6,598 open-source and SaaS tools, with GitHub stats refreshed every day.

SonarQube

Open source

Static code analysis platform that finds bugs, vulnerabilities and maintainability problems in code, in IDEs, pull requests and CI.

sonarqube.org
SonarQube homepage screenshot
GitHub stars
11k
Last commit
yesterday
Repository age
15 years
Version
26.9.0.129388
Licence
LGPL-3.0
Self-hosted
Yes

About SonarQube

SonarQube is a code quality and security platform. Its static analysis uses techniques such as symbolic execution and data and control flow analysis to inspect source code, find bugs and vulnerabilities, and explain what to fix and why. Results appear in the IDE, in pull requests and in CI pipelines.

This repository holds the source of the SonarQube Community Build, the free, open-source edition that shares the analysis used across the product line. It reports reliability bugs, security vulnerabilities and security hotspots, maintainability and structural issues, and coverage on new code. More than 40 programming languages and frameworks are covered, and the same code always produces the same findings.

The project positions itself as a verification step for code written by people or by AI agents before it merges. SonarQube is written in Java and licensed under LGPL-3.0. Commercial editions from SonarSource add further features, while the Community Build can be run on your own servers.

Key features

  • Static analysis for bugs and vulnerabilities
  • Security hotspot review guidance
  • Maintainability and structural issue detection
  • Coverage tracking on new code
  • Support for 40+ languages and frameworks
  • Feedback in IDE, pull requests and CI

Good fit for

  • →Gating pull requests on code quality
  • →Auditing codebases for security issues
Built with
Java
Tags
static-analysis
code-quality
security
ci-cd
sast
java
devsecops

Open-source alternatives to SonarQube

See all

SaaS alternatives to SonarQube

See all