Try our new research platform with insights from 80,000+ expert users

Fortify Static Code Analyzer vs GitLab comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
8.3
Fortify Static Code Analyzer delivers cost savings by mitigating risks early, providing returns up to twenty times the investment.
Sentiment score
7.6
GitLab offers excellent ROI by reducing deployment time, supporting users, improving DevOps scores, and enhancing project management.
Migrating to GitLab is bringing time-saving benefits, and everything is easier to automate.
We have saved time significantly, reducing deployment time from four hours to five minutes per deployment.
 

Customer Service

Sentiment score
6.6
Fortify Static Code Analyzer's customer service is praised for helpfulness but needs improvement in response times and efficiency.
Sentiment score
6.8
GitLab's customer support is generally well-regarded, with users appreciating community forums, fast responses for paid versions, and third-party assistance.
I have interacted with architects for some advice during the implementation, and they were prompt in their response.
I have had meetings where they taught me, explained things, and provided guidance for starting from scratch.
We have rarely needed to escalate issues to technical support since GitLab usually runs seamlessly.
 

Scalability Issues

Sentiment score
7.9
Fortify Static Code Analyzer is scalable for large codebases, integrates with DevOps, and supports enterprise software with high satisfaction.
Sentiment score
7.4
GitLab's scalable container architecture efficiently manages diverse user sizes, with potential improvements for large deployments and on-premises setups.
It has all the features required for our coding and deployment needs, which makes it scalable to our changing requirements.
We're transitioning to OpenShift for future scalability with increased user numbers.
 

Stability Issues

Sentiment score
7.5
Fortify Static Code Analyzer is stable with improved reliability; performance depends on hardware, network, and proper training adherence.
Sentiment score
8.3
GitLab is highly stable, with minimal glitches, reliable performance under pressure, and user satisfaction ratings of 7-10.
I have not encountered any performance or stability issues with GitLab so far.
 

Room For Improvement

Fortify Static Code Analyzer needs improved language support, integration, configuration, user-friendliness, and prioritization to reduce costs and complexity.
GitLab requires better AWS integration, UI, documentation, project management, security, and reduced pricing with enhanced leadership dashboards and testing tools.
It would be beneficial to have a user-friendly interface for setting up these configurations, instead of just writing YAML files.
The UI has remained the same for a couple of years and could benefit from an update with AI features and better customization.
GitLab is a great tool for developers, it lacks project planner features.
 

Setup Cost

Fortify Static Code Analyzer is costly but offers comprehensive enterprise features, with deployment based on developer count.
GitLab offers free and paid plans, with enterprise options valued for features but sometimes seen as expensive.
The pricing of GitLab is reasonable, aligning with what I consider to be average compared to competitors.
The price is high, and it limits user accessibility.
Even when working in other small organizations, we opted for GitLab as it was cost-efficient.
 

Valuable Features

Fortify Static Code Analyzer enhances security with seamless integration, intuitive GUI, real-time feedback, and strong support for developers.
GitLab excels in CI/CD with user-friendly interfaces, seamless integration, automation, and scalability, enhancing productivity and collaboration.
As we implement automated testing and DevSecOps, it speeds up the process by forty to sixty percent.
The Ultimate version offers enhanced features for security scanning through DAST and SAST analysis, which have greatly benefitted our project workflow.
The feature I appreciate the most about GitLab is its ease of use and compatibility, which allows for straightforward building and deployment processes.
 

Categories and Ranking

Fortify Static Code Analyzer
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
16
Ranking in other categories
Static Code Analysis (3rd)
GitLab
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
82
Ranking in other categories
Application Security Tools (8th), Build Automation (1st), Release Automation (2nd), Static Application Security Testing (SAST) (8th), Rapid Application Development Software (12th), Software Composition Analysis (SCA) (5th), Enterprise Agile Planning Tools (2nd), Fuzz Testing Tools (2nd), DevSecOps (3rd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Fortify Static Code Analyzer is designed for Static Code Analysis and holds a mindshare of 11.3%, up 9.8% compared to last year.
GitLab, on the other hand, focuses on Application Security Tools, holds 2.9% mindshare, up 2.6% since last year.
Static Code Analysis
Application Security Tools
 

Featured Reviews

Vishal Dhamke - PeerSpot reviewer
An expansive platform that comes with a comprehensive set of security rules and patterns to identify vulnerabilities
Setting up Fortify Static Application Security Testing (SAST) involves several steps to ensure that the tool is correctly configured and integrated into your development workflow say for instance Installation, License Activation, User Access and Permissions, Integration with Development Environment, Project Configuration, Custom Rules and Policies, etc. The initial setup is very easy, have used the enterprise version and a standalone version. The enterprise version definitely takes an ample amount of time to deploy because it needs to have a server along with other logistics in place along with a proper RBAC. The enterprise version would take an ample amount of time, but the standard version is just a few clicks. A team of four to five people is required for the maintenance and frequent updates are required to keep all the signatures up to date. I would rate the setup a nine out of ten.
Gaurav Chandel - PeerSpot reviewer
Boosted productivity with automated pipelines and seamless collaboration
There are some challenges with repository file management as GitLab may struggle to manage larger files. Improvements could be made regarding size management and file partitioning. Also, the UI has remained the same for a couple of years and could benefit from an update with AI features and better customization.
report
Use our free recommendation engine to learn which Static Code Analysis solutions are best for your needs.
838,713 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
30%
Computer Software Company
14%
Manufacturing Company
10%
Government
6%
Educational Organization
29%
Financial Services Firm
11%
Computer Software Company
11%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortify Static Code Analyzer?
Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like pa...
What is your experience regarding pricing and costs for Fortify Static Code Analyzer?
I rate the pricing of Fortify Static Code Analyzer as a seven out of ten since it is a bit expensive.
What needs improvement with Fortify Static Code Analyzer?
False positives need improvement in the future. Fortify's vulnerability remediation guidance helps improve code security, but I think they need to improve the focus of the solution, as it still Con...
What do you like most about GitLab?
I find the features and version control history to be most valuable for our development workflow. These aspects provide us with a clear view of changes and help us manage requests efficiently.
What is your experience regarding pricing and costs for GitLab?
The pricing of GitLab is reasonable, aligning with what I consider to be average compared to competitors.
What needs improvement with GitLab?
There are missing search features, particularly when searching repositories or applying filters. Additionally, I have encountered issues with the deployment of CI/CD pipelines, especially dealing w...
 

Also Known As

Fortify Static Code Analysis SAST
Fuzzit
 

Overview

 

Sample Customers

Information Not Available
1. NASA  2. IBM  3. Sony  4. Alibaba  5. CERN  6. Siemens  7. Volkswagen  8. ING  9. Ticketmaster  10. SpaceX  11. Adobe  12. Intuit  13. Autodesk  14. Rakuten  15. Unity Technologies  16. Pandora  17. Electronic Arts  18. Nordstrom  19. Verizon  20. Comcast  21. Philips  22. Deutsche Telekom  23. Orange  24. Fujitsu  25. Ericsson  26. Nokia  27. General Electric  28. Cisco  29. Accenture  30. Deloitte  31. PwC  32. KPMG
Find out what your peers are saying about Veracode, Checkmarx, OpenText and others in Static Code Analysis. Updated: January 2025.
838,713 professionals have used our research since 2012.