Gitlab hero border pattern left svg Gitlab hero border pattern right svg

GitLab
vs
Rapid7

Decision Kit

Decision Kit

GitLab vs Rapid7

Rapid7 can crawl and assess web applications to identify vulnerabilities with offerings on-premise and in the cloud. Rapid7’s InsightAppSec assesses and reports on a web application’s compliance to PCI-DSS, HIPAA, OWASP Top Ten, and other regulatory requirements. Integration with Atlassian Jira gives developers full visibility within their existing workflows while the Attack Replay feature lets developers validate vulns and test source code patches on their own.

GitLab Ultimate automatically includes broad security scanning with every code commit including Static and Dynamic Application Security Testing, along with dependency scanning, container scanning, and license management

Feature Comparison
FEATURES

Static Application Security Testing

GitLab allows easily running Static Application Security Testing (SAST) in CI/CD pipelines; checking for vulnerable source code or well known security bugs in the libraries that are included by the application. Results are then shown in the Merge Request and in the Pipeline view. This feature is available as part of Auto DevOps to provide security-by-default.

Learn more about Static Application Security Testing

Secret Detection

GitLab allows you to perform Secret Detection in CI/CD pipelines; checking for unintentionally committed secrets and credentials. Results are then shown in the Merge Request and in the Pipeline view. This feature is available as part of Auto DevOps to provide security-by-default.

Learn more about Secret Detection

Dependency Scanning

Protect your application from vulnerabilities that affect dynamic dependencies by automatically detecting well-known security bugs in your included libraries.

Learn more about Dependency Scanning

Dynamic Application Security Testing

Ensure you are not exposed to web application vulnerabilities like broken authentication, cross-site scripting, or SQL injection by dynamically investigating your running test applications in CI/CD pipelines.

Learn more about application security for containers

Interactive Application Security Testing

IAST combines elements of static and dynamic application security testing methods to improve the overall quality of the results. IAST typically uses an agent to instrument the application to monitor library calls and more. GitLab does not yet offer this feature.

Vulnerability Management

Empower your entire team, and not just Security, to act on security findings with a unified interface for scan results from all GitLab Security scanners.

Learn more about Vulnerability Management

Cloud Native Network Firewall

Prevent attackers from moving through your environment by restricting container network communications to only allow valid traffic flows between application components.

Learn more about Container Network Security

Container Scanning

Run a security scan to ensure the Docker images for your application do not have any known vulnerabilities in the environment where your code is shipped.

Learn more about container scanning

License Compliance

Check that licenses of your dependencies are compatible with your application, and approve or deny them. Results are then shown in the Merge Request and in the Pipeline view.

Learn more about License Compliance

On-demand DAST

Identify vulnerabilities in your running application, independent of code changes or merge requests.

Learn more about On-demand DAST

Site and Scanner profiles for On-demand DAST scans

Reuse configuration profiles quickly with on-demand DAST scans, instead of reconfiguring scans every time you need to run one. Mix different scan profiles with site profiles to quickly conduct scans that cover different areas or depths of your application and API.

Learn more about application security for containers

DAST Configuration UI

Enabling DAST is now as simple as three clicks. This guided configuration experience makes it easier for non-CI experts to get started with GitLab DAST. The tool helps a user create a merge request to enable DAST scanning while leveraging best configuration practices like using the GitLab-managed DAST.gitlab-ci.yml template.

Learn more about the DAST Configuration UI

Scheduling On-demand DAST scans

Set on-demand DAST scans to run on ad hoc or recurring schedules.

Learn more about scheduling on-demand scans