Release 26.9.0.129388
Community Build
Free and open source for productivity & code quality
Static code analysis for 22 languages and frameworks
- Java
- JavaScript
- TypeScript
- Python
- C#
- CloudFormation
- Terraform
- Docker
- Kubernetes/Helm Charts
- Kotlin
- Ruby
- Go
- Scala
- Rust
- Flex
- PHP
- HTML
- CSS
- XML
- VB.NET
- Azure Resource Manager/Bicep
- R
SonarQube runs in a FIPS environment
Detect bugs & basic vulnerabilities in code
Review security hotspots
Track and resolve technical debt
Monitor code quality metrics and history of activity
Basic secrets detection
Covers hard coded usernames, passwords, and public cloud services.
Combine results from third-party tools with SARIF reports
CI/CD integration with GitHub, GitLab, Bitbucket and Azure DevOps
Extensible, with 50+ community plugins
2026.5.1 LTA | September
Developer edition
Essential capabilities for small teams & businesses
Additional languages: C, C++, Obj-C, Dart/Flutter, Swift, ABAP, T-SQL, PL/SQL, YAML, JSON, Ansible, GitHub Actions, Shell, Groovy, PowerShell
AI Code Assurance
Ensures AI generated code is fully understood and verified before reaching production.
Manage your project architecture
AutoConfig for C and C++ projects
Detection of injection vulnerabilities (SAST with taint analysis)
Supported languages
- Java
- C#
- JavaScript
- TypeScript
- Python
- PHP
- Kotlin
- Go
- VB.NET
Powerful secrets detection
Detects 400+ secrets patterns with 340+ rules, including coverage of 248 public, private, commercial, and enterprise cloud services.
Detection of advanced bugs causing runtime errors in Python, Java, C#, and VB.NET
Analysis of feature branches, maintenance branches, and pull requests
Display quality gate status in DevOps pull requests for GitHub, GitLab, Bitbucket, and Azure DevOps
Autoprovision users and groups from GitHub and GitLab
Permissions autosync with GitHub
Display security vulnerabilities in GitHub and GitLab
Collect multiple projects together as an Application for a single view
Standard commercial support available
For detailed pricing, contact sales.
2026.5.1 LTA | September
Enterprise edition
Designed to meet Enterprise-level requirements
Additional languages: Apex, COBOL, Gosu, JCL, MuleSoft DataWeave, PL/I, RPG and VB6
Unlimited integrations with DevOps platforms
Supports the following DevOps platforms
- GitHub
- GitLab
- Bitbucket
- Azure Devops
AI CodeFix
Security engine custom configuration for more powerful taint analysis
Custom rules to detect private secret patterns
Aggregate projects and applications into a portfolio
Project, application, and executive portfolio reports
Security reports for common security standards
Supported standards
- PCI DSS
- OWASP ASVS
- OWASP Top Ten
- OWASP Mobile Top 10
- CWE Top 25
- STIG
- CASA
Regulatory and audit reports to record state & quality of release
Consolidate projects into a central instance
Parallel processing of analysis reports
Pull request decoration and guided setup for monorepos
Additional licenses for testing and staging environments
Automatic user and group provisioning through SCIM with Okta and Azure AD
Standard commercial support
For detailed pricing, contact sales.
24/7 white glove premium support available
For detailed pricing, contact sales.
2026.5.1 LTA | September
Data Center edition
For high availability, scalability, & performance
Autoscaling in a Kubernetes cluster
Component redundancy
Data resiliency
Horizontal scalability
High performance under extreme load
Standard commercial support included
24/7 white glove premium support available
For detailed pricing, contact sales.
Where can I find info on deploying SonarQube Server with Docker, Kubernetes, or Helm?
Visit our Deployment Page for details about the various ways to deploy SonarQube Server including Docker, Kubernetes, and with a Helm Chart.
How do I start using the agentic capabilities in SonarQube?
Start by installing the containers of the agentic capabilities you want: Sonar Vortex, SonarQube Remediation Agent, or SonarQube Hunter Agent. Then you'll need to activate each one to get started using them.
I need help planning my update to the latest LTA.
Visit our LTA Update Hub for help planning a smooth update.
What if I am coming from an older Community Build version?
If you are coming from an older version of Community Build, Check the upgrade path.
How do I find older editions of SonarQube Server?
To find older versions of SonarQube Server, see our historical downloads.