BLOG
Sonar's latest blog posts
Building Confidence and Trust in AI-Generated Code
To tackle the accountability and ownership challenge accompanying AI-generated code, we are introducing Sonar AI Code Assurance
No, C++ static analysis does not have to be painful
No C and C++ static analysis does not need to mean difficult configuration and pain. We explain how Sonar has made the impossible possible with one-click analysis for projects hosted in GitHub. A free automatic analysis of C and C++ projects.
Read blog post >
WeAreDevelopers 2023 - what did you miss?
The Sonar team of developers are just returning from their trip to Berlin where they attended WeAreDevelopers 2023. If you were not able to make it, here is what you missed.
Read blog post >
Working with Multiple Code Variants in C++
Multiple variants of C++ code-bases at build time are a necessary evil on most projects - even if that's just debug and release. This has always made analysis more complex. But now, with first class support in SonarQube Server, multiple code variants are easier to analyze and understand.
Read article >
A Twist in the Code: OpenMeetings Vulnerabilities through Unexpected Application State
Unexpected application states are often overlooked and can introduce severe security vulnerabilities. Read more about this real-world example.
Read article >
New Research from Sonar on Cost of Technical Debt
New original research from Sonar puts a spotlight on the millions of dollars that businesses lose when they fail to implement an optimal approach for software development.
Read Blog post >
How I started my career as a developer
Interviews with Sonar’s Developer Advocates on their careers and what Clean Code means to them.
Read article >
Why SonarQube Server 9.9 LTS is a must-have for PHP Developers
PHP analysis gets faster and better with new rules, fixed false-positives, and much more in SonarQube Server 9.9 LTS.
Read article >
TROOPERS 2023 Conference Takeaways
Read about our key takeaways from the TROOPERS 2023 including our favorite talks and overall experience during the two days conference.
Read article >
TyphoonCon 2023 Wrap Up
Last week, our Vulnerability Researchers traveled to TyphoonCon 2023 in Seoul to present their talk "Patches, collisions and root shells: a Pwn2Own Adventure".
Read article >
Why ORMs and Prepared Statements Can't (Always) Win
We always assume prepared statements and ORMs are enough to protect us from SQL injection, but be careful not to misuse their APIs! Let's look into a real-world case and see what we can learn from it.
Read article >
Why SonarQube Server 9.9 LTS is a must-have for JavaScript and TypeScript Developers
Read about the new features of SonarQube Server 9.9 LTS which help JavaScript and TypeScript developers to write Clean Code.
Read article >