Try our new research platform with insights from 80,000+ expert users
Sonatype Lifecycle Logo

Sonatype Lifecycle Reviews

Vendor: Sonatype
4.2 out of 5

What is Sonatype Lifecycle?

Featured Sonatype Lifecycle reviews

Sonatype Lifecycle mindshare

As of December 2025, the mindshare of Sonatype Lifecycle in the Software Composition Analysis (SCA) category stands at 4.9%, down from 5.3% compared to the previous year, according to calculations based on PeerSpot user engagement data.
Software Composition Analysis (SCA) Market Share Distribution
ProductMarket Share (%)
Sonatype Lifecycle4.9%
Black Duck SCA13.5%
Snyk11.5%
Other70.1%
Software Composition Analysis (SCA)

PeerResearch reports based on Sonatype Lifecycle reviews

TypeTitleDate
CategorySoftware Composition Analysis (SCA)Dec 30, 2025Download
ProductReviews, tips, and advice from real usersDec 30, 2025Download
ComparisonSonatype Lifecycle vs SnykDec 30, 2025Download
ComparisonSonatype Lifecycle vs Black Duck SCADec 30, 2025Download
ComparisonSonatype Lifecycle vs VeracodeDec 30, 2025Download
Suggested products
TitleRatingMindshareRecommending
SonarQube4.0N/A83%134 interviewsAdd to research
Snyk4.111.5%100%50 interviewsAdd to research
 
 
Key learnings from peers
Last updated Dec 14, 2025

Valuable Features

Room for Improvement

ROI

Pricing

Popular Use Cases

Service and Support

Deployment

Scalability

Stability

Review data by company size

By reviewers
Company SizeCount
Small Business11
Midsize Enterprise7
Large Enterprise22
By reviewers
By visitors reading reviews
Company SizeCount
Small Business262
Midsize Enterprise108
Large Enterprise796
By visitors reading reviews

Top industries

By visitors reading reviews
Financial Services Firm
28%
Computer Software Company
10%
Manufacturing Company
9%
Government
7%
Insurance Company
5%
Healthcare Company
3%
Comms Service Provider
3%
Performing Arts
3%
University
3%
Outsourcing Company
3%
Construction Company
2%
Educational Organization
2%
Energy/Utilities Company
2%
Retailer
2%
Media Company
2%
Non Profit
2%
Legal Firm
2%
Transportation Company
2%
Real Estate/Law Firm
2%
Wholesaler/Distributor
1%
Marketing Services Firm
1%
Aerospace/Defense Firm
1%
Hospitality Company
1%
Logistics Company
1%
Recreational Facilities/Services Company
1%
Leisure / Travel Company
1%
Consumer Goods Company
1%
Engineering Company
1%

Compare Sonatype Lifecycle with alternative products

Learn more about Sonatype Lifecycle

Sonatype Lifecycle customers

Related questions

 
Sonatype Lifecycle Reviews Summary
Author infoRatingReview Summary
Presales Engineer at Rah Infotech Pvt Ltd4.5I've used Sonatype Lifecycle mainly for open-source scanning; it's easy to integrate, ensures compliance, and saves time, though improvements in documentation, support, and integration visibility would enhance the overall user experience.
Analista De Sistemas at Dataprev4.5We use Sonatype Lifecycle mainly for managing software artifacts, valuing its vulnerability identification. Despite its stability, we wish for separate offerings of binary management and software analysis to reduce costs. Improved configuration guidance would be beneficial.
Principal DevSecOPs at a computer software company with 10,001+ employees3.5We use Sonatype Lifecycle to scan third-party packages in our software composition, ensuring a secure software supply chain. Its integration into our CICD pipeline is beneficial, though we hope for expanded features, particularly in application security.
Integration Manager at CommScope4.0I work in a service-based company utilizing Sonatype Lifecycle for firewall management and code quality insight. It integrates well with tools like GitLab. While it's valuable, I'd like more frequent updates, especially for cloud-based capabilities and security enhancements.
Vice President, Cybersecurity at a financial services firm with 10,001+ employees5.0We manage software security for 10,000 developers using Fortify for vulnerability detection. The Software Security Center centralizes results, but needs a design update. Despite this, Fortify offers significant ROI, broad language support, and valuable Secure Code Warrior integration.
Sr cyber analyst at a energy/utilities company with 10,001+ employees4.0We use Fortify and Sonatype for secure code and library scanning. While their integration and language support are valuable, Fortify's configuration is complex. It's costly and better suited for enterprises. Identifying vulnerabilities early saves costs during the SDLC.
Sr cyber analyst at a energy/utilities company with 10,001+ employees3.5We use Sonatype Nexus and Fortify to secure our code, appreciating Fortify’s integration capabilities and language support, despite its cost and complex configuration. Transitioning from IBM Appscan, identifying vulnerabilities early helps us save costs in the development process.
Senior manager at a consultancy with 11-50 employees5.0As consultants supporting a primary banking group in Italy, we rely on Sonatype and Fortify for comprehensive code analysis. Fortify excels in reducing vulnerabilities and aligning with compliance requirements, although it could expand language support.