- Sources: primary, discussion
- Summary: The post states that on 2026-10-19 GitLab.com moves its rate limits onto subscription tiers, and that unauthenticated callers are limited to 60 requests per hour per IP address. The unauthenticated cap is measured per IP, so it does not scale with the tier of the project being read. The announcement carries a dated deadline rather than a phased rollout.
- Why it matters: Anonymous automation against a public project is capped regardless of the account it serves, so unauthenticated CI steps, mirrors and badge fetchers have a dated deadline to start sending a token.
- Follow-up: Track whether GitLab publishes the per-tier authenticated limits and whether the date holds.
send feedback on this story