Overview
Product Information on GitLab
What is GitLab?
GitLab Pricing
GitLab Product Images


Overall experience with GitLab
“Comprehensive Security Scanning and Governance Tools Noted in GitLab ASPM Experience”
Badges
About Company
Company Description
GitLab is a comprehensive AI-powered DevSecOps platform for software innovation. As a software delivery platform for development, security, and operations teams, GitLab brings security and compliance to AI-powered workflows throughout the software delivery lifecycle, helping customers deliver secure software faster. GitLab Duo, the company’s suite of AI capabilities, improves team collaboration and reduces the security and compliance risks of AI adoption by bringing the entire software development lifecycle into a single AI-powered application that is privacy-first. With GitLab, customers can visualize their end-to-end value streams, boost developer productivity with out-of-the-box analytics, and secure their software supply chain with SAST, DAST, secret detection, container scanning, and API testing. It enables organizations to increase developer productivity, improve operational efficiency, and accelerate cloud transformations to maximize the overall return on software development.
Company Details
Do You Manage Peer Insights at GitLab?
Access Vendor Portal to update and manage your profile.
Key Insights
A Snapshot of What Matters - Based on Validated User Reviews
User Sentiment About GitLab
Reviewer Insights for: GitLab
Deciding Factors: GitLab Vs. Market Average
Performance of GitLab Across Market Features
GitLab Likes & Dislikes
1. Native DevSecOps Integration: With the ASPM functionality natively embedded in the Ultimate tier, you can tie it directly into your CI/CD pipelines, merge request workflows, and the scanning tools that come along with it (SAST, DAST, dependency scanning) as well as some excellent dashboards with reduced context switching. 2. Comprehensive scan coverage & release gates: The ability to have multiple scanners, both those provided by GitLab and ones I choose to bring in, and to have all of those give guardrails like blocking merge results if certain findings are detected all within one pipeline is a breath of coverage that is hard to find. 3. Security Dashboards, Visibility & Governance Features: The security dashboards that are visible at project and group level, as well as the overall vulnerability reports, compliance center, all provide the ability to see your security posture across multiple projects which is a must for any organization that is held to a compliance or governance standard.
What I like most about GitLab is its all in one platform that integrates code management, issue tracking, and CI/CD pipelines seamlessly. This helps our team efficiently validate releases, track bugs, and deploy updates without switching between multiple tools. The mearge requiest process provides excellent transparency in code change, making testing and verification much smoother. Its automation features save time and reduce manual effort, ensuring faster, more reliable releases and better collaboration between QA and developers teams.
Best part about gitlab is how much it consolidates into one platform. Instead of jumping between tools for code reviews, security scans and project tracking everything is right there in a single interface. Transparency in Gitlab is really good.
1. Noise and Duplicate Findings: Correlating findings across projects can be difficult if you don't have dedicated analysts, especially in the early onboarding phases when the scanners are being properly tuned. Duplicate findings can also be a problem when multiple branches of the same project are being scanned. 2. Customization & Filtering Limitations: When issues are filtered and scored there are too many limitations, specifically with refining dashboards as well as grouping vulnerabilities. 3. Lack of Contextual Prioritization: Unlike other ASPM tools, GitLab doesn't do the best job of explaining and understanding why a finding is prioritized and the actual exploitability of a vulnerability is minimal.
GitLab is a powerfull but has some challenges. It can slow down when handling large repositories or multiple pipelines, impacting testing speed. The interface is complex for new users, making navigation harder initially. Also notification for merge requests or pipeline updates are sometimes delayed, affecting timely coordination during release cycle.
Some features feel a bit heavy or overwhelming, especially for teams that don't use the full GitLab ecosystem. UI gets cluttred at times, and navigating certain settings. Upgrades on self hosted version also require careful planning as a single version jump can occasionally break older pipeline configurations. None of these are deal breakers but they do slow down things at times.
Top GitLab Alternatives
Peer Discussions
What Your Peers Are Saying About GitLab
GitLab Reviews and Ratings
- CLOUD APPLICATION SECURITY ENGINEERGov't/PS/EdEducationReview Source
Comprehensive Security Scanning and Governance Tools Noted in GitLab ASPM Experience
Overall my experience with using GitLab's ASPM functionality has come from being in their Ultimate tier and it has pros and cons, but has been mostly positive. The integration into your pipelines and code is excellent. I did run into issues with noise and DAST authentication issues, but the platform helped us empower developers to handle security issues early on in their workflows. - IT MANAGER<50M USDIT ServicesReview Source
GitLab Enhances Collaboration Yet Faces Performance and Usability Challenges for Teams
My overall experience with GitLab has been excellent. it plays a crucial role in managing our product lifecycle. GitLab makes it easy to track issues, validate release builds, and collaboration efficiently with developers. The CI/CD pipelines save time during development on customer setups, while merge requests help maintain code quality. It has improved our testing visibilty and release accuracy. Overall, GitLab has enhanced productivity, teamwoprk and the overall efficiency of our QA and development processes. - TSE50M-1B USDIT ServicesReview Source
Reliable DevOps Platform with great visibility over the development cycle
Gitlab is one of the most reliable parts of my development workflow. I started using it just for source control but over time we have shift most of our CI/CD and project tracking into it. Platform stays consistent, runs without needing constant fixes. Helped a lot in bringing clarity to release process. - MANAGER1B-10B USDMiscellaneousReview Source
Open Platform Features Make GitLab Accessible and Versatile for Developers Worldwide
GitLab is truly a diverse platform that lets you input, keep, review and share programming pieces on the spot. Since it is an open platform, anyone can access it. That is what makes it versatile and very user-friendly, smooth and widely accessible. It also stands out as the library is very well distributed across the web - if you are unsure and are looking for a piece of advice on programming, you will find this platform taking most of your headaches away. Created to be shared with and by professionals in the field, it benefits both the professionals and newbies in programming. - ENGINEER<50M USDIT ServicesReview Source
GitLab Integrates Security Tools Seamlessly But Advanced Features Require Ultimate Tier
For organizations, GitLab offers a highly comprehensive and automated security experience. Its core strength lies in its "Single Application" architecture, which tightly integrates security, CI/CD, and version control.



