SonarQube
4.4
94

Not Claimed

SonarQube is a tool for inspecting code quality and security, providing remediation guidance for 27 languages. It integrates into workflows to provide feedback in-IDE, in pull requests, and in SonarQube itself. It has over 225,000 deployments and helps small development teams and global organizations improve their code quality and security.
Developer
SonarSource S.A
Category
Security
HQ Location
Geneva, Switzerland
Year Founded
2008
Number of Employees
511
Strengths
  • Code quality analysis

    Provides comprehensive code quality analysis for various programming languages

  • Integration

    Integrates with various development tools and platforms

  • Customization

    Highly customizable to fit specific needs and requirements

Weaknesses
  • Complexity

    Can be complex to set up and configure

  • Resource-intensive

    Requires significant resources to run effectively

  • Limited reporting

    Reporting capabilities are limited compared to other tools

Opportunities
  • Increasing demand for code quality analysis tools in the market
  • Potential for new features and improvements to be added
  • Opportunity to expand into new markets and industries
Threats
  • Competition from other code quality analysis tools in the market
  • Potential security vulnerabilities and risks
  • Changes in regulations and compliance requirements

Ask anything of SonarQube with Workflos AI Assistant

http://www.sonarsource.com
Apolo
Squeak squeak, I'm a cute squirrel working for Workflos and selling software. I have extensive knowledge of our software products and am committed to providing excellent customer service.
What are the pros and cons of the current application?
How are users evaluating the current application?
How secure is the current application?

Review Distribution

  • 👍
    High - rated users

    Feature like Code Analysis and publishing those analysis report to end user. You can use default Quality Gates and Quality Profiles for scanning of your code. In case you want to modify these you can do that and define your own rule. Whenever there's commit in repo you just need to configure the task in your continuous integration pipeline if it passed the parameter only then commit will happens the master/main branch otherwise it will not. With these features you can eliminate the security threats and ensure that developers are following good practices while developing their code. I have integrated it with Azure DevOps.Only thing which I can think can be improved is logging of events. Sometime it becomes hard to debug the issues. Other then that, I think over all this fulfills all the requirements.

  • 🤔
    Average - rated users

    PR analysis and Integration with Bitbucket are most helpful.1. Number of rules should be increased. 2. Few rules should have custom exclusions. Ex: Naming conventions => Organisation-specific words will be there which should be in Capital. 3. Generating a lot of false positives 4. Executive reports should generate based on scheduled triggers. We have 20 projects which are assigned to a Portfolio. if you are going to generate a report and send an email for the first portfolio calculation then the rest of the 19 projects info for that day will be missed. Higher management will think that the generated report is the latest but it is not. 5. PR analysis reports should be generated Quickly.

Media

SonarQube 0a74e87c-fb22-4e4b-a04b-b6eeb696826a.png SonarQube eff2835a-b8e0-420a-86a6-55b279576f60.png SonarQube 31220595-b4dc-4de7-9898-c8fac9a14637.png SonarQube f79b4a91-4389-4b48-8bf3-ccaf85e4422e.png SonarQube a9b6a541-b1b9-43f4-8881-3e6cc889bbfa.png SonarQube f2329725-4493-4c10-8546-a428e1880cbd.png

SonarQube Plan

SonarQube offers a free Community version and paid Enterprise versions with pricing based on the number of lines of code analyzed.
Community $ Free
https://www.sonarsource.com/products/sonarqube/downloads/
Data Center $ Free Trial
Licensed by Lines of Code - Starts at $130,000 per year/instance https://www.sonarsource.com/plans-and-pricing/data-center/
Developer $ Free Trial
Licensed by Lines of Code - Starts at $150 per year/instance https://www.sonarsource.com/plans-and-pricing/developer/
Request a Demo
OK , I Know
Request a Demo
OK , I Know