Try our new research platform with insights from 80,000+ expert users
Sonatype Lifecycle Logo

Sonatype Lifecycle Reviews

Vendor: Sonatype
4.2 out of 5
Badge Ranked 1
339 followers
Start review

What is Sonatype Lifecycle?

Featured Sonatype Lifecycle reviews

Sonatype Lifecycle mindshare

As of May 2025, the mindshare of Sonatype Lifecycle in the Software Composition Analysis (SCA) category stands at 5.2%, down from 6.1% compared to the previous year, according to calculations based on PeerSpot user engagement data.
Software Composition Analysis (SCA)

PeerResearch reports based on Sonatype Lifecycle reviews

TypeTitleDate
CategorySoftware Composition Analysis (SCA)May 31, 2025Download
ProductReviews, tips, and advice from real usersMay 31, 2025Download
ComparisonSonatype Lifecycle vs Black DuckMay 31, 2025Download
ComparisonSonatype Lifecycle vs VeracodeMay 31, 2025Download
ComparisonSonatype Lifecycle vs SnykMay 31, 2025Download
Suggested products
TitleRatingMindshareRecommending
SonarQube Server (formerly SonarQube)4.0N/A81%116 interviewsAdd to research
GitLab4.34.4%97%84 interviewsAdd to research
 
 
Key learnings from peers

Valuable Features

Room for Improvement

ROI

Pricing

Popular Use Cases

Service and Support

Deployment

Scalability

Stability

Review data by company size

By reviewers
By visitors reading reviews

Top industries

By visitors reading reviews
Financial Services Firm
33%
Computer Software Company
12%
Manufacturing Company
9%
Government
8%
Insurance Company
5%
Healthcare Company
4%
University
3%
Comms Service Provider
3%
Non Profit
2%
Energy/Utilities Company
2%
Educational Organization
2%
Construction Company
2%
Retailer
2%
Real Estate/Law Firm
1%
Media Company
1%
Transportation Company
1%
Legal Firm
1%
Outsourcing Company
1%
Aerospace/Defense Firm
1%
Hospitality Company
1%
Performing Arts
1%
Logistics Company
1%
Wholesaler/Distributor
1%
Recreational Facilities/Services Company
1%
Engineering Company
1%

Compare Sonatype Lifecycle with alternative products

Learn more about Sonatype Lifecycle

Sonatype Lifecycle customers

Related questions

 

Sonatype Lifecycle reviews

Sort by:
SrinathKuppannan2 - PeerSpot user
Integration Manager at CommScope
Verified user of Sonatype Lifecycle
Jun 27, 2024
Easily identifies problematic versions and ensures adherence to regulatory standards like HIPAA, critical for industries dealing with sensitive information

Pros

" The violation reports provided by Lifecycle are key, giving specific details on the types of violations and identifying the component within the application."

Cons

"On the security side, I think there's a lot of development needed. There are many security tools on the market, like open-source ones, that Sonatype doesn't integrate with."
GK
Principal DevSecOPs at a computer software company with 10,001+ employees
Verified user of Sonatype Lifecycle
Dec 24, 2024
Product version discussed: One-eighty-one
Provides comprehensive dependency oversight with room for expanded security capabilities

Pros

"The solution provides a comprehensive overview of dependencies and their security status. "

Cons

"It is a bit narrow, and we are expecting more features, especially with respect to SBOM and other detections. "
Find out what your peers are saying about Sonatype Lifecycle. Updated May 2025
853,823 professionals have used our research since 2012.
CL
Analista De Sistemas at Dataprev
Verified user of Sonatype Lifecycle
Mar 24, 2025
Utilize a reliable BRM tool to manage software artifacts efficiently with outstanding vulnerability identification capabilities

Pros

"The most valuable feature for us is Sonatype Lifecycle's capability in identifying vulnerabilities."

Cons

"Both JFrog and Sonatype should redesign their products to separate the binary repository management solution from the software composition analysis solutions."
AA
Sr cyber analyst at a energy/utilities company with 10,001+ employees
Verified user of Sonatype Lifecycle
Dec 29, 2023
Integrates easily with many IDEs, and enables development and security teams to work together

Pros

"I like Fortify Software Security Center or Fortify SSC. This tool is installed on each developer's machine, but Fortify Software Security Center combines everything. We can meet there as security professionals and developers. The developers scan their code and publish the results there. We can then look at them from a security perspective and see whether they fixed the issues. We can agree on whether something is a false positive and make decisions. "

Cons

"It can be tricky if you want to exclude some files from scanning. For instance, if you do not want to scan and push testing files to Fortify Software Security Center, that is tricky with some IDEs, such as IntelliJ. We found that there is an Exclude feature that is not working. We reported that to them for future fixing. It needs some work on the plugins to make them consistent across IDEs and make them easier. "
AA
Sr cyber analyst at a energy/utilities company with 10,001+ employees
Verified user of Sonatype Lifecycle
Oct 26, 2023
Integrates easily with many IDEs, and enables development and security teams to work together

Pros

"Automating the Jenkins plugins and the build title is a big plus. "

Cons

"Fortify Static Code Analyzer has a bit of a learning curve, and I don't find it particularly helpful in narrowing down the vulnerabilities we should prioritize. "
PeerSpot user
Vice President, Cybersecurity at a financial services firm with 10,001+ employees
Verified user of Sonatype Lifecycle
Dec 29, 2023
Seamless to integrate and identify vulnerabilities and frees up staff time

Pros

"The Software Security Center, which is often overlooked, stands out as the most effective feature. "

Cons

"Fortify's software security center needs a design refresh. "
JB
Adjunct at University of Maryland
Verified user of Sonatype Lifecycle
Dec 29, 2023
Good visibility, helps reveal vulnerabilities, and helps remediate issues

Pros

"You can really see what's happening after you've developed something. "

Cons

"Their licensing is expensive. "
VF
Software analyst at a financial services firm
Verified user of Sonatype Lifecycle
Dec 29, 2023
Helps to identify and remediate potential vulnerabilities and saves us costs

Pros

"The reference provided for each issue is extremely helpful. "

Cons

"The price can be improved. "