# www.sonarsource.com llms-full.txt > Sonar provides tools for developers to improve code quality and security through continuous static analysis of both human-written and AI-generated code. This file is the comprehensive link index for LLM discovery and retrieval. For the lightweight discovery file, see: https://www.sonarsource.com/llms.txt --- ## Root - [Home](https://www.sonarsource.com/): To create an account and start improving code quality and security with cloud-based static analysis. --- ## Products ### SonarQube Core - [SonarQube](https://www.sonarsource.com/products/sonarqube/): To explore SonarSource’s solution for code quality and security through comprehensive static code analysis and continuous inspection. - [SonarQube Server](https://www.sonarsource.com/products/sonarqube/server/): To learn about the self-managed solution for code quality and security with advanced static analysis and governance capabilities. - [SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/cloud/): To discover the cloud-based solution for code quality and security with scalable static code analysis and seamless DevOps integration. - [Sign Up for SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/cloud/signup/): To create an account and start improving code quality and security with cloud-based static analysis. - [Sign Up Free for SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/cloud/signup-free/): To start using SonarQube Cloud with a free plan for automated code quality and security analysis. - [Contact SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/cloud/contact/): To get in touch with the team for questions about SonarQube Cloud and its code quality and security capabilities. - [Contact Enterprise Sales](https://www.sonarsource.com/products/sonarqube/cloud/contact-enterprise-sales/): Facilitate inquiries for SonarQube Cloud Enterprise sales and information. - [SonarQube Cloud Features](https://www.sonarsource.com/products/sonarqube/cloud/features/): Highlight SonarQube Cloud's enterprise features for code quality and security in software development. - [Contact Enterprise Sales for SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/cloud/features/integrations/): To explore integrations that embed code quality and security checks directly into your CI/CD pipelines. - [SonarQube Cloud Roadmap](https://www.sonarsource.com/products/sonarqube/cloud/roadmap/): Outline upcoming features and updates for SonarQube Cloud, inviting user feedback on priorities. - [SonarQube Cloud Updates](https://www.sonarsource.com/products/sonarqube/cloud/whats-new/): Highlighting recent updates and features of SonarQube Cloud to enhance user experience. - [SonarQube Cloud New Pricing Plans](https://www.sonarsource.com/products/sonarqube/cloud/new-pricing-plans/): To review updated pricing options and plans for scaling code quality and security in the cloud. - [Advanced Security](https://www.sonarsource.com/products/sonarqube/advanced-security/): Solutions for the secure use of open-source code, including advanced Static Application Security Testing (SAST) and Software Composition Analysis (SCA). - [Advanced Security Free Trial](https://www.sonarsource.com/products/sonarqube/advanced-security/free-trial/): To start a free trial of SonarQube Advanced Security for open-source code analysis and supply chain insights. - [MCP Server](https://www.sonarsource.com/products/sonarqube/mcp-server/): To provide a free, local “Model Context Protocol” server that connects SonarQube (Cloud or Server) with AI-native IDEs and AI agents. - [SonarSweep](https://www.sonarsource.com/products/sonarsweep/): To provide a service that systematically remediates, optimizes, and secures coding datasets used to train coding-capable AI models (LLMs). - [SonarSweep Early Access](https://www.sonarsource.com/products/sonarsweep/early-access/): To request early access to SonarSweep, which validates coding datasets by deduplicating, fixing issues, and filtering noise for LLM training. - [All Sonar Products](https://www.sonarsource.com/products/all/): To compare SonarQube for IDE, SonarQube Cloud, and SonarQube Server and find the best fit for your developer and business needs. - [Auto-Analysis for C and C++ in SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/cloud/features/auto-analysis-for-c-and-cpp/): To use one-click automatic analysis of C and C++ projects in SonarQube Cloud with no configuration required. - [Contact Sales for SonarQube](https://www.sonarsource.com/products/sonarqube/contact-sales/): To contact SonarQube's sales team to learn more about enterprise plans and features. - [SonarQube Free Trial](https://www.sonarsource.com/products/sonarqube/free-trial/): To start a free 14-day trial of SonarQube Cloud with one-click signup, unlimited users, and support for 40+ languages. - [SonarQube Server LTA Update Checklist](https://www.sonarsource.com/products/sonarqube/lta-update-checklist/): To follow a checklist for a smooth and successful update to the latest SonarQube Server LTA. - [SonarQube Server LTA Update Hub](https://www.sonarsource.com/products/sonarqube/lta-update-hub/): To find everything needed to confidently update SonarQube Server to the latest LTA release. - [Migrate to SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/migration-cloud/): To learn how SonarQube Server customers adopting a cloud-first strategy can migrate to SonarQube Cloud. - [SonarQube Roadmap](https://www.sonarsource.com/products/sonarqube/roadmap/): To find out what's coming in upcoming SonarQube releases. - [Why Upgrade SonarQube Server](https://www.sonarsource.com/products/sonarqube/why-upgrade/): To discover how upgrading to the latest SonarQube Server helps teams improve code quality, reduce technical debt, and ship secure software faster. ### Deployment - [SonarQube Deployment Overview](https://www.sonarsource.com/products/sonarqube/deployment/): To explore deployment options for SonarQube, including flexible environments that support scalable code quality and security analysis. - [Install SonarQube from ZIP](https://www.sonarsource.com/products/sonarqube/deployment/install-zip/): To learn how to install SonarQube using the ZIP distribution for manual, self-managed deployment. - [Deploy SonarQube with Docker](https://www.sonarsource.com/products/sonarqube/deployment/docker/): To run SonarQube in a containerized environment using Docker for simplified setup and consistent code quality and security analysis. - [Deploy SonarQube on Kubernetes](https://www.sonarsource.com/products/sonarqube/deployment/kubernetes/): To deploy SonarQube on Kubernetes for cloud-native scalability, resilience, and enterprise-grade code quality and security. ### Downloads - [SonarQube Downloads](https://www.sonarsource.com/products/sonarqube/downloads/): To access available editions of SonarQube for self-managed code quality and security analysis. - [SonarQube LTS Downloads](https://www.sonarsource.com/products/sonarqube/downloads/lts/): To download the Long-Term Support (LTS) version of SonarQube for stability-focused code quality and security management. - [SonarQube 9.9 LTS](https://www.sonarsource.com/products/sonarqube/downloads/lts/9-9-lts/): To download SonarQube 9.9 LTS for long-term stability and enterprise-grade code quality and security analysis. - [SonarQube 8.9 LTS](https://www.sonarsource.com/products/sonarqube/downloads/lts/8-9-lts/): To download SonarQube 8.9 LTS for legacy long-term support of code quality and security initiatives. - [Developer Edition Download Confirmation](https://www.sonarsource.com/products/sonarqube/downloads/success-download-developer-edition/): To confirm and proceed with the download of SonarQube Developer Edition for enhanced code quality and security features. - [Enterprise Edition Download Confirmation](https://www.sonarsource.com/products/sonarqube/downloads/success-download-enterprise-edition/): To confirm and proceed with the download of SonarQube Enterprise Edition for advanced governance and code quality and security controls. - [Data Center Edition Download Confirmation](https://www.sonarsource.com/products/sonarqube/downloads/success-download-data-center-edition/): To confirm and proceed with the download of SonarQube Data Center Edition for high availability and scalable code quality and security. - [Historical SonarQube Downloads](https://www.sonarsource.com/products/sonarqube/downloads/historical-downloads/): To access previous versions of SonarQube for legacy environments and migration support. - [SonarQube LTA Downloads](https://www.sonarsource.com/products/sonarqube/downloads/lta/): To download the Latest Active (LTA) version of SonarQube for up-to-date code quality and security capabilities. ### Editions - [SonarQube Developer Edition](https://www.sonarsource.com/products/sonarqube/developer-edition/): To learn about the Developer Edition of SonarQube that enhances code quality and security analysis with deeper insights and team collaboration features. - [SonarQube Enterprise Edition](https://www.sonarsource.com/products/sonarqube/enterprise-edition/): To explore the Enterprise Edition of SonarQube offering advanced governance, portfolio management, and comprehensive code quality and security controls. - [Upgrade to SonarQube Enterprise Edition](https://www.sonarsource.com/products/sonarqube/enterprise-edition/upgrade/): To find information on upgrading to the Enterprise Edition for expanded capabilities in code quality and security. - [SonarQube Data Center Edition](https://www.sonarsource.com/products/sonarqube/data-center-edition/): To discover the Data Center Edition of SonarQube designed for high availability, scalability, and robust code quality and security analysis across large organizations. ### What's New (All Versions) - [What’s New in SonarQube](https://www.sonarsource.com/products/sonarqube/whats-new/): To explore the latest updates, enhancements, and improvements in SonarQube for advancing code quality and security. - [What’s New in SonarQube – Page 2](https://www.sonarsource.com/products/sonarqube/whats-new/2/): To browse additional SonarQube release updates and feature announcements. - [What’s New in SonarQube – Page 3](https://www.sonarsource.com/products/sonarqube/whats-new/3/): To review continued updates and historical release highlights for SonarQube. - [What’s New in SonarQube – Page 5](https://www.sonarsource.com/products/sonarqube/whats-new/5/): To access earlier SonarQube release notes and feature summaries. - [SonarQube 2025.2 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/2025-2/): To learn about the new features and improvements introduced in SonarQube 2025.2. -[SonarQube 2025.3 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/2025-3/): To discover enhancements and updates delivered in SonarQube 2025.3. -[SonarQube 2025.4 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/2025-4/): To review the latest code quality and security improvements in SonarQube 2025.4. - [SonarQube 2025.5 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/2025-5/): To explore newly released features and performance enhancements in SonarQube 2025.5. - [SonarQube 2025.6 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/2025-6/): To examine updates and refinements included in SonarQube 2025.6. - [SonarQube 10.0 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-0/): To learn about major updates and innovations introduced in SonarQube 10.0. - [SonarQube 10.1 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-1/): To review enhancements and fixes delivered in SonarQube 10.1. - [SonarQube 10.2 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-2/): To explore improvements and feature updates in SonarQube 10.2. - [SonarQube 10.3 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-3/): To discover new capabilities and optimizations in SonarQube 10.3. - [SonarQube 10.4 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-4/): To examine the latest code quality and security enhancements in SonarQube 10.4. - [SonarQube 10.5 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-5/): To learn about feature additions and improvements in SonarQube 10.5. - [SonarQube 10.6 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-6/): To review updates and refinements introduced in SonarQube 10.6. - [SonarQube 10.7 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-10-7/): To explore enhancements and fixes delivered in SonarQube 10.7. - [SonarQube Server 10.8 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-server-10-8/): To discover the latest updates specific to SonarQube Server 10.8. - [SonarQube Server 2025.1 LTA – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-server-2025-1-lta-whats-new/): To learn about the features and improvements included in the SonarQube Server 2025.1 Long-Term Active release. - [SonarQube 9.8 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/sonarqube-9-8/): To review updates and enhancements delivered in SonarQube 9.8. - [SonarQube Server 2026.1 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/2026-1/): To learn how the 2026.1 LTA release supports a "vibe, then verify" approach as AI-generated code and AI-native IDEs become standard in the development lifecycle. - [SonarQube Server 2026.2 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/2026-2/): To explore the redesigned user experience, Java 25 support, unified security reporting, and model-agnostic AI CodeFix introduced in SonarQube Server 2026.2. - [SonarQube Server 2026.3 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/2026-3/): To discover native Model Context Protocol (MCP) connectivity for AI coding assistants, deeper language and pipeline analysis, and streamlined enterprise administration in SonarQube Server 2026.3. - [SonarQube Server 2026.4 – What’s New](https://www.sonarsource.com/products/sonarqube/whats-new/2026-4/): To learn about the AI-specific quality gate, architecture management, agentic-security rules, and faster incremental taint analysis added in SonarQube Server 2026.4. ### SonarQube for IDE - [SonarQube for IDE](https://www.sonarsource.com/products/sonarqube/ide/): To go beyond linting with real-time analysis that catches vulnerabilities as you write, including in AI-generated suggestions. - [SonarQube for IDE Features](https://www.sonarsource.com/products/sonarqube/ide/features/): To explore 5,000+ rules, real-time analysis, automatic issue repair, and other features that help deliver higher-quality, more secure code. - [SonarQube for IDE Connected Mode](https://www.sonarsource.com/products/sonarqube/ide/features/connected-mode/): To discover bugs and security issues from the moment you start writing code by connecting SonarQube for IDE to your SonarQube Server or Cloud instance. - [SonarQube for IDE Deep Education](https://www.sonarsource.com/products/sonarqube/ide/features/deep-education/): To learn how SonarQube for IDE educates developers on coding issues in real time while they write, right inside their AI IDE. - [SonarQube for IDE in Eclipse](https://www.sonarsource.com/products/sonarqube/ide/features/eclipse/): To extend SonarQube into the Eclipse IDE for integrated code quality and security feedback from the first line of code. - [SonarQube for IDE in JetBrains](https://www.sonarsource.com/products/sonarqube/ide/features/jetbrains/): To extend SonarQube into JetBrains IDEs for integrated code quality and security feedback from the first line of code. - [SonarQube for IDE Quick Fixes](https://www.sonarsource.com/products/sonarqube/ide/features/quick-fixes/): To boost coding efficiency with quick fixes that suggest and automatically apply solutions adapted to your code. - [SonarQube for IDE in Visual Studio](https://www.sonarsource.com/products/sonarqube/ide/features/visual-studio/): To ensure code quality and security in Visual Studio by extending SonarQube into the IDE for real-time bug and vulnerability detection. - [SonarQube for IDE in VS Code](https://www.sonarsource.com/products/sonarqube/ide/features/vs-code/): To extend SonarQube into VS Code for integrated code quality and security feedback across human- and AI-generated code. - [SonarQube for IDE Login](https://www.sonarsource.com/products/sonarqube/ide/ide-login/): To sign in and get real-time feedback on code quality and security issues in VS Code, IntelliJ, Cursor, Visual Studio, and more. - [SonarQube for IDE – What’s New](https://www.sonarsource.com/products/sonarqube/ide/whats-new/): To read the latest updates on new features, rules, and language coverage for SonarQube for IDE. - [SonarQube for IDE Eclipse – What’s New](https://www.sonarsource.com/products/sonarqube/ide/whats-new/eclipse/): To review the latest features, rules, and language coverage updates for SonarQube for IDE in Eclipse. - [SonarQube for IDE JetBrains – What’s New](https://www.sonarsource.com/products/sonarqube/ide/whats-new/jetbrains/): To review the latest features, rules, and language coverage updates for SonarQube for IDE in JetBrains. - [SonarQube for IDE Visual Studio – What’s New](https://www.sonarsource.com/products/sonarqube/ide/whats-new/visual-studio/): To review the latest features, rules, and language coverage updates for SonarQube for IDE in Visual Studio. - [SonarQube for IDE VS Code – What’s New](https://www.sonarsource.com/products/sonarqube/ide/whats-new/vs-code/): To review the latest features, rules, and language coverage updates for SonarQube for IDE in VS Code. ### Agentic Analysis & AI Agents - [SonarQube Agentic Analysis](https://www.sonarsource.com/products/sonarqube/agentic-analysis/): To give coding agents a fast, context-aware feedback loop that validates and fixes code before a pull request is even opened. - [SonarQube Agentic Analysis Resources](https://www.sonarsource.com/products/sonarqube/agentic-analysis/resources/): To access guides and resources for setting up and getting the most out of SonarQube Agentic Analysis. - [SonarQube Hunter Agent](https://www.sonarsource.com/products/sonarqube/hunter-agent/): To run AI-powered deep analysis that hunts broken access control, business logic, and authentication flaws that traditional static analysis misses. - [Contact Sales for SonarQube Hunter Agent](https://www.sonarsource.com/products/sonarqube/hunter-agent/contact/): To get in touch with Sonar's team about deploying SonarQube Hunter Agent for deep security analysis. - [SonarQube Remediation Agent](https://www.sonarsource.com/products/sonarqube/remediation-agent/): To automatically fix issues and validate them against the Sonar engine, turning failed quality gates green without manual review cycles. - [SonarQube Remediation Agent Resources](https://www.sonarsource.com/products/sonarqube/remediation-agent/resources/): To access guides and resources for setting up and using the SonarQube Remediation Agent. ### Gitar - [Gitar](https://www.sonarsource.com/products/gitar/): To accelerate pipelines with AI code review that automatically fixes bugs, analyzes CI failures, and commits patches securely inside your own infrastructure. - [Book a Gitar Demo](https://www.sonarsource.com/products/gitar/book-demo/): To contact Sonar's sales team to learn about AI code review from Gitar and its enterprise deployment options. - [Compare Gitar](https://www.sonarsource.com/products/gitar/compare/): To see how Gitar's AI code review and automated fixes compare to other tools on the market. - [Gitar Examples](https://www.sonarsource.com/products/gitar/examples/): To see real examples of Gitar automatically finding issues and generating fixes inside pull requests. - [Gitar Videos](https://www.sonarsource.com/products/gitar/videos/): To watch product demos, tutorials, and walkthroughs showing how Gitar automates fixes and validates against CI. ### Sonar Vortex - [Sonar Vortex](https://www.sonarsource.com/products/sonar-vortex/): To inject codebase context into AI coding agents and verify AI-generated code in real time, cutting token costs and stopping outages before the PR. - [Contact Sales for Sonar Vortex](https://www.sonarsource.com/products/sonar-vortex/contact/): To get in touch with Sonar's team about deploying Sonar Vortex to guide and verify AI agent output in real time. ### Agent Essentials - [Agent Essentials](https://www.sonarsource.com/products/agent-essentials/): To eliminate AI technical debt and cut token costs with Sonar's deterministic code analysis engine for coding agents. - [Contact Sales for Agent Essentials](https://www.sonarsource.com/products/agent-essentials/contact/): To get in touch with Sonar's team about deploying Agent Essentials across your coding agent workflows. ### Context Augmentation - [Sonar Context Augmentation](https://www.sonarsource.com/products/context-augmentation/): To guide AI coding agents with dynamic code context before a single line is generated, eliminating rework and optimizing LLM spend. - [Sonar Context Augmentation Resources](https://www.sonarsource.com/products/context-augmentation/resources/): To access guides and resources for setting up Sonar Context Augmentation with your AI coding agents. ### SonarQube CLI - [SonarQube CLI](https://www.sonarsource.com/sonarqube/cli/): To bring code quality and security analysis into the terminal, scanning for secrets and integrating with Claude Code and other agents. - [SonarQube CLI Commands Reference](https://www.sonarsource.com/sonarqube/cli/commands.html): To browse the full command reference for the SonarQube CLI, including sonar auth, sonar install, sonar integrate, sonar list, and sonar analyze. - [SonarQube CLI Overview](https://www.sonarsource.com/sonarqube/cli/index.html): To get an overview of the SonarQube CLI and how it brings code quality and security scanning into the terminal. ### Pricing & Plans - [SonarQube for IDE License](https://www.sonarsource.com/license/): To find the latest license information for SonarQube for IDE and SonarQube Community Build under the GNU LGPL v3 license. - [SONAR Source-Available License](https://www.sonarsource.com/license/ssal/): To review the latest license information for the SONAR Source-Available License v1.0. - [Open Source Editions](https://www.sonarsource.com/open-source-editions/): To get started for free building high-quality, secure code at every step of the CI/CD pipeline. - [SonarQube Community Build](https://www.sonarsource.com/open-source-editions/sonarqube-community-edition/): To use the free, open-source SonarQube Community Build for smart, integrated code review for developers and small teams. - [Plans and Pricing](https://www.sonarsource.com/plans-and-pricing/): To explore Sonar's pricing and plans for AI and agentic code review, from open-source projects to enterprise scale. - [Contact Sales for Plans and Pricing](https://www.sonarsource.com/plans-and-pricing/contact-sales/): To contact Sonar's sales team to learn more about flagship static analysis coverage across 30+ languages. - [SonarQube Data Center Pricing](https://www.sonarsource.com/plans-and-pricing/data-center/): To see pricing for SonarQube Data Center Edition, built for 99.9% uptime and high availability at enterprise scale. - [Gitar Pricing](https://www.sonarsource.com/plans-and-pricing/gitar/): To review Gitar's pricing, from free PR summaries to paid Core, Pro, and Enterprise plans for AI code review. - [SonarQube Server Pricing](https://www.sonarsource.com/plans-and-pricing/sonarqube/): To review SonarQube Server plans and pricing for static code analysis, code quality, and code security. ### Get Started - [Get Started with SonarQube Cloud](https://www.sonarsource.com/get-started/cloud/): To experience automated code review with SonarQube Cloud, detecting thousands of issue types across 35+ languages with AI-powered analysis. - [Get Started with SonarQube Server](https://www.sonarsource.com/get-started/server/): To deliver real-time code analysis on your own infrastructure with SonarQube Server, including automated compliance reporting for CWE, PCI DSS, and OWASP. --- ## Solutions - [Advanced SAST Solution](https://www.sonarsource.com/solutions/security/sast/): Promotes the Advanced SAST solution for enhancing code security and identifying vulnerabilities in software applications. - [SonarQube Security Solutions](https://www.sonarsource.com/solutions/security/): Promoting SonarQube's integrated security solutions for ensuring code quality and vulnerability detection in software development. - [Code Coverage Solutions](https://www.sonarsource.com/solutions/code-coverage/): Evaluate code quality through detailed code coverage metrics and improve overall software reliability and maintainability. - [Advanced Security Solutions](https://www.sonarsource.com/solutions/security/advanced-security-request/): Promote advanced security solutions for software development to ensure secure code and compliance. - [Sonar's Open Source Commitment](https://www.sonarsource.com/solutions/commitment-to-open-source/): Promoting Sonar's dedication to open-source solutions and engaging with the developer community for continuous improvement. - [Code Review Tool and Solutions](https://www.sonarsource.com/solutions/code-review/): To promote SonarQube as a comprehensive tool for improving code quality and security through effective code reviews. - [AI Code Review Tool and Solutions](https://www.sonarsource.com/solutions/code-review/ai): To promote SonarQube as a comprehensive tool for improving ai code quality and code security through effective ai code reviews. - [Automated Code Review Tool and Solutions](https://www.sonarsource.com/solutions/code-review/automated): To promote SonarQube as a comprehensive automated tool for improving code quality and security through effective automated code reviews. - [AI CodeFix Solutions](https://www.sonarsource.com/solutions/ai/ai-codefix/): Promotes AI CodeFix solutions for accelerated code issue resolution with one-click AI recommendations. - [Developers tools](https://www.sonarsource.com/solutions/for-developers/): Empower developers to write better, quality code through continuous feedback and quality assurance tools. - [Software Composition Analysis](https://www.sonarsource.com/solutions/security/sca/): Promote software composition analysis for identifying vulnerabilities and ensuring compliance in third-party dependencies. - [Software Development Use Cases](https://www.sonarsource.com/solutions/use-cases/): To showcase software development use cases and solutions for improving code quality and managing technical debt. - [Enterprise Software Solutions](https://www.sonarsource.com/solutions/for-enterprise/): Promote Sonar's solutions for secure and efficient enterprise software development. - [Manage Technical Debt](https://www.sonarsource.com/solutions/reduce-technical-debt/): Promote strategies and solutions to manage technical debt and enhance software development quality and efficiency. - [AI Code Assurance Solutions](https://www.sonarsource.com/solutions/ai/ai-code-assurance/): Promote AI Code Assurance solutions for high-quality and secure AI-generated code validation. - [AI Code Quality Solutions](https://www.sonarsource.com/solutions/ai/): Promote AI solutions for quality assurance in code development. - [Advanced Secrets Detection](https://www.sonarsource.com/solutions/secrets-detection/): To promote Sonar's advanced secrets detection solutions that protect source code from security vulnerabilities. - [DevOps Transformation Solutions](https://www.sonarsource.com/solutions/devops-transformation/): Promote tools for enhancing code quality and efficiency in DevOps transformation using Sonar products. - [Infrastructure as Code Security](https://www.sonarsource.com/solutions/infrastructure-as-code/): Promotes a solution for analyzing code quality and security in Infrastructure as Code environments. - [Reduce Outsourcing Risks](https://www.sonarsource.com/solutions/reduce-outsourcing-software-development-risk/): Help organizations minimize risks associated with outsourcing software development by enforcing standardized coding practices. - [Secure By Design Code](https://www.sonarsource.com/solutions/secure-by-design-code/): Promoting secure software development practices to reduce risks and integrate security into the coding lifecycle. - [Validate AI code for security and quality](https://www.sonarsource.com/solutions/ai-code-quality/): Tools and methodologies to ensure that AI-generated code meets security and quality standards. - [Developer security](https://www.sonarsource.com/solutions/developer-security/): Strategies and tools to secure applications and prevent vulnerabilities throughout the development lifecycle. - [Automated code review](https://www.sonarsource.com/solutions/automated-code-review/): A process that ensures code is secure and of high quality through automated checks and balances. - [Compliance reporting](https://www.sonarsource.com/solutions/compliance-and-reporting/): Automates the proof of code compliance to meet regulatory and organizational standards. - [SDLC governance](https://www.sonarsource.com/solutions/code-governance/): Aligns AI and developer standards to ensure compliance and quality throughout the Software Development Life Cycle (SDLC). - [Mobile Developers](https://www.sonarsource.com/solutions/mobile-developers/): Help mobile developers find and fix bugs, vulnerabilities, and code quality issues for Android and iOS projects with instant IDE feedback and audit-ready compliance reports. - [Platform Engineering](https://www.sonarsource.com/solutions/platform-engineering): Enable platform engineering teams to standardize tools, automate quality checks, and boost developer productivity, integrating AI-driven remediation for secure code delivery. - [SonarQube, SonarQube Cloud, and SonarQube Server CI/CD Integrations](https://www.sonarsource.com/solutions/integrations/): This page explains how Sonar products integrate with major DevOps platforms and CI/CD tools to enhance code quality and security through features like pull request decoration and Quality Gates. - [OWASP Security Vulnerability Coverage of Top 10, ASVS & CWE 25 with SonarQube, SonarQube Cloud & SonarQube Server](https://www.sonarsource.com/solutions/security/owasp/): This page details how Sonar's products help address security vulnerabilities based on OWASP Top 10, ASVS, and CWE Top 25 standards, with features like dedicated security reports and early SAST feedback. - [Code Quality Standards](https://www.sonarsource.com/solutions/quality/): Quality Gates give you a clear go/no-go releasability indicator at every analysis and coalesce the team around a shared vision of quality. - [Taint Analysis](https://www.sonarsource.com/solutions/taint-analysis/): SonarQube's taint analysis is a deep security scan that tracks user-controllable data through your entire application, to identify sophisticated injection vulnerabilities. - [Code Architecture](https://www.sonarsource.com/solutions/architecture/): Software architecture is an essential cornerstone of coding, and yet, it is often overlooked. SonarQube’s architecture capabilities help bring software architecture back under your control. - [Software Development for SMBs](https://www.sonarsource.com/solutions/software-development-for-smbs/): Small and medium business development teams face unique pressure to deliver fast and innovate while managing tight budgets, limited resources, and the complexity of modern stacks. - [AI Coding Assistants](https://www.sonarsource.com/solutions/ai/ai-coding-assistants/): To integrate with AI coding assistants and ensure the code they generate is secure and high-quality. - [Cyber Resilience Act Solutions](https://www.sonarsource.com/solutions/cyber-resilience-act/): To give teams an automated verification layer that identifies vulnerabilities early and enforces security standards for Cyber Resilience Act compliance. - [Federal Government Solutions](https://www.sonarsource.com/solutions/federal-government/): To secure federal software with SonarQube, which is STIG-hardened, FIPS-compliant, and aligned with NIST SSDF. - [Enterprise Application Development](https://www.sonarsource.com/solutions/for-enterprise/application-development/): To help enterprises build, maintain, and deliver high-quality applications at scale while keeping code secure, compliant, and maintainable. - [Enterprise Reports](https://www.sonarsource.com/solutions/for-enterprise/reports/): To generate high-level enterprise reports that track code health and risk across projects. - [Enterprise Security Solutions](https://www.sonarsource.com/solutions/for-enterprise/security/): To help enterprises stay ahead of evolving security threats by integrating security analysis directly into the development process. - [Solutions for Teams](https://www.sonarsource.com/solutions/for-teams/): To unite teams around the delivery of code quality so developers can focus on building features that delight users. - [Maintainability Solutions](https://www.sonarsource.com/solutions/maintainability/): To measure and reduce technical debt to ensure long-term software maintainability. - [Reliability Solutions](https://www.sonarsource.com/solutions/reliability/): To identify logic errors and crashes that affect software reliability and performance. - [Software Supply Chain Security](https://www.sonarsource.com/solutions/software-supply-chain-security/): To secure the software supply chain with SCA, Advanced SAST, and secrets detection that block CVEs, malicious packages, and exposed tokens. - [Sonar and AWS](https://www.sonarsource.com/solutions/sonar-and-aws/): To integrate with AWS and automate code quality and security within your cloud pipeline. - [Static Code Analysis](https://www.sonarsource.com/solutions/static-code-analysis/): To use SonarQube as a central hub that consolidates coverage reports with static code analysis results for clear pass/fail quality metrics. - [Token Optimization](https://www.sonarsource.com/solutions/token-optimization/): To cut AI coding costs with better code context and verification that reduces token waste and improves code quality. ### Comparison Pages - [Gitar vs. Qodo](https://www.sonarsource.com/comparison/gitar-vs-qodo/): To compare Gitar's AI code review, which generates fixes and iterates until CI passes, against Qodo's PR Agent. - [SonarQube vs. Checkmarx](https://www.sonarsource.com/comparison/sonarqube-vs-checkmarx/): To see why engineering teams choose SonarQube's unified code quality and security platform over Checkmarx for deterministic verification and transparent pricing. - [SonarQube vs. Coverity](https://www.sonarsource.com/comparison/sonarqube-vs-coverity/): To see why modern development teams switch to SonarQube from Coverity for real-time SAST, SCA, and AI code verification without build-step delays. - [SonarQube vs. GitHub Advanced Security](https://www.sonarsource.com/comparison/sonarqube-vs-github-advanced-security/): To discover why teams choose SonarQube's independent code verification over GitHub Advanced Security to govern human- and AI-generated code across platforms. - [SonarQube vs. GitHub Code Quality](https://www.sonarsource.com/comparison/sonarqube-vs-github-code-quality/): To compare SonarQube's deep analysis, 40+ language support, and enforceable Quality Gates against GitHub Code Quality for verifying AI code. - [SonarQube vs. Semgrep](https://www.sonarsource.com/comparison/sonarqube-vs-semgrep/): To learn why engineering teams choose SonarQube's automated code verification and quality gates over Semgrep's AppSec scanning. - [SonarQube vs. Snyk](https://www.sonarsource.com/comparison/sonarqube-vs-snyk/): To discover why engineering teams choose SonarQube over Snyk for unified code quality and security that enforces maintainability and reliability, not just vulnerability detection. - [SonarQube vs. Veracode](https://www.sonarsource.com/comparison/sonarqube-vs-veracode/): To see why development teams choose SonarQube's unified platform over Veracode for faster feedback, fewer false positives, and less AppSec overhead. --- ## Integrations ### Root - [SonarSource Integrations](https://www.sonarsource.com/integrations/): To explore integrations that connect SonarSource solutions with popular development tools, CI/CD systems, and collaboration platforms to enhance code quality and security workflows. - [Integrations Overview](https://www.sonarsource.com/integrations/overview/): To get an overview of all available integrations and how they extend SonarSource products into your development ecosystem. ### SCM/CI/DevOps - [GitHub Integration](https://www.sonarsource.com/integrations/github/): To connect SonarSource code quality and security analysis with GitHub for streamlined checks and feedback in your development workflow. - [GitLab Integration](https://www.sonarsource.com/integrations/gitlab/): To integrate SonarSource analysis with GitLab CI/CD for automated quality and security checks in merge requests and pipelines. - [Bitbucket Integration](https://www.sonarsource.com/integrations/bitbucket/): To enable SonarSource code quality and security analysis within Bitbucket Cloud and Server development environments. - [Azure Integration](https://www.sonarsource.com/integrations/azure/): To explore tooling and services that connect SonarSource solutions with Microsoft Azure development and DevOps platforms. - [Azure DevOps Integration](https://www.sonarsource.com/integrations/azure/devops/): To integrate SonarSource code quality and security checks into Azure DevOps pipelines. - [Apache Maven Integration](https://www.sonarsource.com/integrations/apache/maven/): To use SonarSource static analysis with Apache Maven builds for automated quality and security insights. - [Gradle Integration](https://www.sonarsource.com/integrations/gradle/): To integrate SonarSource analysis into Gradle build processes for consistent code quality and security reporting. - [NPM Integration](https://www.sonarsource.com/integrations/npm/): To connect SonarSource static analysis with NPM workflows for monitoring JavaScript and TypeScript code quality and security. - [Docker Scout Integration](https://www.sonarsource.com/integrations/docker/scout/): To integrate Docker Scout with SonarSource analysis for enhanced container security and code quality insights. - [Jenkins Integration](https://www.sonarsource.com/integrations/jenkins/): To incorporate SonarSource code quality and security checks into Jenkins CI/CD pipelines. - [Travis CI Integration](https://www.sonarsource.com/integrations/travis-ci/): To enable SonarSource quality and security analysis in Travis CI workflows. - [CircleCI Integration](https://www.sonarsource.com/integrations/circleci/): To connect SonarSource code quality and security tools with CircleCI for continuous inspection in your builds. - [Codemagic Integration](https://www.sonarsource.com/integrations/codemagic/): To integrate SonarSource quality and security analysis into Codemagic CI/CD for mobile and cross-platform development. - [Harness Integration](https://www.sonarsource.com/integrations/harness/): To integrate SonarSource code quality and security tools with Harness CI/CD workflows. - [Amazon CodeCatalyst Integration](https://www.sonarsource.com/integrations/amazon/codecatalyst/): To use SonarSource static analysis within Amazon CodeCatalyst development environments for improved code quality and security. - [Python PyPI Integration](https://www.sonarsource.com/integrations/python/pypi/): To connect SonarSource code quality and security analysis with Python’s PyPI ecosystem for package and dependency monitoring. ### IDE Integrations - [Eclipse Integration](https://www.sonarsource.com/integrations/eclipse/): To integrate SonarSource code quality and security tools into the Eclipse IDE for continuous inspection during development. - [IntelliJ IDEA Integration](https://www.sonarsource.com/integrations/jetbrains/intellij/): To connect SonarSource static analysis with IntelliJ IDEA for real-time code quality and security feedback. - [PyCharm Integration](https://www.sonarsource.com/integrations/jetbrains/pycharm/): To use SonarSource analysis inside PyCharm for enhanced Python code quality and security insights. - [CLion Integration](https://www.sonarsource.com/integrations/jetbrains/clion/): To bring SonarSource code quality and security checks to C/C++ development inside CLion. - [Visual Studio Integration](https://www.sonarsource.com/integrations/microsoft/visual-studio/): To integrate SonarSource code quality and security analysis with Microsoft Visual Studio IDE workflows. - [Visual Studio Code Integration](https://www.sonarsource.com/integrations/microsoft/vs-code/): To connect SonarSource static analysis tools with Visual Studio Code for inline quality and security insights. - [Android Studio Integration](https://www.sonarsource.com/integrations/android/studio/): To embed SonarSource code quality and security analysis into Android Studio for mobile development. - [Cursor Integration](https://www.sonarsource.com/integrations/cursor/): To integrate SonarSource code quality and security capabilities with Cursor for enhanced coding assistance. - [Zed Integration](https://www.sonarsource.com/integrations/zed/): To connect SonarSource static analysis with the Zed editor to provide quality and security feedback during development. ### AI/LLM Integrations - [Claude Integration](https://www.sonarsource.com/integrations/claude/): To integrate SonarSource code quality and security insights with Claude for enhanced analysis and developer assistance. - [Google Gemini CLI Integration](https://www.sonarsource.com/integrations/google/gemini-cli/): To connect SonarSource’s static analysis capabilities with the Google Gemini CLI for streamlined code quality and security checks from the command line. - [Devin Windsurf Integration](https://www.sonarsource.com/integrations/devin-windsurf/): To explore the Devin Windsurf integration with SonarSource tools for extended code quality and security workflows. - [Antigravity Integration](https://www.sonarsource.com/integrations/antigravity-cli/): To keep code quality and security verification inside an Antigravity agent session, catching findings and fixes as the agent writes code. - [Codex Integration](https://www.sonarsource.com/integrations/codex-cli/): To bring code quality and security verification into Codex's agentic development workflow so the agent checks its own output before a pull request opens. - [Devin Integration](https://www.sonarsource.com/integrations/devin/): To achieve top code quality and security by integrating SonarQube with Devin's coding agent. - [GitHub Copilot CLI Integration](https://www.sonarsource.com/integrations/github-copilot-cli/): To connect SonarQube with GitHub Copilot CLI for automated code analysis that protects projects from vulnerabilities. ### Platform/Observability/Workflow - [Slack Integration](https://www.sonarsource.com/integrations/slack/): To connect SonarSource code quality and security alerts with Slack for team notifications and collaboration. - [Atlassian Jira Integration](https://www.sonarsource.com/integrations/atlassian/jira/): To integrate SonarSource static analysis with Jira for linking issues and tracking code quality and security work. - [Atlassian Compass Integration](https://www.sonarsource.com/integrations/atlassian/compass/): To connect SonarSource insights with Compass for enhanced developer experience and code quality observability. - [Port Integration](https://www.sonarsource.com/integrations/port/): To integrate SonarSource capabilities with Port for streamlined developer workflows and code quality visibility. - [JFrog Integration](https://www.sonarsource.com/integrations/jfrog/): To connect SonarSource analysis with JFrog tools for artifact management and improved code quality and security tracking. - [Jellyfish Integration](https://www.sonarsource.com/integrations/jellyfish/): To integrate SonarSource quality and security data with Jellyfish for engineering productivity insights. - [Datadog Integration](https://www.sonarsource.com/integrations/datadog/): To send SonarSource metrics and alerts to Datadog for monitoring code quality and security performance. - [MuleSoft Integration](https://www.sonarsource.com/integrations/mulesoft/): To integrate SonarSource code quality and security insights with MuleSoft for API and integration lifecycle visibility. - [SAP Integration](https://www.sonarsource.com/integrations/sap/): To connect SonarSource static analysis with SAP development environments to enhance code quality and security across enterprise landscapes. --- ## Languages - [Multi-language Analysis Tools](https://www.sonarsource.com/knowledge/languages/): To provide resources and tools for effective static code analysis across multiple programming languages. ### Individual Languages - [Java Language Resources](https://www.sonarsource.com/knowledge/languages/java/): To explore best practices, static analysis guidance, and code quality and security insights for Java development. - [JavaScript Language Resources](https://www.sonarsource.com/knowledge/languages/js/): To access code quality and security resources for JavaScript development, including modern frontend and backend frameworks. - [Python Language Resources](https://www.sonarsource.com/knowledge/languages/python/): To learn about static code analysis and secure coding practices for Python applications. - [C# Language Resources](https://www.sonarsource.com/knowledge/languages/csharp/): To improve code quality and security in C# and .NET projects with tailored analysis guidance. - [Go Language Resources](https://www.sonarsource.com/knowledge/languages/go/): To explore code quality and security recommendations for Go (Golang) development. - [Kubernetes Configuration Resources](https://www.sonarsource.com/knowledge/languages/kubernetes/): To strengthen security and reliability in Kubernetes manifests and configuration files. - [Flex Language Resources](https://www.sonarsource.com/knowledge/languages/flex/): To access static analysis and code quality insights for Flex applications. - [Swift Language Resources](https://www.sonarsource.com/knowledge/languages/swift/): To enhance code quality and security in Swift applications for Apple platforms. - [C++ Language Resources](https://www.sonarsource.com/knowledge/languages/cpp/): To apply advanced static analysis and secure coding practices in C++ development. - [PHP Language Resources](https://www.sonarsource.com/knowledge/languages/php/): To improve PHP code quality and security with actionable static analysis guidance. - [COBOL Language Resources](https://www.sonarsource.com/knowledge/languages/cobol/): To modernize and secure legacy COBOL systems with improved code quality practices. - [T-SQL Language Resources](https://www.sonarsource.com/knowledge/languages/t-sql/): To strengthen database code quality and security in T-SQL scripts and stored procedures. - [Terraform Resources](https://www.sonarsource.com/knowledge/languages/terraform/): To enhance infrastructure-as-code security and maintainability in Terraform configurations. - [VB6 Language Resources](https://www.sonarsource.com/knowledge/languages/vb6/): To support quality improvements and maintainability in legacy Visual Basic 6 applications. - [ABAP Language Resources](https://www.sonarsource.com/knowledge/languages/abap/): To improve code quality and security within SAP ABAP development environments. - [PL/I Language Resources](https://www.sonarsource.com/knowledge/languages/pli/): To access static analysis guidance for maintaining and modernizing PL/I applications. - [RPG Language Resources](https://www.sonarsource.com/knowledge/languages/rpg/): To strengthen code quality and reliability in IBM RPG systems. - [Ruby Language Resources](https://www.sonarsource.com/knowledge/languages/ruby/): To apply code quality and security best practices in Ruby applications and frameworks. - [CSS Resources](https://www.sonarsource.com/knowledge/languages/css/): To improve maintainability and quality in CSS stylesheets. - [VB.NET Language Resources](https://www.sonarsource.com/knowledge/languages/vb-net/): To enhance code quality and security in VB.NET applications. - [Objective-C Language Resources](https://www.sonarsource.com/knowledge/languages/objective-c/): To strengthen code quality and security in Objective-C development. - [Scala Language Resources](https://www.sonarsource.com/knowledge/languages/scala/): To improve Scala code quality and reliability with static analysis best practices. - [XML Resources](https://www.sonarsource.com/knowledge/languages/xml/): To ensure well-formed, secure, and maintainable XML configurations and data files. - [Kotlin Language Resources](https://www.sonarsource.com/knowledge/languages/kotlin/): To enhance Kotlin application quality and security with targeted static analysis. - [Docker Resources](https://www.sonarsource.com/knowledge/languages/docker/): To improve container configuration quality and security in Dockerfiles. - [PL/SQL Language Resources](https://www.sonarsource.com/knowledge/languages/pl-sql/): To strengthen database code quality and security in PL/SQL development. - [Dart Language Resources](https://www.sonarsource.com/knowledge/languages/dart/): To improve code quality and security in Dart applications, including Flutter projects. - [AWS CloudFormation Resources](https://www.sonarsource.com/knowledge/languages/cloudformation/): To enhance security and maintainability in AWS CloudFormation infrastructure templates. - [C Language Resources](https://www.sonarsource.com/knowledge/languages/c/): To apply static analysis and secure coding practices to C development projects. - [Rust Language Resources](https://www.sonarsource.com/knowledge/languages/rust/): To improve reliability, safety, and code quality in Rust applications. - [TypeScript Language Resources](https://www.sonarsource.com/knowledge/languages/ts/): To strengthen code quality and security in TypeScript-based applications. - [HTML Resources](https://www.sonarsource.com/knowledge/languages/html/): To ensure maintainable and standards-compliant HTML code. - [Apex Language Resources](https://www.sonarsource.com/knowledge/languages/apex/): To improve code quality and security in Salesforce Apex development. - [Azure Resource Manager Resources](https://www.sonarsource.com/knowledge/languages/azure-resource-manager/): To enhance infrastructure-as-code quality and security in Azure Resource Manager templates. - [MISRA C++ 2023 Resources](https://www.sonarsource.com/knowledge/languages/cpp/misra-cpp-2023/): To apply MISRA C++ 2023 guidelines for safer, standards-compliant C++ development. --- ## Resources ### Root - [SonarSource Resources](https://www.sonarsource.com/resources/): To explore educational content, insights, and materials focused on improving code quality and security across the software development lifecycle. ### Library - [Resource Library](https://www.sonarsource.com/resources/library/): To browse the full library of guides, articles, reports, and thought leadership on code quality and security. - [Guides](https://www.sonarsource.com/resources/library/guide/): To access in-depth guides covering best practices for code quality, secure coding, and modern development workflows. - [Articles](https://www.sonarsource.com/resources/library/article/): To read expert articles and perspectives on code quality, security, and software engineering trends. ### Library Articles - [Refactoring Guide](https://www.sonarsource.com/resources/library/refactoring/): To learn best practices for code refactoring to improve maintainability, reduce technical debt, and enhance overall software quality. - [Preventing the Trojan Horse in Your Dependencies](https://www.sonarsource.com/resources/library/preventing-the-trojan-horse-in-your-dependencies/): To understand how to protect your software supply chain from malicious dependencies and hidden security risks. - [What Is GitLab?](https://www.sonarsource.com/resources/library/what-is-gitlab/): To explore GitLab’s role in DevOps workflows and how it supports code quality and security practices. - [AI Coding Assistants](https://www.sonarsource.com/resources/library/ai-coding-assistants/): To examine the benefits and risks of AI-powered coding assistants in modern software development. - [Enable Azure OpenAI Instance for AI CodeFix](https://www.sonarsource.com/resources/library/enable-azure-openai-instance-for-ai-codefix/): To configure Azure OpenAI for AI CodeFix to enhance automated code quality and security remediation. - [Shift Left](https://www.sonarsource.com/resources/library/shift-left/): To understand the shift-left approach and how early code analysis improves software quality and application security. - [.NET Developer Guide: Automating Quality](https://www.sonarsource.com/resources/library/net-developer-guide-automating-quality/): To automate code quality and security checks in .NET development workflows. - [AI Code Generation](https://www.sonarsource.com/resources/library/ai-code-generation/): To explore how AI code generation impacts developer productivity, quality, and security. - [Integrated Development Environment (IDE)](https://www.sonarsource.com/resources/library/ide/): To understand the role of IDEs in improving developer efficiency and enforcing code quality standards. - [Code Coverage](https://www.sonarsource.com/resources/library/code-coverage/): To learn how measuring code coverage helps ensure test effectiveness and software quality. - [OWASP Guide](https://www.sonarsource.com/resources/library/owasp/): To understand OWASP standards and how they help improve application security and reduce common vulnerabilities. - [Static Code Analysis Using SonarQube](https://www.sonarsource.com/resources/library/static-code-analysis-using-sonarqube/): To learn how static code analysis with SonarQube improves code quality and security across the SDLC. - [Common Vulnerabilities and Exposures (CVE)](https://www.sonarsource.com/resources/library/common-vulnerabilities-exposures/): To understand how CVEs identify, track, and mitigate publicly disclosed security vulnerabilities. - [Source Code Review](https://www.sonarsource.com/resources/library/source-code-review/): To explore best practices for source code review to improve maintainability, security, and software quality. - [Source Code Management](https://www.sonarsource.com/resources/library/source-code-management/): To learn how effective source code management supports collaboration, traceability, and DevOps efficiency. - [Code Quality 2026](https://www.sonarsource.com/resources/library/code-quality-2026/): To explore emerging trends shaping the future of code quality and secure software development. - [Automated Code Scanning](https://www.sonarsource.com/resources/library/automated-code-scanning/): To understand how automated scanning detects vulnerabilities, bugs, and code smells early in development. - [AI-Assisted Software Development](https://www.sonarsource.com/resources/library/ai-assisted-software-development/): To examine how AI tools enhance development workflows while maintaining code quality and security standards. - [Debugging Guide](https://www.sonarsource.com/resources/library/debugging/): To improve debugging practices and reduce defects in complex software systems. - [Monorepo Guide](https://www.sonarsource.com/resources/library/monorepo/): To understand the benefits and challenges of managing code quality in monorepo architectures. - [Synchronizing SonarQube for IDE with Your Project – Part 2](https://www.sonarsource.com/resources/library/synchronizing-sonarqube-for-ide-with-your-project-part-2/): To learn how to properly synchronize SonarQube for IDE with your project for consistent code quality and security feedback. - [Technical Debt](https://www.sonarsource.com/resources/library/technical-debt/): To understand how technical debt accumulates and how to measure, manage, and reduce it effectively. - [DevOps Guide](https://www.sonarsource.com/resources/library/devops/): To explore DevOps principles and how continuous code quality and security integrate into modern pipelines. - [Infrastructure as Code (IaC)](https://www.sonarsource.com/resources/library/infrastructure-as-code/): To strengthen security and maintainability in infrastructure-as-code practices. - [Detect Secrets in the IDE with SonarQube for IDE](https://www.sonarsource.com/resources/library/detect-secrets-in-the-ide-with-sonarlint/): To prevent hard-coded secrets and sensitive data exposure directly within the IDE. - [Platform Engineering Guide](https://www.sonarsource.com/resources/library/platform-engineering-guide/): To understand how platform engineering improves developer experience and governance at scale. - [CI/CD Guide](https://www.sonarsource.com/resources/library/ci-cd/): To learn how continuous integration and continuous delivery pipelines enforce code quality and security gates. - [Application Security Posture Management (ASPM)](https://www.sonarsource.com/resources/library/application-security-posture-management/): To explore strategies for continuously monitoring and improving application security posture. - [Audit Logging](https://www.sonarsource.com/resources/library/audit-logging/): To understand the role of audit logging in compliance, traceability, and security monitoring. - [OpenSSF Scorecard](https://www.sonarsource.com/resources/library/openssf-scorecard/): To evaluate open-source project security using OpenSSF Scorecard best practices. - [Open Source Package](https://www.sonarsource.com/resources/library/open-source-package/): To understand the risks and governance considerations of using open source packages in modern software development. - [Open Source License](https://www.sonarsource.com/resources/library/open-source-license/): To learn about open source licensing models and how they impact compliance and software distribution. - [Code Review](https://www.sonarsource.com/resources/library/code-review/): To explore best practices for effective code review to improve software quality, maintainability, and security. - [Software Quality Assurance (SQA)](https://www.sonarsource.com/resources/library/software-quality-assurance/): To understand how structured quality assurance processes strengthen overall software quality and reliability. - [Static Application Security Testing (SAST)](https://www.sonarsource.com/resources/library/sast/): To learn how SAST tools detect vulnerabilities and security weaknesses early in the development lifecycle. - [Software Composition Analysis (SCA)](https://www.sonarsource.com/resources/library/software-composition-analysis/): To discover how SCA identifies risks in third-party and open source dependencies. - [A Java Developer’s Guide to SonarQube for IDE – Part 1](https://www.sonarsource.com/resources/library/a-java-developer-s-guide-to-sonarqube-for-ide-part-1/): To get started using SonarQube for IDE to improve Java code quality and security during development. - [SonarQube for IDE Plug-in for Cursor](https://www.sonarsource.com/resources/library/sq-ide-plug-in-for-cursor/): To integrate SonarQube for IDE into Cursor for real-time code quality and security insights. - [Audit Trailing](https://www.sonarsource.com/resources/library/audit-trailing/): To understand audit trailing practices for improving traceability and regulatory compliance. - [Data Resiliency](https://www.sonarsource.com/resources/library/data-resiliency/): To explore strategies for ensuring data durability, recovery, and system reliability. - [Code Smells](https://www.sonarsource.com/resources/library/code-smells/): To understand common code smells and how eliminating them improves maintainability and reduces technical debt. - [.NET Developer Guide: Interpreting Results and Mastering Quality Gates](https://www.sonarsource.com/resources/library/net-developer-guide-interpreting-results-and-mastering-quality-gates/): To learn how to interpret analysis results and enforce quality gates in .NET projects. - [What Is GitHub?](https://www.sonarsource.com/resources/library/what-is-github/): To understand GitHub’s role in source code management and collaborative software development. - [7 Habits of Highly Effective AI Coding](https://www.sonarsource.com/resources/library/7-habits-of-highly-effective-ai-coding/): To adopt best practices for using AI coding assistants while maintaining code quality and security. - [What Is Pair Programming?](https://www.sonarsource.com/resources/library/what-is-pair-programming/): To explore the benefits of pair programming for improving collaboration and software quality. - [SonarQube for IDE Extensions for Visual Studio](https://www.sonarsource.com/resources/library/sonarqube-ide-extensions-visual-studio/): To integrate SonarQube for IDE into Visual Studio for real-time quality and security feedback. - [Software Development Lifecycle (SDLC)](https://www.sonarsource.com/resources/library/sdlc/): To understand the phases of the SDLC and how code quality and security practices fit into each stage. - [Integrating the SonarQube MCP Server with Google Antigravity IDE](https://www.sonarsource.com/resources/library/integrating-the-sonarqube-mcp-server-with-google-antigravity-ide/): To configure and integrate SonarQube MCP Server for enhanced IDE-based analysis. - [SLSA (Supply-chain Levels for Software Artifacts)](https://www.sonarsource.com/resources/library/slsa/): To learn about SLSA standards and strengthening software supply chain security. - [Software Supply Chain Security](https://www.sonarsource.com/resources/library/software-supply-chain-security/): To understand risks in the software supply chain and how to mitigate them. - [Guide to Avoiding Common Software Performance Issues](https://www.sonarsource.com/resources/library/guide-to-avoiding-common-software-performance-issues/): To identify and prevent common performance bottlenecks that impact software reliability and user experience. - [Software Composition Analysis (SCA) Tools](https://www.sonarsource.com/resources/library/software-composition-analysis-sca-tools/): To evaluate SCA tools that detect vulnerabilities and license risks in third-party dependencies. - [What Is PL/SQL?](https://www.sonarsource.com/resources/library/what-is-pl-sql/): To understand PL/SQL fundamentals and how to maintain secure, high-quality database code. - [Critical Code Issues](https://www.sonarsource.com/resources/library/critical-code-issues/): To learn how to identify and prioritize critical issues that threaten code quality and security. - [Open Source Maintainers](https://www.sonarsource.com/resources/library/open-source-maintainers/): To explore the role of open source maintainers in sustaining secure and reliable software ecosystems. - [Exploits](https://www.sonarsource.com/resources/library/exploits/): To understand how exploits work and how proactive code analysis reduces vulnerability exposure. - [Setup SonarQube for IDE Plug-in for IntelliJ](https://www.sonarsource.com/resources/library/setup-sq-ide-plugin-for-intellij/): To configure SonarQube for IDE in IntelliJ for real-time code quality and security feedback. - [Analyze Java Code Using SonarQube Cloud](https://www.sonarsource.com/resources/library/analyze-java-code-using-sonarcloud/): To learn how to analyze Java projects using SonarQube Cloud for automated code quality and security checks. - [Secure Coding](https://www.sonarsource.com/resources/library/secure-coding/): To adopt secure coding practices that prevent vulnerabilities and strengthen application security. - [The Strategic Shift to AI-Native IDEs](https://www.sonarsource.com/resources/library/the-strategic-shift-to-ai-native-ides/): To explore how AI-native IDEs are transforming developer workflows while maintaining quality and security standards. - [How to Integrate SonarQube with Windsurf IDE](https://www.sonarsource.com/resources/library/how-to-integrate-sonarqube-with-windsurf-ide/): To configure SonarQube integration with Windsurf IDE for continuous code quality and security feedback. - [OWASP and LLM Code Generation](https://www.sonarsource.com/resources/library/owasp-llm-code-generation/): To understand OWASP guidance related to large language model (LLM) code generation risks and security considerations. - [LLM Deployment Choice](https://www.sonarsource.com/resources/library/llm-deployment-choice/): To evaluate deployment models for large language models and their implications for security and compliance. - [Autoscaling](https://www.sonarsource.com/resources/library/autoscaling/): To explore autoscaling strategies that improve system performance, resilience, and cost efficiency. - [DevSecOps](https://www.sonarsource.com/resources/library/devsecops/): To integrate security practices directly into DevOps pipelines for continuous application security. - [Error Handling Guide](https://www.sonarsource.com/resources/library/error-handling-guide/): To implement robust error handling practices that improve reliability and maintainability. - [Static Code Analysis](https://www.sonarsource.com/resources/library/static-code-analysis/): To understand how static code analysis detects bugs, vulnerabilities, and code smells early in development. - [Integrating SonarQube MCP Server with Cursor](https://www.sonarsource.com/resources/library/integrating-sonarqube-mcp-server-with-cursor/): To connect the SonarQube MCP Server with Cursor for enhanced IDE-based analysis. - [Code Review in Continuous Integration](https://www.sonarsource.com/resources/library/code-review-continuous-integration/): To combine code review practices with CI workflows to enforce quality gates automatically. - [Threat Intelligence](https://www.sonarsource.com/resources/library/threat-intelligence/): To leverage threat intelligence to proactively manage software vulnerabilities and security risks. - [SonarQube for IDE Extension for VS Code](https://www.sonarsource.com/resources/library/sq-ide-extension-for-vscode/): To integrate SonarQube for IDE into Visual Studio Code for real-time code quality and security feedback. - [Cybersecurity Regulatory Compliance](https://www.sonarsource.com/resources/library/cybersecurity-regulatory-compliance/): To understand how regulatory requirements impact application security and development practices. - [What Is Bitbucket?](https://www.sonarsource.com/resources/library/what-is-bitbucket/): To explore Bitbucket’s role in source code management and CI/CD workflows. - [Cyclomatic Complexity](https://www.sonarsource.com/resources/library/cyclomatic-complexity/): To understand how cyclomatic complexity measures code maintainability and risk. - [What Is SCA Scanning?](https://www.sonarsource.com/resources/library/what-is-sca-scanning/): To learn how software composition analysis scanning detects vulnerable dependencies. - [Linter](https://www.sonarsource.com/resources/library/linter/): To understand how linters enforce coding standards and improve software quality. - [Integrate SonarQube for IDE and GitHub Copilot in VS Code](https://www.sonarsource.com/resources/library/integrate-sonarqube-for-ide-and-github-copilot-in-visual-studio-code/): To combine AI coding assistance with real-time code quality and security checks in VS Code. - [Source Code](https://www.sonarsource.com/resources/library/source-code/): To understand the importance of well-structured, maintainable source code in software development. - [Remote Code Execution (RCE)](https://www.sonarsource.com/resources/library/remote-code-execution/): To learn how remote code execution vulnerabilities occur and how to prevent them. - [Application Security](https://www.sonarsource.com/resources/library/application-security/): To explore practices and tools that strengthen application security throughout the SDLC. - [What Is Azure DevOps?](https://www.sonarsource.com/resources/library/what-is-azure-devops/): To understand Azure DevOps services and how they support CI/CD and collaborative development workflows. - [Open Source](https://www.sonarsource.com/resources/library/open-source/): To explore the benefits, risks, and governance considerations of using open source software. - [AI Agents in the SDLC](https://www.sonarsource.com/resources/library/ai-agents-in-sdlc/): To examine how AI agents are influencing the software development lifecycle while maintaining code quality and security. - [SonarQube on AWS EKS (Kubernetes)](https://www.sonarsource.com/resources/library/sonarqube-aws-eks-kubernetes/): To deploy SonarQube on AWS EKS for scalable, cloud-native code quality and security analysis. - [Why Use a Linter?](https://www.sonarsource.com/resources/library/why-linter/): To understand how linters improve coding standards, maintainability, and defect prevention. - [C Programming Language](https://www.sonarsource.com/resources/library/c-programming-language/): To explore best practices for writing secure and maintainable C code. - [Developer Compliance](https://www.sonarsource.com/resources/library/developer-compliance/): To align development practices with regulatory and organizational compliance requirements. - [Introduction to AI CodeFix](https://www.sonarsource.com/resources/library/introduction-to-ai-codefix/): To learn how AI CodeFix helps remediate code quality and security issues efficiently. - [Enabling Anthropic Claude 3.7 Sonnet for AI CodeFix](https://www.sonarsource.com/resources/library/enabling-anthropic-claude-3-7-sonnet-for-ai-codefix/): To configure Claude 3.7 Sonnet to support AI CodeFix capabilities. - [Vulnerability Management](https://www.sonarsource.com/resources/library/vulnerability-management/): To implement effective vulnerability management processes for secure software delivery. - [What Is C#?](https://www.sonarsource.com/resources/library/what-is-c-sharp/): To understand the fundamentals of C# and how to maintain high code quality and security in .NET development. - [Code Scanning](https://www.sonarsource.com/resources/library/code-scanning/): To explore how automated code scanning detects bugs, vulnerabilities, and maintainability issues early. - [How-to Guide for AI Code Assurance](https://www.sonarsource.com/resources/library/how-to-guide-for-ai-code-assurance/): To implement AI-driven code assurance practices that strengthen quality and security. - [Code Base in Software Development](https://www.sonarsource.com/resources/library/code-base-in-software-development/): To understand how managing a codebase effectively improves maintainability and reduces technical debt. - [Complying with AI Policies in Code Development](https://www.sonarsource.com/resources/library/complying-with-ai-policies-in-code-development/): To align AI-assisted development practices with governance and compliance requirements. - [What Is Jira?](https://www.sonarsource.com/resources/library/what-is-jira/): To explore Jira’s role in issue tracking and DevOps collaboration. - [Improve Your DevOps Pipeline](https://www.sonarsource.com/resources/library/improve-your-devops-pipeline/): To optimize DevOps pipelines with integrated code quality and security controls. - [What Is Bug Detection?](https://www.sonarsource.com/resources/library/what-is-bug-detection/): To understand how automated and manual techniques identify software defects. - [Software Bill of Materials (SBOM)](https://www.sonarsource.com/resources/library/software-bill-of-materials/): To learn how SBOMs improve software supply chain transparency and security. - [.NET Developer Guide: Analyzation](https://www.sonarsource.com/resources/library/net-developer-guide-analyzation/): To analyze .NET projects effectively using automated code quality and security tools. - [Getting Started with SonarQube Cloud](https://www.sonarsource.com/resources/library/getting-started-with-sonarqube-cloud/): To begin using SonarQube Cloud for automated code quality and security analysis in your CI/CD workflows. - [Quality Gate](https://www.sonarsource.com/resources/library/quality-gate/): To understand how quality gates enforce code quality and security standards before code is merged or deployed. - [Software Bugs](https://www.sonarsource.com/resources/library/software-bugs/): To explore the causes of software bugs and how proactive code analysis helps prevent them. - [Strategies for Managing Code Quality in Outsourced Software Development](https://www.sonarsource.com/resources/library/strategies-for-managing-code-quality-in-outsourced-software-development/): To maintain code quality, security, and governance when working with distributed or outsourced teams. - [DevOps Transformation with Static Code Analysis](https://www.sonarsource.com/resources/library/devops-transformation-static-code-analysis/): To drive DevOps transformation by embedding static code analysis into continuous delivery pipelines. - [AI Code Generation: Benefits and Risks](https://www.sonarsource.com/resources/library/ai-code-generation-benefits-risks/): To evaluate the productivity gains and security risks of AI-generated code. - [Generative AI Coding Velocity](https://www.sonarsource.com/resources/library/generative-ai-coding-velocity/): To balance increased AI-driven development speed with sustainable code quality and security. - [NIST SSDF](https://www.sonarsource.com/resources/library/nist-ssdf/): To align development practices with the NIST Secure Software Development Framework. - [Security Technical Implementation Guide (STIG)](https://www.sonarsource.com/resources/library/security-technical-implementation-guide/): To understand STIG requirements and strengthen compliance in secure software development. - [Vibe Coding](https://www.sonarsource.com/resources/library/vibe-coding/): To explore emerging AI-driven coding workflows while maintaining engineering rigor and quality standards. - [Swift Programming Language](https://www.sonarsource.com/resources/library/swift-programming-language/): To explore Swift fundamentals and best practices for writing secure, maintainable applications. - [Developer Security Guide](https://www.sonarsource.com/resources/library/developer-security-guide/): To implement secure coding practices that reduce vulnerabilities and strengthen application security. - [LLM Code Generation](https://www.sonarsource.com/resources/library/llm-code-generation/): To understand how large language models generate code and how to manage associated quality and security risks. - [Secure by Design Starts with Code Quality](https://www.sonarsource.com/resources/library/secure-by-design-starts-with-code-quality/): To embed secure-by-design principles directly into development through strong code quality standards. - [Integrating SonarQube Cloud with Azure](https://www.sonarsource.com/resources/library/integrating-sonarcloud-with-azure/): To connect SonarQube Cloud with Azure DevOps for automated quality and security analysis. - [Software Compliance](https://www.sonarsource.com/resources/library/software-compliance/): To align development workflows with regulatory, licensing, and internal compliance requirements. - [Measuring and Identifying Code-Level Technical Debt: A Practical Guide](https://www.sonarsource.com/resources/library/measuring-and-identifying-code-level-technical-debt-a-practical-guide/): To quantify, track, and reduce technical debt at the code level. - [Amazon Q and Code Quality](https://www.sonarsource.com/resources/library/amazon-q-code-quality/): To integrate Amazon Q workflows while maintaining strong code quality and security controls. - [AutoConfig for C and C++](https://www.sonarsource.com/resources/library/autoconfig-for-c-and-cpp/): To simplify static analysis configuration for C and C++ projects. - [Integrating Quality Gates into CI/CD Pipelines](https://www.sonarsource.com/resources/library/integrating-quality-gates-ci-cd-pipeline/): To enforce automated quality gates within CI/CD pipelines for consistent governance. - [SonarQube README Badges](https://www.sonarsource.com/resources/library/sonarqube-readme-badges/): To display code quality and security status directly in your repository README files. - [Code Secrets](https://www.sonarsource.com/resources/library/code-secrets/): To detect and prevent hard-coded secrets that expose applications to security risks. - [Application Programming Interface (API)](https://www.sonarsource.com/resources/library/application-programming-interface/): To understand APIs and how to secure them within modern software architectures. - [Code Standardization and Risk Mitigation in Software Development](https://www.sonarsource.com/resources/library/code-standardization-and-risk-mitigation-in-software-development/): To reduce risk and improve maintainability through consistent coding standards. - [GitHub Copilot and AI-Generated Code](https://www.sonarsource.com/resources/library/github-copilot-ai-generated-code/): To manage the risks and quality implications of AI-generated code from GitHub Copilot. - [Open Source Intelligence](https://www.sonarsource.com/resources/library/open-source-intelligence/): To leverage open source intelligence to identify risks and vulnerabilities in dependencies. - [Model Context Protocol (MCP)](https://www.sonarsource.com/resources/library/model-context-protocol/): To understand how MCP supports AI tool integrations in development environments. - [Outsourced Software Development and Scope Creep](https://www.sonarsource.com/resources/library/outsourced-software-development-and-scope-creep-three-ways-to-manage-teams-at-the-code-level/): To manage scope, quality, and technical debt when working with outsourced teams. - [Kubernetes Guide](https://www.sonarsource.com/resources/library/kubernetes/): To strengthen Kubernetes configurations and improve infrastructure security and reliability. - [Integrating SonarQube Cloud with GitHub](https://www.sonarsource.com/resources/library/integrating-sonarcloud-with-github/): To connect SonarQube Cloud with GitHub for automated pull request analysis and quality gates. - [Secrets Management](https://www.sonarsource.com/resources/library/secrets-management/): To implement effective secrets management practices that prevent credential leaks and security breaches. - [Integrating SonarQube Cloud with GitLab](https://www.sonarsource.com/resources/library/integrating-sonarcloud-with-gitlab/): To connect SonarQube Cloud with GitLab CI/CD for automated code quality and security checks. - [Shift-Left Security: Advancing Early-Stage Security Integration](https://www.sonarsource.com/resources/library/shift-left-security-advancing-early-stage-security-integration/): To embed security earlier in the development lifecycle to reduce risk and remediation costs. - [FIPS](https://www.sonarsource.com/resources/library/fips/): To understand Federal Information Processing Standards (FIPS) and their relevance to secure software development. - [DevOps Implementation Guide](https://www.sonarsource.com/resources/library/devops-implementation-guide/): To implement DevOps practices that integrate continuous code quality and security controls. - [Distributed Software Development: A Guide to Achieving Code Quality](https://www.sonarsource.com/resources/library/distributed-software-development-a-guide-to-achieving-code-quality/): To maintain consistent code quality across distributed and remote teams. - [SARIF](https://www.sonarsource.com/resources/library/sarif/): To understand the Static Analysis Results Interchange Format (SARIF) and how it standardizes security reporting. - [Google Gemini Code Assist and Code Quality](https://www.sonarsource.com/resources/library/google-gemini-code-assist-quality/): To evaluate Google Gemini Code Assist while maintaining strong code quality and security standards. - [Agentic Automation](https://www.sonarsource.com/resources/library/agentic-automation/): To learn how agentic automation lets AI agents plan, act, and adapt toward a goal, and how to govern it safely. - [Agentic Coding](https://www.sonarsource.com/resources/library/agentic-coding/): To understand agentic coding, how it differs from vibe coding, and how SonarQube helps eliminate verification debt. - [AI Coding Tools and Security Risks](https://www.sonarsource.com/resources/library/ai-coding-tools-security-risks/): To learn the most common AI-generated vulnerabilities, such as SQL injection, XSS, and SSRF, and how to automate the fix. - [AI Guardrails](https://www.sonarsource.com/resources/library/ai-guardrails/): To learn the failure modes, guardrail types, and governance patterns enterprise teams need to keep AI-assisted coding safe. - [AI Technical Debt](https://www.sonarsource.com/resources/library/ai-technical-debt/): To understand how AI technical debt compounds, how it differs from conventional debt, and how to keep it in check. - [Best AI Code Review Tools](https://www.sonarsource.com/resources/library/best-ai-code-review-tools/): To discover the best AI code review tools for scaling PR verification and eliminating false-positive noise with context-aware AI. - [Code Review MCP Server](https://www.sonarsource.com/resources/library/code-review-mcp-server/): To learn how a code review MCP server connects AI agents to code analysis so reviews run inside the development workflow. - [Code Verification](https://www.sonarsource.com/resources/library/code-verification/): To explore static analysis, quality gates, and how to maintain code health as AI-generated code volume grows. - [Configure OpenCode CLI for Sonar Context Augmentation and Agentic Analysis](https://www.sonarsource.com/resources/library/configure-opencode-cli-for-sonar-context-augmentation-and-agentic-analysis/): To connect OpenCode CLI with SonarQube Cloud to guide AI code generation and verify fixes using a project-scoped MCP setup. - [Configure Zed for Sonar Context Augmentation and Agentic Analysis](https://www.sonarsource.com/resources/library/configure-zed-for-sonar-context-augmentation-and-agentic-analysis/): To integrate Zed and SonarQube Cloud to guide code edits and verify quality with automated analysis tools. - [Cyber Resilience Act by Industry](https://www.sonarsource.com/resources/library/cyber-resilience-act-by-industry/): To learn which industries and products are affected by the Cyber Resilience Act, what's exempt, and key compliance deadlines. - [Cyber Resilience Act Compliance for AI-Generated Code](https://www.sonarsource.com/resources/library/cyber-resilience-act-compliance-for-ai-generated-code/): To apply deterministic analysis, quality gates, SCA, SBOMs, and evidence workflows to strengthen CRA compliance for AI-generated code. - [DORA Compliance for Software Teams](https://www.sonarsource.com/resources/library/dora-compliance-software-teams/): To learn how DORA compliance translates into secure development, ICT risk management, resilience testing, and DevSecOps controls. - [Fix Backlog Issues with the SonarQube Remediation Agent](https://www.sonarsource.com/resources/library/fix-backlog-issues-with-the-sonarqube-remediation-agent/): To learn how SonarQube Cloud's Remediation Agent fixes main branch issues with validated pull requests. - [Fix Backlog Issues with the SonarQube Remediation Agent on Azure DevOps](https://www.sonarsource.com/resources/library/fix-backlog-issues-with-the-sonarqube-remediation-agent-on-azure-devops/): To learn how the SonarQube Remediation Agent cleans up Azure Repos issue backlogs with validated pull requests. - [Fix Pull Request Issues with the SonarQube Remediation Agent](https://www.sonarsource.com/resources/library/fix-pull-request-issues-with-the-sonarqube-remediation-agent/): To learn how SonarQube Cloud's Remediation Agent detects issues and delivers verified fixes as pull requests you control. - [Get Started with Gitar](https://www.sonarsource.com/resources/library/get-started-with-gitar/): To install the Gitar GitHub App, review pull requests, and request AI-generated code fixes directly in PRs. - [Get Started with Sonar Context Augmentation and Codex CLI](https://www.sonarsource.com/resources/library/get-started-with-sonar-context-augmentation-and-codex-cli/): To configure Sonar Context Augmentation with Codex CLI so it loads SonarQube Cloud guidelines before coding. - [Get Started with SonarQube Agentic Analysis and Codex CLI](https://www.sonarsource.com/resources/library/get-started-with-sonarqube-agentic-analysis-and-codex-cli/): To configure SonarQube Cloud Agentic Analysis in Codex CLI for CI-level code verification with automated fix loops. - [Get Started with SonarQube Agentic Analysis Using Claude Code](https://www.sonarsource.com/resources/library/get-started-with-sonarqube-agentic-analysis-using-claude-code/): To run CI-grade code quality and security analysis inside Claude Code using SonarQube Agentic Analysis. - [Get Started with SonarQube MCP Server and Gemini Code Assist Agent Mode](https://www.sonarsource.com/resources/library/get-started-with-sonarqube-mcp-server-and-gemini-code-assist-agent-mode/): To connect Gemini Code Assist with the SonarQube Cloud MCP Server to scan, fix, and enforce code quality before review. - [Get Started with the SonarQube Remediation Agent](https://www.sonarsource.com/resources/library/get-started-with-the-sonarqube-remediation-agent/): To learn how the SonarQube Remediation Agent reduces technical debt by creating verified pull requests for security and quality issues. - [Gitar Context Ingestion for Project-Aware Code Reviews](https://www.sonarsource.com/resources/library/gitar-context-ingestion-for-project-aware-code-reviews/): To configure Gitar with project instructions and repository rules for more relevant, convention-aware code reviews. - [Integrating Claude Code with SonarQube MCP Server](https://www.sonarsource.com/resources/library/integrating-claude-code-with-sonarqube-mcp-server/): To connect Claude Code to the SonarQube MCP Server as part of a broader shift toward AI agents performing complex development tasks. - [ISO/IEC 25010 Explained](https://www.sonarsource.com/resources/library/iso-iec-25010-explained/): To explore ISO/IEC 25010 and its nine quality characteristics for boosting code quality, security, and reliability at scale. - [Linting Is Not All You Need](https://www.sonarsource.com/resources/library/linting-is-not-all-you-need/): To discover how SonarQube uncovers hidden vulnerabilities across files with taint and data flow analysis that linters miss. - [LLM Cost Optimization](https://www.sonarsource.com/resources/library/llm-cost-optimization/): To learn practical LLM cost optimization techniques and how cleaner codebases cut the tokens coding agents burn. - [Multilayered Code Verification with Gitar and SonarQube Cloud](https://www.sonarsource.com/resources/library/multilayered-code-verification-with-gitar-sonarqube-cloud/): To combine Gitar and SonarQube Cloud in one GitHub repo for independent AI code review, CI fixes, and quality gate checks. - [SCA Pre-Commit Hook with SonarQube CLI](https://www.sonarsource.com/resources/library/sca-pre-commit-hook-sonarqube-cli/): To set up an SCA pre-commit hook that detects vulnerable dependencies and blocks new dependency risks before they reach the repository. - [Scale Gitar Context Across an Organization](https://www.sonarsource.com/resources/library/scale-gitar-context-across-an-organization/): To scale Gitar context across repositories with organization instructions, Jira objectives, and custom integrations. - [Set Up Sonar Context Augmentation with GitHub Copilot CLI](https://www.sonarsource.com/resources/library/set-up-sonar-context-augmentation-with-github-copilot-cli/): To configure Sonar Context Augmentation for Copilot CLI so agents follow project architecture and coding standards. - [Set Up the SonarQube Plugin for Antigravity](https://www.sonarsource.com/resources/library/set-up-the-sonarqube-plugin-for-antigravity/): To set up the SonarQube plugin for Antigravity with skills, MCP Server, hooks, rules, and secrets scanning. - [Set Up the SonarQube Plugin for Claude Code](https://www.sonarsource.com/resources/library/set-up-the-sonarqube-plugin-for-claude-code/): To connect Claude Code with SonarQube Cloud for real-time code quality, secrets scanning, and project insights. - [Set Up the SonarQube Plugin for Codex](https://www.sonarsource.com/resources/library/set-up-the-sonarqube-plugin-for-codex/): To set up the SonarQube plugin for Codex CLI to scan issues, secrets, dependencies, and quality gates inside coding sessions. - [Set Up the SonarQube Plugin for Cursor](https://www.sonarsource.com/resources/library/set-up-the-sonarqube-plugin-for-cursor/): To configure the SonarQube plugin for Cursor so issue scanning, quality gates, and Agentic Analysis are accessible inside Cursor chat sessions. - [Set Up the SonarQube Plugin for GitHub Copilot CLI](https://www.sonarsource.com/resources/library/set-up-the-sonarqube-plugin-for-github-copilot-cli/): To connect SonarQube with GitHub Copilot CLI using the plugin, CLI, MCP Server, and secrets scanning hook. - [Set Up the SonarQube Power for Kiro](https://www.sonarsource.com/resources/library/set-up-the-sonarqube-power-for-kiro/): To set up the SonarQube power for Kiro to catch bugs, vulnerabilities, and leaked secrets before committing AI-generated code. - [Sonar Context Augmentation and GitHub Copilot in VS Code](https://www.sonarsource.com/resources/library/sonar-context-augmentation-and-github-copilot-in-vs-code/): To set up Sonar Context Augmentation in VS Code so Copilot generates code that follows your architecture and coding standards. - [Sonar Context Augmentation with Claude Code](https://www.sonarsource.com/resources/library/sonar-context-augmentation-claude-code/): To inject project guidelines and architecture awareness into Claude Code for cleaner, enterprise-ready code. - [Sonar Vortex with Claude Code](https://www.sonarsource.com/resources/library/sonar-vortex-with-claude-code/): To follow a complete setup guide for Sonar Vortex in Claude Code, covering context augmentation and agentic analysis. - [SonarQube Advanced Security vs. Other SCA Solutions](https://www.sonarsource.com/resources/library/sonarqube-advanced-security-vs-other-sca-solutions/): To see how SonarQube unifies SAST, code quality, secrets detection, IaC analysis, and SCA to reduce risk in your own code and dependencies. - [SonarQube Agentic Analysis with GitHub Copilot CLI](https://www.sonarsource.com/resources/library/sonarqube-agentic-analysis-github-copilot-cli/): To connect SonarQube Agentic Analysis with GitHub Copilot CLI for automated code verification and faster PR-ready fixes. - [SonarQube Agentic Analysis in VS Code with GitHub Copilot](https://www.sonarsource.com/resources/library/sonarqube-agentic-analysis-in-vs-code-with-github-copilot/): To integrate SonarQube Cloud with VS Code and Copilot for automated code verification and issue remediation before commits. - [SonarQube CLI with Codex CLI](https://www.sonarsource.com/resources/library/sonarqube-cli-codex-cli/): To connect Codex CLI to the SonarQube MCP to automate code fixes and resolve security issues in the terminal. - [SonarQube CLI: What It Does and How to Set It Up](https://www.sonarsource.com/resources/library/sonarqube-cli-what-it-does-and-how-to-set-it-up/): To learn how to install and configure the SonarQube CLI for secrets scanning, dependency checks, and AI agent integration. - [SonarQube vs. Other AI Code Review Tools](https://www.sonarsource.com/resources/library/sonarqube-vs-other-ai-code-review-tools/): To see how deterministic static analysis and AI Code Assurance in SonarQube reduce AI risk compared to other AI code review tools. - [The Agent Centric Development Cycle with the SonarQube CLI](https://www.sonarsource.com/resources/library/the-agent-centric-development-cycle-with-the-sonarqube-cli/): To learn how the SonarQube CLI helps Claude Code use project context, verify edits, and remediate technical debt automatically. - [Tools You Need for a CRA-Ready Codebase](https://www.sonarsource.com/resources/library/tools-you-need-for-a-cra-ready-codebase/): To explore the code security, SBOM, and governance capabilities needed to strengthen Cyber Resilience Act compliance. - [What Are Agentic Workflows?](https://www.sonarsource.com/resources/library/what-are-agentic-workflows/): To learn how agentic workflows let AI agents plan, test, and adapt code while verification keeps quality and security on track. - [What Is Agentic SDLC?](https://www.sonarsource.com/resources/library/what-is-agentic-sdlc/): To learn the benefits and risks of AI coding agents reshaping the SDLC and how to manage code quality and security in agentic workflows. - [What Is AI Code Review?](https://www.sonarsource.com/resources/library/what-is-ai-code-review/): To discover how AI code review scales pull request reviews and catches vulnerabilities early in modern software development. - [What Is an Agent Engine?](https://www.sonarsource.com/resources/library/what-is-an-agent-engine/): To learn what an agent engine is, how it works, and how to verify its output. - [What Is an AI Agent?](https://www.sonarsource.com/resources/library/what-is-an-ai-agent/): To learn the benefits and risks of AI agents and how to ensure the code quality and security of autonomous workflows. - [What Is Secrets Detection?](https://www.sonarsource.com/resources/library/what-is-secrets-detection/): To discover how secrets detection protects code by finding leaked credentials early and enforcing automated checks. - [What Is the Difference Between SAST and DAST?](https://www.sonarsource.com/resources/library/what-is-the-difference-between-sast-and-dast/): To learn the differences between SAST and DAST, what each finds, and why modern teams need both for complete coverage. - [You Need Dependency Checks in Your AI Coding Workflow](https://www.sonarsource.com/resources/library/you-need-dependency-checks-in-your-ai-coding-workflow/): To see how Sonar Vortex and the SonarQube CLI help coding agents evaluate dependency risks before edits and block risky commits. ### Solution Briefs - [Code Quality and Security for Financial Services](https://www.sonarsource.com/resources/solution-briefs/integrated-code-quality-and-security-for-financial-services/): To learn how Sonar provides the code verification layer that lets financial institutions modernize and adopt AI without sacrificing stability. - [Integrated Code Security and Code Quality](https://www.sonarsource.com/resources/solution-briefs/integrated-code-security-code-quality/): To find coding issues in the development workflow and stop them from reaching production. - [Leading Healthcare Organizations Use SonarQube](https://www.sonarsource.com/resources/solution-briefs/leading-healthcare-organizations-use-sonarqube/): To see how Sonar helps healthcare organizations modernize systems and deploy AI with confidence while meeting strict regulatory standards. - [SonarQube Cloud Solution Brief](https://www.sonarsource.com/resources/solution-briefs/sonarcloud/): To learn how Sonar's SaaS platform enables teams to write high-quality, secure code and remediate existing code organically. - [SonarQube Server Solution Brief](https://www.sonarsource.com/resources/solution-briefs/sonarlint/): To learn how Sonar's IDE solution enables teams to write high-quality, secure code and remediate existing code organically. - [SonarQube Solution Brief](https://www.sonarsource.com/resources/solution-briefs/sonarqube/): To learn how Sonar's automated code review platform enables teams to write high-quality, secure code and remediate existing code organically. - [SonarQube Advanced Security Solution Brief](https://www.sonarsource.com/resources/solution-briefs/sonarqube-advanced-security/): To enhance an existing SonarQube setup with advanced open-source code analysis and supply chain insights. - [SonarQube Enterprise Edition Solution Brief](https://www.sonarsource.com/resources/solution-briefs/sonarqube-enterprise-edition/): To learn how SonarQube Server Enterprise accelerates mission-critical software development while reducing technical debt. - [SonarQube MCP Server Solution Brief](https://www.sonarsource.com/resources/solution-briefs/sonarqube-mcp-server/): To learn how the SonarQube MCP Server enables AI agents and AI-native IDEs to find and fix issues using SonarQube's trusted analysis. - [Streamline Codebase Compliance with CRA Using SonarQube](https://www.sonarsource.com/resources/solution-briefs/streamline-your-codebase-compliance-with-cra-using-sonarqube/): To learn how SonarQube helps organizations meet Cyber Resilience Act requirements for secure-by-design software. - [Strengthen Codebase Compliance with DORA Using SonarQube](https://www.sonarsource.com/resources/solution-briefs/strengthen-your-codebase-compliance-with-dora-using-sonarqube/): To learn how SonarQube supports DORA's requirements for proactive risk management and continuous testing. - [Strengthen MISRA C++ Codebase Compliance with SonarQube](https://www.sonarsource.com/resources/solution-briefs/strengthen-your-misra-c-codebase-compliance-with-sonarqube/): To learn how SonarQube helps manage the complexity of modern C++ while maintaining functional safety compliance. - [Strengthen PCI DSS 4.0 Compliance with SonarQube](https://www.sonarsource.com/resources/solution-briefs/strengthen-your-pci-dss-4-0-compliance-with-sonarqube/): To learn how SonarQube embeds security controls throughout the SDLC to support PCI DSS 4.0's continuous compliance requirements. ### Reports, Whitepapers, Research PDFs - [White Papers](https://www.sonarsource.com/resources/white-papers/): To access in-depth white papers on code quality and security, DevOps, and secure software development best practices. - [451 Research Report](https://www.sonarsource.com/resources/451-research-report/): To review independent research insights on application security and static analysis market trends. - [IDC Report](https://www.sonarsource.com/resources/idc-report/): To explore IDC analysis on code quality, application security, and development productivity. - [Developer Survey Report](https://www.sonarsource.com/resources/developer-survey-report/): To understand developer perspectives on code quality, security, and AI-assisted development. - [Developer SDLC Compliance Checklist](https://www.sonarsource.com/resources/developer-sdlc-compliance-checklist/): To use a practical checklist for aligning development workflows with SDLC compliance requirements. - [Developer SDLC Compliance Guide](https://www.sonarsource.com/resources/developer-sdlc-compliance-guide/): To implement structured compliance practices within the software development lifecycle. - [Safeguarding AI-Generated Code](https://www.sonarsource.com/resources/safeguarding-ai-code/): To mitigate risks associated with AI-generated code while maintaining high code quality and security standards. - [GigaOm AST Radar Report](https://www.sonarsource.com/resources/gigaom-ast-radar/): To evaluate application security testing (AST) solutions through GigaOm’s industry analysis. - [G2 Grid Report 2025](https://www.sonarsource.com/resources/g2-grid-report-2025/): To review customer-driven rankings and performance insights from G2’s market grid. - [7 Habits of Highly Effective AI Coding](https://www.sonarsource.com/resources/7-habits-of-highly-effective-ai-coding/): To adopt best practices for using AI coding assistants responsibly and effectively. - [7 Habits of Highly Effective AI Coding – eBook](https://www.sonarsource.com/resources/7-habits-of-highly-effective-ai-coding-ebook/): To download the comprehensive eBook on improving AI-assisted coding while maintaining quality and security. - [The Coding Personalities of Leading LLMs](https://www.sonarsource.com/resources/the-coding-personalities-of-leading-llms/): To compare how leading large language models approach code generation and quality. - [The State of Code Security Report](https://www.sonarsource.com/resources/the-state-of-code-security-report/): To explore trends, risks, and insights shaping modern code security practices. - [The State of Code Reliability Report](https://www.sonarsource.com/resources/the-state-of-code-reliability-report/): To understand key findings on improving software reliability and defect prevention. - [The State of Code Maintainability Report](https://www.sonarsource.com/resources/the-state-of-code-maintainability-report/): To analyze trends in maintainability, technical debt, and long-term code health. - [NIST SSDF Code Security Requirements](https://www.sonarsource.com/resources/nist-ssdf-code-security-requirements/): To align development practices with NIST Secure Software Development Framework requirements. - [Developer Guide to AI-Assisted Software Development](https://www.sonarsource.com/resources/developer-guide-to-ai-assisted-software-development/): To implement AI-assisted development practices while maintaining strong governance and security. - [Cognitive Complexity](https://www.sonarsource.com/resources/cognitive-complexity/): To understand cognitive complexity and how it measures code readability and maintainability. - [Buyer's Guide to Code Quality and Security Checklist](https://www.sonarsource.com/resources/buyers-guide-to-code-quality-and-security-checklist/): To use a practical checklist of six evaluation criteria for engineering leaders assessing code quality and security platforms. - [Buyer's Guide to Code Quality and Security Workbook](https://www.sonarsource.com/resources/buyers-guide-to-code-quality-and-security-workbook/): To work through a hands-on framework for evaluating vendors on developer experience, signal quality, governance, and enterprise scale. - [Developer Survey Report: Enterprise](https://www.sonarsource.com/resources/developer-survey-report-enterprise/): To explore survey findings on the gap between how widely enterprises deploy AI-generated code and how rigorously they verify it. - [DZone Security Trend Report](https://www.sonarsource.com/resources/dzone-security-trend-report/): To learn why independent verification has become the prerequisite for safe AI adoption as more enterprises run AI agents in production. - [G2 Grid Report for Static Code Analysis](https://www.sonarsource.com/resources/g2-grid-report/): To download the G2 Grid Report for Static Code Analysis and see SonarQube's position in the Leader quadrant. - [Gartner Magic Quadrant 2026](https://www.sonarsource.com/resources/gartner-magic-quadrant-2026/): To read about Sonar's recognition as a Leader in Gartner's first Magic Quadrant for technical debt management tools. - [The Agent Centric Development Cycle (AC/DC) eBook](https://www.sonarsource.com/resources/the-agent-centric-development-cycle-acdc/): To learn about the Agent Centric Development Cycle framework for harnessing agentic AI without compromising code quality or security. --- ## Blog ### Root - [SonarSource Blog](https://www.sonarsource.com/blog/): To share insights and updates on coding practices, security, and AI in software development. ### Blog Tags - [AI Blog Tag](https://www.sonarsource.com/blog/tag/ai/): To explore blog articles focused on AI in software development, including AI code generation, AI CodeFix, and AI-assisted quality practices. - [Code Security Blog Tag](https://www.sonarsource.com/blog/tag/code-security/): To read insights and updates on improving code security and preventing software vulnerabilities. - [Code Quality Blog Tag](https://www.sonarsource.com/blog/tag/code-quality/): To discover best practices, trends, and thought leadership on maintaining high code quality. - [Company News Blog Tag](https://www.sonarsource.com/blog/tag/company-news/): To stay updated on SonarSource announcements, milestones, and corporate updates. - [SonarQube Server Blog Tag](https://www.sonarsource.com/blog/tag/sonarqube-server/): To explore updates, features, and best practices related to SonarQube Server. - [SonarQube Cloud Blog Tag](https://www.sonarsource.com/blog/tag/sonarqube-cloud/): To read the latest news, enhancements, and use cases for SonarQube Cloud. - [SonarQube for IDE Blog Tag](https://www.sonarsource.com/blog/tag/sonarqube-for-ide/): To learn about real-time code quality and security feedback within IDE workflows. - [Partner Integrations Blog Tag](https://www.sonarsource.com/blog/tag/partner-integrations/): To explore integration announcements and ecosystem partnerships. - [Governance Blog Tag](https://www.sonarsource.com/blog/tag/governance/): To understand strategies for enforcing quality gates, compliance, and development governance. - [Languages Blog Tag](https://www.sonarsource.com/blog/tag/languages/): To explore articles focused on programming language support and analysis improvements. - [Vulnerability Research Blog Tag](https://www.sonarsource.com/blog/tag/vulnerability-research/): To read in-depth vulnerability research and security findings from SonarSource experts. - [SonarQube MCP Server Blog Tag](https://www.sonarsource.com/blog/tag/sonarqube-mcp-server/): To explore content related to SonarQube MCP Server integrations and AI-powered workflows. ### Individual Blog Articles - [Sonar Named Leader in G2 Spring Report](https://www.sonarsource.com/blog/sonar-named-leader-in-g2-spring-report/): To learn how Sonar was recognized as a leader in G2’s Spring report for code quality and security solutions. - [Exploring the New Enhancements in SonarQube](https://www.sonarsource.com/blog/exploring-the-new-enhancements-in-sonarqube/): To discover the latest features and improvements in SonarQube for advancing code quality and security. - [Thoughts on Claude and Code Security](https://www.sonarsource.com/blog/thoughts-on-claude-code-security/): To examine security considerations and risks associated with AI-generated code from Claude. - [A Comparison of Claude Opus 4.5 and 4.6](https://www.sonarsource.com/blog/a-comparison-of-claude-opus-4-5-and-4-6/): To compare performance, quality, and security implications of different Claude Opus model versions. - [How SonarQube Enables DORA Compliance for Financial Institutions](https://www.sonarsource.com/blog/how-sonarqube-enables-dora-compliance-for-financial-institutions/): To understand how SonarQube supports regulatory compliance such as DORA through code quality and security governance. - [CRA: Navigating Speed and Security with AI Coding](https://www.sonarsource.com/blog/cra-navigating-speed-and-security-with-ai-coding/): To balance development velocity and compliance under the Cyber Resilience Act using AI-assisted coding responsibly. - [Achieve MISRA C 2023 Compliant Source Code](https://www.sonarsource.com/blog/achieve-misra-c-2023-compliant-source-code/): To implement MISRA C 2023 standards for safer, standards-compliant C development. - [Manage Duplicated Code with Sonar](https://www.sonarsource.com/blog/manage-duplicated-code-with-sonar/): To detect and reduce duplicated code to improve maintainability and reduce technical debt. - [The Power of Deeper SAST](https://www.sonarsource.com/blog/sonar-power-of-deeper-sast/): To explore how advanced static application security testing uncovers deeper security vulnerabilities. - [Announcing SonarQube Server 2026.1 LTA](https://www.sonarsource.com/blog/announcing-sonarqube-server-2026-1-lta/): To review new capabilities and long-term active (LTA) enhancements in SonarQube Server 2026.1. - [Using Dashboards with SonarQube Cloud](https://www.sonarsource.com/blog/using-dashboards-with-sonarqube-cloud/): To leverage dashboards for better visibility into code quality and security metrics. - [Solving the Engineering Productivity Paradox](https://www.sonarsource.com/blog/solving-the-engineering-productivity-paradox/): To address productivity challenges while maintaining high code quality and security standards. - [Stop Malicious Packages in Your CI/CD Pipeline with SonarQube](https://www.sonarsource.com/blog/stop-malicious-packages-in-your-ci-cd-pipeline-with-sonarqube/): To prevent malicious open-source packages from compromising your CI/CD workflows. - [Secrets Detection CLI Beta](https://www.sonarsource.com/blog/secrets-detection-cli-beta/): To explore the beta release of a CLI tool for detecting exposed secrets in codebases. - [SonarQube Code Coverage](https://www.sonarsource.com/blog/sonarqube-code-coverage/): To understand how SonarQube measures and visualizes code coverage to strengthen test effectiveness. - [What Is Taint Analysis?](https://www.sonarsource.com/blog/what-is-taint-analysis/): To learn how taint analysis tracks untrusted data flows to prevent injection and other security vulnerabilities. - [SonarQube Bug Detection Advances](https://www.sonarsource.com/blog/sonarqube-bug-detection-advances/): To explore improvements in automated bug detection capabilities. - [Deeper SAST Uncovers Hidden Security Vulnerabilities](https://www.sonarsource.com/blog/deeper-sast-uncovers-hidden-security-vulnerabilities/): To understand how enhanced SAST techniques reveal hidden security flaws. - [State of Open Source Licenses Today](https://www.sonarsource.com/blog/state-of-open-source-licenses-today/): To analyze current trends and risks related to open-source licensing. - [Why Claude Opus 4.6 Requires Verification](https://www.sonarsource.com/blog/why-claude-opus-4-6-requires-verification/): To understand the importance of validating AI-generated code outputs for quality and security. - [Claude Code + SonarQube MCP: Building an Autonomous Code Review Workflow](https://www.sonarsource.com/blog/claude-code-sonarqube-mcp-building-an-autonomous-code-review-workflow/): To integrate Claude Code with SonarQube MCP for automated, AI-assisted code review. - [How AI Is Redefining Technical Debt](https://www.sonarsource.com/blog/how-ai-is-redefining-technical-debt/): To explore how AI-assisted development impacts the measurement and management of technical debt. - [The AI Coding Trust Gap](https://www.sonarsource.com/blog/ai-coding-trust-gap/): To examine the trust challenges associated with AI-generated code and how to mitigate associated risks. - [Agentic AI and the Automation Shift](https://www.sonarsource.com/blog/agentic-ai-automation-shift/): To explore how agentic AI is transforming software automation and impacting code quality and security practices. - [Shadow AI Is Already Writing Your Code](https://www.sonarsource.com/blog/shadow-ai-is-already-writing-your-code/): To understand the risks of ungoverned AI coding tools and how to maintain visibility and control. - [Introducing Audit Logs in SonarQube Cloud: Enhancing Compliance and Security](https://www.sonarsource.com/blog/introducing-audit-logs-in-sonarqube-cloud-enhancing-compliance-and-security/): To learn how audit logs in SonarQube Cloud strengthen governance, traceability, and compliance. - [Announcing SonarQube Advanced Security](https://www.sonarsource.com/blog/announcing-sonarqube-advanced-security/): To discover enhanced security capabilities for deeper vulnerability detection and risk management. - [Cognitive Complexity: Because Testability and Understandability Matter](https://www.sonarsource.com/blog/cognitive-complexity-because-testability-understandability/): To understand cognitive complexity and how it improves code readability and maintainability. - [What Is Code Quality?](https://www.sonarsource.com/blog/what-is-clean-code/): To explore the principles of writing maintainable, reliable, and secure code aligned with modern code quality standards. - [Bugs and Vulnerabilities as First-Class Citizens in the SonarQube Quality Model](https://www.sonarsource.com/blog/bugs-and-vulnerabilities-are-1st-class-citizens-in-sonarqube-quality-model-along-with-code-smells/): To understand how SonarQube prioritizes bugs, vulnerabilities, and code smells within its quality model. - [SonarQube for IDE: Announcing Support for AI-Native IDEs](https://www.sonarsource.com/blog/sonarqube-ide-announcing-support-for-ai-native-ides/): To explore expanded support for AI-native IDE environments in SonarQube for IDE. - [How Sonar Helps with NIST SSDF](https://www.sonarsource.com/blog/how-sonar-helps-with-nist-ssdf/): To align development practices with the NIST Secure Software Development Framework using Sonar solutions. - [How Sonar Helps Achieve a Strong SOC 2 Type II Report](https://www.sonarsource.com/blog/how-sonar-helps-achieve-a-strong-soc-2-type-ii-report/): To support SOC 2 Type II compliance through code quality and security controls. - [ASP.NET Core Web Apps](https://www.sonarsource.com/blog/asp-net-core-web-apps/): To improve code quality and security in ASP.NET Core web applications. - [Introducing Native Jira Cloud Integration for SonarQube Cloud](https://www.sonarsource.com/blog/introducing-native-jira-cloud-integration-for-sonarqube-cloud/): To integrate SonarQube Cloud directly with Jira Cloud for streamlined issue tracking. - [Join the SonarQube Remediation Agent Beta](https://www.sonarsource.com/blog/join-the-sonarqube-remediation-agent-beta/): To participate in the beta program for automated remediation powered by AI. - [Introducing Architecture in SonarQube](https://www.sonarsource.com/blog/introducing-architecture-in-sonarqube/): To explore architectural analysis capabilities for improving maintainability and governance. - [SonarQube and Port Integration](https://www.sonarsource.com/blog/sonarqube-and-port/): To integrate SonarQube insights with Port for enhanced developer experience and visibility. - [A Technical Look at SonarSweep for GPT-OSS-20B](https://www.sonarsource.com/blog/a-technical-look-at-sonarsweep-for-gpt-oss-20b/): To analyze how SonarSweep evaluates and improves AI-generated code quality. - [False Positives: Our Enemies, but Maybe Your Friends](https://www.sonarsource.com/blog/false-positives-our-enemies-but-maybe-your-friends/): To understand false positives in static analysis and how they impact quality and security workflows. - [SonarQube for IDE: Our Journey This Year and a Sneak Peek into 2025](https://www.sonarsource.com/blog/sonarqube-for-ide-our-journey-this-year-and-sneak-peek-into-2025/): To review recent progress and upcoming roadmap highlights for SonarQube for IDE. - [Introducing Scoped Organization Tokens for SonarQube Cloud](https://www.sonarsource.com/blog/introducing-scoped-organization-tokens-for-sonarqube-cloud/): To enhance security and access control with scoped organization tokens in SonarQube Cloud. - [ISO 27001: Why It Matters](https://www.sonarsource.com/blog/iso-27001-importance/): To understand the importance of ISO 27001 certification and how it supports strong security governance and compliance. - [AutoConfig for C++: Code Analysis Redefined](https://www.sonarsource.com/blog/autoconfig-cpp-code-analysis-redefined/): To explore how AutoConfig simplifies and improves static analysis for C++ projects. - [How to Enable Your Development Team to Deliver High-Quality Code](https://www.sonarsource.com/blog/how-to-enable-your-development-team-to-deliver-clean-code/): To empower teams with practices and tools that improve maintainability and code quality. - [Microservices, Major Headaches: Detecting Vulnerabilities in Erxes Microservices](https://www.sonarsource.com/blog/micro-services-major-headaches-detecting-vulnerabilities-in-erxes-microservices/): To uncover security vulnerabilities in microservices architectures and improve application security. - [Apache Dubbo Consumer Risks](https://www.sonarsource.com/blog/apache-dubbo-consumer-risks/): To analyze security risks affecting Apache Dubbo consumers and how to mitigate them. - [Avocado Nightmare 2](https://www.sonarsource.com/blog/avocado-nightmare-2/): To investigate complex security vulnerabilities and exploitation techniques discovered by Sonar researchers. - [Dangerous Import: SourceForge Patches Critical Code Vulnerability](https://www.sonarsource.com/blog/dangerous-import-sourceforge-patches-critical-code-vulnerability/): To examine how a critical vulnerability was introduced and mitigated in a widely used project. - [The State of Code Security](https://www.sonarsource.com/blog/the-state-of-code-security/): To review trends and findings related to modern code security challenges. - [Ollama Remote Code Execution: Securing the Code That Runs LLMs](https://www.sonarsource.com/blog/ollama-remote-code-execution-securing-the-code-that-runs-llms/): To analyze remote code execution vulnerabilities affecting LLM tooling and how to secure them. - [Caught in the Fortinet (3/3): Exploiting FortiClient](https://www.sonarsource.com/blog/caught-in-the-fortinet-how-attackers-can-exploit-forticlient-to-compromise-organizations-3-3/): To understand advanced exploitation techniques targeting FortiClient deployments. - [Code Security for Conversational AI: Uncovering a Zip Slip in Eddi](https://www.sonarsource.com/blog/code-security-for-conversational-ai-uncovering-a-zip-slip-in-eddi/): To explore a Zip Slip vulnerability affecting conversational AI platforms. - [Caught in the Fortinet (1/3): Exploiting FortiClient](https://www.sonarsource.com/blog/caught-in-the-fortinet-how-attackers-can-exploit-forticlient-to-compromise-organizations-1-3/): To examine initial attack vectors targeting FortiClient installations. - [Caught in the Fortinet (2/3): Exploiting FortiClient](https://www.sonarsource.com/blog/caught-in-the-fortinet-how-attackers-can-exploit-forticlient-to-compromise-organizations-2-3/): To analyze follow-up exploitation techniques impacting enterprise environments. - [Remote Code Execution in Melis Platform](https://www.sonarsource.com/blog/remote-code-execution-in-melis-platform/): To investigate a remote code execution vulnerability and remediation strategies. - [Pretalx Vulnerabilities: How to Get Accepted at Every Conference](https://www.sonarsource.com/blog/pretalx-vulnerabilities-how-to-get-accepted-at-every-conference/): To understand vulnerabilities affecting Pretalx and their broader security implications. - [A Twist in the Code: OpenMeetings Vulnerabilities](https://www.sonarsource.com/blog/a-twist-in-the-code-openmeetings-vulnerabilities-through-unexpected-application-state/): To explore security flaws caused by unexpected application states in OpenMeetings. - [Pimcore: One Click, Two Security Vulnerabilities](https://www.sonarsource.com/blog/pimcore-one-click-two-security-vulnerabilities/): To analyze multiple vulnerabilities discovered in Pimcore installations. - [Cacti Unauthenticated Remote Code Execution](https://www.sonarsource.com/blog/cacti-unauthenticated-remote-code-execution/): To review a critical unauthenticated RCE vulnerability in Cacti. - [C# Logging Best Practices](https://www.sonarsource.com/blog/csharp-logging/): To improve logging practices in C# applications for better observability and security. - [OneDev Remote Code Execution](https://www.sonarsource.com/blog/onedev-remote-code-execution/): To analyze a remote code execution vulnerability affecting OneDev and how to mitigate exploitation risks. - [Securing Developer Tools: A New Supply Chain Attack on PHP](https://www.sonarsource.com/blog/securing-developer-tools-a-new-supply-chain-attack-on-php/): To examine a supply chain attack targeting PHP development tooling and its security implications. - [Securing Developer Tools: Argument Injection in VS Code](https://www.sonarsource.com/blog/securing-developer-tools-argument-injection-in-vscode/): To understand how argument injection vulnerabilities can compromise developer environments. - [OpenEMR Remote Code Execution in Your Healthcare System](https://www.sonarsource.com/blog/openemr-remote-code-execution-in-your-healthcare-system/): To explore a critical RCE vulnerability affecting OpenEMR and healthcare systems. - [The Coding Personalities of Leading LLMs](https://www.sonarsource.com/blog/the-coding-personalities-of-leading-llms/): To compare how leading large language models generate code and assess quality and security implications. - [Patches, Collisions, and Root Shells: A Pwn2Own Adventure](https://www.sonarsource.com/blog/patches-collisions-and-root-shells-a-pwn2own-adventure/): To dive into advanced exploitation techniques demonstrated during Pwn2Own. - [Hexacon 2023 Highlights](https://www.sonarsource.com/blog/hexacon2023-highlights/): To review key security research highlights and vulnerability findings presented at Hexacon 2023. - [The State of Code Reliability](https://www.sonarsource.com/blog/the-state-of-code-reliability/): To explore trends and research findings on improving software reliability. - [The State of Code Maintainability](https://www.sonarsource.com/blog/the-state-of-code-maintainability/): To analyze insights on maintainability, complexity, and technical debt. - [Why Code Security Matters Even in Hardened Environments](https://www.sonarsource.com/blog/why-code-security-matters-even-in-hardened-environments/): To understand why secure coding practices remain critical even in hardened infrastructures. - [Diving into JumpServer: Attacker’s Gateway to Internal Networks (1/2)](https://www.sonarsource.com/blog/diving-into-jumpserver-attackers-gateway-to-internal-networks-1-2/): To investigate vulnerabilities that allow attackers to pivot into internal networks. - [Avocado Nightmare 1](https://www.sonarsource.com/blog/avocado-nightmare-1/): To explore the initial findings in a complex vulnerability research case study. - [Reply-to-Calc: The Attack Chain to Compromise Mailspring](https://www.sonarsource.com/blog/reply-to-calc-the-attack-chain-to-compromise-mailspring/): To dissect a multi-step attack chain leading to compromise via Mailspring. - [Double Dash, Double Trouble: A Subtle SQL Injection Flaw](https://www.sonarsource.com/blog/double-dash-double-trouble-a-subtle-sql-injection-flaw/): To understand how subtle SQL injection vulnerabilities can bypass common defenses. - [Beware the Cookie Monster: Cyberhaven Extension Vulnerability Allowed Cookie Theft](https://www.sonarsource.com/blog/beware-the-cookie-monster-cyberhaven-extension-vulnerability-allowed-cookie-theft/): To examine how a browser extension vulnerability enabled session cookie theft. - [Data in Danger: Detecting XSS in Grafana (CVE-2025-2703)](https://www.sonarsource.com/blog/data-in-danger-detecting-xss-in-grafana-cve-2025-2703/): To analyze an XSS vulnerability in Grafana and its security impact. - [10 Unknown Security Pitfalls for Python](https://www.sonarsource.com/blog/10-unknown-security-pitfalls-for-python/): To uncover lesser-known Python security pitfalls and how to prevent common vulnerabilities. - [Disclosing Information with a Side Channel in Django](https://www.sonarsource.com/blog/disclosing-information-with-a-side-channel-in-django/): To examine how side-channel vulnerabilities in Django can leak sensitive information. - [Zimbra Mail: Stealing Clear-Text Credentials via Memcache Injection](https://www.sonarsource.com/blog/zimbra-mail-stealing-clear-text-credentials-via-memcache-injection/): To analyze a memcache injection vulnerability that exposed credentials in Zimbra Mail. - [Odoo: Get Your Content-Type Right or Else](https://www.sonarsource.com/blog/odoo-get-your-content-type-right-or-else/): To understand how improper content-type handling can introduce security vulnerabilities in Odoo. - [It’s a SNMP Trap: Gaining Code Execution on LibreNMS](https://www.sonarsource.com/blog/it-s-a-snmp-trap-gaining-code-execution-on-librenms/): To investigate an exploitation path leading to remote code execution in LibreNMS. - [Checkmk RCE Chain (Part 1)](https://www.sonarsource.com/blog/checkmk-rce-chain-1/): To dissect the first stage of a remote code execution attack chain in Checkmk. - [Zabbix: Case Study of Unsafe Session Storage](https://www.sonarsource.com/blog/zabbix-case-study-of-unsafe-session-storage/): To explore how insecure session storage mechanisms can lead to compromise. - [Securing Developer Tools: Unpatched Code Vulnerabilities in Gogs (Part 1)](https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1/): To analyze unpatched vulnerabilities affecting Gogs and their impact on development environments. - [Securing Kotlin Apps with SonarQube: Real-World Examples](https://www.sonarsource.com/blog/securing-kotlin-apps-with-sonarqube-real-world-examples/): To improve Kotlin application security using practical static analysis examples. - [Java 22: Leveraging Unnamed Variables and Patterns](https://www.sonarsource.com/blog/java-22-leverage-unnamed-variables-and-patterns/): To explore new Java 22 language features and their implications for cleaner, more maintainable code. - [Security Vulnerabilities in CasaOS](https://www.sonarsource.com/blog/security-vulnerabilities-in-casaos/): To examine discovered vulnerabilities in CasaOS and how to mitigate them. - [phpBB3: PHAR Deserialization to Remote Code Execution](https://www.sonarsource.com/blog/phpbb3-phar-deserialization-to-remote-code-execution/): To understand how PHAR deserialization can lead to RCE in phpBB3. - [Spring Framework Pitfalls](https://www.sonarsource.com/blog/spring-framework-pitfalls/): To identify common security and reliability pitfalls in Spring Framework applications. - [PHP Supply Chain Attack on Composer](https://www.sonarsource.com/blog/php-supply-chain-attack-on-composer/): To analyze a supply chain attack targeting Composer in the PHP ecosystem. - [Securing Developer Tools: Git Integrations](https://www.sonarsource.com/blog/securing-developer-tools-git-integrations/): To explore security risks in Git integrations and how to harden development workflows. - [Securing Developer Tools: Package Managers](https://www.sonarsource.com/blog/securing-developer-tools-package-managers/): To examine security risks in package managers and how supply chain attacks can compromise development environments. - [OpenEMR 5.0.2.1 Command Injection Vulnerability](https://www.sonarsource.com/blog/openemr-5-0-2-1-command-injection-vulnerability/): To analyze a command injection vulnerability affecting OpenEMR and its security impact. - [Pandora FMS 7.4.2 Critical Code Vulnerabilities Explained](https://www.sonarsource.com/blog/pandora-fms-742-critical-code-vulnerabilities-explained/): To understand critical vulnerabilities discovered in Pandora FMS and how they were exploited. - [Pitfalls of Desanitization: Leaking Customer Data from osTicket](https://www.sonarsource.com/blog/pitfalls-of-desanitization-leaking-customer-data-from-osticket/): To explore how improper desanitization can lead to sensitive customer data exposure. - [Code Vulnerabilities Leak Emails in Proton Mail](https://www.sonarsource.com/blog/code-vulnerabilities-leak-emails-in-proton-mail/): To investigate vulnerabilities that exposed user email data in Proton Mail. - [Code Vulnerabilities Put Skiff Emails at Risk](https://www.sonarsource.com/blog/code-vulnerabilities-put-skiff-emails-at-risk/): To examine security flaws that threatened confidentiality in Skiff’s email platform. - [Remote Code Execution in Tutanota Desktop Due to Code Flaw](https://www.sonarsource.com/blog/remote-code-execution-in-tutanota-desktop-due-to-code-flaw/): To analyze an RCE vulnerability impacting the Tutanota desktop application. - [NoSQL Injections in Rocket.Chat](https://www.sonarsource.com/blog/nosql-injections-in-rocket-chat/): To understand how NoSQL injection vulnerabilities can compromise real-time communication platforms. - [Why ORMs and Prepared Statements Can’t Always Win](https://www.sonarsource.com/blog/why-orms-and-prepared-statements-cant-always-win/): To explore limitations of ORMs and prepared statements in preventing injection vulnerabilities. - [Sanitize Client-Side? Why Server-Side HTML Sanitization Is Doomed to Fail](https://www.sonarsource.com/blog/sanitize-client-side-why-server-side-html-sanitization-is-doomed-to-fail/): To examine the pitfalls of improper HTML sanitization strategies. - [Never Underestimate CSRF: Why Origin Reflection Is a Bad Idea](https://www.sonarsource.com/blog/never-underestimate-csrf-why-origin-reflection-is-a-bad-idea/): To analyze CSRF vulnerabilities and the dangers of flawed origin validation. - [Front-End Frameworks: When Bypassing Built-In Sanitization Backfires](https://www.sonarsource.com/blog/front-end-frameworks-when-bypassing-built-in-sanitization-might-backfire/): To understand how bypassing framework protections can introduce XSS and other vulnerabilities. - [Hack the Stack with LocalStack](https://www.sonarsource.com/blog/hack-the-stack-with-localstack/): To explore how misconfigurations in local cloud emulation tools can expose security risks. - [Ghost Admin Takeover](https://www.sonarsource.com/blog/ghost-admin-takeover/): To investigate vulnerabilities that enabled administrative account compromise in Ghost CMS. - [Path Traversal Vulnerabilities in Icinga Web](https://www.sonarsource.com/blog/path-traversal-vulnerabilities-in-icinga-web/): To analyze path traversal flaws that allowed unauthorized file access. - [Checkmk RCE Chain (Part 2)](https://www.sonarsource.com/blog/checkmk-rce-chain-2/): To continue exploring the multi-stage remote code execution chain in Checkmk. - [Checkmk RCE Chain (Part 3)](https://www.sonarsource.com/blog/checkmk-rce-chain-3/): To examine the final exploitation steps in the Checkmk RCE attack chain. - [Visual Studio Code Security: A Deep Dive into Your Favorite Editor](https://www.sonarsource.com/blog/visual-studio-code-security-deep-dive-into-your-favorite-editor/): To examine security risks and attack surfaces within Visual Studio Code and its extensions. - [New Spring Framework Rules in SonarQube](https://www.sonarsource.com/blog/new-spring-framework-rules-in-sonarqube/): To explore new static analysis rules that strengthen security and reliability in Spring applications. - [No, C Static Analysis Does Not Have to Be Painful](https://www.sonarsource.com/blog/no-c-static-analysis-does-not-have-to-be-painful/): To demonstrate how modern static analysis simplifies improving C code quality and security. - [Sonar at Pwn2Own Toronto 2022](https://www.sonarsource.com/blog/sonar-at-pwn2own-toronto-2022/): To review Sonar’s participation and vulnerability research showcased at Pwn2Own Toronto 2022. - [TyphoonCon 2023 Wrap-Up](https://www.sonarsource.com/blog/typhooncon-2023-wrap-up/): To summarize key security research insights and conference highlights from TyphoonCon 2023. - [Java SAST Benchmarks: Why You Shouldn’t Trust Them Blindly](https://www.sonarsource.com/blog/java-sast-benchmarks-why-you-shouldn-t-trust-them-blindly/): To critically evaluate SAST benchmark methodologies and their limitations. - [Troopers 2023 Conference Takeaways](https://www.sonarsource.com/blog/troopers-2023-conference-takeaways/): To reflect on key security trends and vulnerability research presented at Troopers 2023. - [Black Hat 2023 Overview](https://www.sonarsource.com/blog/blackhat-2023-overview/): To review major themes and research findings from Black Hat 2023. - [Reflections from OffensiveCon 2023](https://www.sonarsource.com/blog/reflections-from-offensivecon-2023/): To explore advanced offensive security insights shared at OffensiveCon 2023. - [Bits from Hexacon 2022](https://www.sonarsource.com/blog/bits-from-hexacon-2022/): To recap notable vulnerability research and security discussions from Hexacon 2022. - [Diving into JumpServer: Attacker’s Gateway to Internal Networks (2/2)](https://www.sonarsource.com/blog/diving-into-jumpserver-attackers-gateway-to-internal-networks-2-2/): To continue analyzing exploitation techniques that enable internal network compromise. - [The Tainted Voyage: Uncovering Voyager’s Vulnerabilities](https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/): To investigate vulnerabilities discovered in Voyager and their security implications. - [Magento RCE via XSS](https://www.sonarsource.com/blog/magento-rce-via-xss/): To understand how a cross-site scripting flaw led to remote code execution in Magento. - [Zimbra Webmail Compromise via Email](https://www.sonarsource.com/blog/zimbra-webmail-compromise-via-email/): To analyze how crafted emails enabled compromise of Zimbra webmail systems. - [WordPress CSRF to RCE](https://www.sonarsource.com/blog/wordpress-csrf-to-rce/): To examine how a CSRF vulnerability escalated to remote code execution in WordPress. - [Horde Webmail RCE via Email](https://www.sonarsource.com/blog/horde-webmail-rce-via-email/): To analyze how crafted emails led to remote code execution in Horde Webmail. - [RainLoop: Emails at Risk Due to Code Flaw](https://www.sonarsource.com/blog/rainloop-emails-at-risk-due-to-code-flaw/): To examine vulnerabilities that exposed user emails in RainLoop. - [SonarQube for IDE Supports Go Analysis](https://www.sonarsource.com/blog/sonarlint-supports-go-analysis/): To explore expanded Go language support in SonarQube for IDE for improved code quality and security. - [Exploiting Hibernate Injections](https://www.sonarsource.com/blog/exploiting-hibernate-injections/): To understand how Hibernate-based injection vulnerabilities can lead to serious security breaches. - [Encoding Differentials: Why Charset Matters](https://www.sonarsource.com/blog/encoding-differentials-why-charset-matters/): To explore how character encoding mismatches can introduce subtle security flaws. - [Joomla: Multiple XSS Vulnerabilities](https://www.sonarsource.com/blog/joomla-multiple-xss-vulnerabilities/): To investigate cross-site scripting vulnerabilities affecting Joomla installations. - [mXSS: The Vulnerability Hiding in Your Code](https://www.sonarsource.com/blog/mxss-the-vulnerability-hiding-in-your-code/): To understand mutation-based XSS (mXSS) and how it bypasses common sanitization defenses. - [Remote Code Execution in Mailcow: Always Sanitize Error Messages](https://www.sonarsource.com/blog/remote-code-execution-in-mailcow-always-sanitize-error-messages/): To analyze how improper error handling led to RCE in Mailcow. - [Sonar at JSNation 2023 in Amsterdam](https://www.sonarsource.com/blog/sonar-at-jsnation-2023-in-amsterdam/): To recap insights and highlights from JSNation 2023. - [Sonar’s Scoring on the Top 3 Java SAST Benchmarks](https://www.sonarsource.com/blog/sonar-s-scoring-on-the-top-3-java-sast-benchmarks/): To evaluate Sonar’s performance across leading Java SAST benchmark tests. - [Reflections from DevNexus: The Largest Java Conference in the U.S.A.](https://www.sonarsource.com/blog/reflections-from-devnexus-the-largest-java-conference-in-the-u-s-a/): To review key Java ecosystem trends and conference insights from DevNexus. - [WordPress File Delete to Code Execution](https://www.sonarsource.com/blog/wordpress-file-delete-to-code-execution/): To examine how a file deletion flaw escalated to remote code execution in WordPress. - [Smartstore.NET: Malicious Message Leading to E-Commerce Takeover](https://www.sonarsource.com/blog/smartstorenet-malicious-message-leading-to-e-commerce-takeover/): To analyze how a crafted message enabled compromise of an e-commerce platform. - [MyBB Stored XSS to RCE](https://www.sonarsource.com/blog/mybb-stored-xss-to-rce/): To understand how a stored XSS vulnerability escalated to remote code execution in MyBB. - [Enhancing SAST Detection: Leveraging Benchmarks for Measuring Progress](https://www.sonarsource.com/blog/enhancing-sast-detection-leveraging-benchmarks-for-measuring-progress/): To explore how benchmarks can guide improvements in static application security testing. - [Why Mail Is Dangerous in PHP](https://www.sonarsource.com/blog/why-mail-is-dangerous-in-php/): To investigate common security pitfalls in PHP mail handling implementations. - [Grav CMS Code Execution Vulnerabilities](https://www.sonarsource.com/blog/grav-cms-code-execution-vulnerabilities/): To analyze vulnerabilities that enabled code execution in Grav CMS. - [WordPress Core Unauthenticated Blind SSRF](https://www.sonarsource.com/blog/wordpress-core-unauthenticated-blind-ssrf/): To examine an unauthenticated server-side request forgery vulnerability in WordPress core. - [WordPress Object Injection Vulnerability](https://www.sonarsource.com/blog/wordpress-object-injection-vulnerability/): To understand how object injection vulnerabilities can compromise WordPress environments. - [5 Risks of Outsourcing Software Development and How to Avoid Them](https://www.sonarsource.com/blog/5-risks-of-outsourcing-software-development-and-how-to-avoid-them/): To understand the risks of outsourcing software development and tactics for minimizing them in delivered software. - [Sonar Quality Code for Your DevOps Workflow](https://www.sonarsource.com/blog/Sonar-Clean-Code-for-your-DevOps-workflow/): To streamline a DevOps workflow with Code Quality practices from Sonar. - [A Cleaner Codebase Results in Less Token Usage](https://www.sonarsource.com/blog/a-cleaner-codebase-results-in-less-token-usage/): To see how Sonar's research across 540 AI agent runs shows cleaner codebases use fewer tokens with no drop in task completion. - [Agentic Analysis Beta](https://www.sonarsource.com/blog/agentic-analysis-beta/): To verify AI code in real time and stop security risks before pull requests using the SonarQube engine in open beta. - [AGENTS.md Is a Workaround, Not a Solution](https://www.sonarsource.com/blog/agents-md-is-a-workaround-not-a-solution/): To examine why AGENTS.md became the standard place to brief a coding agent, and where it falls short. - [AI Can Write Java 25 Right with SonarQube](https://www.sonarsource.com/blog/ai-can-write-java-25-right-with-sonarqube/): To learn Java 25 risks and how SonarQube identifies critical issues in AI-generated code before it ships. - [AI Code Assurance from Sonar](https://www.sonarsource.com/blog/ai-code-assurance-sonar/): To learn how Sonar AI Code Assurance validates AI-generated code through a structured, comprehensive analysis process. - [AI CodeFix from Sonar](https://www.sonarsource.com/blog/ai-codefix-sonar/): To learn how Sonar AI CodeFix suggests code fixes for issues discovered by SonarQube and SonarQube Cloud analysis. - [Analysis Evidence from SonarQube Now Available in JFrog AppTrust](https://www.sonarsource.com/blog/analysis-evidence-from-sonarqube-now-available-in-jfrog-apptrust/): To learn how SonarQube's automated code review integrates with JFrog AppTrust to govern AI-driven development speed. - [Announcing Native MCP Server in SonarQube Cloud](https://www.sonarsource.com/blog/announcing-native-mcp-server-in-sonarqube-cloud/): To address the code verification bottleneck created by AI-assisted development with a native MCP Server in SonarQube Cloud. - [Announcing the SonarQube MCP Server](https://www.sonarsource.com/blog/announcing-sonarqube-mcp-server/): To learn how the SonarQube MCP Server helps teams maintain code quality and security standards as AI-generated code volume grows. - [Announcing SonarSweep: Improving Training Data Quality for Coding LLMs](https://www.sonarsource.com/blog/announcing-sonarsweep-improving-training-data-quality-for-coding-llms/): To learn how SonarSweep improves the quality and security of training data used by coding-capable LLMs. - [Automating Quality Gate Success with Claude Opus 4.6 and the SonarQube MCP](https://www.sonarsource.com/blog/automating-quality-gate-success-with-claude-opus-4-6-and-sonarqube-mcp/): To see how pairing Claude Opus 4.6 with the SonarQube MCP helps prevent failed quality gates before they happen. - [Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities](https://www.sonarsource.com/blog/basic-http-authentication-risk-uncovering-pyspider-vulnerabilities/): To learn how SonarQube Cloud detected two vulnerabilities tied to basic HTTP authentication in the open-source pyspider project. - [Beyond Cheap Code: The Next Commit](https://www.sonarsource.com/blog/beyond-cheap-code-the-next-commit/): To explore lessons on AI code verification, cognitive surrender, and building reliable agent loops. - [CLI vs. IDE](https://www.sonarsource.com/blog/cli-vs-ide/): To choose the AI coding environment that fits your style while keeping code quality and security consistent with SonarQube. - [Code Standards for Resilient Flask Web Applications](https://www.sonarsource.com/blog/code-standards-for-resilient-flask-web-applications/): To build resilient Flask APIs with strong code quality and security standards using SonarQube. - [Cut Your Coding Agents' Cost with Sonar Semantic Code Navigation](https://www.sonarsource.com/blog/cut-your-coding-agents-cost-with-sonar-semantic-code-navigation/): To see how semantic code graphs help coding agents find change locations faster and complete updates more efficiently. - [Cyber Resilience Act and AI Velocity](https://www.sonarsource.com/blog/cyber-resilience-act-ai-velocity/): To ensure EU Cyber Resilience Act compliance without slowing AI-assisted development using automated code verification. - [Excessive Expansion: Uncovering Critical Security Vulnerabilities in Jenkins](https://www.sonarsource.com/blog/excessive-expansion-uncovering-critical-security-vulnerabilities-in-jenkins/): To learn how two vulnerabilities discovered in Jenkins could let attackers achieve remote code execution. - [Five SonarQube Cloud Features for Developers Who Want Quality Code](https://www.sonarsource.com/blog/five-sonarcloud-features-for-developers-that-want-clean/): To explore five features that help developers and teams deliver code quality consistently and efficiently. - [Four New Languages Arrive in SonarQube Cloud](https://www.sonarsource.com/blog/four-new-languages-arrive-in-sonarqube-cloud/): To learn about four new languages now supported for deterministic code verification in SonarQube Cloud. - [GoCD Pre-Auth Pipeline Takeover](https://www.sonarsource.com/blog/gocd-pre-auth-pipeline-takeover/): To learn how critical security issues in GoCD could be exploited by unauthenticated attackers. - [GoCD Vulnerability Chain](https://www.sonarsource.com/blog/gocd-vulnerability-chain/): To learn how three more vulnerabilities in GoCD could be chained by attackers to leak or modify internal code. - [How Reasoning Impacts LLM Coding Models](https://www.sonarsource.com/blog/how-reasoning-impacts-llm-coding-models/): To explore how GPT-5's four reasoning modes affect functional correctness, code quality, security, and cost. - [How SonarQube Minimizes False Positives](https://www.sonarsource.com/blog/how-sonarqube-minimizes-false-positives/): To learn how SonarQube's static analysis engine works under the hood to deliver accurate results. - [How Timely Delivery Comes from Transparent Outsourced Software Development Communication](https://www.sonarsource.com/blog/how-timely-delivery-comes-from-transparent-outsourced-software-development-communication/): To learn why transparent communication is essential for timely delivery when working with outsourced development teams. - [How to Optimize SonarQube for Reviewing AI-Generated Code](https://www.sonarsource.com/blog/how-to-optimize-sonarqube-for-reviewing-ai-generated-code/): To avoid the technical debt and reliability issues that unguarded AI-generated code introduces downstream. - [Increase Velocity with Quality as You Code](https://www.sonarsource.com/blog/increase-velocity-with-clean-as-you-code/): To keep working on new projects without sacrificing quality or getting bogged down in refactoring legacy code. - [Interview with a SonarSource Developer](https://www.sonarsource.com/blog/interview-with-a-sonarsource-developer/): To hear a SonarSource developer's perspective on programming, security, and writing code with SonarQube Cloud. - [Introducing Sonar Context Augmentation](https://www.sonarsource.com/blog/introducing-sonar-context-augmentation/): To learn how Sonar Context Augmentation injects SonarQube into AI agents for fewer errors, lower costs, and better AI code review. - [Introducing Sonar Foundation Agent](https://www.sonarsource.com/blog/introducing-sonar-foundation-agent/): To learn about Sonar Foundation Agent, a coding agent for general software issues developed by the former AutoCodeRover team. - [Introducing Sonar Vortex](https://www.sonarsource.com/blog/introducing-sonar-vortex/): To learn how Sonar Vortex guides and verifies AI agent output in real time alongside the now-GA SonarQube Remediation Agent. - [Leveraging SonarQube, SonarQube Cloud, and SonarQube for IDE for Effective Shift-Left Practices](https://www.sonarsource.com/blog/leveraging-sonarqube-sonarcloud-and-sonarlint-for-effective-shift-left-practices/): To move critical code quality checks earlier in the development lifecycle using Sonar's shift-left tools. - [Mastering FastAPI Quality Standards with SonarQube](https://www.sonarsource.com/blog/mastering-fastapi-quality-standards-with-sonarqube/): To improve code quality and security, reduce technical debt, and build secure Python APIs with FastAPI and SonarQube. - [Migrating to SonarQube Cloud Just Got a Whole Lot Easier](https://www.sonarsource.com/blog/migrating-to-sonarqube-cloud-just-got-a-whole-lot-easier/): To learn how the Sonar Migration Tool helps teams move to SonarQube Cloud faster with automated migration reporting. - [Mini Shai-Hulud Targets AI Coding Agents](https://www.sonarsource.com/blog/mini-shai-hulud-targets-ai-coding-agents/): To learn how Mini Shai-Hulud targets AI coding agents through trusted project configs and what to audit now. - [Now Available: SonarQube Plugin for Claude Code](https://www.sonarsource.com/blog/now-available-sonarqube-plugin-for-claude-code/): To learn how the Claude Code plugin for SonarQube brings real-time code quality and security analysis into the terminal. - [Now Available: SonarQube Plugin for Codex](https://www.sonarsource.com/blog/now-available-sonarqube-plugin-for-codex/): To learn how the SonarQube plugin for Codex adds real-time code quality checks and issue remediation to AI coding workflows. - [Now Available: SonarQube Plugin for GitHub Copilot CLI](https://www.sonarsource.com/blog/now-available-sonarqube-plugin-for-github-copilot-cli/): To connect GitHub Copilot CLI to SonarQube for quality gates, dependency risk checks, and agent-driven analysis. - [Now Introducing SonarQube Cloud Enterprise and SonarQube Cloud Team](https://www.sonarsource.com/blog/now-introducing-sonarcloud-enterprise-and-sonarcloud-team/): To learn about two new plans expanding the SonarQube Cloud offering for teams and enterprises. - [OpenAI GPT-5.6: Sol and Terra](https://www.sonarsource.com/blog/openai-gpt-5-6-sol-and-terra/): To learn what changed in GPT-5.6 coding performance, from correctness gains to new security and concurrency challenges. - [OpenRefine Zip Slip](https://www.sonarsource.com/blog/openrefine-zip-slip/): To learn how SonarQube Cloud detected a critical Zip Slip vulnerability in the open-source application OpenRefine. - [pfSense Vulnerabilities Found by SonarQube Cloud](https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/): To learn how SonarQube Cloud discovered multiple vulnerabilities leading to remote code execution on pfSense CE 2.7.0. - [The Power of Quality Code](https://www.sonarsource.com/blog/power-of-clean-code/): To understand why code quality matters and how a quality codebase makes it easier to introduce changes. - [Protecting Your AI Code](https://www.sonarsource.com/blog/protecting-your-ai-code/): To learn about the "Rules File Backdoor" vector, where configuration files are manipulated through hidden Unicode characters. - [Secure Agents from Leaking Secrets with the New SonarQube CLI](https://www.sonarsource.com/blog/secure-agents-from-leaking-secrets-with-the-new-sonarqube-cli/): To learn how the SonarQube CLI open beta moves security checks directly into the developer's agentic workflow. - [Seven Habits of Highly Effective AI Coding](https://www.sonarsource.com/blog/seven-habits-of-highly-effective-ai-coding/): To learn which AI coding habits organizations should adopt to responsibly harness AI tools at scale. - [Seven Questions for Assessing Cyber Resilience Act Codebase Readiness](https://www.sonarsource.com/blog/seven-questions-for-assessing-cyber-resilience-act-codebase-readiness/): To assess Cyber Resilience Act codebase readiness across secure defaults, testing, traceability, and security enforcement. - [Sonar Joins the Open Secure AI Alliance](https://www.sonarsource.com/blog/sonar-joins-the-open-secure-ai-alliance/): To learn how Sonar is helping strengthen AI code security through open-source collaboration with industry leaders. - [Sonar Supports OpenAI's Call for Collective Action on Cyber Defense](https://www.sonarsource.com/blog/sonar-supports-openai-call-for-collective-action-on-cyber-defense/): To learn why Sonar supports OpenAI's call for industry-wide collective action on cyber defense. - [SonarQube Cloud Finds Bugs in High-Quality Python Projects](https://www.sonarsource.com/blog/sonarcloud-finds-bugs-in-high-quality-python-projects/): To see what SonarQube Cloud catches in projects like TensorFlow and NumPy that other linters miss. - [SonarQube 9.8 Is Here](https://www.sonarsource.com/blog/sonarqube-9-8-is-here/): To check out what's new in SonarQube 9.8 and download the latest version. - [SonarQube Advanced Security Now Available](https://www.sonarsource.com/blog/sonarqube-advanced-security-now-available/): To learn about the general availability of SonarQube Advanced Security, the first fully integrated solution for code quality and code security. - [State of Code Developer Survey Report: The Current Reality of AI Coding](https://www.sonarsource.com/blog/state-of-code-developer-survey-report-the-current-reality-of-ai-coding/): To explore findings from Sonar's analysis of over 750 billion lines of code scanned daily. - [TeamCity Vulnerability](https://www.sonarsource.com/blog/teamcity-vulnerability/): To learn how a critical vulnerability in TeamCity could let attackers steal source code and poison build artifacts. - [Technical Debt's Impact on Development Speed and Code Quality](https://www.sonarsource.com/blog/technical-debt-s-impact-on-development-speed-and-code-quality/): To learn how proactively addressing technical debt helps teams build resilient, scalable software. - [The Architecture Gap: Why Your Code Becomes Hard to Change](https://www.sonarsource.com/blog/the-architecture-gap-why-your-code-becomes-hard-to-change/): To learn what architectural drift is and how to bridge the gap between whiteboard designs and actual codebases. - [The Coding Personalities of Leading LLMs: GPT-5 Update](https://www.sonarsource.com/blog/the-coding-personalities-of-leading-llms-gpt-5-update/): To see how GPT-5's coding personality compares against previously evaluated leading LLMs. - [The Future Is AC/DC: The Agent-Centric Development Cycle](https://www.sonarsource.com/blog/the-future-is-ac-dc-the-agent-centric-development-cycle/): To learn why traditional Continuous Integration is giving way to a new agent-centric development cycle. - [The Future of Software Development Is AC/DC](https://www.sonarsource.com/blog/the-future-of-software-development-is-acdc/): To explore Sonar's approach to code verification and technical debt reduction as AI agents write more code. - [The Next State of Code Developer Survey Is Open](https://www.sonarsource.com/blog/the-next-state-of-code-developer-survey-is-open/): To take part in Sonar's next State of Code developer survey on AI's impact on software engineering. - [The Power of Taint Analysis: Uncovering a Critical Code Vulnerability in OpenAPI Generator](https://www.sonarsource.com/blog/the-power-of-taint-analysis-uncovering-critical-code-vulnerability-in-openapi-generator/): To learn how taint analysis uncovered a critical vulnerability in the OpenAPI Generator, discovered by SonarQube Cloud. - [The Return of Shai-Hulud](https://www.sonarsource.com/blog/the-return-of-shai-hulud/): To learn how the Shai-Hulud npm worm spreads and how SonarQube detects malicious packages before they reach production. - [Welcoming Gitar to Sonar](https://www.sonarsource.com/blog/welcoming-gitar-to-sonar/): To learn how Sonar's acquisition of Gitar integrates automated AI code review and remediation into its verification platform. - [Who Are You? The Importance of Verifying Message Origins](https://www.sonarsource.com/blog/who-are-you-the-importance-of-verifying-message-origins/): To learn why verifying the origin of JavaScript message events matters, illustrated by two vulnerabilities found in Squidex. - [Why Sonar Signed the Open Weights and American AI Leadership Letter](https://www.sonarsource.com/blog/why-sonar-signed-the-open-weights-and-american-ai-leadership-letter/): To discover why Sonar signed the Open Weights and American AI Leadership letter and why openness matters for trusted AI. - [Why Your Supply Chain Attack Surface Is Expanding](https://www.sonarsource.com/blog/why-your-supply-chain-attack-surface-is-expanding/): To learn how supply chain attacks spread through dependencies and pipelines and how to protect software early. - [Your AI Agent Doesn't Know Your Codebase's Context or Constraints](https://www.sonarsource.com/blog/your-ai-agent-doesnt-know-your-codebases-context-or-constraints/): To learn why AI coding agents need codebase context to reduce architectural drift and unnecessary token usage. - [Your AI Bill Is a Code Quality Problem](https://www.sonarsource.com/blog/your-ai-bill-is-a-code-quality-problem/): To learn how code quality affects AI agent efficiency, token consumption, and long-term software costs. --- ## Customer Stories ### Root - [Customer Stories](https://www.sonarsource.com/customers/): To explore how leading organizations use Sonar solutions to improve code quality and security at scale. - [Customer Stories (Alternate Path)](https://www.sonarsource.com/customer-stories/): To choose from a list of companies and organizations successfully implementing Sonar to increase quality, security, and analysis. ### Individual Customer Stories - [FedEx Customer Story](https://www.sonarsource.com/customers/fedex/): To learn how FedEx strengthens code quality and security across its global software systems. - [Nasdaq Customer Story](https://www.sonarsource.com/customers/nasdaq/): To discover how Nasdaq ensures reliable and secure software in high-stakes financial environments. - [National Australia Bank Customer Story](https://www.sonarsource.com/customers/national-australia-bank/): To see how National Australia Bank advances code quality and regulatory compliance. - [Digital Turbine Customer Story](https://www.sonarsource.com/customers/digital-turbine/): To explore how Digital Turbine improves development efficiency and code quality. - [Allegiant Customer Story](https://www.sonarsource.com/customers/allegiant/): To understand how Allegiant enhances software reliability and security in aviation systems. - [Vattenfall Customer Story](https://www.sonarsource.com/customers/vattenfall/): To learn how Vattenfall strengthens maintainability and governance across energy software platforms. - [CETIM Customer Story](https://www.sonarsource.com/customers/cetim/): To see how CETIM improves engineering software quality and compliance. - [EDF Customer Story](https://www.sonarsource.com/customers/edf/): To discover how EDF ensures secure and maintainable software in the energy sector. - [Renta Customer Story](https://www.sonarsource.com/customers/renta/): To explore how Renta improves development workflows and code quality standards. - [Infotel Customer Story](https://www.sonarsource.com/customers/infotel/): To learn how Infotel embeds code quality and security into enterprise development. - [Betsson Customer Story](https://www.sonarsource.com/customers/betsson/): To understand how Betsson maintains secure and high-quality software in the gaming industry. - [ANS Customer Story](https://www.sonarsource.com/customers/ans/): To see how ANS enhances DevOps practices with continuous code quality monitoring. - [Centene Customer Story](https://www.sonarsource.com/customers/centene/): To explore how Centene strengthens healthcare software reliability and security. - [AUTO1 Customer Story](https://www.sonarsource.com/customers/auto1/): To discover how AUTO1 maintains scalable, high-quality software across digital platforms. - [SGS Customer Story](https://www.sonarsource.com/customers/sgs/): To learn how SGS improves governance and quality assurance in global operations. - [Covéa Customer Story](https://www.sonarsource.com/customers/covea/): To understand how Covéa ensures secure and maintainable insurance software systems. - [BAE Systems Customer Story](https://www.sonarsource.com/customers/bae-systems/): To see how BAE Systems reinforces secure software development in defense environments. - [AVIV Group Customer Story](https://www.sonarsource.com/customers/aviv-group/): To explore how AVIV Group enhances code quality across digital marketplaces. - [Kroger Customer Story](https://www.sonarsource.com/customers/kroger/): To discover how Kroger strengthens application reliability and security in retail systems. - [HubSpot Customer Story](https://www.sonarsource.com/customers/hubspot/): To learn how HubSpot integrates continuous code quality into rapid product development. - [Wolters Kluwer Customer Story](https://www.sonarsource.com/customers/wolters-kluwer/): To explore how Wolters Kluwer maintains compliance-driven software quality. - [Accor Customer Story](https://www.sonarsource.com/customers/accor/): To understand how Accor improves digital platform reliability and maintainability. - [Allianz Customer Story](https://www.sonarsource.com/customers/allianz/): To see how Allianz strengthens secure software development in financial services. - [Zalando Customer Story](https://www.sonarsource.com/customers/zalando/): To discover how Zalando scales code quality across high-growth e-commerce systems. - [IBM Customer Story](https://www.sonarsource.com/customers/ibm/): To learn how IBM leverages Sonar solutions to enhance enterprise software quality and security. - [Crédit Agricole Customer Story](https://www.sonarsource.com/customers/credit-agricole/): To explore how Crédit Agricole ensures regulatory-compliant and secure banking software. - [Dassault Aviation Customer Story](https://www.sonarsource.com/customers/dassault-aviation/): To understand how Dassault Aviation maintains high-reliability and safety-focused software systems. - [Fidelity Customer Story](https://www.sonarsource.com/customers/fidelity/): To see how Fidelity improves secure and maintainable financial software development. - [NEC Customer Story](https://www.sonarsource.com/customers/nec/): To explore how NEC enhances global software quality and operational resilience. - [Safran Customer Story](https://www.sonarsource.com/customers/safran/): To learn how Safran strengthens secure and safety-critical software engineering practices. - [ANS Customer Story (Alternate Path)](https://www.sonarsource.com/customer-stories/ans/): To learn how ANS integrated SonarQube into its development workflow alongside GitLab and Jenkins. - [Axoft/Tango Software Customer Story](https://www.sonarsource.com/customer-stories/axoft-tango-software/): To learn how Tango chose SonarQube and SonarQube Server to analyze code for quality and coverage. - [BAE Systems Customer Story (Alternate Path)](https://www.sonarsource.com/customer-stories/bae-systems/): To learn how BAE Systems, an international defense and aerospace company, strengthens its security and cybersecurity solutions. - [Cisco Customer Story](https://www.sonarsource.com/customer-stories/cisco/): To learn how Cisco's engineering leadership identified the need to verify a growing volume of AI-assisted code. - [ConfigCat Customer Story](https://www.sonarsource.com/customer-stories/configcat/): To learn how ConfigCat uses SonarQube Cloud to maintain high code quality and security across multiple programming languages. - [DATEV Customer Story](https://www.sonarsource.com/customer-stories/datev/): To learn about DATEV's journey to code quality with SonarQube. - [DEPT Customer Story](https://www.sonarsource.com/customer-stories/dept/): To learn how DEPT centralized SonarQube Cloud across global teams and cut troubleshooting time by 30%. - [Freshworks Customer Story](https://www.sonarsource.com/customer-stories/freshworks/): To learn how Freshworks manages code quality across more than 2,000 repositories supporting over 74,000 customers. - [Global Financial Leader Customer Story](https://www.sonarsource.com/customer-stories/global-financial-leader/): To learn how a global financial leader with roughly 20,000 software engineers uses SonarQube to meet banking industry standards. - [Global Luxury Car Manufacturer Customer Story](https://www.sonarsource.com/customer-stories/global-luxury-car-manufacturer/): To learn how a global luxury car manufacturer manages risk and governance across 550+ active Java projects with SonarQube. - [IMSA Customer Story](https://www.sonarsource.com/customer-stories/imsa/): To learn how IMSA used SonarQube to establish a mandatory quality gate that reduced production bugs and built a culture of accountability. - [M&T Bank Customer Story](https://www.sonarsource.com/customer-stories/m-t-bank/): To learn how M&T Bank saw a return on its code quality and security investment within six months of choosing SonarQube. - [Recognyte Customer Story](https://www.sonarsource.com/customer-stories/recognyte/): To learn how AI-driven real estate intelligence company Recognyte sees immediate ROI with SonarQube Cloud. - [RR Mechatronics Customer Story](https://www.sonarsource.com/customer-stories/rr-mechatronics/): To learn about RR Mechatronics' strategic approach to technical debt with SonarQube. - [Skyscanner Customer Story](https://www.sonarsource.com/customer-stories/skyscanner/): To learn how Sonar's SaaS capabilities help Skyscanner decrease issues and increase development team productivity. - [Xero Customer Story](https://www.sonarsource.com/customer-stories/xero/): To learn how Xero transitioned its code quality and security infrastructure from on-premises to SonarQube Cloud. --- ## Company ### Root - [SonarSource Company Overview](https://www.sonarsource.com/company/): To learn about SonarSource’s mission, values, and commitment to improving code quality and security across the software industry. - [About SonarSource](https://www.sonarsource.com/company/about/): To explore detailed information about SonarSource’s history, leadership, and vision. - [SonarSource Newsroom](https://www.sonarsource.com/company/newsroom/): To access the latest company news, announcements, and media coverage. - [Press Releases](https://www.sonarsource.com/company/press-releases/): To read official press releases about company milestones, partnerships, and product updates. - [Press Kit](https://www.sonarsource.com/company/press-kit/): To download media assets, logos, and resources for press and analyst use. - [Partners](https://www.sonarsource.com/company/partners/): To explore SonarSource’s ecosystem of technology, consulting, and integration partners. - [Careers at SonarSource](https://www.sonarsource.com/company/careers/): To find career opportunities and learn about working at SonarSource. - [Contact SonarSource](https://www.sonarsource.com/company/contact/): To get in touch with the SonarSource team for general inquiries or support. - [Cookie Policy](https://www.sonarsource.com/company/cookie-policy/): To review how SonarSource uses cookies and similar technologies on its websites. - [Privacy Policy](https://www.sonarsource.com/company/privacy/): To understand SonarSource’s privacy practices and how user data is collected, used, and protected. - [Contact a Partner](https://www.sonarsource.com/company/contact-partner/): To explore partnership opportunities with Sonar, trusted by over 7 million developers. - [Sonar in the News](https://www.sonarsource.com/company/coverage/): To find articles, interviews, and media coverage of Sonar, SonarQube, SonarQube Cloud, and SonarQube for IDE. - [Sonar Customers Overview](https://www.sonarsource.com/company/customers/): To learn how over 400,000 organizations across industries trust Sonar to deploy code quality consistently and reliably. ### Partner Pages - [APAC Partner Program](https://www.sonarsource.com/company/partners/apac/): To learn about Sonar's Value Added Partner Program for the APAC region. - [Channel Partner Program](https://www.sonarsource.com/company/partners/channel/): To explore Sonar's Partnership Program, which lets reseller partners bring code quality to customers worldwide. - [Cloud Partner Program](https://www.sonarsource.com/company/partners/cloud/): To learn how Sonar partners with top cloud service providers to simplify building and delivering secure software. - [EMEA Partner Program](https://www.sonarsource.com/company/partners/emea/): To learn about Sonar's Value Added Partner Program for the EMEA region. - [LATAM Partner Program](https://www.sonarsource.com/company/partners/latam/): To learn about Sonar's Value Added Partner Program for the LATAM region. - [North America Partner Program](https://www.sonarsource.com/company/partners/north-america/): To learn about Sonar's Value Added Partner Program for North America. - [Public Sector Partner Program](https://www.sonarsource.com/company/partners/public-sector/): To learn about Sonar's Public Sector Partner Program. - [Technology Partner Program](https://www.sonarsource.com/company/partners/technology/): To learn about Sonar's Technology Partner Program. ### Press Releases - [Sonar Raises $412 Million](https://www.sonarsource.com/company/press-releases/sonar-raises-412-million/): To read the press release announcing Sonar’s $412M funding round supporting expansion in code quality and security offerings. - [Sonar to Acquire Tidelift](https://www.sonarsource.com/company/press-releases/sonar-to-acquire-tidelift/): To learn about Sonar’s strategic acquisition of Tidelift to enhance its open source management capabilities. - [Tariq Shaukat Joins Sonar as Co-CEO](https://www.sonarsource.com/company/press-releases/tariq-shaukat-joins-sonar-as-co-ceo/): To read the announcement of Tariq Shaukat joining Sonar’s leadership team as Co-CEO. - [Sonar Acquires AutoCodeRover to Supercharge Developers with AI Agents](https://www.sonarsource.com/company/press-releases/sonar-acquires-autocoderover-to-supercharge-developers-with-ai-agents/): To explore how Sonar’s acquisition of AutoCodeRover accelerates AI-driven development workflows. - [Sonar ISO Certification](https://www.sonarsource.com/company/press-releases/sonar-iso-certification/): To learn about Sonar achieving ISO certification for its quality and security management systems. - [Sonar Leadership Team Announcement](https://www.sonarsource.com/company/press-releases/sonar-leadership-team/): To read about updates to Sonar’s executive leadership team. - [Sonar Appoints Jean Compeau as CFO and Eyal Ben-David as CLO](https://www.sonarsource.com/company/press-releases/sonar-appoints-jean-compeau-as-chief-financial-officer-and-eyal-ben-david-as-chief-legal-officer/): To see the announcement of new executive appointments to strengthen Sonar’s finance and legal leadership. - [Sonar Records Growth in 2022](https://www.sonarsource.com/company/press-releases/sonar-record-growth-2022/): To review Sonar’s press release on its record growth achievements in 2022. - [Sonar Acquires Gitar](https://www.sonarsource.com/company/press-releases/sonar-acquires-gitar/): To read the announcement combining agentic AI reasoning with Sonar's zero-trust, multilayered code verification platform. - [Sonar Announces New Free Tier of SonarQube](https://www.sonarsource.com/company/press-releases/sonar-announces-new-free-tier-of-sonarqube/): To read about Sonar's launch of a free SaaS tier for private code analysis. - [Sonar Claims Top Spot on SWE-bench Leaderboard](https://www.sonarsource.com/company/press-releases/sonar-claims-top-spot-on-swe-bench-leaderboard/): To read how Sonar Foundation Agent, paired with Anthropic's Claude Opus 4.5, achieved top scores on SWE-bench. - [Sonar Extends Code Security Coverage with SonarQube Advanced Security](https://www.sonarsource.com/company/press-releases/sonar-extends-code-security-coverage-with-sonarqube-advanced-security/): To read about SonarQube Advanced Security's expanded Software Composition Analysis coverage for first-party, AI-generated, and open-source code. - [Sonar Introduces the Agent Centric Development Cycle](https://www.sonarsource.com/company/press-releases/sonar-introduces-the-agent-centric-development-cycle/): To read about Sonar's introduction of the Agent Centric Development Cycle (AC/DC), a methodology built for AI-generated code at scale. - [Sonar Launches Sonar Vortex and SonarQube Remediation Agent](https://www.sonarsource.com/company/press-releases/sonar-launches-sonar-vortex-and-sonarqube-remediation-agent/): To read about the launch of Sonar Vortex and the SonarQube Remediation Agent for AI code verification, governance, and efficiency. - [Sonar Launches SonarQube Hunter Agent](https://www.sonarsource.com/company/press-releases/sonar-launches-sonarqube-hunter-agent/): To read about the general availability of SonarQube Hunter Agent, an AI-powered agent built to catch high-impact vulnerabilities. - [Sonar Named a Leader in the 2026 Gartner Magic Quadrant](https://www.sonarsource.com/company/press-releases/sonar-named-a-leader-in-the-2026-gartner-magic-quadrant/): To read about Sonar being named a Leader in the 2026 Gartner Magic Quadrant for Technical Debt Management Tools. - [Sonar New Deep Analysis Capability](https://www.sonarsource.com/company/press-releases/sonar-new-deep-analysis-capability/): To read about a new innovation that discovers vulnerabilities created by the interaction of source code with third-party libraries. - [Sonar Signs Open Weights and American AI Leadership Letter](https://www.sonarsource.com/company/press-releases/sonar-signs-open-weights-and-american-ai-leadership-letter/): To read about Sonar joining more than 230 companies calling for policies that strengthen open-weight AI innovation. - [Sonar Streamlines Product Naming to Reflect Core Mission](https://www.sonarsource.com/company/press-releases/sonar-streamlines-product-naming-to-reflect-core-mission-of-code-quality-and-security/): To read about Sonar aligning its offering under the SonarQube name to simplify its product brand experience. - [Sonar to Take Center Stage at AI Engineer World's Fair](https://www.sonarsource.com/company/press-releases/sonar-to-take-center-stage-at-ai-engineer-worlds-fair/): To read about Sonar's talks and keynote at the AI Engineer World's Fair in San Francisco. ### Events & Webinars - [SonarSource Events](https://www.sonarsource.com/resources/events/): To explore upcoming events, conferences, and community engagements where SonarSource shares insights on code quality, security, and DevOps practices. - [SonarSource World Tour 2025](https://www.sonarsource.com/resources/events/world-tour-2025/): To learn about the SonarSource World Tour 2025 schedule, locations, and session topics focused on advancing code quality and secure software development. - [SonarSource Webinars](https://www.sonarsource.com/resources/webinars/): To access live and on-demand webinars covering static analysis, code quality and security, AI in software development, and best practices. - [Unpacking the State of Code Reliability Webinar](https://www.sonarsource.com/resources/webinars/unpacking-the-state-of-code-reliability/): To watch a webinar that dives into research findings and strategies for improving software reliability across teams and pipelines. - [Sonar Connect Bangkok](https://www.sonarsource.com/resources/events/sonar-connect-bangkok/): To join Sonar Connect Bangkok and explore how engineering teams can move faster with AI while keeping code quality and security top priorities. - [Sonar Connect Copenhagen](https://www.sonarsource.com/resources/events/sonar-connect-copenhagen/): To join Sonar Connect Copenhagen and explore how engineering teams can move faster with AI while keeping code quality and security top priorities. - [Sonar Connect London](https://www.sonarsource.com/resources/events/sonar-connect-london/): To join Sonar Connect London and explore how engineering teams can move faster with AI while keeping code quality and security top priorities. - [Sonar Connect Madrid](https://www.sonarsource.com/resources/events/sonar-connect-madrid/): To join Sonar Connect Madrid and explore how engineering teams can move faster with AI while keeping code quality and security top priorities. - [Sonar Connect Vienna](https://www.sonarsource.com/resources/events/sonar-connect-vienna/): To join Sonar Connect Vienna and explore how engineering teams can move faster with AI while keeping code quality and security top priorities. - [Sonar Connect Warsaw](https://www.sonarsource.com/resources/events/sonar-connect-warsaw/): To join Sonar Connect Warsaw and explore how engineering teams can move faster with AI while keeping code quality and security top priorities. - [Sonar Connect Washington, D.C.](https://www.sonarsource.com/resources/events/sonar-connect-washington-dc/): To join Sonar Connect Washington, D.C. and explore how engineering teams can move faster with AI while keeping code quality and security top priorities. - [Sonar Connect Zurich](https://www.sonarsource.com/resources/events/sonar-connect-zurich/): To join Sonar Connect Zurich and explore how engineering teams can move faster with AI while keeping code quality and security top priorities. - [World Tour: New York City](https://www.sonarsource.com/resources/events/world-tour/new-york-city/): To register for Sonar's World Tour stop in New York City. - [World Tour: Tokyo](https://www.sonarsource.com/resources/events/world-tour/tokyo/): To register for Sonar's World Tour stop in Tokyo. - [Quality Code for Python Webinar](https://www.sonarsource.com/resources/webinars/clean-code-for-python-webinar/): To learn how to write and remediate high-quality, secure Python code with Sonar's solution. - [Past Webinars](https://www.sonarsource.com/resources/webinars/past-webinars/): To catch up on past webinars covering Sonar's latest features, integrations, and approaches to code quality. - [Secure by Design Webinar](https://www.sonarsource.com/resources/webinars/secure-by-design/): To hear how a shift-left approach and code quality serve as a catalyst for secure code. ### Demo - [Request a Demo](https://www.sonarsource.com/request-demo/): To schedule a personalized demo of Sonar solutions and see how code quality and security insights can be integrated into your development workflows. - [Product Demos](https://www.sonarsource.com/product-demos/): To explore on-demand product demonstrations that showcase Sonar solutions in action, including static analysis, quality gates, and security features. --- ## Legal ### Root - [Legal Overview](https://www.sonarsource.com/legal/): To review SonarSource’s legal frameworks, policies, and documents governing the use of its products and services. - [Website Terms of Use](https://www.sonarsource.com/legal/website-terms-of-use/): To understand the terms and conditions that apply to your use of the SonarSource website. - [UK Modern Slavery Act Statement](https://www.sonarsource.com/legal/uk-modern-slavery-act-statement/): To read SonarSource’s statement on compliance with the UK Modern Slavery Act and its commitment to ethical practices. - [SonarSource Terms and Conditions (PDF)](https://www.sonarsource.com/docs/sonarsource_terms_and_conditions.pdf): To review the full terms and conditions governing the licensing and use of SonarSource products and services. - [SonarQube Advanced Security Supplemental Terms](https://www.sonarsource.com/legal/advanced-security-terms/): To review the supplemental terms for SonarQube Advanced Security, including grants, intellectual property, and DORA requirements. - [Agent Essentials Supplemental Terms](https://www.sonarsource.com/legal/agent-essentials/): To review the supplemental terms governing Agentic Analysis, Context Augmentation, and Remediation Agent under Agent Essentials. - [AI Annex](https://www.sonarsource.com/legal/ai/): To review the AI Annex governing use of SonarSource software that utilizes large language models and similar technologies. - [Legal Archive](https://www.sonarsource.com/legal/archive/): To access archived versions of SonarSource's legal terms and agreements. - [Archived Advanced Security Terms (2026-06)](https://www.sonarsource.com/legal/archive/advanced-security-terms-2026-06/): To review the archived version of the SonarQube Advanced Security supplemental terms dated June 2026. - [Archived AI CodeFix Terms (2026-06)](https://www.sonarsource.com/legal/archive/ai-codefix-terms-2026-06/): To review the archived Early Access release terms that applied to AI CodeFix as of June 2026. - [Archived Primary Agreement](https://www.sonarsource.com/legal/archive/primary-agreement/): To review a prior version of the agreement setting out the terms for SonarSource's software and related services. - [Archived SonarQube Terms and Conditions (2026-06)](https://www.sonarsource.com/legal/archive/sonarqube-terms-and-conditions-2026-06/): To review the archived version of the SonarQube terms and conditions dated June 2026. - [Acceptable Use Policy](https://www.sonarsource.com/legal/aup/): To review the Acceptable Use Policy governing the use of all SonarSource products. - [Candidate Privacy Notice](https://www.sonarsource.com/legal/candidate-privacy-notice/): To understand what personal information SonarSource collects during the recruitment process and how it's used. - [SonarQube Cloud Free and Team Plan Terms](https://www.sonarsource.com/legal/cloud-free-and-team/): To review the supplemental terms governing use of SonarQube Cloud under the Free Tier or Team Plan. - [Data Processing Addendum](https://www.sonarsource.com/legal/data-processing-addendum/): To review the Data Processing Addendum that supplements SonarSource's core product agreements. - [DORA Regulatory Requirements Annex](https://www.sonarsource.com/legal/dora/): To review SonarSource's commitments for compliance with the EU's Digital Operational Resilience Act (DORA). - [Early Access Program Terms](https://www.sonarsource.com/legal/early-access/): To review the terms governing Sonar's Early Access program, covering Preview Add-Ons like Remediation Agent and Agentic Analysis. - [Gitar Supplemental Terms](https://www.sonarsource.com/legal/gitar/): To review the supplemental terms governing access to and use of Gitar as Sonar AI Software. - [Hunter Agent Supplemental Terms](https://www.sonarsource.com/legal/hunter-agent/): To review the supplemental terms governing access to and use of SonarQube Hunter Agent. - [Indirect Reseller Agreement Terms](https://www.sonarsource.com/legal/indirect-reseller-agreement-terms/): To review the terms governing SonarSource's indirect reseller agreements. - [Primary Agreement](https://www.sonarsource.com/legal/primary-agreement/): To review the agreement setting out the terms on which SonarSource provides its software and related services. - [Security Technical and Organizational Measures](https://www.sonarsource.com/legal/security-tom/): To review the technical and organizational measures SonarSource maintains to protect customer data security and confidentiality. - [SonarQube Cloud Service Level Agreement](https://www.sonarsource.com/legal/sonarcloud/service-level-agreement/): To review the Service Level Agreement covering uptime and support commitments for SonarQube Cloud. - [SonarQube Cloud Terms of Service](https://www.sonarsource.com/legal/sonarcloud/terms-of-service/): To review SonarSource's supplemental terms for SonarQube Cloud, incorporating the Primary Customer Agreement and Service Level Agreement. - [SonarQube Terms and Conditions](https://www.sonarsource.com/legal/sonarqube/terms-and-conditions/): To review the terms and conditions relating to the use of the SonarQube product. - [SonarQube Remediation Agent Supplemental Terms](https://www.sonarsource.com/legal/sqra/): To review the supplemental terms governing access to and use of the SonarQube Remediation Agent. - [Sub-processors List](https://www.sonarsource.com/legal/sub-processors/): To review SonarSource's current list of subprocessors involved in hosting, support, and data processing. - [Support Terms](https://www.sonarsource.com/legal/support-terms/): To review the terms and conditions related to SonarQube Support. - [Trial, Complimentary, and Early Access Terms](https://www.sonarsource.com/legal/trial-complimentary-and-early-access/): To review the supplemental terms governing Complimentary Access and optional Preview Add-Ons. - [Sonar Vortex Supplemental Terms](https://www.sonarsource.com/legal/vortex/): To review the supplemental terms governing access to and use of Sonar Vortex. --- ## Static Assets ### Documents - [The Coding Personalities of Leading LLMs (PDF)](https://www.sonarsource.com/the-coding-personalities-of-leading-llms.pdf): To download the detailed PDF comparing how leading large language models perform in code generation and quality evaluation. - [The State of Code Reliability (PDF)](https://www.sonarsource.com/the-state-of-code-reliability.pdf): To access the full report on trends, insights, and strategies for improving software reliability across organizations. - [The State of Code Security (PDF)](https://www.sonarsource.com/the-state-of-code-security.pdf): To download the comprehensive report on modern code security challenges and mitigation strategies. - [The State of Code Maintainability (PDF)](https://www.sonarsource.com/the-state-of-code-maintainability.pdf): To review findings on maintainability trends, technical debt, and long-term code health. - [The State of Code Languages (PDF)](https://www.sonarsource.com/the-state-of-code-languages.pdf): To explore analysis on programming language usage, risks, and best practices in software development. - [7 Habits of Highly Effective AI Coding (eBook PDF)](https://www.sonarsource.com/7-habits-of-highly-effective-ai-coding-ebook.pdf): To download the eBook on best practices for using AI code assistants while maintaining high quality and secure code. - [ANS Customer Story (2025 PDF)](https://www.sonarsource.com/ans-customer-story-2025.pdf): To download the detailed ANS customer success story showcasing improvements in code quality and security. - [BAE Systems Customer Story (2025 PDF)](https://www.sonarsource.com/BAE-Stystems-Customer-Story-2025.pdf): To access the BAE Systems customer story PDF highlighting secure and maintainable software practices. - [Cognitive Complexity (PDF)](https://www.sonarsource.com/docs/CognitiveComplexity.pdf): To read an in-depth PDF explaining cognitive complexity, its measurement, and its impact on readability and maintainability. ### Support - [Support Center](https://www.sonarsource.com/support/): To access help, technical support resources, and assistance for SonarSource products and services. - [Onboarding Resources](https://www.sonarsource.com/onboarding/): To explore onboarding guides and resources that help teams get started with Sonar solutions quickly and effectively. - [Onboarding Projects to SonarQube](https://www.sonarsource.com/onboarding/onboarding-projects-to-sonarqube/): To watch a webinar walkthrough of onboarding projects with SonarQube. - [Onboarding Projects to SonarQube Cloud](https://www.sonarsource.com/onboarding/onboarding-projects-to-sonarqube-cloud/): To watch a webinar walkthrough of onboarding projects with SonarQube Cloud. - [Operating Your SonarQube Instance](https://www.sonarsource.com/onboarding/operating-your-sonarqube-instance/): To watch a webinar walkthrough of the SonarQube installation process. - [SonarQube Best Practices for Developers](https://www.sonarsource.com/onboarding/sonarqube-best-practices-for-developers/): To watch a webinar walkthrough of best practices for using SonarQube. - [Trust Center](https://www.sonarsource.com/trust-center/): To review SonarSource’s commitments and practices around security, privacy, compliance, and reliability. - [Accessibility Statement](https://www.sonarsource.com/accessibility/): To understand SonarSource’s accessibility standards and how it ensures inclusive access to its digital content. - [Brand Identity Resources](https://www.sonarsource.com/brand-identity/): To download brand assets and guidelines for using SonarSource logos and visual elements. - [Solution Briefs](https://www.sonarsource.com/resources/solution-briefs/): To explore concise solution briefs that outline key value propositions, use cases, and benefits of SonarSource offerings. - [Customer Stories (Resources)](https://www.sonarsource.com/resources/customer-stories/): To browse customer success stories highlighting real-world impact of Sonar solutions on code quality and security practices. - [All Resources](https://www.sonarsource.com/resources/all/): To access the full catalog of resources — including webinars, reports, guides, articles, and events — from SonarSource. - [Languages Knowledge Landing Page](https://www.sonarsource.com/lp/knowledge/languages/): To discover knowledge resources and best practices for static code analysis across multiple programming languages. - [MISRA C++ 2023 Knowledge Landing Page](https://www.sonarsource.com/lp/knowledge/languages/cpp/misra-cpp-2023/): To learn how SonarQube's automated code review positions teams for MISRA C++:2023 certification with full coverage. --- ## Learn ### Root - [Sonar Learning Center](https://www.sonarsource.com/learn/): To improve code quality and application security with expert-created courses and bite-sized modules that fit busy schedules. - [Course Catalog](https://www.sonarsource.com/learn/course-catalog/): To browse the full Sonar Learning Center course catalog, covering SonarQube Cloud, SonarQube Server, and Advanced Security. ### Courses - [Ramping Quality Gates: A Practical Guide](https://www.sonarsource.com/learn/course/core-concepts/2f785e41-5bb7-4236-ba7f-a4c449ab9c58/ramping-quality-gates-a-practical-guide-for-enforcing-code-quality-and-security-standards/): To implement a tiered quality gate framework that enforces code quality and security standards across an organization. - [Understanding Project Metrics in SonarQube Server](https://www.sonarsource.com/learn/course/core-concepts/3a1c4581-9a8c-4c74-8c5d-0ced314223ad/understanding-project-metrics-in-sonarqube-server/): To learn how SonarQube metrics are defined and how to interpret project scan results. - [Introduction to Rules, Quality Profiles, and Quality Gates in SonarQube](https://www.sonarsource.com/learn/course/core-concepts/4ce5a772-5253-41dd-b521-8f7c72a7c6dd/introduction-to-rules-quality-profiles-and-quality-gates-in-sonarqube/): To learn how SonarQube rules, quality profiles, and quality gates work together to improve code quality. - [Administering Quality Gates in SonarQube](https://www.sonarsource.com/learn/course/core-concepts/a0f784bb-0722-4c97-ac5f-9e250686014b/administering-quality-gates-in-sonarqube/): To learn how to create a custom quality gate in SonarQube and apply it to projects. - [Configuring Code Analysis for SonarQube Cloud with GitHub Actions](https://www.sonarsource.com/learn/course/sonarqube-cloud/08b944e7-e0e0-4fa6-90c9-467cdfb47dda/configuring-code-analysis-for-sonarqube-cloud-with-github-actions/): To set up automated scanning in a GitHub Actions workflow and review code analysis results. - [Initial SonarQube Cloud Set-Up with Bitbucket](https://www.sonarsource.com/learn/course/sonarqube-cloud/6026e0b7-1566-44d6-95b9-1fab00c0848a/initial-sonarqube-cloud-set-up-with-bitbucket/): To configure SonarQube Cloud to connect with Bitbucket and analyze projects. - [Setting Up SSO for SonarQube Cloud Using Entra ID](https://www.sonarsource.com/learn/course/sonarqube-cloud/8096c134-d770-46c6-8dea-4f692e88e4e3/setting-up-sso-for-sonarqube-cloud-using-entra-id/): To integrate Entra ID with SonarQube Cloud for secure single sign-on and group management. - [Initial SonarQube Cloud Enterprise Set-Up](https://www.sonarsource.com/learn/course/sonarqube-cloud/e390f0fe-64f4-4840-b74c-e63598af72f2/initial-sonarqube-cloud-enterprise-set-up/): To configure SonarQube Cloud to manage an Enterprise subscription and use enhanced features. - [Setting Up SonarQube for IDE in Connected Mode with Eclipse](https://www.sonarsource.com/learn/course/sonarqube-for-ide/decf1afe-f6bf-45d3-aa21-ea2d97a9fc93/setting-up-sonarqube-for-ide-in-connected-mode-with-eclipse/): To set up SonarQube for IDE in Connected Mode within Eclipse. - [Introduction to SonarQube for IDE](https://www.sonarsource.com/learn/course/sonarqube-for-ide/fd73ccb2-f4c6-4d5d-816b-edec87873345/introduction-to-sonarqube-for-ide/): To learn how to find and fix issues earlier in code using the shift-left approach with SonarQube for IDE. - [Configuring Pull Request Decoration for SonarQube Server with Bitbucket Cloud Pipelines](https://www.sonarsource.com/learn/course/sonarqube-server/16851436-6147-454a-9767-d821b9da78ef/configuring-pull-request-decoration-for-sonarqube-server-with-bitbucket-cloud-pipelines/): To set up Bitbucket pull request decoration that enforces quality gates with SonarQube. - [Installing SonarQube Server Data Center Edition on Amazon EKS](https://www.sonarsource.com/learn/course/sonarqube-server/adba64c6-265a-4846-aacc-a89e600023da/installing-sonarqube-server-data-center-edition-on-amazon-elastic-kubernetes-service-eks/): To deploy SonarQube Server Data Center Edition on Amazon EKS using Terraform. *Note: each course above also resolves at a shorter alias, `/learn/courses//` — these are the same pages and are not listed twice.* --- ## Landing Pages ### Product Demo Pages - [AI Code Assurance Interactive Demo](https://www.sonarsource.com/lp/products/ai-code-assurance-navattic-demo/): To see an interactive demo of how the AI Code Assurance workflow instills confidence in every line of AI-generated code. - [SonarQube Advanced Security Interactive Demo](https://www.sonarsource.com/lp/products/sonarqube/advanced-security-navattic-demo/): To see an interactive demo of how SonarQube Advanced Security minimizes risk and reduces technical debt. - [SonarQube Enterprise Edition Landing Page](https://www.sonarsource.com/lp/products/sonarqube/enterprise-edition/): To learn about SonarQube Enterprise Edition features like Security Reports, Portfolio Management, and Executive Reports, and request a free trial. - [SonarQube G2 Leader Landing Page](https://www.sonarsource.com/lp/products/sonarqube/g2-leader/): To start finding and fixing security vulnerabilities in application code with SonarQube. - [SonarQube Interactive Demo](https://www.sonarsource.com/lp/products/sonarqube/navattic-demo/): To see an interactive demo of how SonarQube minimizes risk and reduces technical debt. - [SonarQube Secure Design Interactive Demo](https://www.sonarsource.com/lp/products/sonarqube/secure-design-demo/): To view an interactive demo of the advanced security detection capabilities available in SonarQube. - [Why Upgrade SonarQube Landing Page](https://www.sonarsource.com/lp/products/sonarqube/why-upgrade/): To learn about SonarQube Enterprise Edition features and request a free trial. ### Solution Landing Pages - [Quality Code Landing Page](https://www.sonarsource.com/lp/solutions/clean-code/): To learn how code quality practices make code fit for development and production through structure and consistency. - [Security Landing Page](https://www.sonarsource.com/lp/solutions/security/): To learn how Sonar's SAST and Deeper SAST code security tools help uncover hidden vulnerabilities. --- ## Microsites & Interactive Tools - [Financial Services Industry Page](https://www.sonarsource.com/Industry/financial-services/): To learn how SonarQube helps financial institutions deliver high-quality, secure code amid strict regulatory demands. - [Healthcare Industry Page](https://www.sonarsource.com/Industry/healthcare/): To learn how SonarQube drives secure, compliant healthcare software development while protecting patient data. - [Retail Industry Page](https://www.sonarsource.com/Industry/retail/): To learn how SonarQube helps retail teams secure customer data and achieve PCI DSS compliance. - [Agent-Centric Development](https://www.sonarsource.com/agent-centric-development/): To learn how SonarQube serves as an independent, agent-agnostic trust and verification layer for AI-generated code. - [Agent-Centric Development: Guide Stage](https://www.sonarsource.com/agent-centric-development/guide/): To learn how Sonar Vortex injects structured, queryable architecture context at the start of every agentic session. - [Agent-Centric Development: Solve Stage](https://www.sonarsource.com/agent-centric-development/solve/): To learn how the SonarQube Remediation Agent generates and validates verified fixes without a manual review cycle. - [Agent-Centric Development: Verify Stage](https://www.sonarsource.com/agent-centric-development/verify/): To learn how SonarQube and Gitar run verification together at both the agent's inner loop and sandbox exit. - [Sonar Developer Hub](https://www.sonarsource.com/developers/): To access API documentation, tutorials, and resources for building integrations with Sonar products. - [Disclosed Vulnerabilities](https://www.sonarsource.com/disclosed-vulnerabilities/): To review vulnerabilities that Sonar's security research team has responsibly disclosed across open-source projects after a fix is available. - [Request an AI Demo](https://www.sonarsource.com/request-ai-demo/): To request a demo showing how Sonar mitigates the risks of AI-generated code with AI Code Assurance and AI CodeFix. - [Sonar Research](https://www.sonarsource.com/research/): To explore Sonar's analysis of billions of lines of human- and AI-generated code revealing trends in reliability, security, and maintainability. - [Secure Design Demo](https://www.sonarsource.com/secure-design-demo/): To request a demo showing how AI Code Assurance validates AI-generated code from GitHub Copilot before it reaches production. - [The Coding Personalities of Leading LLMs (SEM Landing Page)](https://www.sonarsource.com/sem/the-coding-personalities-of-leading-llms/): To explore the habits, blind spots, and archetypes of top LLMs and the risks each brings to a codebase. - [Software Development ROI Calculator](https://www.sonarsource.com/software-development-roi-calculator/): To calculate the return on investment of SonarQube and see the financial benefits of improved code quality. - [The Coding Personalities of Leading LLMs (Microsite)](https://www.sonarsource.com/the-coding-personalities-of-leading-llms/): To explore the habits, blind spots, and archetypes of the top LLMs and the risks each brings to a codebase. - [Coding Personalities Leaderboard](https://www.sonarsource.com/the-coding-personalities-of-leading-llms/leaderboard/): To view independent analysis of code generation quality, vulnerabilities, and bugs for leading LLMs. - [Coding Personalities Leaderboard: Opus 4.6 Thinking](https://www.sonarsource.com/the-coding-personalities-of-leading-llms/leaderboard/model/opus-4-6-thinking/): To view the coding personality analysis for the Opus 4.6 Thinking model on the leaderboard. - [Request a Model for the Coding Personalities Leaderboard](https://www.sonarsource.com/the-coding-personalities-of-leading-llms/request-model/): To request that a new LLM be added to the Coding Personalities leaderboard analysis. - [The State of Code](https://www.sonarsource.com/the-state-of-code/): To discover the most common and critical issues found across 7.9 billion lines of analyzed code, in a four-part report series. - [The State of Code: Developer Survey Report](https://www.sonarsource.com/the-state-of-code/developer-survey-report/): To explore survey findings from over 1,100 developers on how generative AI is changing software engineering workflows. - [Trademark Use](https://www.sonarsource.com/trademark-use/): To review SonarSource's trademarks, including Sonar, SonarSource, SonarQube, SonarQube Server, and SonarQube Cloud. --- # End of llms-full.txt