Software development has shifted. It’s no longer just human-centric; it’s agent-driven. To help you scale your AI code output without collapsing under technical debt, we're launching three new Open Betas to support the Agent Centric Development Cycle: 🤖 Sonar Context Augmentation: Injects real-time, project-specific context from SonarQube directly into your AI agent's workflow before it writes a single line of code. Your standards, your architecture, your constraints — surfaced at the right moment, not dumped all at once. ⚙️ SonarQube Agentic Analysis: Brings Sonar's trusted analysis engine directly into the agent's generation loop, verifying code meets your functional, non-functional, and compliance standards in real time. ✅ SonarQube Remediation Agent: Generates verified, ready-to-review PRs the moment SonarQube flags something, and works through your existing backlog systematically — one PR at a time, on your team's terms. Together, they form one continuous, self-improving loop. Read the full story on how they work together: https://bit.ly/4cfqAAp
Sonar
Softwareentwicklung
Vernier, Geneva 38.831 Follower:innen
Trusted by 7M devs, Sonar is committed to enabling developers and organizations to build better code for better software
Info
Sonar is the trust and verification layer for AI code, and the industry standard for automated code review for 17+ years. Sonar delivers deterministic, repeatable, and actionable code verification at scale by integrating code quality and code security into a single platform. The company analyzes more than 750 billion lines of code daily to ensure software is secure, reliable, and maintainable. Sonar is rooted in the open source community and is trusted by 7M+ developers globally, including teams at Snowflake, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company. To learn more about Sonar, please visit: www.sonar.com
- Website
-
https://sonarsource.com/
Externer Link zu Sonar
- Branche
- Softwareentwicklung
- Größe
- 501–1.000 Beschäftigte
- Hauptsitz
- Vernier, Geneva
- Art
- Privatunternehmen
- Gegründet
- 2008
- Spezialgebiete
- software quality, open source, code quality management, ALM, Continuous Inspection und Code Analysis
Produkte
SonarQube
Tools für die statische Code-Analyse
The SonarQube platform delivers automated code quality and security analysis for modern development teams. Designed to seamlessly integrate with your CI/CD pipelines and DevOps tooling, it continuously reviews your source code to uncover bugs, security vulnerabilities, security hotspots, code smells, and architecture issues before code is merged or released. With broad support for 40+ programming languages and frameworks, SonarQube empowers developers and organizations to uphold high standards of code health across web, mobile, embedded, and cloud-native apps. It’s trusted by more than 7 million developers, underscoring its industry leadership as a critical solution for secure, maintainable, and high-quality software development.
Orte
Beschäftigte von Sonar
Updates
-
AI writes the code 🤝 SonarQube makes sure it's right. This is the maturity shift happening in software development right now — we're moving beyond asking LLMs to write code and hoping for the best, toward binding AI agents to a governance contract. The SonarQube MCP Server makes that possible. Paired with Claude Opus 4.6, it gives your AI agent direct access to real-time SonarQube data, so it addresses the specific issues blocking your quality gate — not its best guess at what might be wrong. Coverage is treated as a requirement, not an afterthought. And the fix is verified locally before it ever reaches CI. Check out our step-by-step guide so you can set this up in your own projects today: https://bit.ly/4m2NZsr
-
Your dependencies called. They want to know if you've verified them lately. In an era where teams use AI to rapidly prototype and build, generating code at speed only adds value if that code is trustworthy. SonarQube Advanced Security makes that achievable — with malicious package detection integrated directly into your CI/CD pipeline, automatically comparing dependencies against constantly updated lists of known malicious software, with real-time feedback the moment a risky dependency is introduced and quality gate enforcement to fail pipelines automatically if anything is flagged. Keep the speed. Keep the trust. See how 👇 https://bit.ly/4uUc2h1
-
SonarQube Server 2026.2 is here. 🚀 This release is built for teams who need to move fast without compromising on code quality or security — and it's packed with updates that matter: 🤖 Model-agnostic AI CodeFix: Intelligent remediation suggestions directly in your self-managed environment — no source code leaving your firewall, no exposure to public LLMs. 🌐 Expanded language & framework support: Java 25, FastAPI, Flask, Django, Groovy, and enhanced Apex — including new rules purpose-built to catch the subtle bugs AI coding assistants introduce. 🔒 Unified security reporting: SCA data, SBOM, and first-party code health together in one report — a complete picture of your codebase and software supply chain risk. Update your instance today, or talk to us about migrating to SonarQube Cloud for automatic updates and the same enterprise capabilities. 👇 https://bit.ly/4sBUwg2
-
brb, moving into the Wiz House at #RSAC2026 🏠 Looking for afternoon plans? Don't miss our 3pm session on the Agent Centric Development Cycle ⚡ Hear from Sonar VP Donald Fischer on how to build a secure development process using agents, and the critical partnerships and integrations you need to innovate freely while reducing technical debt.
-
Turns out "ship it and hope for the best" isn't a security strategy. The sixth installment of our State of Code: Developer Survey report series looks at how the best development teams are keeping security front and center as AI becomes a daily part of their workflow. With teams using an average of four AI tools—and 35% of that usage happening through personal, ungoverned accounts—building verification into the process is what separates teams that move fast responsibly from those that accumulate risk. The orgs getting this right are integrating automated verification directly into their workflows so AI speed leads to real security gains, not just faster output. Read our blog post for more insights: https://bit.ly/4rQXVpU
-
Imagine an AI wingman that not only writes code, but autonomously verifies it against your organization’s specific quality gates. 🤯 We've embedded the SonarQube MCP Server directly within SonarQube Cloud to make AI-integrated development more seamless than ever. This native integration closes the context gap by giving your AI assistants—like Claude Desktop, GitHub Copilot, or custom LLM agents—a direct line to Sonar’s deep analysis. ☁️💡 Now, your AI tools can perform high-value tasks directly within the conversational flow, helping you identify issues as you work so you can do it right, the first time. See how it works: https://bit.ly/4bK9OZ1
-
The silos between development and cloud security are officially coming down. 🧱🔨 With our Sonar + Wiz integration, bringing Sonar’s deep SAST insights directly into the Wiz Security Graph, we’re enabling teams to identify "toxic combinations" where code-level vulnerabilities meet runtime exposure. Met us at the Wiz House during #RSAC2026 (661 Howard St.) to learn more. And don’t miss the Wiz party that Tuesday! More here: https://bit.ly/4r6HbLf
-
High-performance engineering thrives when code verification is a natural, frictionless part of the software development lifecycle. 🚀 With automatic provisioning for GitHub repositories now generally available on SonarQube Cloud, we're eliminating the manual overhead of project setup. Every new repository is verified from the very first commit, providing actionable insights from day 1 without ongoing admin intervention. Maintain your organization’s standards by default and build a secure-by-default environment that scales with your team. See how it works: https://bit.ly/4bRpjiS