TrustRadius: an HG Insights company

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    HackerOne

    Score9 out of 10
    N/AHackerOne is a hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be exploited, from the company of the same name in San Francisco. The service is used for vulnerability location, pen testing, bug bounty, and vulnerability triage services.N/A

    OpenText Dimensions CM

    Score8 out of 10
    N/ADimensions CM is Software Change and Configuration Management for Agile development, developed by Serena Software and now sold by OpenText.N/A
    Pricing
    HackerOneOpenText Dimensions CM
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    HackerOneOpenText Dimensions CM
    Free Trial
    NoNo
    Free/Freemium Version
    NoNo
    Premium Consulting/Integration Services
    NoNo
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional DetailsFor more information please email www.hackerone.com/contact or find us on the AWS Marketplace: https://aws.amazon.com/marketplace/seller-profile?id=10857e7c-011b-476d-b938-b587deba31cf—
    More Pricing Information
    Best Alternatives
    HackerOneOpenText Dimensions CM
    Small Businesses
    No answers on this topic
    GitHub
    Score9.2 out of 10
    Medium-sized Companies
    No answers on this topic
    Git
    Score10 out of 10
    Enterprises
    No answers on this topic
    Perforce P4
    Score7.5 out of 10
    All AlternativesView all alternativesView all alternatives
    User Ratings
    HackerOneOpenText Dimensions CM
    Likelihood to Recommend
    7.0
    (2 ratings)
    9.0
    (1 ratings)
    User Testimonials
    HackerOneOpenText Dimensions CM
    Likelihood to Recommend
    HackerOne
    It is one of the good platforms for security researchers to submit bugs and other vulnerabilities, it however, has some challenges, in terms of un-verified and duplicate submissions.
    Incentivized
    Read full review
    OpenText
    Serena CM is well suited to highly controlled, audited, and process driven environments. It will allow strict segregation of duties, and change traceability. If implemented correctly it will help you quickly build trusts with your auditors. It is also well suited to environments that require constant branching and merging. Due to the complexity of the product and learning curve for your development and operations team it may be overkill in a small shop with loose rules
    Incentivized
    Read full review
    Pros
    HackerOne
    • Filter for spammy bug reports
    • Nice central interface
    • Payment/reward system is nice
    Incentivized
    Read full review
    OpenText
    • Code Promotion: Dimensions CM allows supervisors to control changes to code, in that they delegate requests to developers, and act as a gatekeeper prior to promoting to the next environment. This functionality is configurable so you can set up a workflow that best fits the structure and requirements of your own company.
    • Code Repository for changes and versioning: Code can be checked out by item or by synchronizing folders. Code revisions can be compared against other revisions or work files. Item histories show which developers made which modifications, and which supervisor and operations personnel were involved in assigning the request and promoting the code to each environment. Additionally a pedigree will show a stream diagram which graphically displays branches and merges.
    • Deployment: Serena Change Management offers help automating deployment including integrations with SVN and Jenkins. Its newer versions also have a powerful graphical deployment automation tool (Serena Deployment Automation- SDA). It comes with a certain amount of licenses built-in. If you have a many nodes to deploy to there will be separate licensing costs for that.
    Incentivized
    Read full review
    Cons
    HackerOne
    • A lot of duplicate bugs get reported, although it does offer automatic suggestion of previously reported bugs that may be duplicates, it is far from perfect.
    • Anyone can report bugs, a lot of them are not verified before submission. This sometimes leads to a lot of time spent in verifying if the bug is really actionable.
    • Each submission has to be treated with equal potential, a lot of time, some time gets invested in vulnerabilities that aren't as important as some others.
    Incentivized
    Read full review
    OpenText
    • The only major negative that I have encountered with Serena CM product is that the very power and flexibility of the tool means there is a risk that you will make a mess of things. In other words it gives you plenty of rope to tangle yourself with. I recommend careful, well thought out deployments implementing the built in roles and workflows that can be turned on and configured, using a consistent methodology.
    • My experience with the Serena help desk support has not been impressive. Though reasonably polite and diligent, the technicians were well trained, and often gave bad advise and terrible scripts. On several occasions I had to rewrite scripts they have me; if I had run them as provided they would have caused even more difficulties than the problem I was trying to solve. I speak of the support in the past tense because I conditioned myself not to call them, it was usually just easier to solve nay problems my self. They do have a good account management team though, and for any major issues you can go thru them.
    Incentivized
    Read full review
    Alternatives Considered
    HackerOne
    These were very close and we liked HackerOne better. For a time we did have both and we felt the need to consolidate the information into one platform and end of life our internal offering. Overall we've been fairly happy with HackerOne.
    Incentivized
    Read full review
    OpenText
    Serena CM is superior to Microsoft Team Foundation Server (TFS) in overall functionality, but does not have very good native integration with Microsoft. Therefore in a Microsoft centric shop with no audit needs ,TFS would be better. Otherwise I would choose Serena CM
    Incentivized
    Read full review
    Return on Investment
    HackerOne
    • Bugs that can't be tracked internally are submitted by external researchers, which is an important factor for security vulnerabilities.
    • Even if the bugs reported are duplicates, there still is provision to award reputation points, that keep the researchers engaged.
    • It also requires a lot of verification and validation, as a lot of the submissions are unverified to begin with.
    Incentivized
    Read full review
    OpenText
    • Serena has facilitated our annual completion of various audit and technology control certifications. These certifications make a huge difference to our company's reputation and bottom line.
    • There has been no negative impact on our company.
    Incentivized
    Read full review
    ScreenShots