DeviQA, Cobalt and GitLab: the latest vendor and product news

Oleg Sadikov
Oleg Sadikov, chief executive officer at DeviQA

Your weekly roundup of the most important QA, software testing and software delivery launches for banks and financial services firms, alongside investments, acquisitions and other vendor news.


This week, DeviQA formalises its approach to testing AI-generated code, GitLab adds governed agentic workflows and Cobalt makes its autonomous penetration-testing platform generally available.

Elsewhere, Dynatrace agrees to acquire AI evaluation specialist Arize for $915 million, while CodeRabbit raises $143 million as demand grows for independent scrutiny of AI-generated software.

DeviQA standardises AI-code testing

DeviQA has formalised a testing methodology for software developed or modified using tools such as GitHub Copilot, Claude Code and Cursor.

The quality-engineering firm said conventional testing remains relevant but must be strengthened to address failure modes introduced by AI-generated code. These can include incorrect assumptions, incomplete business logic, unnecessary changes and hidden dependencies, even when the resulting code is syntactically correct.

The methodology places greater emphasis on independent verification, behavioural impact analysis, adversarial testing and the validation of AI-generated tests.

Regression scope is based on potential effects across workflows, integrations, permissions, data and dependencies rather than simply the amount of code changed.


“The industry is moving code generation faster than verification can keep pace.”

– Oleg Sadikov, CEO of DeviQA

AI-created tests are also assessed for meaningful assertions, business relevance and failure-path coverage. DeviQA cautioned against treating tests generated from the same assumptions as the underlying implementation as independent evidence that the software works.

The methodology is now being applied across DeviQA engagements involving AI-assisted development.

For banks, the independent-verification principle is particularly important. Allowing one AI system, or closely related models, to generate both an implementation and the tests used to approve it risks reproducing the same misunderstanding across both layers.

Cobalt rolls out autonomous pentesting

Cobalt is making its Autonomous Pentest offering generally available during August, following its debut at Black Hat USA.

Sonali Shah

The product uses AI-supported orchestration to conduct frequent offensive testing across application portfolios. Findings can be routed into systems including Jira, GitHub and Slack, with proof of exploitability, reproduction steps and remediation guidance.

Cobalt said the system draws on more than 10,000 critical and high-severity findings. It is supported by the vendor’s network of approximately 500 vetted penetration testers, with human-led testing retained for deeper and compliance-driven assessments.

“Meeting the demands of today’s development cycles requires more than automating traditional pentesting,” said Cobalt chief executive Sonali Shah.

The product reflects the growing division of security testing between frequent autonomous assessments and more extensive exercises led by human specialists.

Banks considering autonomous penetration testing will need strict targeting controls, separation from sensitive production services and records showing exactly what the platform attempted. They will also need a clear escalation route when an autonomous assessment discovers a weakness that could affect live customer, payment or identity systems.

GitLab expands governed agentic delivery

GitLab has released version 19.3 of its software-delivery platform, adding tools for building agentic workflows, managing secrets and addressing security vulnerabilities.

Its Flow Creator Agent allows users to describe a workflow in natural language and receive a runnable flow definition, reducing the need to write the underlying configuration manually.

GitLab has also made its Secrets Manager available to GitLab.com customers as a paid add-on. Credentials can be stored and retrieved within the same platform used to manage code and pipelines, under existing access controls.

Other additions include bulk remediation of vulnerability backlogs, automated management of auditor access through LDAP groups and webhooks covering merge-request reviews and deployment approvals.

New CI/CD variables allow pipeline logic to identify how many times a job has been retried and which tags have been assigned to it. That can help teams distinguish an initial test failure from a successful retry rather than allowing unstable tests to disappear inside an overall passing pipeline.

For regulated firms, natural-language automation will still require change controls, version histories and human approval. Making a delivery workflow easier to create does not remove the need to prove what it can access, which tests it executes and under what conditions it may promote code.

Dynatrace moves into AI evaluation

Dynatrace has agreed to acquire AI evaluation and observability specialist Arize for $915 million.

The transaction will combine Arize’s tools for evaluating model outputs and agent behaviour with Dynatrace’s monitoring of applications, infrastructure, GPU usage and business processes.

Jason Lopatecki

The vendors are positioning the combination as an end-to-end system extending from AI experimentation and deployment-readiness assessments to runtime evaluation and production observability.

Arize chief executive and co-founder Jason Lopatecki and co-founder Aparna Dhinakaran will join Dynatrace after the transaction closes. Lopatecki will continue to lead the Arize team.

The deal is expected to close later in the current quarter or early in Dynatrace’s third fiscal quarter, subject to regulatory approval.

Bringing pre-production evaluation and live observability together could help financial firms compare expected AI behaviour with what models and agents actually do after deployment.

However, monitoring data alone will not establish whether an output was accurate, fair or compliant; firms will still need defined evaluation criteria and accountable human owners.

CodeRabbit raises $143M

AI code-review vendor CodeRabbit has raised $143 million in a funding round valuing the company at $1.5 billion.

The round was co-led by Atomico and Smash Capital, with participation from Datadog and Hirtle Callaghan. It follows a $60 million Series B completed less than a year earlier.

CodeRabbit reviews proposed software changes, explains their likely impact and checks code for vulnerabilities and maintainability risks. The vendor said it now conducts more than two million reviews each week for more than 17,000 customers, including payments company Adyen.

The company recently opened a London office and plans further expansion across Europe and Asia. It will also invest more than $10 million during the next year to keep its AI-supported code-review and agent tools free for open-source maintainers.

The investment illustrates the growing market for verification tools as AI coding increases the volume of software changes requiring review.

For banks, AI-supported code review may increase the percentage of changes receiving scrutiny, but it should supplement rather than replace testing against business requirements. A review system can identify suspicious code patterns without proving that a payment, lending or customer-onboarding process behaves correctly from end to end.


NEXT MONTH

REGISTER TODAY – SIMPLY CLICK HERE


Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

SIGN UP HERE TODAY


READ MORE


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS