GitLab vs Sonatype Lifecycle comparison

Cancel
You must select at least 2 products to compare!
GitLab Logo
4,165 views|3,359 comparisons
Sonatype Logo
17,108 views|9,847 comparisons
Comparison Buyer's Guide
Executive Summary
Updated on Mar 20, 2023

We performed a comparison between Gitlab and Sonatype Nexus Lifecycle based on our users’ reviews in five categories. After reading all of the collected data, you can find our conclusion below.

  • Ease of Deployment: Sonatype Nexus Lifecycle’s setup is straightforward, well-documented, and takes about three months to roll out. For GitLab, deployment is fairly easy, and the adoption process requires a focus on education.
  • Features: Nexus Lifecycle is praised for email alerts, a friendly interface, open source policies, component blockage, and security accuracy. GitLab was praised for its all-in-one platform and future roadmap.
  • Pricing: Nexus Lifecycle is pricey but provides value with transparent licensing and unlimited scans. GitLab has three editions, with the premium/ultimate edition having more features at a higher cost.
  • Service and Support: Sonatype Nexus Lifecycle offers strong tech support with expert architects, while GitLab has top-rated customer service but uncertain long-term support.
  • ROI: For Sonatype Nexus Lifecycle, it's hard to quantify the ROI, but it helped to avoid security issues and keep apps up-to-date, while for GitLab, a new adoption is expected to show an ROI within a year.

Comparison Results: Based on the parameters we compared, Sonatype Nexus Lifecycle comes out ahead of GitLab. Although both products have valuable features and can be estimated as high-end solutions, our reviewers found that GitLab’s price is higher and has uncertain long-term support.

To learn more, read our detailed GitLab vs. Sonatype Lifecycle Report (Updated: September 2023).
734,963 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"GitLab's best features are maintenance, branch integration, and development infrastructure.""The solution is stable.""I like that you can use GitLab as a double-sided solution for both DevOps and version management. It's a good product for working in these two areas, and the user interface makes it easy to understand.""The solution's most valuable feature is that it is compatible with GitHub. The product's integration capabilities are sufficient for our small company of 35 people.""The SaaS setup is impressive, and it has DAST solutioning.""GitLab is being used as a repository for our codebase and it is a one stop DevOps tool we use in our team.""For us, Gitlab's most valuable feature is the integration with Cypress. We're using Cypress as an automation tool, so we're using GitLab as a tool for running in parallel.""The most important features of GitLab for us are issue management and all the CI/CD tools. Another aspect that I love about GitLab is the UI."

More GitLab Pros →

"The integrations into developer tooling are quite nice. I have the integration for Eclipse and for Visual Studio. Colleagues are using the Javascript IDE from JetBrains called WebStorm and there is an integration for that from Nexus Lifecycle. I have not heard about anything that is not working. It's also quite easy to integrate it. You just need to set up a project or an app and then you just make the connection in all the tools you're using.""Vulnerability detection accuracy is good.""The most valuable features of the Sonatype Nexus Lifecycle are the evaluation of the unit test coverage, vulnerability scanning, duplicate code lines, code smells, and unnecessary loops.""Due to the sheer amount of vulnerabilities and the fact that my company is still working on eliminating all vulnerabilities, it's still too early for me to say what I like most about Sonatype Nexus Lifecycle. Still, one of the best functions of the product is the guidance it gives in finding which components or applications have vulnerabilities. For example, my team had a vulnerability or a CVE connected to Apache last week. My team couldn't find which applications had the vulnerability initially, but using Sonatype Nexus Lifecycle helped. My team deployed new versions on that same day and successfully eliminated the vulnerabilities, so right now, the best feature of Sonatype Nexus Lifecycle is finding which applications have vulnerabilities.""Sonatype support is quite responsive. When we needed something, we could reach out and set up a meeting. They provide the best support possible.""The most important features of the Sonatype Nexus Lifecycle are the vulnerability reports.""The IQ server and repo are the most valuable.""Lifecycle lets developers see any vulnerabilities or AGPL license issues associated with code in the early stages of development. The nice thing is that it's built into the ID so that they can see all versions of a specific code."

More Sonatype Lifecycle Pros →

Cons
"GitLab could improve by having more plugins and better user-friendliness.""We have only seen a couple of issues on Gitlab, which we use for building some of the applications.""The user interface could be more user-friendly. We do most of our operations through the website interface but it could be better.""Perhaps the integration could be better.""There is room for improvement in GitLab Agents.""GitLab can improve the integration with third-party applications. It could be made easier. Additionally, having API control from my application could be helpful.""GitLab would be improved with the addition of templates for deployment on local PCs.""GitLab's Windows version is yet not available and having this would be an improvement."

More GitLab Cons →

"The team managing Nexus Lifecycle reported that their internal libraries were not being identified, so they have asked Sonatype's technical team to include that in the upcoming version.""The solution is not an SaaS product.""Sonatype Nexus Lifecycle can improve by having a feature to automatically detect vulnerabilities. Additionally, if it could automatically push the dependencies or create notifications it would be beneficial.""It could be because I need to learn more about Sonatype Nexus Lifecycle, but as a leader, if I want to analyze the vulnerability situation and how it is and the forecast, I'd like to look at the reports and understand what the results mean. It's been challenging for me to understand the reports and dashboards on Sonatype Nexus Lifecycle, so I'll need to take a course or watch some YouTube tutorials about the product. If Sonatype Nexus Lifecycle has documentation that could help me properly analyze the vulnerability situation and what the graphs mean, then that would be helpful. I need help understanding what each graph is showing, and it seems my company is the worst, based on the chart. Still, I need clarification, so if there were some documentation, a more extensive knowledge base, or a question mark icon you could hover over that would explain what each data on the graph means, that would make Sonatype Nexus Lifecycle better.""Sonatype Nexus Lifecycle can improve the functionality. Some functionalities are missing from the UI that could be accessed using the API but they are not available. For example, seeing more than the 100 first reports or, seeing your comments when you process a waiver for a vulnerability or a violation.""The reporting could be better.""In the beginning, we sometimes struggle to access the customer environment. The customer must issue the required certificates because many customers use cell phone certificates, and Sonatype needs a valid CA certificate.""We got a lot of annotations for certain libraries when it comes to Java, but my feeling, and the feeling of a colleague as well, is that we don't get as many for critical libraries when it comes to .NET, as if most of them are really fine... It would be good if Sonatype would check the status of annotations for .NET packages."

More Sonatype Lifecycle Cons →

Pricing and Cost Advice
  • "I don't mind the price because I use the free version."
  • "We are using its free version, and we are evaluating its Premium version. Its Ultimate version is very expensive."
  • "The price of GitLab could be better, it is expensive."
  • "I'm not aware of the licensing costs because those were covered by the customer."
  • "GitLab is an open-source solution."
  • "GitLab's pricing is good compared to others on the market."
  • "In terms of the pricing for GitLab, on a scale of one to five, with one being expensive and five being cheap, I'm rating pricing for the solution a four. It could still be cheaper because right now, my company has a small team, and sometimes it's difficult to use a paid product for a small team. You'd hope the team will grow and scale, but currently, you're paying a high license fee for a small team. I'm referring to the GitLab license that has premium features and will give you all features. This can be a problem for management to approve the high price of the license for a team this small."
  • "This product is not very expensive but the price can be better."
  • More GitLab Pricing and Cost Advice →

  • "In comparison with other tools, Sonatype Nexus Lifecycle could be more expensive. Still, at the same time, my company prioritizes security, so the pricing for Sonatype Nexus Lifecycle hasn't been an issue. If IT security weren't at the top of the list for my company, somebody would have raised the question about cost and how Sonatype Nexus Lifecycle is in terms of ROI. So far, there's been no question about the price. The cost of Sonatype Nexus Lifecycle hasn't been a problem so far. My company pays for the license yearly, plus technical support."
  • More Sonatype Lifecycle Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
    734,963 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:We are using the open-source version, anyone can download it.
    Top Answer:The documentation is confusing. Sometimes, it is incomplete or has incorrect information. I have informed the vendor about it. Some features in the GitLab Community Edition are not available to us.
    Top Answer:We like the data that Sonatype Nexus Lifecycle consistently delivers. This solution helps us in fixing and understanding the issues a lot quicker. The policy engine allows you to set up different… more »
    Top Answer:The IQ server and repo are the most valuable.
    Top Answer:Their pricing is within the same range as the enterprise bundle, around $50,000 US dollars.
    Ranking
    Views
    4,165
    Comparisons
    3,359
    Reviews
    47
    Average Words per Review
    402
    Rating
    8.6
    Views
    17,108
    Comparisons
    9,847
    Reviews
    10
    Average Words per Review
    825
    Rating
    7.9
    Comparisons
    Also Known As
    Fuzzit
    Sonatype Nexus Lifecycle, Nexus Lifecycle
    Learn More
    Overview

    GitLab is a DevOps platform used for DevOps adoption, including pipeline development, automation, deployment, version control, and CI/CD. It is also used as a repository for code, issue, and configuration management. It can be deployed on-premise or in the cloud and is used by various industries. 

    The most valuable features include integration with CIE, rapid deployment, ease of use, good customer support, stability, scalability, automation, and security. GitLab has helped organizations save time by providing easy merging of code and frequent updates.

    GitLab Benefits

    Some of the ways that organizations can benefit by deploying GitLab include:

    • Easy solution configuration. GitLab does not require organizations to devote significant time and other resources to bringing it online. It can be quickly installed by a business’s IT team to any device or cloud that is most convenient for them. IT teams can install it using either GUI installer or a command line installer, depending on what is more convenient for them.
    • Source code storage and management security. Developers can use GitLab to control who is able to access the source code that they are working on and manage the security of the location where the code is being stored. Gitlab makes it so that users get to decide the privacy status of their code and storage. This keeps unauthorized individuals from gaining access to their sensitive and proprietary code.
    • DevOps feedback. GitLab gives users the ability to learn from what they are doing and improve their DevOps practices. It will assign to their DevOps pipeline scores that can enable them to see where they might be lacking and do better.

    GitLab Features

    • Secret detection customization. Users can set GitLab to scan for sensitive data that might have accidentally been stored with the source code under development. Users can set custom parameters and discover at-risk data before it can be leaked.
    • Custom notifications. This feature makes it easy for developers to keep track of the changes that are being applied to their projects. They can set GitLab so that it sends them a notification when changes are made. These notifications can be customized to meet the developer's specific needs.
    • Built-in CI/CD capabilities. Users are able to build, test, and deploy their software without turning to outside integrations. The CI/CD automation is built-in so that all of these functions can be easily automated as necessary.

    Reviews from Real Users

    GitLab is a solution that stands out when compared to many of its competitors. Two major advantages it offers are the overall completeness of the solution and the way that it enables application developers to work on various parts of a given project simultaneously.

    Kulbhushan M., co-founder and technical architect at Think NYX Technologies LLP, writes, “The SaaS setup is impressive, and it has DAST solutions. It also has dependency check and scanning mechanisms. If we were using other solutions, they would have to be configured, and we would have to set them to us as a third party, but GitLab is straightforward. GitLab is a single solution that helps us do everything we need.”

    Zeeshan R., a software engineer at OZ, writes, “The best thing is that as the developers work on separate tasks, all of the code goes there and the other team members don't have to wait on each other to finish. We can all work on our code in tandem.”

    Sonatype Lifecycle is an open-source security and dependency management software that uses only one tool to automatically find open-source vulnerabilities at every stage of the System Development Life Cycle (SDLC). Users can now minimize security vulnerabilities, permitting organizations to enhance development workflow. Sonatype Lifecycle gives the user complete control over their software supply chain, allowing them to regain wasted time fighting risks in the SDLC. In addition, this software unifies the ability to define rules, actions, and policies that work best for your organizations and teams.

    Sonatype Lifecycle allows users to help their teams discover threats before an attack has the chance to take place by examining a database of known vulnerabilities. With continuous monitoring at every stage of the development life cycle, Sonatype Lifecycle enables teams to build secure software. The solution allows users to utilize a complete automated solution within their existing workflows. Once a potential threat is identified, the solution’s policies will automatically rectify it.

    Benefits of Open-source Security Monitoring

    As cybersecurity attacks are on the rise, organizations are at constant risk for data breaches. Managing your software supply chain gets trickier as your organization grows, leaving many vulnerabilities exposed. With easily accessible source code that can be modified and shared freely, open-source monitoring gives users complete transparency. A community of professionals can inspect open-source code to ensure fewer bugs, and any open-source dependency vulnerability will be detected and fixed rapidly. Users can use open-source security monitoring to avoid attacks through automatic detection of potential threats and rectification immediately and automatically.

    Reviews from Real Users

    Sonatype Lifecycle software receives high praise from users for many reasons. Among them are the abilities to identify and rectify vulnerabilities at every stage of the SDLC, help with open-source governance, and minimize risk.

    Michael E., senior enterprise architect at MIB Group, says "Some of the more profound features include the REST APIs. We tend to make use of those a lot. They also have a plugin for our CI/CD.”

    R.S., senior architect at a insurance company, notes “Specifically features that have been good include:

    • the email notifications
    • the API, which has been good to work with for reporting, because we have some downstream reporting requirements
    • that it's been really user-friendly to work with.”

    "Its engine itself is most valuable in terms of the way it calculates and decides whether a security vulnerability exists or not. That's the most important thing. Its security is also pretty good, and its listing about the severities is also good," says Subham S., engineering tools and platform manager at BT - British Telecom.

    Offer
    Learn more about GitLab
    Learn more about Sonatype Lifecycle
    Sample Customers
    Siemens, University of Washington, Equinix, Paessler AG, CNCF, Ticketmaster, CERN, Vaadin
    Genome.One, Blackboard, Crediterform, Crosskey, Intuit, Progress Software, Qualys, Liberty Mutual Insurance
    Top Industries
    REVIEWERS
    Financial Services Firm18%
    Computer Software Company18%
    Manufacturing Company14%
    Retailer11%
    VISITORS READING REVIEWS
    Educational Organization27%
    Computer Software Company12%
    Financial Services Firm10%
    Manufacturing Company7%
    REVIEWERS
    Financial Services Firm28%
    Computer Software Company14%
    Insurance Company14%
    Manufacturing Company10%
    VISITORS READING REVIEWS
    Financial Services Firm32%
    Computer Software Company13%
    Government9%
    Insurance Company6%
    Company Size
    REVIEWERS
    Small Business45%
    Midsize Enterprise8%
    Large Enterprise48%
    VISITORS READING REVIEWS
    Small Business15%
    Midsize Enterprise34%
    Large Enterprise51%
    REVIEWERS
    Small Business26%
    Midsize Enterprise18%
    Large Enterprise55%
    VISITORS READING REVIEWS
    Small Business15%
    Midsize Enterprise9%
    Large Enterprise76%
    Buyer's Guide
    GitLab vs. Sonatype Lifecycle
    September 2023
    Find out what your peers are saying about GitLab vs. Sonatype Lifecycle and other solutions. Updated: September 2023.
    734,963 professionals have used our research since 2012.

    GitLab is ranked 6th in Application Security Tools with 50 reviews while Sonatype Lifecycle is ranked 7th in Application Security Tools with 8 reviews. GitLab is rated 8.6, while Sonatype Lifecycle is rated 7.8. The top reviewer of GitLab writes "Powerful, mature, and easy to set up and manage". On the other hand, the top reviewer of Sonatype Lifecycle writes "Automated process for downloading open source libraries has significantly decreased developer workload". GitLab is most compared with Microsoft Azure DevOps, Bamboo, AWS CodePipeline, TeamCity and Fortify Static Code Analyzer, whereas Sonatype Lifecycle is most compared with SonarQube, Black Duck, Fortify Static Code Analyzer, Checkmarx and Snyk. See our GitLab vs. Sonatype Lifecycle report.

    See our list of best Application Security Tools vendors and best Software Composition Analysis (SCA) vendors.

    We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.