Audience

Companies searching for a solution to manage and empower their dev teams

About SonarQube

SonarSource builds world-class products for Code Quality and Security. Our open-source and commercial code analyzer - SonarQube - supports 27 programming languages, empowering dev teams of all sizes to solve coding issues within their existing workflows. We embrace progress - whether it's multi-language applications, teams composed of different backgrounds or a workflow that's a mix of modern and legacy, SonarQube has you covered. SonarQube fits with your existing tools and proactively raises a hand when the quality or security of your codebase is at risk. SonarQube can analyze branches of your repo, and notify you directly in your Pull Requests! Our mission is to empower developers first and grow an open community around code quality and code security. Jenkins, Azure DevOps server and many others. Thousands of automated Static Code Analysis rules, protecting your app on multiple fronts, and guiding your team.

Integrations

Ratings/Reviews - 2 User Reviews

Overall 5.0 / 5
ease 5.0 / 5
features 5.0 / 5
design 5.0 / 5
support 5.0 / 5

Company Information

SonarSource
United States
www.sonarqube.org

Videos and Screen Captures

SonarQube Screenshot 1
You Might Also Like
Enterprise AI Search, Intranet, and Wiki in one platform. Icon
Enterprise AI Search, Intranet, and Wiki in one platform.

Your company’s all-in-one solution for trusted information

Cut through the noise and end information overload with Guru, an all-in-one wiki, intranet, and knowledge base that serves as your company's single source of truth.
Learn More

Product Details

Platforms Supported
SaaS
Training
Documentation

SonarQube Frequently Asked Questions

Q: What kinds of users and organization types does SonarQube work with?
Q: What languages does SonarQube support in their product?
Q: What other applications or services does SonarQube integrate with?
Q: What type of training does SonarQube provide?

SonarQube Product Features

Application Security

Open Source Component Monitoring
Source Code Analysis
Training Resources
Vulnerability Detection
Analytics / Reporting
Third-Party Tools Integration
Vulnerability Remediation

Static Application Security Testing (SAST)

Application Security
Dashboard
Debugging
Deployment Management
IDE
Multi-Language Scanning
Real-Time Analytics
Source Code Scanning
Vulnerability Scanning

Static Code Analysis

Analytics / Reporting
Code Standardization / Validation
Multiple Programming Language Support
Provides Recommendations
Standard Security/Industry Libraries
Vulnerability Management

SonarQube Additional Categories

SonarQube Reviews

Write a Review
  • Aman V.
    Technical Lead
    Used the software for: 2 Years
    Frequency of Use: Weekly
    User Role: User
    Company Size: 20,000 or More
    Design
    Ease
    Features
    Pricing
    Support
    Probability You Would Recommend?
    1 2 3 4 5 6 7 8 9 10

    "Industry standard code quality tool"

    Posted 2022-04-01

    Pros: Great User Interface / Dashboard.
    Different tiers of bugs - helps identify and fix only the critical issues.
    Suggestions to fix the issue.
    Jenkins integration.
    Also available as SaaS offering.
    Also shows security defects.

    Cons: The only con i can think of is expensive license which is not optimal for personal projects (unless open source). There is a free trial though.

    Overall: SonarQube is used across the industry as the go-to solution for code review. It has an impressive interface which provides all the information - issue, the code where it occurred and the optimal solution suggestion; at one place.

    Read More...
  • Daniel M.
    Security Architect
    Used the software for: Less than 6 months
    Frequency of Use: Daily
    User Role: User
    Company Size: 500 - 999
    Design
    Ease
    Features
    Pricing
    Support
    Probability You Would Recommend?
    1 2 3 4 5 6 7 8 9 10

    "Excellent Product"

    Posted 2019-04-01

    Pros: - Accurate results and no bullshit findings
    - Very fast analysis
    - Handy configuration features for analysis customization
    - Nice interface
    - Plenty integration options

    Cons: - It has its price but its worth every penny. Similar vendors are more expensive with significantly less value.

    Overall: I integrated SonarQube into my SDLC and it reliably detects and blocks security issues

    Read More...
  • Previous
  • You're on page 1
  • Next