1.8K
2K
+ 1
53

What is SonarQube?

SonarQube provides an overview of the overall health of your source code and even more importantly, it highlights issues found on new code. With a Quality Gate set on your project, you will simply fix the Leak and start mechanically improving.
SonarQube is a tool in the Code Review category of a tech stack.
SonarQube is an open source tool with 10K GitHub stars and 2.1K GitHub forks. Here’s a link to SonarQube's open source repository on GitHub

Who uses SonarQube?

Companies
466 companies reportedly use SonarQube in their tech stacks, including deleokorea, Alibaba Travels, and Trendyol Group.

Developers
1153 developers on StackShare have stated that they use SonarQube.

SonarQube Integrations

Jenkins, Bitbucket, Travis CI, Gradle, and Apache Maven are some of the popular tools that integrate with SonarQube. Here's a list of all 21 tools that integrate with SonarQube.
Pros of SonarQube
26
Tracks code complexity and smell trends
16
IDE Integration
9
Complete code Review
2
Difficult to deploy
Decisions about SonarQube

Here are some stack decisions, common use cases and reviews by companies and developers who chose SonarQube in their tech stack.

Lana Grant
Sr Software Developer at Intellibridge · | 2 upvotes · 82.3K views
Needs advice
on
SonarSonar
and
ReSharperReSharper

I need to get a comparative analysis of code quality control features that exist in ReSharper but are lacking in SonarQube. Please advise.

See more
Lana Grant
Sr Software Developer at Intellibridge · | 3 upvotes · 242K views
Needs advice
on
ReSharperReSharper
and
SonarQubeSonarQube

I need to compile a comparative analysis of the differences between ReSharper and SonarQube features. Please share your experience/knowledge.

See more
Needs advice
on
Code ClimateCode Climate
and
SonarQubeSonarQube

We have heavy Oracle ERP customizations in the company and some amount of Java/JSP customizations, for which the QA team has to do code review manually. For Java code review SonarQube may be good, but is it the best? And for PL/SQL, Oracle Forms/Oracle reports which tool can do Code review automation?

Please suggest.

See more
Needs advice
on
SonarQubeSonarQube

Hello,

I have a generic question regarding SonarQube.

Suppose I have 5M lines of code in the enterprise edition, and I want to share the cost across multiple platforms, what is the feasible way of cross charging the teams? through which parameter of usage?

I do not want to share it evenly because the number of platforms can increase in the future and randomly considering a parameter will not be an ideal one as there will be a chance of uneven cost distribution.

Could someone who is working in a central team give real examples of how can this be achieved? A solution that can work for both the central team and platforms.

Regards, Priya

See more
Needs advice
on
ESLintESLintPrettierPrettier
and
SonarQubeSonarQube

We have Ember.js applications also React applications, currently, we are using ESLint + Prettier, What values does the SonarQube provide in addition to this?

See more
Needs advice
on
Coverity ScanCoverity Scan
and
SonarQubeSonarQube

Can you just give brief about the differences between Coverity Scan and SonarQube. Which one is better and what are pros and cons of this

See more

SonarQube's Features

  • Multi-language
  • Detect tricky issues
  • Security analysis
  • Enhance your workflow

SonarQube Alternatives & Comparisons

What are some alternatives to SonarQube?
ReSharper
It is a popular developer productivity extension for Microsoft Visual Studio. It automates most of what can be automated in your coding routines. It finds compiler errors, runtime errors, redundancies, and code smells right as you type, suggesting intelligent corrections for them.
Checkmarx
It is a provider of state-of-the-art application security solution: static code analysis software, seamlessly integrated into development process.
Codacy
Codacy automates code reviews and monitors code quality on every commit and pull request on more than 40 programming languages reporting back the impact of every commit or PR, issues concerning code style, best practices and security.
FindBugs
It detects possible bugs in Java programs. Potential errors are classified in four ranks: scariest, scary, troubling and of concern. This is a hint to the developer about their possible impact or severity.
Veracode
It seamlessly integrates application security into the software lifecycle, effectively eliminating vulnerabilities during the lowest-cost point in the development/deployment chain, and blocking threats while in production.
See all alternatives

SonarQube's Followers
2001 developers follow SonarQube to keep up with related blogs and decisions.