We just raised a $30M Series A: Read our story
Cancel
You must select at least 2 products to compare!
GitLab Logo
10,840 views|9,668 comparisons
WhiteSource Logo
19,149 views|15,040 comparisons
Top Review
Find out what your peers are saying about GitLab vs. WhiteSource and other solutions. Updated: September 2021.
542,267 professionals have used our research since 2012.
Quotes From Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:

Pros
"We like that we can create branches and then the branches can be reviewed and you can mesh those branches back. You can independently work with your own branch, you don't need to really control the core of other people.""Everything is easy to configure and easy to work with.""A user friendly solution.""It speeds up our development, it's faster, safer, and more convenient.""The best thing is that as the developers work on separate tasks, all of the code goes there and the other team members don't have to wait on each other to finish.""GitLab offers a good interface for doing code reviews between two colleagues.""This product is always evolving, and they listen to the customers.""It is very useful for reviews. We are using branch merging operations and full reset operations. It is also very useful for merging our code and tracking another branch. The graph diagrams of Git are very useful. Its interface is straightforward and not too complex for us."

More GitLab Pros »

"Attribution and license due diligence reports help us with aggregating the necessary data that we, in turn, have to provide to satisfy the various licenses copyright and component usage disclosures in our software.""The most valuable features are the reporting, customizing libraries "In-house, White list, license selection", comparing the products/projects, and License & Copyright resolution.""For us, the most valuable tool was open-source licensing analysis.""It gives us full visibility into what we're using, what needs to be updated, and what's vulnerable, which helps us make better decisions.""The reporting capability gives us the option to generate an open-source license report in a single click, which gets all copyright and license information, including dependencies.""With the fix suggestions feature, not only do you get the specific trace back to where the vulnerability is within your code, but you also get fix suggestions.""Our dev team uses the fix suggestions feature to quickly find the best path for remediation.""The most valuable feature is the unified JAR to scan for all langs (wss-scanner jar)."

More WhiteSource Pros »

Cons
"I would like to see static analysis also embedded in GitLab. That would also help us. If there's something that it does internally by GitLab and then that is already tied up with your pipeline and then it can tell you that you're coding is good or your code is not great. Based on that, it would pass or fail. That should be streamlined. I would think that would help to a greater extent, in terms of having one solution rather than depending on multiple vendors.""The only thing our company is really waiting on in terms of features is the development of metrics.""Reporting could be improved.""I would like to see better integration with project management tools such as Jira.""The documentation could be improved to help newcomers better understand things like creating new branches.""We are having a few problems integrating with Jira at the moment, which is something that our IT department is investigating.""It would be really good if they integrated more features in application security.""It can be free for commercial use."

More GitLab Cons »

"Some detected libraries do not specify a location of where in the source they were matched from, which is something that should be enhanced to enable quicker troubleshooting.""WhiteSource needs improvement in the scanning of the containers and images with distinguishing the layers.""If anything, I would spend more time making this more user-friendly, better documenting the CLI, and adding more examples to help expand the current documentation.""WhiteSource Prioritize should be expanded to cover more than Java and JavaScript.""It would be nice to have a better way to realize its full potential and translate it within the UI or during onboarding.""The UI is not that friendly and you need to learn how to navigate easily.""The UI can be slow once in a while, and we're not sure if it's because of the amount of data we have, or it is just a slow product, but it would be nice if it could be improved.""The dashboard UI and UX are problematic."

More WhiteSource Cons »

Pricing and Cost Advice
"I think that we pay approximately $100 USD per month.""The price is okay.""It seems reasonable. Our IT team manages the licenses.""Its price is fine. It is on the cheaper side and not expensive. You have to pay additionally for GitLab CI/CD minutes. Initially, we used the free version. When we ran out of GitLab minutes, we migrated to the paid version.""It is very expensive. We can't bear it now, and we have to find another solution. We have a yearly subscription in which we can increase the number of licenses, but we have to pay at the end of the year."

More GitLab Pricing and Cost Advice »

"Pricing is competitive.""The solution involves a yearly licensing fee.""As we were using an SaaS-based service, the solution must be scalable, although my understanding is that this is based on the licensing model one is using.""WhiteSource is much more affordable than Veracode."

More WhiteSource Pricing and Cost Advice »

report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
542,267 professionals have used our research since 2012.
Questions from the Community
Top Answer: We like that we can have an all-encompassing product and don't have to implement different solutions.
Top Answer: It is very expensive. We can't bear it now, and we have to find another solution. We have a yearly subscription in which we can increase the number of licenses, but we have to pay at the end of the… more »
Top Answer: We would like to generate document pages from the sources. Right now, we can't do that. The testing could be better in that, for the code quality, now we use an external product and maybe the internal… more »
Top Answer: The license management of WhiteSource was at a good level. As compared to other tools that I have used, its functionality for the licenses for the code libraries was quite good. Its UI was also fine.
Top Answer: We have ended our relationship with WhiteSource. We were using an agent that we built in the pipeline so that you can scan the projects during build time. But unfortunately, that agent didn't work at… more »
Top Answer: I would rate WhiteSource a three out of ten considering the fact that we couldn't use it while we were paying for it. It had good features, but we couldn't use it.
Ranking
Views
10,840
Comparisons
9,668
Reviews
15
Average Words per Review
389
Rating
8.2
Views
19,149
Comparisons
15,040
Reviews
13
Average Words per Review
417
Rating
8.5
Comparisons
Learn More
Overview

GitLab is a single application with features for the whole software development and operations (DevOps) lifecycle.

The leading solution for agile open source security and license compliance management, WhiteSource integrates with the DevOps pipeline to detect vulnerable open source libraries in real-time.

It provides remediation paths and policy automation to speed up time-to-fix. It also prioritizes vulnerability alerts based on usage analysis.

We support over 200 programming languages and offer the widest vulnerability database aggregating information from dozens of peer-reviewed, respected sources.

Offer
Learn more about GitLab
Learn more about WhiteSource
Sample Customers
Siemens, University of Washington, Equinix, Paessler AG, CNCF, Ticketmaster, CERN, Vaadin
Microsoft, Autodesk, NCR, Comcast, Nokia, Forgerock, indeed.com, GE digital, KPMG, LivePerson, Jack Henry and Associates
Top Industries
REVIEWERS
Mining And Metals Company18%
Computer Software Company18%
Transportation Company9%
Financial Services Firm9%
VISITORS READING REVIEWS
Computer Software Company23%
Comms Service Provider22%
Government9%
Financial Services Firm8%
REVIEWERS
Computer Software Company33%
Media Company11%
Energy/Utilities Company11%
Consumer Goods Company11%
VISITORS READING REVIEWS
Computer Software Company35%
Comms Service Provider19%
Financial Services Firm7%
Manufacturing Company5%
Company Size
REVIEWERS
Small Business53%
Midsize Enterprise12%
Large Enterprise35%
REVIEWERS
Small Business33%
Midsize Enterprise7%
Large Enterprise60%
VISITORS READING REVIEWS
Small Business17%
Midsize Enterprise9%
Large Enterprise74%
Find out what your peers are saying about GitLab vs. WhiteSource and other solutions. Updated: September 2021.
542,267 professionals have used our research since 2012.

GitLab is ranked 4th in Software Composition Analysis (SCA) with 15 reviews while WhiteSource is ranked 3rd in Software Composition Analysis (SCA) with 13 reviews. GitLab is rated 8.2, while WhiteSource is rated 8.4. The top reviewer of GitLab writes "Provides or mandates quantitative code into the Master". On the other hand, the top reviewer of WhiteSource writes "Policy automation and automatic fix suggestions help us to save time in finding and solving problems". GitLab is most compared with Microsoft Azure DevOps, Tekton, TeamCity, Sonatype Nexus Lifecycle and GoCD, whereas WhiteSource is most compared with SonarQube, Black Duck, Snyk, Sonatype Nexus Lifecycle and Veracode. See our GitLab vs. WhiteSource report.

See our list of best Software Composition Analysis (SCA) vendors.

We monitor all Software Composition Analysis (SCA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.