Portfolio Management
Group projects to match your internal hierarchy. Portfolios give you immediate insight into the health of all the projects across an entire department, including your projects’ releasability.
Designed for high availability and scalability
Start your free 14-day Data Center Edition trial and get:
horizontal scalability, high availability, and high performance under extreme load
Analyze the quality of the code in your preferred language. Patch bugs, close vulnerabilities, and follow best practices with a single source of truth.
Easily onboard projects. Integrate with GitHub Actions, GitLab CI/CD, Azure Pipelines, Bitbucket Pipelines, and Jenkins to auto-trigger analysis and show code health status where you work.
Declare custom frameworks you use to capture user input and/or persist it. The injection flaw detection engine tracks the non-sanitized user input.
The UI is crafted for clarity so developers easily understand the problem flow from the vulnerability source to the code location (‘sink’) where the compromise occurs
Super-fast analysis helps you quickly assess where the code stands in pull requests and branches so you can remediate issues while your code is still fresh in mind.
Coding issues are found at the right time and in the right place seamlessly in your dev workflow. Benefit from 5,000+ rules and industry-leading taint analysis of Java, C#, PHP, Python, and more.
Set your specific coding standards to align your team on code health and achieve your code quality goals. Plus Learn as You Code elevates your developer's skills to the same high level.
Add the SonarLint extension to your favorite IDE and find coding issues on the fly as you code. SonarQube settings synchronize to SonarLint, ensuring your team follows a single governed standard of Clean Code.
Group projects to match your internal hierarchy. Portfolios give you immediate insight into the health of all the projects across an entire department, including your projects’ releasability.
Generate, export and schedule reports in PDF format to ensure visibility of key metrics to all stakeholders.
Project PDF reports give you the current Quality Gate status and any failing conditions, plus the major metric values on New Code. You can download from the interface or subscribe to have them delivered straight to your inbox every day, and issues export allows you to extract all Issues and Security Hotspots in a project for import into other systems.
- Dedicated reports to track application security against categories of the OWASP and CWE Top 25 standards
- Shortens the Security Vulnerability feedback loop and helps developers fix security holes faster
- Export a PDF of the top reports
Developer Edition, Enterprise Edition, and Data Center Edition are priced per instance per year and based on your lines of code (LOC). An instance is an installation of SonarQube. You pay per instance for a maximum number of LOC to be analyzed.
Get in touch with sales for pricing specific to your needs.
Trusted and loved by 7 million developers & 400,000+ organizations