SonarQube is an automated code review solution, serving as the verification layer for code quality and SDLC security. SonarQube is used to ensure that code is secure, reliable, and maintainable. It is available through SaaS or self-managed deployment.
If you have a highly bureaucratic organization that is heavily focused on procurement, Emptoris can provide some value. It seemed to be very good at linking the contract information to procurement for better spend control. If you are trying to implement a standalone contract management solution that allows you to easily create contracts and store them in a central location, this isn't the tool for you. There doesn't appear to be a simplified implementation. In general, when a SaaS solution has a complicated and expensive implementation, I am very skeptical. This does not show that the vendor is trying to move customers forward on a single code base. If that many things need to be done during implementation, you are starting to customize the solution for every customer. This hurts the vendor's ability to scale and make improvements in the future.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
SonarQube is excellent if you start using it at the beginning when developing a new system, in this situation you will be able to fix things before they become spread and expensive to correct. It’s a bit less suitable to use on existing code with bad design as it’s usually too expensive to fix everything and only allows you to ensure the situation doesn’t get worse.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Document protection - the Check Out contract feature is a great way to allow external parties to make modifications to contract language without the ability to accept those changes. Those redlines can then be imported back into Emptoris and reviewed or further modified as needed.
Notifications & reminders - you can trigger an email manually from within the system, or you can configure automated notifications andreminders to alert users when a new task is received or has aged a given amount of days, etc.
Interview wizard - there is a lot of value in the interview wizard. Administrators can configure screens with selecting options via check boxes, radio buttons, or typed-in values. Variables and conditions can be used to selectively populate fields within the contract or apply other options, making for a quick and convenient method to generate contracts conforming to corporate standards.
Field customization - administrators can customize a list of options for various fields including contract substatus, address type, and user created business term variables.
Approvals - many different options are available to configure approvals to trigger automatically upon presenting and/or executing the contract including specific individuals, one or more approver groups, or based upon various criteria including terms within the contract, type of contract, or the contract's owning organization.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Detecting bugs and vulnerabilities: SonarQube can identify a wide range of bugs and vulnerabilities in code, such as null pointer exceptions, SQL injection, and cross-site scripting (XSS) attacks. It uses static analysis to analyze the code and identify potential issues, and it can also integrate with dynamic analysis tools to provide even more detailed analysis.
Measuring code quality: SonarQube can measure a wide range of code quality metrics, such as cyclomatic complexity, duplicated code, and code coverage. This can help teams understand the quality of their code and identify areas that need improvement.
Providing actionable insights: SonarQube provides detailed information about issues in the code, including the file and line number where the issue occurs and the severity of the issue. This makes it easy for developers to understand and address issues in the code.
Integrating with other tools: SonarQube can be integrated with a wide range of development tools and programming languages, such as Git, Maven, and Java. This allows teams to use SonarQube in their existing development workflow and take advantage of its powerful code analysis capabilities.
Managing technical debt: SonarQube provides metrics and insights on the technical debt on the codebase, enabling teams to better prioritize issues to improve the quality of the code.
Compliance with coding standards: SonarQube can check the code against industry standards like OWASP, CWE and more, making sure the code is compliant with security and coding standards.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Reporting, Emptoris comes with standard reports which can not always can be fit into our business. This needs to be improved. I hope Emptoris is addressing this issue in their latest releases.
Though the feature of editing language in MS word is excellent, loading MS word takes time.
Importing a new custom quality profile on SonarQube is a bit tricky, it can be made easier
Every second time when we want to rerun the server, we have to restart the whole system, otherwise, the server stops and closes automatically
When we generate a new report a second time and try to access the report, it shows details of the old report only and takes a lot of time to get updated with the details of the new and fresh report generated
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
There are a lot of new, exciting products coming out in every field and I believe that there is always something better right over the horizon. If it was my choice, I would review my usage of Emptoris and other software periodically to make sure I'm using the most efficient software possible.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
The above rating for the overall support from Emptoris is for their product / product support, roll out training and refresher training / ongoing training, which is not only good but superior. There is no major or reconizable bad review that can be given to Emptoris at this point in time, from where is stands.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
We we easily able to integrate the SonarQube steps into our TFS process via the Microsoft Marektplace, we didn't have the need to call SonarQube support. We've used their online documentation and community forum if we ran into any issues.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
I am a fan of Ariba to be used for the entire lifecycle of Sourcing. From RFX's to cutting PO's. I feel Emptoris misses the boat on the idea of a "One Stop Shop" for all of your Sourcing/Purchasing needs
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
SonarQube is an open-source. It's a scalable product. The costs for this application, for the kind of job it does, are pretty descent. Pipeline scan is more secured in SonarQube. Its a very good tool and its support multiple languages. Its main core competency is of static code analysis and that is why SonarQube exists and it does it exceedingly well. The quality of scan on code convention, best practices, coding standards, unit test coverage etc makes them one of the best competent tool in the market
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
We won the 2005 Baseline Magazine Award for best ROI related to a technology implementation with an ROI 5544% (see 2005 Baseline ROI Awards, GlaxoSmithkline).
We always felt we could do "two times the work, with half the people and deliver double the savings".
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Positive ROI from the standpoint of flagging several issues that would have otherwise likely been unaddressed and caused more time to be spent closer to launch
Slightly positive ROI from time-saving perspective (it's an automated check which is nice, but depending on the issues it finds, can take developers time to investigate and resolve)