AppSecNews
SAST Commercial, free tier Established

SonarQube

by Sonar

Self hosted analysis server that scans repositories for quality and security issues, enforces quality gates and tracks findings over time.

Visit sonarqube.org (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run SonarQube in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Which capabilities sit in which edition changes between releases, confirm the current edition matrix
  • Language list per edition differs, confirm

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

SonarQube is a server that receives analysis results from scanners run in your build and turns them into a tracked, queryable state of the codebase. The scanners parse source per language, build a syntax tree and a symbol table, then apply rule sets divided into bugs, code smells, vulnerabilities and security hotspots. The hotspot concept is deliberate: rather than asserting that a cryptographic call or a permissive CORS setting is a vulnerability, it flags code where a security relevant decision was made and asks a reviewer to confirm the context makes it safe.

In the commercial editions the analysis extends to interprocedural taint tracking. Untrusted input from request parameters, headers and files is propagated through the call graph, and findings are reported with the full flow from source to sink, which is what makes SQL injection, path traversal and cross site scripting detectable rather than guessed at. Around this sits the quality gate: conditions on new code, typically zero new vulnerabilities plus coverage and duplication thresholds, which the build queries and fails on.

Where it fits

A scanner step runs in every pipeline and publishes to a central server. The quality gate is the enforcement point at merge time, with branch and pull request analysis comparing against the target branch so only new problems block a merge. Compiled languages need the scanner to wrap the build so it can see bytecode and resolved types, which is the main setup cost. Platform teams own the server, developers consume results through pull request decoration and the IDE extension.

Strengths

  • The new code quality gate is the most practical adoption pattern in this space: it stops the bleeding without demanding a legacy cleanup first.
  • Broad language coverage from a single server, with consistent rule presentation across all of them.
  • Taint analysis with a visible source to sink flow in the commercial editions, which makes triage defensible rather than a judgement call.

Limitations

  • The free Community Build omits taint analysis, branch analysis and pull request decoration, the features most security programs actually need. Evaluating on the free tier will misrepresent the product.
  • Security rules are a minority of the rule set. This is a code quality platform with security capability, and teams sometimes buy it expecting a dedicated SAST tool.
  • Self hosting means running and upgrading a server and a database that grows steadily with analysis history.

Who it suits

Well suited to organizations that want one platform covering many languages and that value gating on new code across every repository. Less suited to a team that wants only vulnerability detection, or one unwilling to operate a server and its database.

Used SonarQube? Recommend it under your own name and title.

Recommend this tool