About SonarQube
SonarQube is a code quality and security platform. Its static analysis uses techniques such as symbolic execution and data and control flow analysis to inspect source code, find bugs and vulnerabilities, and explain what to fix and why. Results appear in the IDE, in pull requests and in CI pipelines.
This repository holds the source of the SonarQube Community Build, the free, open-source edition that shares the analysis used across the product line. It reports reliability bugs, security vulnerabilities and security hotspots, maintainability and structural issues, and coverage on new code. More than 40 programming languages and frameworks are covered, and the same code always produces the same findings.
The project positions itself as a verification step for code written by people or by AI agents before it merges. SonarQube is written in Java and licensed under LGPL-3.0. Commercial editions from SonarSource add further features, while the Community Build can be run on your own servers.
Key features
- Static analysis for bugs and vulnerabilities
- Security hotspot review guidance
- Maintainability and structural issue detection
- Coverage tracking on new code
- Support for 40+ languages and frameworks
- Feedback in IDE, pull requests and CI
Good fit for
- →Gating pull requests on code quality
- →Auditing codebases for security issues
- Built with
- Java
- Tags
- static-analysis
- code-quality
- security
- ci-cd
- sast
- java
- devsecops
Open-source alternatives to SonarQube
See all
Semgrep
Security
Lightweight static analysis for many languages. Find bug variants with patterns that look
LGPL-2.1vs Snyk★ 17k
Horusec
Security
Horusec is an open source tool that improves identification of vulnerabilities in your pro
Apache-2.0vs Checkmarx★ 1.3k
Dependency-Track
Security
Dependency-Track is an intelligent Component Analysis platform that allows organizations t
Apache-2.0vs Snyk★ 4.3k
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
Trivy
Security
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code rep
Apache-2.0vs Snyk★ 38k
reviewdog
CI/CD & DevOps
🐶 Automated code review tool integrated with any code analysis tools regardless of progra
MITvs Codacy★ 9.6k
SaaS alternatives to SonarQube
See all
Codacy
Developer Tools
Automated code quality and security analysis for pull requests
SaaS
DeepSource
Developer Tools
Static analysis and code health platform with auto-fix suggestions
SaaS
Checkmarx
Security
Application security testing platform with SAST, SCA and API security
SaaSVeracode
Security
Application security testing platform covering static, dynamic and software composition
SaaS
SonarQube Cloud
Developer Tools
Hosted code quality and security analysis for pull requests, from Sonar
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaS

