We performed a comparison between Checkmarx One and GitLab based on real PeerSpot user reviews.
Find out in this report how the two Application Security Tools solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."Most valuable features include: ease of use, dashboard. interface and the ability to report."
"Both automatic and manual code review (CxQL) are valuable."
"Overall, the ability to find vulnerabilities in the code is better than the tool that we were using before."
"The most valuable features are the easy to understand interface, and it 's very user-friendly."
"The user interface is modern and nice to use."
"The solution is always updating to continuously add items that create a level of safety from vulnerabilities. It's one of the key features they provide that's an excellent selling point. They're always ahead of the game when it comes to finding any vulnerabilities within the database."
"We use the solution to validate the source code and do SAST and security analysis."
"I like that you don't have to compile the code in order to execute static code analysis. So, it's very handy."
"I find the features and version control history to be most valuable for our development workflow. These aspects provide us with a clear view of changes and help us manage requests efficiently."
"The code merging capability is something that we use very frequently."
"GitLab is being used as a repository for our codebase and it is a one stop DevOps tool we use in our team."
"The solution's most valuable feature is that it is compatible with GitHub. The product's integration capabilities are sufficient for our small company of 35 people."
"GitLab integrates well with other platforms."
"The solution makes the CI/CD pipelines easy to execute."
"CI/CD is very good. The version control system is also good. These are the two features that we use."
"The most valuable feature of GitLab is its security."
"Checkmarx needs to improve the false positives and provide more accuracy in identifying vulnerabilities. It misses important vulnerabilities."
"I would like to see the rate of false positives reduced."
"Checkmarx being Windows only is a hindrance. Another problem is: why can't I choose PostgreSQL?"
"The integration could improve by including, for example, DevSecOps."
"Its pricing model can be improved. Sometimes, it is a little complex to understand its pricing model."
"Its user interface could be improved and made more friendly."
"The solution's user interface could be improved because it seems outdated."
"Micro-services need to be included in the next release."
"Their RBAC is role-based access, which is fine but not very good."
"Reporting could be improved."
"The initial setup was quite challenging because it takes some time to understand how to pull out or push the code."
"The user interface could be more user-friendly. We do most of our operations through the website interface but it could be better."
"We do face issues in our company when we run out of disk space."
"The documentation is confusing."
"GitLab's UI could be improved."
"There is a need to improve or adopt AI into the ecosystem like a co-pilot, which Microsoft has done with GitHub."
Checkmarx One is ranked 3rd in Application Security Tools with 67 reviews while GitLab is ranked 6th in Application Security Tools with 70 reviews. Checkmarx One is rated 7.6, while GitLab is rated 8.6. The top reviewer of Checkmarx One writes "The report function is a great, configurable asset but sometimes yields false positives". On the other hand, the top reviewer of GitLab writes "Powerful, mature, and easy to set up and manage". Checkmarx One is most compared with SonarQube, Veracode, Fortify on Demand, Snyk and Kiuwan, whereas GitLab is most compared with Microsoft Azure DevOps, SonarQube, Bamboo, AWS CodePipeline and Tekton. See our Checkmarx One vs. GitLab report.
See our list of best Application Security Tools vendors, best Static Application Security Testing (SAST) vendors, and best DevSecOps vendors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.