Skip to content
Home

SonarQube

Automates code quality and security reviews with static analysis to detect bugs, vulnerabilities, secrets and maintainability issues and provide fix guidance

www.sonarsource.com/products/sonarqubeTesting & QAVernier, Switzerland501-1000SonarSource Sàrl

The product is a static analysis and code verification platform that automates code quality and security reviews, detecting bugs, vulnerabilities, secrets, and maintainability issues before deployment and providing fix guidance. It is for developers, engineering and platform teams, and IT/security teams in businesses of all sizes that build software. It is delivered as a cloud SaaS and as a self-managed server with an IDE extension and CI/CD integrations, using quality gates and synchronized rules across the workflow.

Key features

  • Static application security testing (SAST)
  • Software composition analysis (SCA)
  • Secrets detection in code
  • Quality gates for CI/CD pipelines
  • Real-time IDE analysis and guidance
  • Automated code fix suggestions
  • Maintainability and reliability metrics
  • Technical debt tracking
  • Compliance reporting (NIST SSDF, OWASP, CWE)
  • Branch and pull request analysis
  • Support for 40+ languages and frameworks
  • AI-generated code verification
  • X0.2/day
  • LinkedIn0.2/day
GTM channels
  • Blog
  • Partner program
  • Marketplace
  • Community
  • API
  • Docs
  • Changelog
ICP
  • Software developers
  • Engineering teams
  • Security teams
VendorSonar