SonarSource SonarQube Logo

SonarSource SonarQube

Code quality and security platform with SAST, SCA, and AI-powered remediation

Visit website
Claim and verify your listing
0

SonarSource SonarQube Description

SonarQube is a comprehensive code quality and security platform that analyzes code in 35+ programming languages to detect issues and enforce standards for maintainability, reliability, and security. The platform provides automated code review capabilities that scan all branches, pull requests, and merges as code is committed or pushed, applying expertly curated rules and industry compliance standards. It offers both cloud-based (SonarQube Cloud) and self-hosted (SonarQube Server) deployment options. Key capabilities include Static Application Security Testing (SAST) with taint analysis to detect injection vulnerabilities like SQL injection, XSS, and SSRF; Software Composition Analysis (SCA) for dependency security; secrets detection; and Infrastructure as Code (IaC) scanning. The platform features AI CodeFix, which uses large language models to generate context-aware fix suggestions for bugs and security issues directly within developer workflows. SonarQube integrates seamlessly into CI/CD pipelines and provides real-time feedback in IDEs and DevOps tools. It tracks quality metrics including technical debt, maintainability, and reliability across entire codebases. The platform supports custom detection rules and policies to enforce organization-specific security standards. SonarQube Cloud offers zero maintenance with automatic updates, 99.9% uptime SLA, and SOC 2 Type II certification, while SonarQube Server provides complete data residency control and air-gapped deployment options.

SonarSource SonarQube FAQ

Common questions about SonarSource SonarQube including features, pricing, alternatives, and user reviews.

SonarSource SonarQube is Code quality and security platform with SAST, SCA, and AI-powered remediation developed by SonarSource. It is a Application Security solution designed to help security teams with Sast, Code Security, Static Analysis.

Have more questions? Browse our categories or search for specific tools.

FEATURED

Heeler Application Security Auto-Remediation Logo

Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.

Hudson Rock Cybercrime Intelligence Tools Logo

Cybercrime intelligence tools for searching compromised credentials from infostealers

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

Mandos Fractional CISO Logo

Fractional CISO services for B2B companies to build security programs

POPULAR

RoboShadow Logo

Automated vulnerability assessment and remediation platform

13
OSINTLeak Real-time OSINT Leak Intelligence Logo

Real-time OSINT monitoring for leaked credentials, data, and infrastructure

8
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

6
TestSavant AI Security Assurance Platform Logo

AI security assurance platform for red-teaming, guardrails & compliance

5
Mandos Brief Logo

Weekly cybersecurity newsletter covering security incidents, AI, and leadership

5
View Popular Tools →

Stay Updated with Mandos Brief

Get strategic cybersecurity insights in your inbox