Innovative features to systematically track and improve Code Quality and Code Security in your applications
Enhance your Workflow with Developer Edition
Available for both cloud-based and self-hosted platforms
Whether you're self-hosted or SaaS, on-prem or in-cloud, we have you covered.
Import repositories and provision projects from your DevOps Platform.
Easily navigate your environment’s analysis configuration with built-in wizards.
Automatically differentiate between main branch and PR - no extra config required.
Commit to Developer-Led Security
Find and review Security Hotspots (uses of
security-sensitive code) in
Available for:
Automatically detect Vulnerabilities (including
Injection Flaws) in:
Available for:
The UI is crafted for clarity so developers easily understand the problem flow from the vulnerability source to the code location (‘sink’) where the compromise occurs
Issue visualizer to track untrusted user input throughout the execution flow
Making sure user-provided data is sanitized before it hits critical systems (database, file system, OS, etc.) helps ensure your code security. Taint analysis tracks untrusted user input throughout the execution flow - across not just methods but also from file to file.
Get highly relevant rules for critical languages to help keep your code secure.
Manage your team's success: Release quality code across projects every time
An Application is a synthetic project composed of projects that ship together; if one isn't ready to ship, none of them are. SonarQube Developer Edition provides you with:
Aggregate quality gate
One place to know if your project set is shippable
Easily visualize the pieces of the projects that work together
Catch tricky bugs, track Code Smells and fix Technical Debt in 24 languages supported:
Licensed by Lines of Code - Starts at $150