SonarQube Server

Home

Request trial

INTEGRATED CODE QUALITY AND CODE SECURITY

Produce high quality code—from the start

SonarQube Server provides actionable code intelligence to continuously improve code quality and code security so developers can build better, faster. Deploys anywhere, on-prem or in the cloud environment of your choice.

Request a demo
main branch of code is passed

TRUSTED BY OVER 7M DEVELOPERS AND 400K ORGANIZATIONS

  • Mercedes Benz
  • Nvidia
  • U.S. Army
  • Santander
  • Costco
  • Request demo
  • Take a product tour
  • Sonar Community
  • Contact us
WHAT IS SONARQUBE SERVER

The industry standard for integrated code quality and code security

Improve code reliability, security, and maintainability, while minimizing repetitive, manual tasks.

Works within your DevSecOps workflows

Easily onboard projects. Integrate with GitHub Actions, GitLab CI/CD, Azure Pipelines, Bitbucket Pipelines, and Jenkins to auto-trigger analysis and show code health status where you work.


Prevent the release of substandard code

Quality gates fail your build pipelines when code quality doesn’t meet your defined standards. Eliminate issues in new code, reducing risk and saving costs from late discovery in the SDLC.

High performance and operability

Deploy your way, on-prem, in the cloud, as a server, with Docker, or with Kubernetes. Multi-threading, multiple compute engines, and language-specific loading delivers optimal performance.

Unmatched accuracy and analysis speed

Industry-leading accuracy maximizes signal and minimizes noise while reducing time-draining work. Receive actionable code health metrics in minutes instead of hours.

Security for first-party and open-source code

Broad vulnerability detection with unrivaled ability to find deeply hidden security issues. Developer-first security analysis for all code: open source, developer-written, and AI-generated.

Unify and elevate teams to a standard

Set your specific coding standards to align your teams around a unified vision of code health. Learn as You Code explanations elevate your developers' skills to the same high level.

Start left by fixing issues in the IDE

Find and remediate issues in real-time as you code with SonarQube for IDE. When connected to SonarQube Server, your coding policies are followed in the IDE.

Connected Mode

Measure and track test coverage of your code

The percentage of code exercised by tests provides valuable insight into code health. SonarQube identifies areas with low test coverage that need improvement.

Code coverage

Find issues in AI-generated code and fix them quickly

AI Code Assurance

Sonar AI Code Assurance is a verification process for detecting AI-generated code and then running it through a structured and comprehensive analysis. This ensures all new code meets the highest standards of quality and security before moving to production.

View AI Code Assurance

AI CodeFix

Sonar AI CodeFix leverages LLMs to suggest code fixes for issues detected by SonarQube Server and SonarQube Cloud. With a single click, get AI-driven fix suggestions directly in your IDE on how to resolve a range of issues, streamlining issue resolution.

View AI CodeFix
SECURITY VULNERABILITY DETECTION

Secure your code base

Static app security testing

Sonar’s static application security testing (SAST) engine detects security vulnerabilities in your code and guides you through resolution before you build and test your application. With SAST, you can achieve robust application security and compliance for complex projects.

Explore SAST

Secrets detection

SonarQube Server includes a powerful secrets detection tool, one of the most comprehensive solutions for detecting and removing secrets in code. Together with SonarQube for IDE, it prevents secrets from leaking out and becoming a serious security breach.

Explore secrets detection

Security standards compliance

SonarQube Server helps you comply with common code security standards, such as the NIST SSDF, OWASP, CWE, STIG, and CASA. Your code is automatically checked for vulnerabilities and provides reports on how your code stands against these standards.

Explore NIST SSDF

Protect your next-gen SDLC with trusted monitors and controls

Deeply integrated into your enterprise environment

SonarQube Server can be deployed into your enterprise environment, whether in the cloud or on-prem, regardless of your infrastructure. With scalable pricing, you only pay for what you need.

Strategic oversight with actionable code intelligence

Security reports, project aggregation for executive-level reporting, and regulatory reports provide the oversight larger organizations need to evaluate the quality and risk of their software assets.

Open source roots, editions for all needs

Community Build

Free and open source for dev productivity and code quality.

Get started

Developer Edition

Essential capabilities for small teams and businesses.

View features

Enterprise Edition

Deeper insights and performance for enterprise.

View features

Data Center Edition

Mission critical availability, scalability, and performance.

Learn features

Your programming language—covered

Coverage for dozens of the most popular languages, frameworks and IaC platforms

Want to see SonarQube Server in action?

Need help getting started?

The Sonar Community is a vibrant, interactive space where Sonar team members and community users get together to discuss all things Sonar. You’ll find detailed articles and technical discussions that cover the most common use cases, and some tricky ones. Plus, the Community is the place to collaborate on new features, provide feedback, and learn more from other developers.

community member helps provide an update on sonar product development
someone using an atm

"Since implementing SonarQube, our organization has seen a 30% reduction in critical code issues, a 25% increase in code quality scores, and a 20% reduction in code vulnerabilities.”

Shivagangadhara J, Cloud Architect

someone using an atm

Shivagangadhara J, Cloud Architect

"Since implementing SonarQube, our organization has seen a 30% reduction in critical code issues, a 25% increase in code quality scores, and a 20% reduction in code vulnerabilities.”

Get SonarQube updates delivered directly to your inbox

By signing up, you will receive product and marketing information about upcoming SonarQube updates, new releases, news, and events.

Select your preferred languages
I do not wish to receive promotional emails about upcoming SonarQube updates, new releases, news and events.

By submitting this form, you agree to the storing and processing of your personal data as described in the  Privacy Policy and Cookie Policy. You can withdraw your consent by unsubscribing at any time.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.