Try our new research platform with insights from 80,000+ expert users

Fortify Static Code Analyzer vs GitLab comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
8.3
Fortify Static Code Analyzer provides cost-effective early vulnerability detection, yielding substantial ROI and enhancing security and development efficiency.
Sentiment score
7.6
GitLab offers excellent ROI by reducing deployment time, supporting users, improving DevOps scores, and enhancing project management.
Migrating to GitLab is bringing time-saving benefits, and everything is easier to automate.
We have saved time significantly, reducing deployment time from four hours to five minutes per deployment.
 

Customer Service

Sentiment score
6.7
Fortify Static Code Analyzer support is praised for responsiveness, but some desire improved handling of complex issues and modern options.
Sentiment score
6.8
GitLab's customer support is generally well-regarded, with users appreciating community forums, fast responses for paid versions, and third-party assistance.
The customer service and support for Fortify Static Code Analyzer are better than those for LoadRunner.
I have interacted with architects for some advice during the implementation, and they were prompt in their response.
I have had meetings where they taught me, explained things, and provided guidance for starting from scratch.
We have rarely needed to escalate issues to technical support since GitLab usually runs seamlessly.
 

Scalability Issues

Sentiment score
8.0
Fortify Static Code Analyzer is highly scalable, efficiently handles large codebases, and integrates well with DevOps pipelines.
Sentiment score
7.4
GitLab's scalable container architecture efficiently manages diverse user sizes, with potential improvements for large deployments and on-premises setups.
Fortify Static Code Analyzer integrates well and is scalable.
It has all the features required for our coding and deployment needs, which makes it scalable to our changing requirements.
We're transitioning to OpenShift for future scalability with increased user numbers.
 

Stability Issues

Sentiment score
7.5
Fortify Static Code Analyzer is stable and reliable, with minor versioning issues affecting stability across different setups.
Sentiment score
8.3
GitLab is highly stable, with minimal glitches, reliable performance under pressure, and user satisfaction ratings of 7-10.
The stability of Fortify Static Code Analyzer is generally good.
I have not encountered any performance or stability issues with GitLab so far.
 

Room For Improvement

Fortify needs better language support, user interface, integration, and resource management, with improved configuration and pricing for small businesses.
GitLab requires better AWS integration, UI, documentation, project management, security, and reduced pricing with enhanced leadership dashboards and testing tools.
It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers.
It would be beneficial to have a user-friendly interface for setting up these configurations, instead of just writing YAML files.
The UI has remained the same for a couple of years and could benefit from an update with AI features and better customization.
GitLab is a great tool for developers, it lacks project planner features.
 

Setup Cost

Fortify Static Code Analyzer is seen as pricey but valued for flexibility and capability, best for larger enterprises.
GitLab offers free and paid plans, with enterprise options valued for features but sometimes seen as expensive.
The pricing of Fortify Static Code Analyzer is good, with a flexible model that allows customers to choose a setup that suits their needs.
The price is high, and it limits user accessibility.
The pricing of GitLab is reasonable, aligning with what I consider to be average compared to competitors.
Even when working in other small organizations, we opted for GitLab as it was cost-efficient.
 

Valuable Features

Fortify Static Code Analyzer enhances DevOps with flexible, automated code analysis, real-time alerts, and comprehensive integration and compliance tools.
GitLab excels in CI/CD with user-friendly interfaces, seamless integration, automation, and scalability, enhancing productivity and collaboration.
The most valuable feature of Fortify Static Code Analyzer is its extensive language support, covering many languages from legacy ones to the newest.
The Ultimate version offers enhanced features for security scanning through DAST and SAST analysis, which have greatly benefitted our project workflow.
As we implement automated testing and DevSecOps, it speeds up the process by forty to sixty percent.
The feature I appreciate the most about GitLab is its ease of use and compatibility, which allows for straightforward building and deployment processes.
 

Categories and Ranking

Fortify Static Code Analyzer
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
17
Ranking in other categories
Static Code Analysis (3rd)
GitLab
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
82
Ranking in other categories
Application Security Tools (8th), Build Automation (1st), Release Automation (2nd), Static Application Security Testing (SAST) (7th), Rapid Application Development Software (12th), Software Composition Analysis (SCA) (5th), Enterprise Agile Planning Tools (2nd), Fuzz Testing Tools (2nd), DevSecOps (3rd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Fortify Static Code Analyzer is designed for Static Code Analysis and holds a mindshare of 11.5%, up 9.5% compared to last year.
GitLab, on the other hand, focuses on Application Security Tools, holds 3.0% mindshare, up 2.6% since last year.
Static Code Analysis
Application Security Tools
 

Featured Reviews

Aphiwat Leetavorn. - PeerSpot reviewer
Provides extensive language support and enhances secure coding practices
The deployment of Fortify Static Code Analyzer needs to be simplified. It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers. This change would facilitate easier installations and ensure all necessary components are connected and ready to use.
Gaurav Chandel - PeerSpot reviewer
Boosted productivity with automated pipelines and seamless collaboration
There are some challenges with repository file management as GitLab may struggle to manage larger files. Improvements could be made regarding size management and file partitioning. Also, the UI has remained the same for a couple of years and could benefit from an update with AI features and better customization.
report
Use our free recommendation engine to learn which Static Code Analysis solutions are best for your needs.
842,651 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
30%
Computer Software Company
13%
Manufacturing Company
10%
Government
7%
Educational Organization
26%
Financial Services Firm
12%
Computer Software Company
11%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortify Static Code Analyzer?
Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like pa...
What is your experience regarding pricing and costs for Fortify Static Code Analyzer?
I rate the pricing of Fortify Static Code Analyzer as a seven out of ten since it is a bit expensive.
What needs improvement with Fortify Static Code Analyzer?
False positives need improvement in the future. Fortify's vulnerability remediation guidance helps improve code security, but I think they need to improve the focus of the solution, as it still Con...
What do you like most about GitLab?
I find the features and version control history to be most valuable for our development workflow. These aspects provide us with a clear view of changes and help us manage requests efficiently.
What is your experience regarding pricing and costs for GitLab?
The pricing of GitLab is reasonable, aligning with what I consider to be average compared to competitors.
What needs improvement with GitLab?
Certain features in Jira are not available in GitLab, such as the functionality to have weights at the milestone and epic levels. Hopefully, these features will be resolved with work items in GitLa...
 

Also Known As

Fortify Static Code Analysis SAST
Fuzzit
 

Overview

 

Sample Customers

Information Not Available
1. NASA  2. IBM  3. Sony  4. Alibaba  5. CERN  6. Siemens  7. Volkswagen  8. ING  9. Ticketmaster  10. SpaceX  11. Adobe  12. Intuit  13. Autodesk  14. Rakuten  15. Unity Technologies  16. Pandora  17. Electronic Arts  18. Nordstrom  19. Verizon  20. Comcast  21. Philips  22. Deutsche Telekom  23. Orange  24. Fujitsu  25. Ericsson  26. Nokia  27. General Electric  28. Cisco  29. Accenture  30. Deloitte  31. PwC  32. KPMG
Find out what your peers are saying about Veracode, Checkmarx, OpenText and others in Static Code Analysis. Updated: February 2025.
842,651 professionals have used our research since 2012.