IT AI Index
Index Vendors › GitLab SAST · September 2026 Edition
GitLab · 1 category · Named, not ranked

GitLab SAST

18Judge labels
1First choices
1Negative labels
9 of 12Models named it
1Category
September 2026 Edition. Every number here is derived from the raw labels under vendor table vv2026-09.2, every buyer segment counted.
Standing
9 labels, too few to rank
A product needs 10 labels in a category before a share or quadrant is stated. GitLab SAST was named 9 times in SAST, where Semgrep led with 47%. The labels and the evidence are below, counted exactly.
By buyer segmentRead the same way at every buyer size.
In sast · each standing computed within its segment · bars are 0 to 100 · the accent bar is the product's own best reading

Standing by category

Every category where a model named GitLab SAST for a mid-market B2B company. Share is first choices across the direct, paraphrase, budget and scale prompts; rank is within every product named in that category.
CategoryFunctionShareRankNegative rateLabelsQuadrant
Static application security testingDeveloper platform0%11 of 470%9under 10 labels · led by Semgrep at 47%

Movement

This is the first edition on this tier, so no move can be computed for GitLab SAST yet. From the next edition this section shows, per buyer segment, whether its share moved by more than the measured noise floor.

By model

How each model treated GitLab SAST across every prompt where it was named for a mid-market B2B company. Twelve models, six prompts per category.
ModelFirst choiceAlternativeMentionNegativeLabels
Claude Haiku 4.500000
GPT-5.4 mini00000
Gemini 3.5 Flash02002
Perplexity Sonar00101
Grok 4.1 Fast00101
Mistral Small01102
DeepSeek V4 Flash00202
Llama 4 Maverick00000
Qwen 3.7 Flash01001
Kimi K200000
GLM 4.7 FlashX00000
MiniMax M2.500000

By framing

Which of the six questions produced the naming. By model says how often; this says asked what. The first-choice count on the right carries the marks of the models that produced it.
FramingLabels by classFirst choices
Direct6 labelsNone
Paraphrase2 labelsNone
Comparative6 labelsNone
Budget-constrained0 labelsNone
Scale-constrained3 labels1
Negative1 labelNone
First choiceAlternativeMentionNegative18 labels in all, every segment counted; 1 of the 1 first choices count toward share, since the comparative and negative framings do not. The bar is one segment per label class, to scale within the framing.

What the models said for it

Verbatim evidence the judge attached to positive labels.

“If you are already paying for GitLab Ultimate, however, you should absolutely start by turning on its built-in SAST tools” Gemini 3.5 Flash · SAST · paraphrase prompt · alternative
“Best if you are a "DevSecOps" shop that wants one single pane of glass for everything from commit to production.” Qwen 3.7 Flash · SAST · direct prompt · alternative
“Best if Already Deeply Native to Your VCS: GitHub Advanced Security (GHAS) or GitLab Ultimate” Gemini 3.5 Flash · SAST · direct prompt · alternative
“For DevSecOps integration: GitLab Advanced SAST” Mistral Small · SAST · comparative prompt · alternative

And against it

Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.

No model argued against it.

Named alongside

The products named in the same answers as GitLab SAST, over the 18 answers that named it. Took the first choice instead counts the answers where the other product was the first choice and GitLab SAST was named but was not.
ProductSame answerTook the first choice insteadHead to head
Semgrep15 of 188Not in the top three
SonarQube15 of 182Not in the top three
Checkmarx One14 of 183Not in the top three
Veracode12 of 182Not in the top three
Snyk Code11 of 180Not in the top three
Aikido Security9 of 183Not in the top three
OpenText Fortify8 of 180Not in the top three
CodeQL7 of 180Not in the top three
Snyk4 of 181Not in the top three
GitHub Advanced Security4 of 180Not in the top three
A head-to-head page exists where both products are in a category's top three. The other rows are the same fact without a page behind them, so they link to the product instead.

What carried it into the answer

The sites and pages cited by the answers that named GitLab SAST. A fact about retrieval, not a lever on the model.

Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 13 of the 18 answers that named GitLab SAST and are not a share of its labels.

Domains cited

appsecsanta.com9
corgea.com9
dev.to8
zeropath.com8
ox.security7
augmentcode.com6
cycode.com6
jit.io6
pixee.ai6
checkmarx.com5

Seventy of the seventy domain citations in answers naming GitLab SAST came from somebody else's page.

Pages cited

Pages are listed as the models cited them.

Names read as GitLab SAST

What the judge wrote, as written, with how often. The vendor table decides that these count as GitLab SAST; a claim can dispute any of them.
GitLab Ultimate 4GitLab 1GitLab Advanced SAST 1
Is this your product?

Claim this page

Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when GitLab SAST's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as GitLab SAST, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.

It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at gitlab.com is approved on the spot, any other address is reviewed by hand.

Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.

Subscribe to the pack