Best Static Code Analysis Tools

Static analysis tool reviews covering true versus false positive rates, language coverage, CI speed, baseline handling and rule customization.

1 products

by Sonar

No reviews yet

SonarQube Server is self-hosted code quality and security analysis for development teams, from a free Community Build to Data Center clustering.

Features

Has Quality gate that fails the build
Has Pull request decoration with findings
Has New-code-only analysis against a baseline
Has Custom rule authoring
Has Rule set configuration per project
Has SAST security vulnerability rules
Has Hardcoded secrets detection
Has Software composition analysis of dependencies
Has Code duplication detection
Has Complexity and maintainability metrics
Has Test coverage import and tracking
Has IDE plugin with live findings
Has Analysis for 20 or more languages
Has Infrastructure-as-code scanning
Missing Automated fix suggestions for findings
Has Portfolio-level quality dashboards
Has Self-hosted analysis server
Has Free analysis for open source projects