HCL AppScan and GitLab operate in the software security and development space. GitLab appears to have the upper hand with its comprehensive feature set and ease of integration, enhancing user experience in development functions.
Features: HCL AppScan offers advanced security testing tools, thorough vulnerability assessments, and support for various technologies. GitLab features a DevOps platform, seamless CI/CD pipeline integration, and collaborative tools, providing broader development support beyond security testing.
Room for Improvement: HCL AppScan users note the need for better report customization, integration flexibility, and interoperability. GitLab users highlight occasional performance issues, enhanced documentation, and product efficiency improvement.
Ease of Deployment and Customer Service: HCL AppScan deployment is complex due to its extensive security capabilities, but it has strong customer service. GitLab offers straightforward deployment within its integrated ecosystem, with users reporting satisfactory customer service.
Pricing and ROI: HCL AppScan incurs higher setup costs, with users recognizing security-related returns. GitLab's flexible pricing model is seen as providing strong ROI through its comprehensive features supporting complete development workflows.
We have saved time significantly, reducing deployment time from four hours to five minutes per deployment.
Migrating to GitLab is bringing time-saving benefits, and everything is easier to automate.
I have interacted with architects for some advice during the implementation, and they were prompt in their response.
I have had meetings where they taught me, explained things, and provided guidance for starting from scratch.
We have rarely needed to escalate issues to technical support since GitLab usually runs seamlessly.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
It has all the features required for our coding and deployment needs, which makes it scalable to our changing requirements.
For scaling, other deployment options from GitLab's side need to be adopted.
In terms of scalability, GitLab in the cloud is easy to scale.
The updates are frequent and demanding, happening at least once a week due to security reasons.
I have not encountered any performance or stability issues with GitLab so far.
It is essential to conduct proper testing, such as unit tests and code coverage, within the SDLC pipelines.
It would be beneficial to have a user-friendly interface for setting up these configurations, instead of just writing YAML files.
Improvements are needed for stability, as the system tends to degrade over a few days and often requires a restart.
The pricing of GitLab is reasonable, aligning with what I consider to be average compared to competitors.
The price is high, and it limits user accessibility.
The pricing and cost are on par with other tools and are neither too expensive nor cheap.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
As we implement automated testing and DevSecOps, it speeds up the process by forty to sixty percent.
The Ultimate version offers enhanced features for security scanning through DAST and SAST analysis, which have greatly benefitted our project workflow.
By integrating GitLab as a DevOps platform, we have enhanced agility, improved our time to market, and different teams can work collaboratively on various projects.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
GitLab is a complete DevOps platform that enables teams to collaborate and deliver software faster.
It provides a single application for the entire DevOps lifecycle, from planning and development to testing, deployment, and monitoring.
With GitLab, teams can streamline their workflows, automate processes, and improve productivity.
IBM Security AppScan enhances web application security and mobile application security, improves application security program management and strengthens regulatory compliance. By scanning your web and mobile applications prior to deployment, AppScan enables you to identify security vulnerabilities and generate reports and fix recommendations.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.