Sonar's latest blog posts
Solving the Engineering Productivity Paradox
Sonar CEO, Tariq Shaukat, shares how AI-generated code absolutely must be reviewed before it's merged into your codebase, and how SonarQube can help.


Interview with Sonar Python Developers Part 1
Why should I learn Python language? When should I use Python? Is tooling around Python development mature?
Read Blog post >

Sonar ❤️ Compiler Explorer: Write clean C++ code inside your browser
Sonar ❤️ Compiler Explorer: Write clean C++ code inside your browser
Read Blog post >
Get new blogs delivered directly to your inbox!
Stay up-to-date with the latest Sonar content. Subscribe now to receive the latest blog articles.

Paying maintainers: the HOWTO
It is no surprise that lots of well-intentioned people have failed to figure out how to effectively pay maintainers.
Read article >

Pretalx Vulnerabilities: How to get accepted at every conference
We recently discovered two vulnerabilities in pretalx and found a generic technique to gain code execution from a file write.
Read article >

Another 9 reasons to upgrade to SonarQube Server 9.9 LTS
SonarQube Server 9.9 LTS is here! We're back with another 9 reasons you should prioritise upgrading as soon as possible.
Read article >

How bad code destroys developer velocity
When bad code gets overlooked, it can create lasting problems and ultimately impact developer productivity and velocity.
Read Blog post >

Announcing SonarQube Server 10.0
Learn what features - like faster first analysis and better user management with SCIM - are available to you and your teams in SonarQube Server 10.0!
Read article >

It’s a (SNMP) Trap: Gaining Code Execution on LibreNMS
Our researchers discovered a vulnerability in LibreNMS, which could be exploited by attackers to gain RCE by sending a single SNMP trap.
Read article >

Sonar is the Clean Code solution for your DevOps workflow
Clean Code from Sonar aims to streamline your DevOps workflow so that your organization can yield the best possible results from your software.
Read Blog post >

Your Guide to Clean Code in Cloud Native Apps
Companies are adopting cloud native practices because it puts their core business first and affords them speed and efficiency advantages over the competition. However, reaping these rewards requires a solid, sustainable foundation - a Clean Code foundation.
Read Blog post >

The top 5 common TypeScript issues found by SonarQube for IDE
We crunched the data from SonarQube for IDE to discover the top 5 most common TypeScript issues. This is a summary of the top 5
Read Blog post >