SonarQube Cloud
Submit idea
Under Consideration
Coming Next
Released
Project Branches & Pull Requests
Clear and effective new code configuration options
6
Simplify the concept of branches
17
Easily change the main branch of a project
19
New Pull Request issues on unchanged code
219
Fixed issues in Pull Requests
112
Receive annotations in GitHub Pull Requests
84
AI Capabilities
Automatic PR Creation from AI CodeFix Suggestions
2
Issues
Personal dashboard improvements
8
Understand issues faster with visual representations
7
Enhanced diff highlighting for code examples
10
Snooze issues
6
AI generated Unit Tests
6
Quality Profiles & Quality Gates
Fine-tune behavior around Quality Gates and new code availability
17
Changes to Quality Gate and Quality Profile configurations are visible
6
Accessibility as a software quality
11
Sustainability and Green IT as a software quality
18
SonarQube for IDE
Activate SonarQube for IDE connected mode from SonarQube Server or SonarQube Cloud web interface
6
Integration
Slack notifications
82
Connect to GitHub Enterprise Server
3
Guide administrators to setup analysis on Jenkins
0
Quality Gate pipe for Maven projects on Bitbucket Cloud
5
Change the organization binding
4
Administrators can transfer projects between organizations
3
Connect to self-hosted GitLab instances
6
Connect to on-premise Bitbucket Server
0
Connect to on-premise Azure DevOps Server
1
Support Azure DevOps Service Principals instead of Personal Access Tokens
18
Use OIDC to set GitHub Actions analysis instead of secrets
8
Identity & Access Management
Synchronize your GitHub teams with SonarQube Cloud groups
22
Outside collaborators from GitHub are synchronized
7
SCIM support
12
Synchronize members on SonarQube Cloud for GitLab organizations
3
Restrict user list to a specific company email domain
8
Operability
Automatically import your repositories
116
Migrate from SonarQube Server to SonarQube Cloud
26
Add mobile support to the web application
4
Bring your own key - BYOK
0
Reporting
Reporting Capabilities
42
Account and organization audit logs
26
Managers can assess if softwares are compliant with "Digital Operational Resilience Act" (DORA)
0
Summary of all analysis problems/warnings for projects
4
WCAG Accessibility report
9
SonarQube can export findings as SARIF output
13
Quantify the value Sonar brings to your organization
6
Software Composition Analysis (SCA)
Malicious package detection
1
End of Life dependency detection
1
Code Security / SAST: Capabilities
Detect second-order vulnerabilities
4
Detect Prototype Pollution vulnerabilities
10
Raise Vulnerabilities in inline JavaScript code inside HTML files
6
Detect PHP Server-Side Template Injection (SSTI)
2
Detect C# Server-Side Template Injection (SSTI)
2
SAST for Swift
0
Code Security / SAST: Framework Support
Detect Taint Vulnerability issues in Blazor Apps
5
Medoo PHP Database Framework support
2
Support for Java Streams in security analysis
4
DotNet ASP.NET Core 6.0 "Minimal APIs" support
6
Python Starlette
2
Quarkus support in security analysis
6
Eclipse Vert.x support in security analysis
0
Detect security issues on Cloud Deployment Manager files
0
Detect security misconfigurations in Chef files
0
Detect security misconfigurations in Puppet files
1
Code Quality: Capabilities
Rules for error-free Python coroutines
1
Performance rules for Python
5
Rules for effective use of Python Collections
0
Rules for effective use of Python comprehensions
0
Sonar can load Rubycritic reports
3
.NET String Comparison Rules
0
.NET Localisation Rules
0
Testable code rules
4
Help C# Developers catch errors in Regular Expressions
1
Sonar helps .NET developers apply good practices around authentication and authentication
1
Rules to help developers use the {fmt} C++ library at best
3
Assess if my C code is compliant with MISRA C 2023 standard
17
Assess if my C code is compliant with MISRA C 2012 standard
27
Assess if my C code is compliant with SEI CERT C
8
Assess if my C++ code is compliant with SEI CERT C++
6
Assess if my C++ code is compliant AUTOSAR C++14
13
Asses if my C code is compliant with BARR-C:2018
1
Help C and C++ developers writing regexp running fast, with the correct amount of resources and really doing what developers intended
1
Java Code Quality rules for Azure Functions
1
Java Code Quality rules for Google Cloud Functions
2
Analyze my C++ code against MISRA C++ 2023 rules
22
Apply main code rules to test code
0
Logging rules for Python
0
API usage rules for Python
0
Memory management rules for Python
0
Performance as a software quality
15
When is it helpful to be able to change the type of a rule or issue?
0
Support lcov coverage format for C and C++
0
Code Quality: Framework Support
ASP.NET Webforms support
3
ASP.NET Razor Pages support
1
ASP.NET rules
1
Avoid common pitfalls in Minimal APIs
0
Avoid common pitfalls in ASP.NET pipeline configuration
0
Entity Framework Core rules
1
Analyse Unity Projects
5
Sonar helps DevOps people to have clean Docker Compose code
20
Detect security misconfigurations in Pulumi files
4
Support the Connexion Python web framework
0
Matplotlib library support in Python analysis
0
Support Analysis of Databricks Notebooks Magic Commands & Imports
26
Support Seaborn library for Python
0
Support Microsoft's type libraries and COM interfaces through the use of #import
2
Support C++/CLI
6
Support Cuda extensions
15
Support OpenMP extensions
10
Sonar detects security issues in JSP files using JSTL 3 `jakarta.tags.*` tags
0
Help developers with Spring Data
3
Project Reactor support
6
Spring Cloud support
3
RxAndroid support
0
RxJava3 support
3
React Native support
41
Keras library support in Python analysis
0
Support "Kustomized" variants of Kubernetes YAML configurations
1
Sonar raises more issues on Docker shell commands
0
Code Quality rules for Hugging Face
0
Detect uses of functions IPV6 incompatible
1
Best practices to use C++'s Algorithms library
1
Code Analysis: User Experience
Automatic Analysis of Azure DevOps Repositories
0
Automatic analysis is available for Azure DevOps
4
Automatic analysis is available for Bitbucket Cloud
5
Automatic analysis is available for GitLab
3
Automatic analysis includes test and coverage reports
62
Automatic analysis analyzes all branches
4
Exploring updates to code coverage and duplication
27
Bring external results to the automatic analysis of your projects
7
//NOSONAR ignores a specific list of rules (like @SuppressWarnings)
26
Code coverage is computed in parallel to the analysis
6
Support for dotCover and DeterministicSourcePaths
3
Simplified Scanner for .NET
1
Import Mutation Testing Results
11
Support custom rules for C and CPP
16
Analyze multiple code variants built on distinct hosts
3
Analyze multiple code variants built on the same host
7
Expand compiler support
31
Support C/C++/Objective-C analysis on Windows Arm64
3
Provide an Azure Devops task to analyze C and C++
6
Automatic Analysis of GitLab Repositories
1
Analyze .NET code with the Scanner CLI
0
Code Analysis: Language Version Support
R support
52
Support Java 23
0
Elixir support
86
Java analysis for Spark usage
0
Support SQL
1
Delphi support
43
Support Rego Language / Open Policy Agent (OPA)
10
OpenAPI support
23
Scan GitHub workflow files
0
Scan GitLab CI files
1
Scan AzureDevOps pipelines
1
Automatically detect the presence of AI-generated code
0
Support Powershell
7
Support Q
0
Support Groovy
16
Support sh/bash
5
Support Snowflake SQL
1
Help data professionals avoid pitfalls with Snowflake SQL
Custom Rules for any language
2