

HCL AppScan and GitHub compete in the software development tools category. HCL AppScan holds the upper hand in security features, whereas GitHub excels in collaboration and development tools.
Features: HCL AppScan provides robust vulnerability detection, integration with the SDLC, and AI-powered enhancements. It offers both static and dynamic testing capabilities. GitHub is well-known for its collaboration and version control features. It integrates with various tools, supports CI/CD pipelines, and provides a reliable platform for source code management.
Room for Improvement: HCL AppScan needs to address high false positives, centralize management for static and dynamic scans, and offer better tool integration. It could also expand language coverage and container support. GitHub could improve project management features, enhance conflict resolution in merges, and provide a more user-friendly interface along with stronger security features.
Ease of Deployment and Customer Service: HCL AppScan provides flexible deployment options across on-premises and cloud environments but can struggle with technical support speed, particularly regional resources. GitHub's cloud-based deployment is easy to integrate and highly regarded for its straightforward setup and positive customer service, though it could enhance support features.
Pricing and ROI: HCL AppScan has a higher cost but offers valuable security features that justify the investment, according to users, with a notable ROI. GitHub is more cost-effective, offering many features for free, making it accessible to a broader audience. Its paid plans are affordable, especially for small to medium enterprises, thanks to its open-source nature.
Using GitHub reduces, on average, one to two hours of time daily for making things ready, so it has very good metrics.
The technical support from GitHub is generally good, and they communicate effectively.
Some forums help you get answers faster since you just type in your concern and see resolutions from other engineers.
I have not used GitHub's technical support extensively because there are many resources and a robust knowledge base available due to the large user community.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
There is still room for improvement when it comes to the speed of response.
We have never had a problem with scalability, so I would rate it at least eight to nine.
GitHub is more scalable than on-prem solutions, allowing for cloud-based scaling which is beneficial for processing large workloads efficiently.
I can easily give updates from VS Code and commit messages directly to the GitHub repository by just using Git commands.
If a skilled developer uses it, it is ten out of ten for stability.
It provides a reliable environment for code management.
GitHub is mostly stable, but there can be occasional hiccups.
Since we've been using HCL AppScan for about three months, we really have not encountered a false positive.
When working with the CI/CD pipeline and somebody is writing the workflow file, it would be best to include the AI feature so if they write incorrect code, it will notify me about it in the same dashboard, eliminating the need to use third-party tools to review the file.
I am providing this feedback for Copilot because it seems more widespread and more companies allow it rather than Amp, and it would be beneficial if they catch up with Amp on this capability.
Security could make GitHub better. OWASP Top Ten security advisors could be integrated on GitHub, and it could provide checks and advice.
If I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present.
I have not encountered any initial setup cost for that.
Normally, GitHub is not expensive, but it would be welcome if it reduces costs for developing countries.
The pricing of GitHub is reasonable, with the cost being around seven dollars per user per month for private repositories.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
The pull request facility for code review.
GitHub Actions allow for creating multiple jobs that run in different stages such as build, test, and deploy, which enable better visibility and control over the deployment pipeline.
For branching, it works well, especially in an agile environment.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
I have utilized its interactive application security testing, as well as both static application security testing, dynamic application security testing, and IAST.
| Product | Mindshare (%) |
|---|---|
| GitHub | 2.7% |
| HCL AppScan | 2.3% |
| Other | 95.0% |


| Company Size | Count |
|---|---|
| Small Business | 43 |
| Midsize Enterprise | 14 |
| Large Enterprise | 55 |
| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 6 |
| Large Enterprise | 31 |
GitHub is a platform that enhances collaboration and version control among developers, utilizing robust integration tools and features suitable for distributed teams. Its capabilities cater to diverse coding and project workflows, supporting effective team contributions and project deployments.
GitHub efficiently manages code repositories, facilitating seamless collaboration in distributed environments. It incorporates features beneficial for continuous integration and continuous deployment with tools like Jenkins and GitHub Actions. Recognized for its code-sharing, security, and branch management capabilities, GitHub serves as a versatile development hub. However, there's room for enhancement in project management, testing, and AI integration, with users expressing a need for better documentation, reporting, and enhanced user experience through improved automation and interface simplification.
What features make GitHub essential?GitHub is implemented widely in software development industries, supporting teams that require centralized platforms for code management. It is crucial for maintaining code integrity and facilitating developer communication. Industries rely on it for integrating tools essential for their CI/CD pipelines, accelerating project timelines, and organizing development tasks through collaborative workflows.
HCL AppScan offers quick vulnerability detection with effective SDLC integration and is known for its user-friendly interface and seamless security integration.
HCL AppScan provides dynamic and static scanning to identify vulnerabilities like XSS and SQL injection. It integrates well into CI/CD pipelines, supports multiple languages, and offers web and dynamic scanning, helping businesses ensure security across development lifecycles. Users benefit from API coverage, Postman integration, and its ability to function in cloud and on-premise environments, facilitating a shift from DevOps to DevSecOps practices.
What features define HCL AppScan?HCL AppScan is leveraged in sectors requiring rigorous security checks, such as finance and healthcare, where it conducts comprehensive scans and offers insights into potential vulnerabilities. Its robust scanning capabilities aid companies in maintaining compliance and security standards.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.