SonarQube Server

by Sonar • • Static Code Analysis Tools

No reviews yet
Free plan available View plans

SonarQube Server is self-hosted code quality and security analysis for development teams, from a free Community Build to Data Center clustering.

SonarQube Server is static code analysis software that development teams run on their own infrastructure to check code quality and security. It is made by Sonar (SonarSource Sàrl), an independent company based in Geneva. The server analyzes source code for bugs, security vulnerabilities, security hotspots, code smells and architecture issues, and it reports results per project and per pull request. SonarQube Cloud, the hosted service from the same company, is a separate product. Analysis results feed Quality Gates, which set pass or fail conditions on new code and stop a build when a condition is missed. Quality Profiles decide which rules apply to each language and project. Taint analysis looks for injection and cross-site scripting flaws, and secrets detection looks for credentials committed to source files. The server also reports duplicated code, cognitive and cyclomatic complexity, and test coverage imported from a project's own reports. Developer Edition adds branch analysis, pull request decoration and AI Code Assurance. Enterprise Edition adds Portfolios and management reporting, MISRA C++:2023 compliance and the paid Advanced Security product for dependency analysis and advanced SAST. Data Center Edition adds high availability clustering and autoscaling. The Community Build suits open source maintainers, individual developers and small teams that want a free, self-managed analyzer. Developer Edition fits product teams that review changes through pull requests. Enterprise Edition fits organizations that need one view across many projects, and Data Center Edition fits very large code bases that call for a clustered, highly available server. The editions are licensed per instance per year on lines of code, with Enterprise and Data Center sold through the sales team. The server runs on-premises, in Docker or on Kubernetes, and connects to GitHub, GitLab, Bitbucket and Azure DevOps. It also works with Jenkins, Jira Cloud, Slack and JFrog. Developers see the same findings in VS Code and IntelliJ through SonarQube for IDE in connected mode. Typical jobs are gating pull requests in CI, reviewing AI-generated code before it merges, and producing compliance reports.

Features

  • Included: Quality gate that fails the build
  • Included: Pull request decoration with findings
  • Included: New-code-only analysis against a baseline
  • Included: Custom rule authoring
  • Included: Rule set configuration per project
  • Included: SAST security vulnerability rules
  • Included: Hardcoded secrets detection
  • Included: Software composition analysis of dependencies
  • Included: Code duplication detection
  • Included: Complexity and maintainability metrics
  • Included: Test coverage import and tracking
  • Included: IDE plugin with live findings
  • Included: Analysis for 20 or more languages
  • Included: Infrastructure-as-code scanning
  • Not included: Automated fix suggestions for findings
  • Included: Portfolio-level quality dashboards
  • Included: Self-hosted analysis server
  • Included: Free analysis for open source projects

Additional Features

  • Quality Gates on new code
  • Quality Profiles per language and project
  • Ratings for security, reliability and maintainability
  • Security hotspots review
  • Taint analysis for injection and cross-site scripting
  • Secrets detection in source files
  • Branch analysis
  • Pull request decoration
  • AI Code Assurance
  • Architecture management
  • Cognitive and cyclomatic complexity metrics
  • Duplicated lines and blocks statistics
  • Coverage report import and coverage on new code
  • Custom rules through the Java plugin API and XPath
  • Terraform, Kubernetes, Docker, CloudFormation and Ansible analysis
  • Portfolios and management reporting
  • Advanced Security dependency analysis (paid, from Enterprise)
  • MISRA C++:2023 compliance
  • High availability clustering and autoscaling
  • SonarQube for IDE connected mode
  • Docker and Kubernetes deployment

Best for

  • Development teams that need code analysis to run on their own infrastructure
  • Open source maintainers and small teams starting on the free Community Build
  • Teams gating pull requests on GitHub, GitLab, Bitbucket or Azure DevOps
  • Engineering organizations reporting code quality across many projects
  • Large code bases that need a high availability cluster
  • Teams reviewing AI-generated code before it merges
  • Security teams tracking hotspots, secrets and vulnerabilities in source code

Use cases

  • Failing a CI build when new code breaks the Quality Gate
  • Commenting on pull requests with new issues before merge
  • Reviewing AI-generated code with AI Code Assurance
  • Finding hardcoded secrets in a repository
  • Flagging SQL injection and cross-site scripting through taint analysis
  • Enforcing one rule set per language with Quality Profiles
  • Tracking test coverage on new code across releases
  • Scanning Terraform and Kubernetes files for misconfigurations
  • Rolling quality results of many projects into one Portfolio report
  • Producing compliance reports for regulated software
  • Running analysis in a high availability cluster for a very large code base
  • Checking C++ code against MISRA C++:2023

Screenshots & Videos

Explore SonarQube Server in action

Projects And Quality Dashboard
View full size
Projects And Quality Dashboard

User Reviews

Write a Review

No reviews yet

Be the first to share your experience with this software.

Want to claim this brand?

To claim this brand, please contact support.