Overview
What is SonarQube?
SonarQube is a code quality and vulnerability solution for development teams that integrates with CI/CD pipelines to ensure the software you produce is secure, reliable, and maintainable.
SonarQube: The mandatory tool to elevate your code quality quality
Code Quality is a Must!
Sonarqube - The ultimate tool for end to end code analysis
SonarQube, you don't need to search more!
SonarQube- A perfect QC for Reviewers
SonarQube: Helper of Dev and organisation for better code quality and security practices.
Easy to use DecSecOps application
SonarQube - solid static code analysis tool
Easy to use DevSecOps tool
Let the SonarQube guide your devs towards a better future.
Cost effective way to find and correct issues early
Don't Skip Static Analysis with Sonar!
SonarQube your free & friendly DevSecOps tool
SonarQube Must in Code Pipeline
SonarQube: A great solution for code quality management and analysis
Awards
Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards
Pricing
Community
Free
Developer EDITION
Starts at $160
Enterprise EDITION
Starts at $21,000
Entry-level set up fee?
- No setup fee
Offerings
- Free Trial
- Free/Freemium Version
- Premium Consulting/Integration Services
Starting price (does not include set up fee)
- $160 per year per installation
Product Demos
Understanding Issues with Multiple Locations
SonarQube analysis with Jenkins
GitHub: Block the Merge of a Pull Requests
Product Details
- About
- Integrations
- Competitors
- Tech Details
- FAQs
What is SonarQube?
SonarQube is a self-managed open-source platform that helps developers create code devoid of quality and vulnerability issues. By integrating with DevOps platforms in the Continuous Integration (CI) pipeline, SonarQube continuously inspects projects across multiple programming languages, providing immediate status feedback while coding. SonarQube’s quality gates become part of the release pipeline, displaying pass/fail results for new code based on quality profiles that can be customized to a company's standards. Following Sonar’s Clean as You Code methodology guarantees that only software of the highest quality makes it to production. At its core, SonarQube includes a static code analyzer that identifies bugs, security vulnerabilities, hidden secrets, and code smells. The platform guides the user through issue resolution, fostering a culture of continuous improvement. SonarQube’s reporting helps dev teams to monitor their codebase's overall health and quality across multiple projects in their portfolio. UltimatelySonarQube aims to enable users to achieve a state of Clean Code, leading to secure, reliable, and maintainable software.
SonarQube Screenshots
SonarQube Integrations
SonarQube Competitors
SonarQube Technical Details
Deployment Types | On-premise, Software as a Service (SaaS), Cloud, or Web-Based |
---|---|
Operating Systems | Windows, Linux, Mac, Cloud |
Mobile Application | No |
Supported Countries | Global |
Supported Languages | Community localization plugins support several languages. |
Frequently Asked Questions
Comparisons
Compare with
Reviews and Ratings
(87)Community Insights
- Business Problems Solved
- Pros
- Cons
- Recommendations
SonarQube has proven to be invaluable for software engineering companies looking to ensure code quality and prevent the release of faulty software. Users have utilized SonarQube for a wide range of use cases, including generating code quality reports, detecting bugs, vulnerabilities, and code smells, and analyzing code coverage for JUnit tests. The software serves as a static application security tool, helping to identify and fix security issues and vulnerabilities in code. It is seamlessly integrated into Azure DevOps Continuous Integration pipelines, providing detailed issue descriptions and code highlights to identify vulnerabilities. With its comprehensive analysis of the codebase, SonarQube helps in enforcing good practices and preventing bugs, serving as a quality gate for software development. By utilizing static code analysis, SonarQube helps developers create bug-free code and detect vulnerabilities early on, saving valuable time in the development process. Additionally, SonarQube aids in maintaining code quality, improving coding structure, and ensuring code reliability and security. Beyond these primary use cases, users have found value in using SonarQube to check code coverage, follow coding suggestions, manage technical debt, monitor unit test coverage for C++ projects, track bugs and code quality while the security team focuses on vulnerability scanning, and adhere to industry standards. Its customization options allow users to tailor the rules to their specific needs and enable toll-gating to prevent bad code from reaching production. The plugin-based framework of SonarQube ensures extensibility for new use cases and has been highly regarded by users who find it easy to integrate with existing tools and infrastructure. Whether it's identifying design flaws before committing or merging code or tracking legacy code issues and offering solutions for improvement, SonarQube plays a crucial role in improving the overall quality of software development projects across various industries.
Efficient and Precise Code Quality Reports: Multiple users have praised SonarQube for its highly efficient and precise code quality reports. This feature has allowed them to gain a comprehensive understanding of their code's quality, identify areas for improvement, and enhance the overall quality of their code.
Detection of Bugs and Vulnerabilities: Reviewers have found SonarQube's ability to highlight bugs and vulnerabilities in the codebase to be a valuable asset. This feature has helped them identify potential issues early on, enabling them to take proactive measures to improve the code's quality and security.
Valuable Code Remediation Suggestions: Many users have expressed appreciation for SonarQube's suggestions for code remediation and resolution. These suggestions have proven extremely valuable in helping them make their code cleaner, more maintainable, and ultimately improving long-term code quality.
Tricky Importing of Custom Quality Profile: Reviewers have found that importing a new custom quality profile on SonarQube can be challenging and tricky, causing frustration during the setup process.
Inconvenient Server Restart Requirement: Some users have reported the inconvenience of having to restart the server every second time in order to rerun it, which disrupts their workflow and wastes time.
Slow Report Generation and Updating: Several reviewers have mentioned that generating a new report on SonarQube takes a significant amount of time. Additionally, they have experienced delays in updating the details of the new report, as it continues to display information from previous reports instead.
Based on user feedback, here are the most common recommendations for using SonarQube:
Consider using SonarQube if your team size is above 10. For smaller groups, it is recommended to use the community version or integrate Sonarlint with IDE for free.
Integrate SonarQube with CI servers like Cloudbees and Jenkins, as well as version control and testing tools like UFT. This will make the development process smoother and more efficient.
Leverage SonarQube's features, such as code coverage analysis, testing, and code health monitoring. Users find these features valuable for understanding code conventions, maintaining code quality, and identifying security issues or code smells in applications.
Attribute Ratings
Reviews
(1-24 of 24)Code Quality is a Must!
Sonarqube - The ultimate tool for end to end code analysis
SonarQube: Helper of Dev and organisation for better code quality and security practices.
Easy to use DecSecOps application
SonarQube - solid static code analysis tool
Easy to use DevSecOps tool
Let the SonarQube guide your devs towards a better future.
Cost effective way to find and correct issues early
Don't Skip Static Analysis with Sonar!
SonarQube your free & friendly DevSecOps tool
SonarQube Must in Code Pipeline
- Multi-language support: SonarQube supported all the languages used in our codebase while some of the other tools did not.
- Customizable quality profiles: SonarQube allowed teams to create custom quality profiles that aligned with their specific coding standards and best practices. Other tools did not provide the option or was cumbersome to do so.
- Integration with CI tools: SonarQube integrated easily Jenkins and Azure DevOps. Other tools were harder to integrate.
- Detailed reporting and visualization: SonarQube provided a wide range of reports and visualizations that provided the level of detail needed from developers to upper management. Other tools did not not have such reports or were limited to a certain audience.
- Large community support: SonarQube has a large and active community of users and contributors, which means that it benefits from a wide range of plugins and integrations, as well as a wealth of knowledge and best practices.
- Access control and security: SonarQube provides role-based access control that was not present in other tools or was harder to setup.
SonarQube to make your project secure
SonarQube review by a Hybris Developer
SonarQube, the best choice for a Static Code Analysis tool leveraging application security at large
Using SonarQube professionally for more than 7 years and fully recommend it to any Software Engineer
Also the overall tooling and integrations provided by SonarQube is stellar and very other competitors can provide such services and IDE integrations.
The output results from SonarQube tests can be easily read, including by other services for automation purposes, and creating reports for audits or other teams is nice and easy.
SonarQube: The go-to tool for code quality
- Codacy and WhiteSource
- Pros
- Code quality tests
- Code quality trending
- Security analysis
- Claims integrations with BitBucket, JIRA, Slack, although hard to find detail on their web page.
- Cons
- Website is light on technical details
- Relatively new product from a small startup. https://www.crunchbase.com/organization/codacy
- No BitBucket code review integration
- $15/per user/per month, no free tier
- Pros
- BitBucket code review integration.
- Open source license and vulnerability testing.
- Cons
- No code analysis, just open source dependency checking.
SAST Tools selection - SonarQube to the rescue
Scans results and depth of tweaking/whitelisting code snippets is easier with SonarQube.