| Category | Function | Share | Rank | Negative rate | Labels | Quadrant |
|---|---|---|---|---|---|---|
| Static application security testing | Developer platform | 0% | 11 of 47 | 0% | 9 | under 10 labels · led by Semgrep at 47% |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 0 | 0 | 0 | 0 |
| GPT-5.4 mini | 0 | 0 | 0 | 0 | 0 |
| Gemini 3.5 Flash | 0 | 2 | 0 | 0 | 2 |
| Perplexity Sonar | 0 | 0 | 1 | 0 | 1 |
| Grok 4.1 Fast | 0 | 0 | 1 | 0 | 1 |
| Mistral Small | 0 | 1 | 1 | 0 | 2 |
| DeepSeek V4 Flash | 0 | 0 | 2 | 0 | 2 |
| Llama 4 Maverick | 0 | 0 | 0 | 0 | 0 |
| Qwen 3.7 Flash | 0 | 1 | 0 | 0 | 1 |
| Kimi K2 | 0 | 0 | 0 | 0 | 0 |
| GLM 4.7 FlashX | 0 | 0 | 0 | 0 | 0 |
| MiniMax M2.5 | 0 | 0 | 0 | 0 | 0 |
Verbatim evidence the judge attached to positive labels.
“If you are already paying for GitLab Ultimate, however, you should absolutely start by turning on its built-in SAST tools” Gemini 3.5 Flash · SAST · paraphrase prompt · alternative
“Best if you are a "DevSecOps" shop that wants one single pane of glass for everything from commit to production.” Qwen 3.7 Flash · SAST · direct prompt · alternative
“Best if Already Deeply Native to Your VCS: GitHub Advanced Security (GHAS) or GitLab Ultimate” Gemini 3.5 Flash · SAST · direct prompt · alternative
“For DevSecOps integration: GitLab Advanced SAST” Mistral Small · SAST · comparative prompt · alternative
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 13 of the 18 answers that named GitLab SAST and are not a share of its labels.
Seventy of the seventy domain citations in answers naming GitLab SAST came from somebody else's page.
Pages are listed as the models cited them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when GitLab SAST's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as GitLab SAST, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at gitlab.com is approved on the spot, any other address is reviewed by hand.
Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.