9.17.0 and later that delegates open-ended objectives to a locally run, goal-driven flow with an independent judge. The MCP tool governance feature is in beta, with feedback directed to issue #628378. On September 17, 2026, GitLab 19.4 was released with the following features. We are excited to recognize Jimmy https://gitlab.com/jspagnola , a Level 4 contributor, as this month’s Notable Contributor https://contributors.gitlab.com/notable-contributors Jimmy contributed across the GitLab codebase, client-go , and the Terraform provider to ensure that tokens, service accounts, and push mirrors can be managed end to end through infrastructure as code. Previously, you could only apply AI agent tool governance https://docs.gitlab.com/user/ai-governance/tool-governance/ rules to internal GitLab Duo Agent Platform tools. Tools available to both GitLab Duo Agent Platform and third-party agents through the GitLab MCP server followed fixed rules that could not be changed. You can now govern GitLab MCP server tools from the same place as internal GitLab Duo Agent Platform tools. They appear alongside internal tools in your group and project GitLab Duo settings, where you can set a mode for each tool: You can now restrict access to MCP Model Context Protocol servers by allowing or denying access to: This feature gives you assurance that AI agents within Duo Agent Platform are operating within governed boundaries and can only access MCP tools that are within their scope to perform their activities, sessions, and tasks. These controls apply consistently wherever AI agents run, including: This feature is currently in beta and we welcome your feedback in issue 628378 https://gitlab.com/gitlab-org/gitlab/-/issues/628378 . Use the Vulnerability Context Flow to produce context to triage vulnerabilities more efficiently and intelligently. The flow produces context in the following three categories: Advanced SAST now scans Kotlin, Dart, and Scala codebases with the same deep taint analysis that covers Java, Python, and other supported languages, all delivered through the Software Factory architecture with per-language front-ends and framework-aware rule gating. All three additions are verified using deliberately vulnerable real-code repositories, with findings reported as code flows from source to sink. GitLab license data now carries SPDX license expressions, including compound declarations such as MIT OR Apache-2.0 or GPL-2.0-only WITH Classpath-exception-2.0 . Previously these were reported as unknown in the dependency list and were invisible to license approval policies. Composite licenses now appear in the dependency list with their operator AND , OR , WITH , and license approval policies can allow or deny them the same way they handle single-license dependencies. Expressions declared in a CycloneDX SBOM have been supported since GitLab 19.3. This release adds them to the license data GitLab synchronizes. Offline instances receive expressions only after downloading the v3 license data https://docs.gitlab.com/topics/offline/quick start guide/ download-v3-license-data . GitLab Duo CLI now includes a /goal slash command that delegates open-ended objectives to a governed, goal-driven flow that runs locally. You describe a goal and GitLab Duo handles implementation and verification, using an independent judge to decide when you have achieved your goal or reached the iteration limit. You stay in control the whole time: pause, update the goal, or redirect the agent at any time. The /goal slash command requires GitLab 19.3 and later, and GitLab Duo CLI 9.17.0 and later. To get started, run /goal