

HCL AppScan and GitLab are two prominent products competing in the software development and security domain. While HCL AppScan stands out for its robust security focus, particularly in detecting vulnerabilities, GitLab excels with its CI/CD pipeline capabilities, making it a popular choice for streamlining DevOps workflows.
Features: HCL AppScan is notable for its strong security emphasis, especially in identifying vulnerabilities such as XSS and SQL injection. It offers comprehensive language support and integrates well with the SDLC, offering valuable security measures during development. GitLab is preferred for its superior CI/CD pipeline features, automating deployment processes and aiding in source code management. It provides a seamless interface for DevOps and offers built-in tools for continuous integration.
Room for Improvement: HCL AppScan users have reported issues like false positives and difficulties with CI/CD integration, alongside some outdated UI components. GitLab could improve its AWS integration and refine its user interface. Additionally, it would benefit from enhanced security features and more user-friendly documentation. Both solutions encounter integration challenges; however, HCL AppScan is more focused on usability, while GitLab's issues relate to cloud services.
Ease of Deployment and Customer Service: HCL AppScan supports on-premises and hybrid cloud deployments but receives mixed reviews regarding customer support, with regional variations in service quality. GitLab offers a flexible deployment model across public, private, and hybrid clouds. Its customer service is generally viewed positively, with more consistent feedback compared to HCL AppScan.
Pricing and ROI: HCL AppScan is considered expensive, with users highlighting its cost-efficiency benefits, particularly in reducing vulnerabilities. It's noted for offering a strong ROI by cutting costs and enhancing security for some users. GitLab presents a combination of free and paid plans, with Premium and Ultimate versions that offer additional features at higher prices. Despite being seen as costly for smaller teams, its pricing is deemed reasonable given the rich feature set.
Migrating to GitLab is bringing time-saving benefits, and everything is easier to automate.
We have saved time significantly, reducing deployment time from four hours to five minutes per deployment.
In terms of operational efficiency, a ten to twenty percent increase in speed could quite easily be seen from using the Issues and Epics tracking feature.
We have rarely needed to escalate issues to technical support since GitLab usually runs seamlessly.
I have interacted with architects for some advice during the implementation, and they were prompt in their response.
I have had meetings where they taught me, explained things, and provided guidance for starting from scratch.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
There is still room for improvement when it comes to the speed of response.
It has all the features required for our coding and deployment needs, which makes it scalable to our changing requirements.
We're transitioning to OpenShift for future scalability with increased user numbers.
For scaling, other deployment options from GitLab's side need to be adopted.
I have not encountered any performance or stability issues with GitLab so far.
The updates are frequent and demanding, happening at least once a week due to security reasons.
We raised a request with GitLab support, but they were unable to help because they could not find the root cause of what went wrong.
Since we've been using HCL AppScan for about three months, we really have not encountered a false positive.
It would be beneficial to have a user-friendly interface for setting up these configurations, instead of just writing YAML files.
It is essential to conduct proper testing, such as unit tests and code coverage, within the SDLC pipelines.
GitLab can improve its user interface to make conflict resolution more user-friendly.
If I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present.
Even when working in other small organizations, we opted for GitLab as it was cost-efficient.
The pricing of GitLab is reasonable, aligning with what I consider to be average compared to competitors.
The price is high, and it limits user accessibility.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
As we implement automated testing and DevSecOps, it speeds up the process by forty to sixty percent.
The Ultimate version offers enhanced features for security scanning through DAST and SAST analysis, which have greatly benefitted our project workflow.
By integrating GitLab as a DevOps platform, we have enhanced agility, improved our time to market, and different teams can work collaboratively on various projects.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
I have utilized its interactive application security testing, as well as both static application security testing, dynamic application security testing, and IAST.
| Product | Mindshare (%) |
|---|---|
| GitLab | 2.0% |
| HCL AppScan | 2.3% |
| Other | 95.7% |


| Company Size | Count |
|---|---|
| Small Business | 38 |
| Midsize Enterprise | 10 |
| Large Enterprise | 49 |
| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 6 |
| Large Enterprise | 31 |
GitLab offers a secure and user-friendly platform for CI/CD pipeline management, code repository control, and collaboration, enhancing development speed and efficiency. It facilitates automation with extensive customization and tool integration, ideal for DevOps processes.
GitLab supports source code management, version control, and collaborative development. It's frequently used in CI/CD processes to automate builds and deployments while integrating DevOps practices. GitLab allows companies to manage repositories, automate pipelines, conduct code reviews, and maintain development lifecycles. The platform supports infrastructure and configuration management, enabling efficient code collaboration, deployment automation, and comprehensive repository handling. Many organizations commit and deploy developed code using GitLab's capabilities.
What are GitLab's most valuable features?In specific industries, GitLab serves as a backbone for source code management and CI/CD implementation. Companies leverage its capabilities for infrastructure management and deployment automation, thus streamlining project delivery timelines. Its ability to handle configuration management and code repositories effectively aids in maintaining development lifecycles, making it a preferred choice for organizations committed to enhancing their DevOps practices.
HCL AppScan offers quick vulnerability detection with effective SDLC integration and is known for its user-friendly interface and seamless security integration.
HCL AppScan provides dynamic and static scanning to identify vulnerabilities like XSS and SQL injection. It integrates well into CI/CD pipelines, supports multiple languages, and offers web and dynamic scanning, helping businesses ensure security across development lifecycles. Users benefit from API coverage, Postman integration, and its ability to function in cloud and on-premise environments, facilitating a shift from DevOps to DevSecOps practices.
What features define HCL AppScan?HCL AppScan is leveraged in sectors requiring rigorous security checks, such as finance and healthcare, where it conducts comprehensive scans and offers insights into potential vulnerabilities. Its robust scanning capabilities aid companies in maintaining compliance and security standards.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.