

Black Duck SCA and GitLab compete in software composition analysis, with GitLab offering a comprehensive suite of DevOps features, while Black Duck SCA provides specialized vulnerability detection and compliance tracking. GitLab is often seen as superior in providing integrated development tools, while Black Duck SCA is notable for its security-centered focus.
Features: Black Duck SCA includes advanced vulnerability detection, robust open-source compliance management, and detailed risk analysis. GitLab provides features like CI/CD pipelines, integrated version control, and comprehensive project management tools. Black Duck’s main strength is its pinpoint security analysis, while GitLab is recognized for its all-encompassing development toolset.
Room for Improvement: Black Duck SCA could enhance its user interface and ease of use, provide more intuitive automation for repeated tasks, and offer improved integration with other DevOps tools. GitLab might work on strengthening its security scanning capabilities, offer more customization in project management, and further optimize its existing features for high-scale enterprises.
Ease of Deployment and Customer Service: Black Duck SCA requires a sophisticated setup process, with specialized, in-depth support available for successful deployment. GitLab offers a more straightforward cloud-based or on-premises deployment process, complemented by extensive documentation and active community support, which simplifies the initial setup phase.
Pricing and ROI: Black Duck SCA has a higher initial setup cost but provides a high ROI for organizations with stringent security requirements. GitLab offers flexible pricing models, delivering broad value, especially appealing to teams seeking a single platform for their DevOps needs.
If you're using it on critical external programs where there is regulatory compliance on ensuring that the source code is clean from open-source, there's substantial ROI.
Migrating to GitLab is bringing time-saving benefits, and everything is easier to automate.
We have saved time significantly, reducing deployment time from four hours to five minutes per deployment.
In terms of operational efficiency, a ten to twenty percent increase in speed could quite easily be seen from using the Issues and Epics tracking feature.
There are some pain points with the response time and first-level support quality.
We have rarely needed to escalate issues to technical support since GitLab usually runs seamlessly.
I have interacted with architects for some advice during the implementation, and they were prompt in their response.
I have had meetings where they taught me, explained things, and provided guidance for starting from scratch.
I would rate the scalability of Black Duck 8 or 9.
It has all the features required for our coding and deployment needs, which makes it scalable to our changing requirements.
We're transitioning to OpenShift for future scalability with increased user numbers.
For scaling, other deployment options from GitLab's side need to be adopted.
I have not encountered any performance or stability issues with GitLab so far.
The updates are frequent and demanding, happening at least once a week due to security reasons.
We raised a request with GitLab support, but they were unable to help because they could not find the root cause of what went wrong.
It can improve on the security side of it, specifically vulnerabilities identification.
The documentation is not really on the mark.
There are areas for improvement such as false positives and the scanning of containers.
It would be beneficial to have a user-friendly interface for setting up these configurations, instead of just writing YAML files.
It is essential to conduct proper testing, such as unit tests and code coverage, within the SDLC pipelines.
GitLab can improve its user interface to make conflict resolution more user-friendly.
Even when working in other small organizations, we opted for GitLab as it was cost-efficient.
The pricing of GitLab is reasonable, aligning with what I consider to be average compared to competitors.
The price is high, and it limits user accessibility.
The most valuable feature of Black Duck is the composition analysis feature, which is effective for security risk management.
Black Duck's ability to identify dependencies very accurately has been most valuable in identifying and mitigating risks.
If that component has a vulnerability from any of the sources, it should be considered and shown regardless of whether it is vulnerable from different sources.
As we implement automated testing and DevSecOps, it speeds up the process by forty to sixty percent.
The Ultimate version offers enhanced features for security scanning through DAST and SAST analysis, which have greatly benefitted our project workflow.
By integrating GitLab as a DevOps platform, we have enhanced agility, improved our time to market, and different teams can work collaboratively on various projects.
| Product | Mindshare (%) |
|---|---|
| Black Duck SCA | 11.7% |
| GitLab | 3.7% |
| Other | 84.6% |

| Company Size | Count |
|---|---|
| Small Business | 6 |
| Large Enterprise | 17 |
| Company Size | Count |
|---|---|
| Small Business | 36 |
| Midsize Enterprise | 10 |
| Large Enterprise | 46 |
Black Duck is an essential tool for software composition analysis and license compliance. It identifies vulnerabilities effectively and supports security management in DevOps environments, offering integration, performance stability, and community support.
Organizations rely on Black Duck for seamless integration in CI/CD pipelines, thorough scanning of source and binary codes, and management of operational risks associated with open-source and commercial licenses. It plays a crucial role in security risk management and delivers a robust policy management framework. Users value its ease of use and reliable community support while benefiting from its comprehensive dependency visualization capabilities. Despite its strengths, there is room for enhancement in integration with other tools, UI friendliness, and reporting features.
What are Black Duck's key features?
What should users look for in ROI?
Enterprise environments use Black Duck extensively for security, compliance, and risk management, ensuring software meets regulatory standards and mitigates vulnerabilities. Its implementation in specific industries aids in controlled and secure software development processes, underlining its role in maintaining rigorous security standards while delivering dependable performance.
GitLab offers a secure and user-friendly platform for CI/CD pipeline management, code repository control, and collaboration, enhancing development speed and efficiency. It facilitates automation with extensive customization and tool integration, ideal for DevOps processes.
GitLab supports source code management, version control, and collaborative development. It's frequently used in CI/CD processes to automate builds and deployments while integrating DevOps practices. GitLab allows companies to manage repositories, automate pipelines, conduct code reviews, and maintain development lifecycles. The platform supports infrastructure and configuration management, enabling efficient code collaboration, deployment automation, and comprehensive repository handling. Many organizations commit and deploy developed code using GitLab's capabilities.
What are GitLab's most valuable features?In specific industries, GitLab serves as a backbone for source code management and CI/CD implementation. Companies leverage its capabilities for infrastructure management and deployment automation, thus streamlining project delivery timelines. Its ability to handle configuration management and code repositories effectively aids in maintaining development lifecycles, making it a preferred choice for organizations committed to enhancing their DevOps practices.
We monitor all Software Composition Analysis (SCA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.