Whether you're an individual developer tinkering on an open source project, a growing team needing branch analysis, or a large enterprise managing compliance and scalability, there's an edition built for your specific needs. But what's the real difference between the different SonarQube Server editions? Our recent blog post breaks it all down. 📖 Get the scoop on key features for each edition to find the perfect fit to manage your code quality and code security at scale. Read the full comparison: https://bit.ly/4nsO0ok #SonarQube #DevOps #CodeQuality #CodeSecurity #DevSecOps #PlatformEngineering
Sonar
Softwareentwicklung
Vernier, Geneva 33.849 Follower:innen
Trusted by 7M devs, Sonar is committed to enabling developers and organizations to build better code for better software
Info
Sonar helps prevent code quality and security issues from reaching production, amplifies developers' productivity in concert with AI assistants, and improves the developer experience with streamlined workflows. Sonar analyzes all code, regardless of who writes it—your internal team or genAI—resulting in more secure, reliable, and maintainable software. Rooted in the open-source community, Sonar’s solutions support over 30 programming languages, frameworks, and infrastructure technologies. Trusted by more than 400,000 organizations and 7 million developers globally, Sonar is considered integral to delivering better software.
- Website
-
https://sonarsource.com/
Externer Link zu Sonar
- Branche
- Softwareentwicklung
- Größe
- 501–1.000 Beschäftigte
- Hauptsitz
- Vernier, Geneva
- Art
- Privatunternehmen
- Gegründet
- 2008
- Spezialgebiete
- software quality, open source, code quality management, ALM, Continuous Inspection und Code Analysis
Orte
Beschäftigte von Sonar
Updates
-
Are your generative AI projects delivering true ROI? 🤖 Coding assistants are accelerating development, but they also introduce new complexities. Maintaining code quality and code security is paramount to control technical debt and realize the full value of your AI investment. Join us for Sonar Connect Zurich on November 18th to address these crucial challenges head-on. We will explore: ➡️ Success factors for #GenAI coding projects, based on data from thousands of customers ➡️ Critical best practices for realizing the expected ROI from your AI investments ➡️ The latest #SonarQube features and our product roadmap Connect with the #SonarTeam, network with industry peers, and gain the insights needed to secure your organization’s future. Seats are limited. Register today: https://bit.ly/48NsJ5g. #CodeQuality #CodeSecurity #SonarConnect
-
-
Sonar hat dies direkt geteilt
At Google, 𝟯𝟬% 𝗼𝗳 𝗻𝗲𝘄 𝗰𝗼𝗱𝗲 now comes from AI, yet productivity 𝗯𝗮𝗿𝗲𝗹𝘆 moved. Here is why: This is what’s called the 𝘦𝘯𝘨𝘪𝘯𝘦𝘦𝘳𝘪𝘯𝘨 𝘱𝘳𝘰𝘥𝘶𝘤𝘵𝘪𝘷𝘪𝘵𝘺 𝘱𝘢𝘳𝘢𝘥𝘰𝘹. AI models are shipping more code than ever… But they’re also creating more insecure, over-engineered code that needs to be reviewed, debugged, and maintained. 𝗠𝗮𝗰𝗵𝗶𝗻𝗲𝘀 𝘄𝗿𝗶𝘁𝗲 𝗳𝗮𝘀𝘁𝗲𝗿 𝗯𝘂𝘁 𝗵𝘂𝗺𝗮𝗻𝘀 𝘀𝗽𝗲𝗻𝗱 𝗹𝗼𝗻𝗴𝗲𝗿 𝗺𝗮𝗸𝗶𝗻𝗴 𝘀𝗲𝗻𝘀𝗲 𝗼𝗳 𝗶𝘁. Sonar analyzed how different LLMs behave using SonarQube and found that each one has its own “coding personality”: 🧠 Claude Sonnet 4 – the senior architect. Over-engineers every feature. 💻 GPT-5 minimal – the baseline performer. Reliable, but verbose. 🎨 Llama 3.2 – the unfulfilled promise. Brilliant one day, chaotic the next. ⚡ OpenCoder 8B – the rapid prototyper. Fast, but brittle. The real challenge now is speeding up validation of human- and AI-generated code without losing quality. That’s where SonarQube helps by automating deep static analysis and enforcing quality gates across every line of code. 🔗 Check out the Free Research Report on LLM Personalities. Link in the comments! P.S. Which LLM personality do you relate to most? I think I’m a bit like Llama :) #LLM #Developers #Coding #GenAI
-
AI is generating more code, but it can be flawed, as its trained on public repos that have bugs, vulnerabilities, and technical debt. This "garbage in, garbage out" problem simply shifts the bottleneck to human developers who have to review and fix it. Manish Kapur dives into this in his latest The New Stack article, covering why we must look beyond 'shift left' and focus on the quality of AI training data to truly unlock productivity. Check it out! 👇
Instead of just generating more code faster and creating a downstream review bottleneck, we can train models to generate better code from the start. By Manish Kapur, thanks to Sonar
-
Generative AI is fast, but it can also be messy. 📈 As AI-assisted code floods your projects, how do you prevent an explosion of technical debt and security vulnerabilities? The promise of AI is huge, but the ROI is only real if you can control the risk. That's why Sonar, along with our partners HEPAPI and Amazon Web Services (AWS), is hosting an exclusive event in Istanbul. We're bringing experts together to share data-driven strategies for success. Join Sonar Connect Istanbul to: 🔹 Discuss the real challenges (and solutions!) for achieving AI ROI 🔹 Learn to secure your code against new AI-driven risks 🔹 Get insights from thousands of customer projects Don't just use AI; learn to master it. Spaces are limited for this in-person strategy session. Save your seat! https://bit.ly/3Wvbe2e #CodeQuality #CodeSecurity #SonarConnect
-
-
We all know AI coding tools are game-changers, but they have a "garbage in, garbage out" problem. 🗑️➡️🤖 They are often trained on public code riddled with bugs and security flaws. SonarSweep tackles this problem at the source! 💡 It's designed to systematically remediate, optimize, and secure the coding datasets used to train LLMs. Think of it as a quality filter for AI training data. 🧹✨ We’re enabling more reliable, secure, and maintainable AI-generated code for everyone. Learn more about SonarSweep: https://bit.ly/3WjsdV8 #SonarQube #CodeQuality #CodeSecurity #SoftwareDevelopment
-
-
Is your team writing code faster with AI, only to get stuck in a new code review bottleneck? This is the AI productivity paradox, and it's a challenge many engineering leaders are facing. We're bringing together a small group of industry peers to discuss how to solve it. Join our exclusive roundtable in NYC (Nov. 13) or London (Dec. 11) to share strategies for harnessing AI's power while maintaining code quality and true development velocity. This isn't a lecture—it's a high-level conversation. Seats are limited to ensure a valuable discussion. Request your spot: https://bit.ly/47sN2mj #AI #SoftwareDevelopment #EngineeringLeadership #DevOps #CodeQuality #SonarRoundtable
-
-
In today's fast-paced development world, security and compliance aren't just nice-to-haves; they're critical. Audit logs provide the essential traceability you need to answer "who did what, and when?" 🕵️♂️ With this new feature in #SonarQube Cloud Enterprise, you can: ✅ Enhance compliance for standards like SOC 2, GDPR, and ISO 27001 ✅ Accelerate security incident investigations ✅ Ensure accountability for all administrative actions This initial release focuses on core IAM events and is available via a new API for easy integration with your SIEM tools. 📈 Ready to level up your organization's security and compliance posture? https://bit.ly/4oCla5Z #CodeQuality #CodeSecurity #DevSecOps
-
-
Sonar hat dies direkt geteilt
I've been using AI coding assistants for 2+ years now. The amount of code I can write in a day has increased by 40%. But my actual productivity increased maybe 15%. AI coding tools are creating a NEW bottleneck in software development. And most teams haven't even noticed yet. Google found that more than 30% of new code across their orgs now comes from AI tools. Sounds impressive, right? But the overall engineering velocity improved by only about 10%. That’s what Sonar calls the engineering productivity paradox. The good part: AI helps you write more code. The bad part: it doesn’t help you ship production-ready apps faster. Because writing code isn’t the hard part anymore. Making sure it’s secure, reliable, and maintainable is. I’ve seen this first-hand in .NET projects. GitHub Copilot, Cursor, Claude - they're phenomenal at creating boilerplate, implementing algorithms, even architecting solutions. It looks fine at a glance, but once you dig in, you'll find subtle bugs, security gaps, missing null checks, unawaited tasks, magic strings… The bottleneck moved from code CREATION to code VERIFICATION. Which is why I started leaning more on SonarQube to ship faster. It finds problems in my code early. This means less time fixing things later. It doesn't just say "this is wrong". It tells you why it's wrong and how to fix it. If you're working on a .NET repo (especially with AI-generated code), it's worth checking out. It'll catch stuff that's easy to overlook when you're moving fast. You can learn more here: https://fandf.co/42R5OSK Here’s what’s been working for me: - I use Cursor for speed - SonarQube for guardrails Fast generation + automated verification = actual productivity gains. P.S. Huge thank you to Sonar for sponsoring this post.
-
Managing open source vulnerabilities doesn't have to be complex. See Marc Rufer's latest post on how #SonarQube's Software Composition Analysis (SCA) helps developers find and fix security issues in their dependencies, right in their existing workflow. #SonarCommunity #OpenSource #CodeQuality #CodeSecurity
Blogged: Software Composition Analysis in SonarQube Advanced Security for SonarQube Cloud #sca #sonarqube #sonarqubecloud #security #sbom #licensecompliance