No more typing reviews! Try our Samantha, our new voice AI agent.
Sonatype Lifecycle Logo

Sonatype Lifecycle Reviews

Vendor: Sonatype
4.2 out of 5

What is Sonatype Lifecycle?

Featured Sonatype Lifecycle reviews

Sonatype Lifecycle mindshare

As of June 2026, the mindshare of Sonatype Lifecycle in the Software Composition Analysis (SCA) category stands at 4.1%, down from 5.3% compared to the previous year, according to calculations based on PeerSpot user engagement data.
Software Composition Analysis (SCA) Mindshare Distribution
ProductMindshare (%)
Sonatype Lifecycle4.1%
Snyk11.1%
Black Duck SCA9.2%
Other75.6%
Software Composition Analysis (SCA)

PeerResearch reports based on Sonatype Lifecycle reviews

TypeTitleDate
CategorySoftware Composition Analysis (SCA)Jun 23, 2026Download
ProductReviews, tips, and advice from real usersJun 23, 2026Download
ComparisonSonatype Lifecycle vs SnykJun 23, 2026Download
ComparisonSonatype Lifecycle vs VeracodeJun 23, 2026Download
ComparisonSonatype Lifecycle vs Black Duck SCAJun 23, 2026Download
Suggested products
TitleRatingMindshareRecommending
SonarQube4.0N/A84%135 interviewsAdd to research
Snyk4.111.1%100%51 interviewsAdd to research
 
 
Key learnings from peers
Last updated May 24, 2026

Valuable Features

Room for Improvement

ROI

Pricing

Popular Use Cases

Service and Support

Deployment

Scalability

Stability

Review data by company size

By reviewers
Company SizeCount
Small Business11
Midsize Enterprise7
Large Enterprise24
By reviewers
By visitors reading reviews
Company SizeCount
Small Business310
Midsize Enterprise117
Large Enterprise542
By visitors reading reviews

Top industries

By visitors reading reviews
Financial Services Firm
22%
Manufacturing Company
11%
Computer Software Company
8%
Government
6%
Construction Company
6%
Outsourcing Company
5%
Comms Service Provider
5%
Insurance Company
4%
Healthcare Company
4%
Performing Arts
3%
University
3%
Media Company
3%
Marketing Services Firm
2%
Energy/Utilities Company
2%
Retailer
2%
Educational Organization
2%
Transportation Company
2%
Non Profit
2%
Legal Firm
2%
Wholesaler/Distributor
2%
Real Estate/Law Firm
1%
Logistics Company
1%
Recreational Facilities/Services Company
1%
Hospitality Company
1%
Aerospace/Defense Firm
1%
Consumer Goods Company
1%
Pharma/Biotech Company
1%
Leisure / Travel Company
1%

Compare Sonatype Lifecycle with alternative products

Learn more about Sonatype Lifecycle

Sonatype Lifecycle customers

Related questions

 
Sonatype Lifecycle Reviews Summary
Author infoRatingReview Summary
Presales Engineer at Rah Infotech Pvt Ltd4.5I've used Sonatype Lifecycle mainly for open-source scanning; it's easy to integrate, ensures compliance, and saves time, though improvements in documentation, support, and integration visibility would enhance the overall user experience.
Security Consultant at Deloitte4.0I use Sonatype Lifecycle for early SAST/SCA, significantly improving DevSecOps by integrating security left and reducing vulnerabilities. While stable and scalable, it needs better alert prioritization and reporting customization. Overall, it saves me 40% time and effort.
Analista De Sistemas at Dataprev4.5We use Sonatype Lifecycle mainly for managing software artifacts, valuing its vulnerability identification. Despite its stability, we wish for separate offerings of binary management and software analysis to reduce costs. Improved configuration guidance would be beneficial.
Integration Manager at CommScope4.0I work in a service-based company utilizing Sonatype Lifecycle for firewall management and code quality insight. It integrates well with tools like GitLab. While it's valuable, I'd like more frequent updates, especially for cloud-based capabilities and security enhancements.
Principal DevSecOPs at a computer software company with 10,001+ employees3.5We use Sonatype Lifecycle to scan third-party packages in our software composition, ensuring a secure software supply chain. Its integration into our CICD pipeline is beneficial, though we hope for expanded features, particularly in application security.
Sr cyber analyst at a energy/utilities company with 10,001+ employees4.0We use Fortify and Sonatype for secure code and library scanning. While their integration and language support are valuable, Fortify's configuration is complex. It's costly and better suited for enterprises. Identifying vulnerabilities early saves costs during the SDLC.
Sr cyber analyst at a energy/utilities company with 10,001+ employees3.5We use Sonatype Nexus and Fortify to secure our code, appreciating Fortify’s integration capabilities and language support, despite its cost and complex configuration. Transitioning from IBM Appscan, identifying vulnerabilities early helps us save costs in the development process.
DevOps engineer at a tech vendor with 10,001+ employees4.0We use Sonatype Container for uploading and managing our builds, finding it reliable with a clear UI. It's efficient in cleanup and artifact management. However, it could improve on handling larger files and simplifying RBAC controls.
Vice President, Cybersecurity at a financial services firm with 10,001+ employees5.0We manage software security for 10,000 developers using Fortify for vulnerability detection. The Software Security Center centralizes results, but needs a design update. Despite this, Fortify offers significant ROI, broad language support, and valuable Secure Code Warrior integration.
Adjunct at University of Maryland5.0I use Sonatype Lifecycle as a SaaS tool to identify and fix vulnerabilities in static code. Its management view and Software Security Center are valuable, helping track and resolve issues efficiently. Combining it with Fortify improves application security and compliance.
@RahulVerma  - PeerSpot reviewer
@RahulVerma
Presales Engineer at Rah Infotech Pvt Ltd
Dec 10, 2025
Compliance used to slow us down. Sonatype Lifecycle turned it into an automated, streamlined step that accelerates delivery instead of blocking it.
SangramGupta - PeerSpot reviewer
SangramGupta
Security Consultant at Deloitte
May 19, 2026
Integrated DevSecOps has enabled earlier risk detection and reduced remediation effort
CL
Carlos Leão
Analista De Sistemas at Dataprev
Mar 24, 2025
Utilize a reliable BRM tool to manage software artifacts efficiently with outstanding vulnerability identification capabilities
SrinathKuppannan2 - PeerSpot reviewer
SrinathKuppannan2
Integration Manager at CommScope
Jun 26, 2024
Easily identifies problematic versions and ensures adherence to regulatory standards like HIPAA, critical for industries dealing with sensitive information
GK
Goutham Kumar
Principal DevSecOPs at a computer software company with 10,001+ employees
Dec 24, 2024
Provides comprehensive dependency oversight with room for expanded security capabilities
AA
Amal Alshehri
Sr cyber analyst at a energy/utilities company with 10,001+ employees
Dec 29, 2023
Integrates easily with many IDEs, and enables development and security teams to work together
AA
Amal Alshehri
Sr cyber analyst at a energy/utilities company with 10,001+ employees
Oct 26, 2023
Integrates easily with many IDEs, and enables development and security teams to work together
AJ
AbhilashJain
DevOps engineer at a tech vendor with 10,001+ employees
Apr 24, 2025
Consistently manages artifacts with clear UI and effective cleanup
reviewer2317233 - PeerSpot reviewer
reviewer2317233
Vice President, Cybersecurity at a financial services firm with 10,001+ employees
Dec 29, 2023
Seamless to integrate and identify vulnerabilities and frees up staff time
JB
Jumani Blango
Adjunct at University of Maryland
Dec 29, 2023
Good visibility, helps reveal vulnerabilities, and helps remediate issues