# Home

Documentation for SonarQube Server, SonarQube Cloud, and SonarQube for IDE.

<p align="center"><strong>Reduce outages, improve security, lower risk.</strong></p>

<figure><picture><source srcset="/files/BDE3zdFzDDRsMK4LIq3b" media="(prefers-color-scheme: dark)"><img src="/files/OhSmGAh79bdYTykgzPbl" alt=""></picture><figcaption></figcaption></figure>

<table data-view="cards"><thead><tr><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><mark style="color:$primary;">Agent Centric Development Cycle (AC/DC)</mark></td><td><a href="/spaces/zYzZGUqhw8kWwKnXrN2I">/spaces/zYzZGUqhw8kWwKnXrN2I</a></td></tr><tr><td><mark style="color:$primary;">SonarQube Developer Tools</mark></td><td><a href="/spaces/EhCrTztgxKYZFqWYjvNz">/spaces/EhCrTztgxKYZFqWYjvNz</a></td></tr><tr><td></td><td></td></tr></tbody></table>

<table data-view="cards" data-full-width="false"><thead><tr><th></th><th data-hidden data-card-cover-dark data-type="image">Cover image (dark)</th><th data-hidden data-card-cover data-type="image">Cover image</th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><mark style="color:$primary;">SonarQube Cloud documentation</mark></td><td><a href="/files/I1KY0uViN69MDlAdQd3R">/files/I1KY0uViN69MDlAdQd3R</a></td><td><a href="/files/hRqKFJOGSU1mnIwaYZM4">/files/hRqKFJOGSU1mnIwaYZM4</a></td><td><a href="/spaces/B4UT2GNiZKjtxFtcFAL7">/spaces/B4UT2GNiZKjtxFtcFAL7</a></td></tr><tr><td><a href="/spaces/2oR4S7aAgfaoiEmIKjM5">SonarQube Server 2026.4 documentation</a></td><td><a href="/files/A7Wtv7NEYjobLSrdic87">/files/A7Wtv7NEYjobLSrdic87</a></td><td><a href="/files/1vRGQx0BtkkIYOpW5dU4">/files/1vRGQx0BtkkIYOpW5dU4</a></td><td></td></tr><tr><td><mark style="color:$primary;">SonarQube Server 2026.3 documentation</mark></td><td><a href="/files/A7Wtv7NEYjobLSrdic87">/files/A7Wtv7NEYjobLSrdic87</a></td><td><a href="/files/1vRGQx0BtkkIYOpW5dU4">/files/1vRGQx0BtkkIYOpW5dU4</a></td><td><a href="/spaces/9k439yOkBUXTchVsVnQG">/spaces/9k439yOkBUXTchVsVnQG</a></td></tr><tr><td><mark style="color:$primary;">SonarQube Server 2026.1 LTA documentation</mark></td><td><a href="/files/A7Wtv7NEYjobLSrdic87">/files/A7Wtv7NEYjobLSrdic87</a></td><td><a href="/files/1vRGQx0BtkkIYOpW5dU4">/files/1vRGQx0BtkkIYOpW5dU4</a></td><td><a href="/spaces/LWhbesChsC4Yd1BbhHhS">/spaces/LWhbesChsC4Yd1BbhHhS</a></td></tr><tr><td><mark style="color:$primary;">SonarQube Server 2025.4 LTA documentation</mark></td><td><a href="/files/A7Wtv7NEYjobLSrdic87">/files/A7Wtv7NEYjobLSrdic87</a></td><td><a href="/files/1vRGQx0BtkkIYOpW5dU4">/files/1vRGQx0BtkkIYOpW5dU4</a></td><td><a href="/spaces/yDv2XwTC1xoOKBYeCK45">/spaces/yDv2XwTC1xoOKBYeCK45</a></td></tr><tr><td><mark style="color:$primary;">SonarQube Server 2025.1 LTA documentation</mark></td><td><a href="/files/A7Wtv7NEYjobLSrdic87">/files/A7Wtv7NEYjobLSrdic87</a></td><td><a href="/files/1vRGQx0BtkkIYOpW5dU4">/files/1vRGQx0BtkkIYOpW5dU4</a></td><td><a href="/spaces/4FzELVjsPO4ijRo3jtBV">/spaces/4FzELVjsPO4ijRo3jtBV</a></td></tr></tbody></table>

<table data-view="cards" data-full-width="false"><thead><tr><th></th><th data-hidden data-card-cover-dark data-type="image">Cover image (dark)</th><th data-hidden data-card-cover data-type="image">Cover image</th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><mark style="color:$primary;">SonarQube Cli Documentation</mark></td><td><a href="/files/e7Tjve6Xeyh6FamLUpVn">/files/e7Tjve6Xeyh6FamLUpVn</a></td><td><a href="/files/qlUy6LFptXAabjHJ9zLG">/files/qlUy6LFptXAabjHJ9zLG</a></td><td><a href="/spaces/eHsJzr9cYhsTa0LTZlmo">/spaces/eHsJzr9cYhsTa0LTZlmo</a></td></tr><tr><td><mark style="color:$primary;">SonarQube for VS Code Documentation</mark></td><td><a href="/files/ieHFaDFrkC2jIoG2wF5l">/files/ieHFaDFrkC2jIoG2wF5l</a></td><td><a href="/files/TSEL9nJzzeqcQAgNzWsl">/files/TSEL9nJzzeqcQAgNzWsl</a></td><td><a href="/spaces/6LPRABg3ubAJhpfR5K0Y">/spaces/6LPRABg3ubAJhpfR5K0Y</a></td></tr><tr><td><mark style="color:$primary;">SonarQube for IntelliJ Documentation</mark></td><td><a href="/files/ieHFaDFrkC2jIoG2wF5l">/files/ieHFaDFrkC2jIoG2wF5l</a></td><td><a href="/files/TSEL9nJzzeqcQAgNzWsl">/files/TSEL9nJzzeqcQAgNzWsl</a></td><td><a href="/spaces/NvI4wotPmITyM0mnsmtp">/spaces/NvI4wotPmITyM0mnsmtp</a></td></tr><tr><td><mark style="color:$primary;">SonarQube MCP Server</mark></td><td><a href="/files/73ghzgzknCneDmeEzr2u">/files/73ghzgzknCneDmeEzr2u</a></td><td><a href="/files/8QCw1wjzOAqvM2akbFww">/files/8QCw1wjzOAqvM2akbFww</a></td><td><a href="/spaces/NMPi6OcwuaQpPV3mp3TU">/spaces/NMPi6OcwuaQpPV3mp3TU</a></td></tr><tr><td><mark style="color:$primary;">SonarQube for Visual Studio Documentation</mark></td><td><a href="/files/ieHFaDFrkC2jIoG2wF5l">/files/ieHFaDFrkC2jIoG2wF5l</a></td><td><a href="/files/TSEL9nJzzeqcQAgNzWsl">/files/TSEL9nJzzeqcQAgNzWsl</a></td><td><a href="/spaces/5CSDwdOaYoOAGYNiRqgl">/spaces/5CSDwdOaYoOAGYNiRqgl</a></td></tr><tr><td><mark style="color:$primary;">SonarQube for Eclipse Documentation</mark></td><td><a href="/files/ieHFaDFrkC2jIoG2wF5l">/files/ieHFaDFrkC2jIoG2wF5l</a></td><td><a href="/files/TSEL9nJzzeqcQAgNzWsl">/files/TSEL9nJzzeqcQAgNzWsl</a></td><td><a href="/spaces/kadXEH8HkykK7lKaDvVq">/spaces/kadXEH8HkykK7lKaDvVq</a></td></tr><tr><td><mark style="color:$primary;">SonarQube Community Build Documentation</mark></td><td><a href="/files/X5A1SdRAHICzb0hYTRiO">/files/X5A1SdRAHICzb0hYTRiO</a></td><td><a href="/files/tT7O875ME8fhcNH5mdwi">/files/tT7O875ME8fhcNH5mdwi</a></td><td><a href="/spaces/bqrfLGeD0Y9vE5l9Le42">/spaces/bqrfLGeD0Y9vE5l9Le42</a></td></tr></tbody></table>

<table data-full-width="false"><thead><tr><th>Log in or download SonarQube</th><th data-hidden data-type="files"></th><th data-hidden data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="https://sonarcloud.io/login">Log in to SonarQube Cloud</a></td><td><a href="/files/BauZNE6cSMoWbmt3t1zM">/files/BauZNE6cSMoWbmt3t1zM</a></td><td><a href="https://sonarcloud.io/login?_gl=1*qoa3nr*_gcl_au*MjE0MTczNTAzMy4xNzQwMzg4MzYw*_ga*MTE2OTkyODc2OC4xNzQwMzg4MzU5*_ga_9JZ0GZ5TC6*MTc0MDQ1MjkwMy4yLjEuMTc0MDQ2MTY3OS41OC4wLjA.">https://sonarcloud.io/login?_gl=1*qoa3nr*_gcl_au*MjE0MTczNTAzMy4xNzQwMzg4MzYw*_ga*MTE2OTkyODc2OC4xNzQwMzg4MzU5*_ga_9JZ0GZ5TC6*MTc0MDQ1MjkwMy4yLjEuMTc0MDQ2MTY3OS41OC4wLjA.</a></td></tr><tr><td><a href="https://www.sonarsource.com/products/sonarqube/downloads/">Download SonarQube Server</a></td><td><a href="/files/GTblowQGo9dFia05mY6Y">/files/GTblowQGo9dFia05mY6Y</a></td><td><a href="https://www.sonarsource.com/products/sonarqube/downloads/?_gl=1*qoa3nr*_gcl_au*MjE0MTczNTAzMy4xNzQwMzg4MzYw*_ga*MTE2OTkyODc2OC4xNzQwMzg4MzU5*_ga_9JZ0GZ5TC6*MTc0MDQ1MjkwMy4yLjEuMTc0MDQ2MTY3OS41OC4wLjA.">https://www.sonarsource.com/products/sonarqube/downloads/?_gl=1*qoa3nr*_gcl_au*MjE0MTczNTAzMy4xNzQwMzg4MzYw*_ga*MTE2OTkyODc2OC4xNzQwMzg4MzU5*_ga_9JZ0GZ5TC6*MTc0MDQ1MjkwMy4yLjEuMTc0MDQ2MTY3OS41OC4wLjA.</a></td></tr><tr><td><a href="https://www.sonarsource.com/products/sonarqube/ide/ide-login/">Install SonarQube for IDE</a></td><td><a href="/files/eR9oh7tjNXKQY7jKiTsG">/files/eR9oh7tjNXKQY7jKiTsG</a></td><td><a href="https://www.sonarsource.com/products/sonarqube/ide/ide-login/">https://www.sonarsource.com/products/sonarqube/ide/ide-login/</a></td></tr></tbody></table>


# What is Sonarqube?

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding.

The SonarQube platform delivers automated code quality and security analysis for modern development teams. Designed to seamlessly integrate with your CI/CD pipelines and DevOps tooling, it continuously reviews your source code to uncover bugs, security vulnerabilities, security hotspots, code smells, and architecture issues before code is merged or released. With broad support for 40+ programming languages and frameworks, SonarQube empowers developers and organizations to uphold high standards of code health across web, mobile, embedded, and cloud-native apps. It’s trusted by more than 7 million developers, underscoring its industry leadership as a critical solution for secure, maintainable, and high-quality software development.

Customers can choose between two delivery methods for SonarQube—as [a cloud-based, software-as-a-service (SaaS) offering](https://docs.sonarsource.com/sonarqube-cloud/) or as a [self-managed, self-hosted server side solution](https://docs.sonarsource.com/sonarqube-server/2026.1/).

The SonarQube platform also includes an IDE plugin, [SonarQube for IDE](https://docs.sonarsource.com/sonarqube-for-vs-code/), that brings real-time static analysis, quick-fix guidance, and security issue detection directly into your coding editor.

Key capabilities of our platform include:<br>

* Automated code review
* Code quality analysis
* Code security analysis
* Architecture
* Remediation&#x20;
* Secrets detection
* IaC scanning
* Static Application Security Testing (SAST)
* Taint analysis
* Mobile Application Security Testing (MAST)
* Open source license management
* CI/CD integration
* Project and portfolio management
* Governance and compliance
* Reporting and analytics


# About Sonar

Sonar is the industry standard for code verification and automated code review, trusted by 75% of the Fortune 100 to keep all code safe.

Sonar helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally


# SonarQube integrations

Seamlessly integrate SonarQube into your developer toolchain to build code quality and security into your development workflow.

## Sonar certified integrations

Some of our certified integrations include:

* [Cortex](https://www.sonarsource.com/integrations/cortex/) which allows you to pull in a wide range of code quality and security metrics.
* [Jellyfish](https://www.sonarsource.com/integrations/jellyfish/) which provides engineering leaders with valuable insights into how code quality impacts their team's performance and delivery.
* [JFrog](https://www.sonarsource.com/integrations/jfrog/) which provides trusted auditing for software packages by enriching artifacts and builds with signed attestation metadata.
* [Port](https://www.sonarsource.com/integrations/port/) which brings SonarQube's code quality and security metrics directly into your internal developer portal.

## First and third party integrations

Please see the list of all available [SonarQube integrations](https://www.sonarsource.com/integrations/overview/).

## Partner with Sonar

Interested in partnering with Sonar? Fill out [the form](https://www.sonarsource.com/company/contact-partner/) and let us know how we can collaborate


# Cyber Resilience Act capability mapping

Maps the EU Cyber Resilience Act (CRA) requirements to SonarQube capabilities, including quality gates, Advanced Security, SBOM export, and dependency risk review.

This page maps supported [EU Cyber Resilience Act](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act) requirements to SonarQube capabilities.

This mapping shows how SonarQube capabilities that are already part of a normal development workflow, including code analysis, pull request checks, quality gates, dependency analysis, and issue tracking, can be configured to strengthen CRA-related controls and provide evidence for compliance and cybersecurity processes.

## Using SonarQube as CRA supporting evidence

To use SonarQube outputs as part of a CRA evidence process:

1. Analyze all code continuously in CI and on pull requests. See [CI-based analysis](https://docs.sonarsource.com/sonarqube-cloud/analyzing-source-code/ci-based-analysis) and [pull request analysis](https://docs.sonarsource.com/sonarqube-cloud/analyzing-source-code/pull-request-analysis) for SonarQube Cloud, or [CI tools](https://docs.sonarsource.com/sonarqube-server/2026.3/analyzing-source-code/ci-integration) and [pull request analysis](https://docs.sonarsource.com/sonarqube-server/2026.3/discovering/code-analysis/pull-request-analysis) for SonarQube Server.
2. Use [quality profiles](https://docs.sonarsource.com/sonarqube-cloud/standards/managing-quality-profiles/understanding-quality-profiles) (SonarQube Cloud) or [quality profiles](https://docs.sonarsource.com/sonarqube-server/2026.3/quality-standards-administration/managing-quality-profiles/understanding-quality-profiles) (SonarQube Server) to define the security, reliability, and maintainability checks applied to each project.
3. Use [quality gates](https://docs.sonarsource.com/sonarqube-cloud/standards/managing-quality-gates/introduction-to-quality-gates) (SonarQube Cloud) or [quality gates](https://docs.sonarsource.com/sonarqube-server/2026.3/quality-standards-administration/managing-quality-gates/introduction-to-quality-gates) (SonarQube Server) to enforce release and pull request controls.
4. Use [Advanced Security](https://docs.sonarsource.com/sonarqube-cloud/advanced-security/introduction) (SonarQube Cloud) or [Advanced Security](https://docs.sonarsource.com/sonarqube-server/2026.3/advanced-security/introduction) (SonarQube Server) for SCA, Advanced SAST, dependency risks, and SBOM export.
5. Review [dependencies](https://docs.sonarsource.com/sonarqube-cloud/advanced-security/viewing-dependencies) (SonarQube Cloud) or [dependencies](https://docs.sonarsource.com/sonarqube-server/2026.3/advanced-security/viewing-dependencies) (SonarQube Server), export SBOMs at release time, and store release SBOMs with the manufacturer's release records.
6. Review and assign [dependency risks](https://docs.sonarsource.com/sonarqube-cloud/advanced-security/reviewing-and-fixing-dependency-risks) (SonarQube Cloud) or [dependency risks](https://docs.sonarsource.com/sonarqube-server/2026.3/advanced-security/reviewing-and-fixing-dependency-risks) (SonarQube Server), update statuses, add justification where needed, and use dependency risk reports as evidence.
7. Import external findings through [SARIF reports](https://docs.sonarsource.com/sonarqube-cloud/analyzing-source-code/importing-external-issues/importing-issues-from-sarif-reports) (SonarQube Cloud) or [SARIF reports](https://docs.sonarsource.com/sonarqube-server/2026.3/analyzing-source-code/importing-external-issues/importing-issues-from-sarif-reports) (SonarQube Server) where other security tools are part of the workflow.
8. Use [AI CodeFix](https://docs.sonarsource.com/agent-centric-development-cycle/solve/ai-codefix) or the [SonarQube Remediation Agent](https://docs.sonarsource.com/agent-centric-development-cycle/solve/remediation-agent), where available, to help prepare fixes for eligible issues.

## CRA capability mapping

This page focuses on CRA requirements where SonarQube can provide controls and evidence through code analysis, dependency analysis, pull request checks, quality gates, issue workflows, and remediation tracking. Manufacturers can combine these outputs with their broader cybersecurity, release, legal, and customer communication processes to support their overall CRA compliance program.

### Annex I, Part I, point 2(a): No known exploitable vulnerabilities

SonarQube supports this requirement by identifying vulnerabilities and exploitable weaknesses in first-party code and third-party dependencies before release, and by enforcing quality gates on branches and pull requests. This helps manufacturers reduce the risk of shipping products with known exploitable weaknesses and build release control into the SDLC.

### Annex I, Part I, point 2(b): Secure by default configuration

SonarQube supports this requirement by detecting insecure configurations or defaults, such as hardcoded secrets, weak cryptographic parameters, or permissive privileges in all kinds of code, application settings, and Infrastructure as Code. This helps manufacturers make secure configuration repeatable, enforceable, and traceable across the SDLC.

### Annex I, Part I, point 2(d): Secure access control

SonarQube supports this requirement by analyzing all access control, authentication, and privilege management functionalities in code for security weaknesses, and by blocking related security issues via quality gates. This helps manufacturers establish a control mechanism that ensures protection from unauthorized access.

### Annex I, Part I, point 2(e): Secure data transmission

SonarQube supports this requirement by detecting cryptography issues, such as missing data encryption, the use of weak ciphers or protocols, or insecure cryptographic parameters. This helps manufacturers protect the confidentiality of processed data and confirm it's encrypted using state-of-the-art mechanisms.

### Annex I, Part I, point 2(f): Integrity of data, commands, programs, and configuration

SonarQube supports this requirement by identifying critical security vulnerabilities, such as command injection, code injection, SQL injection, prompt injection, or arbitrary file writes/reads that could lead to a security breach and put the integrity of applications, data, or deployment environments at risk. This helps manufacturers strengthen integrity protections against unauthorized manipulations or modifications.

### Annex I, Part I, point 2(h): Protect against denial-of-service attacks

SonarQube supports this requirement by checking for over 1,500 different types of reliability issues. These issues can slow down or even crash the application, and can be effectively used in denial-of-service attacks. Detecting and remediating these issues helps manufacturers protect against these types of attacks.

### Annex I, Part I, point 2(j): Limiting attack surfaces, including external interfaces

SonarQube supports this requirement by helping manufacturers review code, Infrastructure as Code, and dependencies for issues that may expose externally reachable functionality, insecure interfaces, or exploitable paths. With SAST, taint analysis, IaC scanning, secrets detection, SCA, Advanced SAST, and quality gates in CI and pull requests, teams can make attack-surface review repeatable and traceable across the SDLC.

### Annex I, Part II, point 1: Identification and documentation of vulnerabilities and components

SonarQube supports this requirement by performing software composition analysis, maintaining dependency and risk inventories, and exporting SBOMs in standard formats. This helps manufacturers document product composition and track vulnerability exposure across the software supply chain.

### Annex I, Part II, point 2: Addressing and remediating vulnerabilities without delay

SonarQube supports this requirement by helping manufacturers detect, prioritize, and remediate vulnerabilities and dependency risks during development. With SCA, quality gates, IDE and MCP integration, AI CodeFix, and the SonarQube Remediation Agent where available, teams can fix issues as code is written, helping reduce the time between detection and remediation across the SDLC.

### Annex I, Part II, point 3: Effective and regular tests and reviews

SonarQube supports this requirement by analyzing code continuously in CI, on branches, and on pull requests, and by importing external findings where needed. This helps manufacturers make application security review repeatable, continuous, and traceable across the SDLC.

### Annex I, Part II, point 6: Sharing vulnerability information

SonarQube supports this requirement by providing security reports that summarize all detected vulnerabilities in first-party code and third-party components, including a CRA-specific security report. This helps manufacturers facilitate the sharing of information about potential vulnerabilities in their products, or the lack thereof.

### Article 13(2) and 13(3): Cybersecurity risk assessment

SonarQube supports the product cybersecurity risk assessment by providing continuously updated evidence on code vulnerabilities, security hotspots, dependency risks, and remediation status. This helps manufacturers strengthen the software and software-supply-chain inputs to a documented, living risk assessment.

### Article 13(5): Due diligence on third-party components

SonarQube supports this requirement by identifying third-party software dependencies, highlighting associated vulnerability and license-policy risks, and providing an option to export SBOMs for review. This helps manufacturers assess whether integrated components introduce unacceptable cybersecurity risk before and after integration.

### Article 13(6) and 13(7): Component vulnerability handling and documentation

SonarQube supports this requirement by helping teams detect dependency risks, document relevant findings, assign and track review and remediation status, and maintain issue and dependency records over time. For dependency vulnerabilities, SonarQube also provides fix guidance such as affected versions, complete or partial fixed versions, and upgrade information. This helps manufacturers build a more structured process for documenting software vulnerabilities and feeding newly discovered issues back into product security reviews.

## Related pages

* [SonarQube rules](https://docs.sonarsource.com/sonarqube-cloud/standards/managing-rules/rules) (SonarQube Cloud) / [SonarQube rules](https://docs.sonarsource.com/sonarqube-server/2026.3/quality-standards-administration/managing-rules/rules) (SonarQube Server)
* [Understanding quality gates](https://docs.sonarsource.com/sonarqube-cloud/standards/managing-quality-gates/introduction-to-quality-gates) (SonarQube Cloud) / [Understanding quality gates](https://docs.sonarsource.com/sonarqube-server/2026.3/quality-standards-administration/managing-quality-gates/introduction-to-quality-gates) (SonarQube Server)
* [Advanced Security](https://docs.sonarsource.com/sonarqube-cloud/advanced-security/introduction) (SonarQube Cloud) / [Advanced Security](https://docs.sonarsource.com/sonarqube-server/2026.3/advanced-security/introduction) (SonarQube Server)
* [Viewing dependencies](https://docs.sonarsource.com/sonarqube-cloud/advanced-security/viewing-dependencies) (SonarQube Cloud) / [Viewing dependencies](https://docs.sonarsource.com/sonarqube-server/2026.3/advanced-security/viewing-dependencies) (SonarQube Server)
* [Reviewing and fixing dependency risks](https://docs.sonarsource.com/sonarqube-cloud/advanced-security/reviewing-and-fixing-dependency-risks) (SonarQube Cloud) / [Reviewing and fixing dependency risks](https://docs.sonarsource.com/sonarqube-server/2026.3/advanced-security/reviewing-and-fixing-dependency-risks) (SonarQube Server)
* [Importing SARIF reports](https://docs.sonarsource.com/sonarqube-cloud/analyzing-source-code/importing-external-issues/importing-issues-from-sarif-reports) (SonarQube Cloud) / [Importing SARIF reports](https://docs.sonarsource.com/sonarqube-server/2026.3/analyzing-source-code/importing-external-issues/importing-issues-from-sarif-reports) (SonarQube Server)


# About the Agent Centric Development Cycle

Sonar's Agent Centric Development Cycle helps you ensure code generated by agents is verified in SonarQube and fixed before it reaches your repository.

## Overview

The Agent Centric Development Cycle (AC/DC) is Sonar’s framework for building software in an AI-driven world, where agents handle much of the coding and humans govern quality.\
It defines three loops where work happens:

* [The agentic loop](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/agentic-loop), where agents implement tasks such as new features, bug fixes, or refactorings. Sonar Vortex guides your agent and verifies its code as it is written.
* [The CI verification loop](/agent-centric-development-cycle/in-your-pull-requests-the-ci-verification-loop/ci-verification-loop), where zero-trust, multi-layered code review and a quality gate prevent problems from being merged into the mainline branch. SonarQube analysis raises issues and passes or fails the quality gate, and Gitar adds AI-powered code review.
* [The code maintenance loop](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/code-maintenance-loop), where agents asynchronously address legacy issues. The Remediation Agent and AI CodeFix propose fixes for issues already in your codebase.

Each loop feeds the next, with agents delivering code to a pull request that is verified and gated.

This workflow helps agents produce code that aligns more closely with project standards, catches issues earlier, and shortens the review-to-fix cycle.

The diagram below shows where AC/DC features fit in this cycle.

```mermaid
%%{init: {'theme': 'base', 'themeVariables': {
  'primaryColor': '#E6F2FF',
  'primaryBorderColor': '#126ED3',
  'primaryTextColor': '#111827',
  'clusterBkg': 'rgba(18,110,211,0.06)',
  'clusterBorder': '#126ED3',
  'lineColor': '#126ED3'
}}}%%
flowchart LR
  %% Loops laid out left-to-right, details descending within each phase

  subgraph AgenticLoop["Agentic loop"]
    direction LR
    VX["Sonar Vortex
---
Project-specific context before work starts
Analysis of modifications during generation"]
  end

  subgraph CIVerificationLoop["CI verification loop"]
    direction LR
    GTR["Gitar
---
AI-powered code review: inline comments,
summaries, walkthroughs, diagrams on PRs"]

  SQ["SonarQube
---
Analyzes new code, raises issues,
passes or fails the quality gate"]
  end

  subgraph CodeMaintenanceLoop["Code maintenance loop"]
    direction LR
    RA["Remediation Agent
---
Fixes PR & backlog issues,
re-analyzes fixes"]
    CF["AI CodeFix
---
Generates fixes for individual SonarQube issues"]
  end

  %% Left-to-right flow between phases
  AgenticLoop --> CIVerificationLoop
  CIVerificationLoop --> CodeMaintenanceLoop
  RA -.->|Fixes return as pull requests| CIVerificationLoop
```

## What you need

AC/DC features have different subscription requirements:

* Sonar Vortex (context augmentation and agentic analysis) and the Remediation Agent are part of Sonar Agent Essentials, which requires a separate subscription to your SonarQube Cloud Team (annual) or Enterprise plan. See [Subscription plans](/sonarqube-cloud/administering-sonarcloud/managing-subscription/subscription-plans).
* AI CodeFix is available with SonarQube Cloud Team and Enterprise plans, and with SonarQube Server Enterprise and Data Center editions.
* Gitar is a Sonar product that can be purchased separately.

## Get started

Start with the [agentic loop](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/agentic-loop) to set up Sonar Vortex in your agent, then move on to the [CI verification loop](/agent-centric-development-cycle/in-your-pull-requests-the-ci-verification-loop/ci-verification-loop) and the [code maintenance loop](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/code-maintenance-loop).

## Related pages

* [SonarQube CLI in agentic workflows](/agent-centric-development-cycle/developer-tools/sonarqube-cli-in-agentic-workflows)
* [Agent plugins](/agent-centric-development-cycle/developer-tools/agent-plugins)
* [Code quality and security in the age of AI and agentic development](https://www.sonarsource.com/resources/library/buyers-guide-to-code-quality-and-security/)


# What is the agentic loop?

The agentic loop covers everything that happens inside your agent as it works, and how SonarQube helps guide and verify that work.

All the work happening inside an agent is what we describe as "the agentic loop".

Once you submit a prompt, your agent explores the codebase, plans its work, and implements that plan. You then either ask it to refine or correct the result, which starts the loop again, or you push the code and open a pull request.

Two things help your agent throughout that loop:

* Guide: deliver information beyond the prompt so your agent works efficiently and generates code that follows your standards
* Verify: scan the generated code as early as possible, so problems reach the agent while it can still fix them

This is what [Sonar Vortex](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex) is designed to help with.


# What is Sonar Vortex?

This section explains how Sonar Vortex enhances the efficiency of agents.

Sonar Vortex is a product that equips your coding agent to write code that fits your project, and to check that code as it is produced. It works with Claude Code, Codex, GitHub Copilot CLI, Cursor, and Antigravity, among others.

Vortex gives your agent:

* Code navigation tools
* Constraints and guidance
* Continuous verification of the code as it is being generated

The goal is code of higher quality, produced faster and at a lower cost.

## Why your agent needs it

A coding agent suffers from two main limitations:

* It does not know your project
* It does not know your constraints and has no way to verify that its code is aligned with them

The first limitation means the agent spends effort, and tokens, reading your codebase with textual search such as grep, find, and glob, every time you start a session or change direction. If you have been using agents extensively, you may have experienced this "eternal new-joiner" feeling.

The second limitation means the agent may generate code that works but *looks and feels* wrong: code that ignores your coding standards, disrespects the layers of your application, or introduces dependencies that violate your policies. The analysis at the pull request level catches these problems eventually, but correcting them costs frustration, delay, and either human time or follow-up agentic sessions.

Writing extensive documentation in your repository solves neither problem well. It goes stale, it costs tokens to keep current, your agent may forget to update it, and it verifies nothing.

## The Guide-Verify-Solve loop

Sonar Vortex equips your agent with a guide-verify-solve loop to ensure pull requests pass quality gates the first time, leading to faster code reviews with no back-and-forth. The loop has three steps:

1. [**Guide**](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-context): Vortex injects code intelligence, architectural awareness, coding guidelines, third-party license policies, and security information into the LLM context before it writes or edits code.
2. [**Verify**](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-analysis): Vortex verifies the resulting code with full CI-level precision.
3. **Solve**: The LLM refines the code based on analysis results and corrects the issues it introduced.

```mermaid
%%{init: {'themeVariables': {'actorBkg': 'rgba(18, 110, 211, 0.06)', 'actorBorder': '#126ED3', 'actorLineColor': '#126ED3', 'signalColor': '#126ED3', 'labelBoxBorderColor': '#126ED3'}}}%%
sequenceDiagram
    participant User
    participant LLM as AI Agent
    participant Vortex as Vortex<br/>(Guide & Verify)

    User->>LLM: Request code generation
    LLM->>Vortex: Request guidelines & architecture
    Vortex-->>LLM: Inject coding standards & structure (Guide)
    LLM->>LLM: Generate code
    LLM->>Vortex: Analyze generated code (Verify)
    Vortex-->>LLM: Return analysis results

    alt Issues found
        LLM->>LLM: Refine code based on issues (Solve)
        LLM->>Vortex: Re-analyze code
        Vortex-->>LLM: Return analysis results
    end

    LLM-->>User: Return verified code
```

The outcome: green quality gates and mergeable pull requests, for fewer tokens.

## Learn more

* [Sonar Vortex context](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-context): how Vortex delivers context to your agent to reduce tokens
* [Sonar Vortex analysis](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-analysis): how Vortex verifies your agent's code to keep quality high

## Get started with Vortex

Learn how to [install Vortex for your agent](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides).


# Sonar Vortex context

Sonar Vortex injects repository-aware context into your AI agent, guiding code changes with architectural awareness and project-specific guidelines.

## Overview

Sonar Vortex guides your agent inside the [agentic loop](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/agentic-loop) of the [Agent Centric Development Cycle](/agent-centric-development-cycle). It connects to SonarQube Cloud and provides deep, project-specific context to AI agents before they write or edit code. Agents can access these capabilities through the SonarQube CLI-installed skill, or through a locally running SonarQube MCP Server that connects to SonarQube Cloud.

This ensures that the resulting code isn't generic and adheres to your repository's unique standards.

### Core capabilities

* **Architectural awareness**: Helps agents navigate complex class hierarchies, trace upstream/downstream call flows, and understand execution paths.
* **Intelligent guidelines**: Automatically injects relevant coding rules, quality standards, and security requirements based on your project's history and the current task.
* **Semantic navigation**: Moves beyond simple text matching to retrieve code based on its actual meaning and structure using Abstract Syntax Trees (AST), semantics, and control flow information.
* **Third-party dependency guidance**: Helps agents assess the health and safety of third-party dependencies before they're introduced or updated.

## Tool categories

Sonar Vortex provides four context augmentation capability categories. For supported agents, the recommended setups are the SonarQube agent plugin and the SonarQube CLI, which install an agent skill that uses the local Context Augmentation tool. You can also expose the same capabilities as MCP tools by configuring a locally running SonarQube MCP Server that connects to SonarQube Cloud. Each category currently supports a specific set of languages, and we're actively expanding language coverage and adding more categories.

| Category                                     | Description                                                                                                                                                                                                                                                                                                                                              | Supported languages                                                                                                                                                     |
| -------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Coding Guidelines**                        | Recommends Sonar rules to follow, based on the project's historical SonarQube issues filtered by what the agent is about to do (prompt nature and categories).                                                                                                                                                                                           | All [SonarQube Cloud languages](/sonarqube-cloud/analyzing-source-code/languages)                                                                                       |
| **Third-party dependency health and safety** | Assesses whether a third-party dependency is healthy and safe to use before it is introduced or updated. Currently covers known security vulnerabilities, supply-chain malware, and license compliance, with more checks in progress. Available only with the [SCA](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca) feature. | All [SCA-supported languages and package managers](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca#supported-languages-and-package-managers) |
| **Architecture**                             | Exposes the current architecture graph and user-defined architectural constraints, so the agent understands the current architecture and stays aligned with the intended design.                                                                                                                                                                         | All [languages supported by Architecture](/sonarqube-cloud/architecture#supported-languages)                                                                            |
| **Semantic navigation**                      | Helps the agent understand the meaning of the code rather than relying on text-based grep, by exposing call stacks, class hierarchies, references, and exact source locations. This lets the agent navigate the codebase and modify the right places effectively.                                                                                        | Java, C#, JavaScript, TypeScript, Python, and Rust                                                                                                                      |

The full list of tools exposed by Sonar Vortex for context augmentation, with their input parameters, is defined on the [SonarQube MCP Server Tools](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-mcp-server/reference/tools) page.

### Context augmentation for coding guidelines

The Sonar Vortex tool for guidelines injects relevant Sonar rules into the LLM context:

* Based on your prompt: for example, if your prompt involves access to DB, include all guidelines about DB.
* Based on the SonarQube issues found in files modified or related to the LLM task: for example, if the LLM plans to modify `DBStorage.java`, include guidelines from past issues in `DBStorage.java`.

![Diagram showing how Sonar Vortex Tools for Guidelines combine prompt classification from Sonar Rules with historically relevant issues from past analysis to augment the LLM context.](/files/VmztJoJLBUMcgH7SyrOU)

### Context augmentation for architecture

The Sonar Vortex tools for architecture give the LLM understanding of both the current architecture and the user-defined intended constraints, powered by semantic data from SonarQube Cloud's [Architecture](/sonarqube-cloud/architecture) feature. These tools enable the LLM to:

* Build "the right thing", better aligning with user goals, avoiding mistakes and rework.
* Build "the thing right", provide an output that is in line with architecture expectations.

![Diagram showing Sonar Vortex Tools for Architecture exposes context to the LLM based on SonarQube Architecture analysis configuration and results.](/files/MolIpUWAw0KMO2jAvM0R)

### Context augmentation for semantic navigation

The Sonar Vortex tools for semantic navigation give the agent an understanding of the code's meaning, helping it find the right locations to modify based on meaning rather than text. With this context, the agent can:

* Reach the correct solution faster by jumping straight to the right symbols, references, types, call flows, class hierarchies, etc.
* Reduce token usage and cost, by avoiding blind reads of entire files.
* Produce safer, less buggy changes, by surfacing every relevant location that needs updating so nothing is missed.

![Diagram showing Sonar Vortex Tools for semantic navigation expose context to the LLM based on the universal dependency graph built from the local workspace.](/files/HUCDenCm5j4m5TpljLLH)

## Setup

For step-by-step setup instructions, see [Installing Vortex](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides).

## Related pages

* [Sonar Vortex analysis](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-analysis)
* [MCP Server](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-mcp-server/)
* [Tools](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-mcp-server/reference/tools)


# Sonar Vortex analysis

Sonar Vortex lets AI agents verify code changes with the precision of a full CI scan, in seconds instead of minutes.

## Overview

Sonar Vortex verifies your agent's code inside the [agentic loop](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/agentic-loop) of the [Agent Centric Development Cycle](/agent-centric-development-cycle). It performs Sonar's trusted, deterministic analysis right inside your agent, reusing the context from a previous SonarQube Cloud CI analysis to deliver results in record times. This lets AI agents verify code changes with minimal latency while maintaining full CI analysis precision.

## How it works

During a CI analysis, SonarQube collects and stores your project's context: its dependencies, compiled artifacts, type information, and build configuration, tagged by project key and branch. This is why your project must be analyzed in your CI pipeline on a long-lived branch before you can use Vortex analysis.

When your agent analyzes a file, that context is restored on demand, so the analysis runs with the same inputs as a full CI scan without recomputing any of them.

## Making verification automatic

For most agents, the SonarQube plugin configures hooks, custom instructions, or both, so that Vortex analyzes the files your agent edits without you having to ask.

For details, see the installation instructions for your agent in [Installing Vortex](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides).

## Supported languages

Sonar Vortex analysis is available for the following languages:

* Java
* JavaScript
* TypeScript
* C#
* C
* C++
* Python
* Dart
* Swift
* Kotlin
* Go
* Objective-C
* PHP
* PowerShell
* Shell
* Ruby
* Apex
* SQL
* VB.NET
* CSS
* HTML
* Terraform
* Docker
* Kubernetes
* Groovy

Taint analysis (injection vulnerabilities detection) is also supported for Java, JavaScript, TypeScript, C# and VB.NET. Secrets detection is supported for all files.

> **Note:** If your Java project was analyzed using [Automatic analysis](https://docs.sonarsource.com/sonarqube-cloud/analyzing-source-code/automatic-analysis/), only basic analysis results are returned.

## Setup

For step-by-step setup instructions, see [Installing Vortex](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides).

## Related pages

* [Sonar Vortex context](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-context)
* [MCP Server](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-mcp-server/)
* [Tools](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-mcp-server/reference/tools)


# Installing Vortex

How to install Sonar Vortex for your agent using the SonarQube plugin, the SonarQube CLI, or the SonarQube MCP Server.

## Prerequisites

Check the [prerequisites for Vortex](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/vortex-prerequisites).

## Installing Vortex in an agent

Find your agent in the following list and follow the instructions:

* [Install Vortex for Claude Code](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/install-vortex-claude-code)
* [Install Vortex for Codex](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/install-vortex-codex)
* [Install Vortex for GitHub Copilot CLI](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/install-vortex-copilot)
* [Install Vortex for Cursor](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/install-vortex-cursor)
* [Install Vortex for Antigravity](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/install-vortex-antigravity)
* [Install Vortex for Kiro](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/install-vortex-kiro)

If your agent is not in the list, install Vortex by [configuring the SonarQube MCP server](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/install-vortex-with-mcp).

## Checking your installation

After installing, confirm that your agent can reach Vortex. See [Checking your setup](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup).

## Using Vortex inside your agent

Your agent uses Vortex automatically, based on the skills and hooks installed for your agent type. You do not need to do anything beyond approving the tools as your agent starts using them.


# Prerequisites

The SonarQube Cloud prerequisites to meet before you install and use Sonar Vortex.

Before you start, make sure you meet the following prerequisites.

## SonarQube Cloud admin settings

You have purchased Sonar Agent Essentials for your SonarQube Cloud organization or your SonarQube Cloud enterprise. Sonar Agent Essentials requires an Enterprise plan or an annual Team plan.

## Project settings

Make sure your project:

* Is analyzed in your CI pipeline on a [long-lived branch](https://docs.sonarsource.com/sonarqube-cloud/analyzing-source-code/branch-analysis/main-vs-long-lived-branches)
* Uses SonarQube Cloud [Architecture](/sonarqube-cloud/architecture), for the best guidance of your agent

You also need your project key, which you pass to the `sonar integrate` command when you install Vortex through the SonarQube CLI. You can find it in your project's settings in SonarQube Cloud.


# Vortex for Claude Code

How to install Vortex for Claude Code using the SonarQube plugin or the SonarQube CLI.

You have two ways to install Vortex for Claude Code:

* Using the Claude Code SonarQube plugin
* Using the SonarQube CLI

Once installed, both options result in exactly the same thing, as the plugin installs the SonarQube CLI for you and automates the integration in the agent. We recommend that individual developers use the SonarQube plugin, and teams or organizations use the CLI directly for automated deployments.

## Installing Vortex for Claude Code using the SonarQube plugin

### Step 1: Install the SonarQube plugin for Claude Code

Install the SonarQube plugin:

```bash
claude plugin install sonarqube@claude-plugins-official
```

For more details, see [Claude Code](/agent-centric-development-cycle/developer-tools/agent-plugins/claude-code).

### Step 2: Run the integration skill

Run the guided integration skill from an agent session opened in your project folder:

```claude
/sonarqube:sonar-integrate
```

The skill installs or updates the SonarQube CLI, authenticates it, and runs `sonar integrate` to set up context augmentation and agentic analysis for the current project.

### Step 3: Restart your agent

If your agent is running, restart it so the integration is loaded for the current project.

### Step 4: Verify your setup

[Verify the setup](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup): ask your agent *"What is the current architecture of the project? Limit the answer to the top-level blocks."*

## Installing Vortex for Claude Code using the SonarQube CLI

### Step 1: Install the SonarQube CLI

[Install the SonarQube CLI](https://github.com/SonarSource/sonarqube-documentation/tree/main/content-output/cli/default/quickstart-guide.md#step-1-install-the-cli) and [authenticate](https://github.com/SonarSource/sonarqube-documentation/tree/main/content-output/cli/default/quickstart-guide.md#step-2-authenticate).

### Step 2: Integrate your project

Run the following command at the root of your project's repository:

```bash
sonar integrate claude --project <your_project_key>
```

The CLI asks you questions. Answer "yes" when asked if you want "Context Augmentation" and "Agentic Analysis".

### Step 3: Restart your agent

If your agent is running, restart it so the integration is loaded for the current project.

### Step 4: Verify your setup

[Verify the setup](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup): ask your agent *"What is the current architecture of the project? Limit the answer to the top-level blocks."*


# Vortex for Codex

How to install Vortex for Codex using the SonarQube plugin or the SonarQube CLI.

You have two ways to install Vortex for Codex:

* Using the Codex SonarQube plugin
* Using the SonarQube CLI

Once installed, both options result in exactly the same thing, as the plugin installs the SonarQube CLI for you and automates the integration in the agent. We recommend that individual developers use the SonarQube plugin, and teams or organizations use the CLI directly for automated deployments.

## Installing Vortex for Codex using the SonarQube plugin

### Step 1: Install the SonarQube plugin for Codex

* From your shell, register the marketplace:

  ```bash
  codex plugin marketplace add SonarSource/sonarqube-agent-plugins
  ```
* Start a Codex session, run `/plugins`, search for `sonarqube`, and install it.

For more details, see [Codex CLI](/agent-centric-development-cycle/developer-tools/agent-plugins/codex-cli).

### Step 2: Run the integration skill

After installing the plugin, finish setup by running the guided integration skill:

```
$sonar-integrate
```

The skill installs or updates the SonarQube CLI, authenticates it, and runs `sonar integrate` to set up context augmentation and agentic analysis for the current project.

### Step 3: Restart your agent

If your agent is running, restart it so the integration is loaded for the current project.

### Step 4: Verify your setup

[Verify the setup](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup): ask your agent *"What is the current architecture of the project? Limit the answer to the top-level blocks."*

## Installing Vortex for Codex using the SonarQube CLI

### Step 1: Install the SonarQube CLI

[Install the SonarQube CLI](https://github.com/SonarSource/sonarqube-documentation/tree/main/content-output/cli/default/quickstart-guide.md#step-1-install-the-cli) and [authenticate](https://github.com/SonarSource/sonarqube-documentation/tree/main/content-output/cli/default/quickstart-guide.md#step-2-authenticate).

### Step 2: Integrate your project

Run the following command at the root of your project's repository:

```bash
sonar integrate codex --project <your_project_key>
```

The CLI asks you questions. Answer "yes" when asked if you want "Context Augmentation" and "Agentic Analysis".

### Step 3: Restart your agent

If your agent is running, restart it so the integration is loaded for the current project.

### Step 4: Verify your setup

[Verify the setup](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup): ask your agent *"What is the current architecture of the project? Limit the answer to the top-level blocks."*


# Vortex for Cursor

How to install Vortex for Cursor using the SonarQube plugin or the SonarQube CLI.

You have two ways to install Vortex for Cursor:

* Using the Cursor SonarQube plugin
* Using the SonarQube CLI

Once installed, both options result in exactly the same thing, as the plugin installs the SonarQube CLI for you and automates the integration in the agent. We recommend that individual developers use the SonarQube plugin, and teams or organizations use the CLI directly for automated deployments.

## Installing Vortex for Cursor using the SonarQube plugin

### Step 1: Install the SonarQube plugin for Cursor

The SonarQube plugin is published in the `sonar` marketplace catalog on the [Cursor marketplace](https://cursor.com/marketplace/sonarsource), sourced from the [SonarSource/sonarqube-agent-plugins](https://github.com/SonarSource/sonarqube-agent-plugins) repository.

In Cursor's chat, install the plugin:

```
/add-plugin sonarqube
```

You can also install it from Cursor's marketplace panel. For more details, see [Cursor](/agent-centric-development-cycle/developer-tools/agent-plugins/cursor).

### Step 2: Run the integration skill

After installing the plugin, finish setup by running the guided integration skill:

```
/sonar-integrate
```

The skill installs or updates the SonarQube CLI, authenticates it, and runs `sonar integrate` to set up context augmentation and agentic analysis for the current project.

### Step 3: Restart your agent

If your agent is running, restart it so the integration is loaded for the current project.

### Step 4: Verify your setup

[Verify the setup](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup): ask your agent *"What is the current architecture of the project? Limit the answer to the top-level blocks."*

## Installing Vortex for Cursor using the SonarQube CLI

### Step 1: Install the SonarQube CLI

[Install the SonarQube CLI](https://github.com/SonarSource/sonarqube-documentation/tree/main/content-output/cli/default/quickstart-guide.md#step-1-install-the-cli) and [authenticate](https://github.com/SonarSource/sonarqube-documentation/tree/main/content-output/cli/default/quickstart-guide.md#step-2-authenticate).

### Step 2: Integrate your project

Run the following command at the root of your project's repository:

```bash
sonar integrate cursor --project <your_project_key>
```

The CLI asks you questions. Answer "yes" when asked if you want "Context Augmentation" and "Agentic Analysis".

### Step 3: Restart your agent

If your agent is running, restart it so the integration is loaded for the current project.

### Step 4: Verify your setup

[Verify the setup](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup): ask your agent *"What is the current architecture of the project? Limit the answer to the top-level blocks."*


# Vortex for GitHub Copilot CLI

How to install Vortex for GitHub Copilot CLI using the SonarQube plugin or the SonarQube CLI.

You have two ways to install Vortex for GitHub Copilot CLI:

* Using the GitHub Copilot CLI SonarQube plugin
* Using the SonarQube CLI

Once installed, both options result in exactly the same thing, as the plugin installs the SonarQube CLI for you and automates the integration in the agent. We recommend that individual developers use the SonarQube plugin, and teams or organizations use the CLI directly for automated deployments.

## Installing Vortex for GitHub Copilot CLI using the SonarQube plugin

### Step 1: Install the SonarQube plugin for GitHub Copilot CLI

Install the SonarQube plugin from the `awesome-copilot` marketplace, which is registered by default in GitHub Copilot CLI:

* From your shell, run `copilot plugin install sonarqube@awesome-copilot`.
* Or inside an interactive Copilot CLI session, run `/plugin install sonarqube@awesome-copilot`.

For more details, see [GitHub Copilot CLI](/agent-centric-development-cycle/developer-tools/agent-plugins/github-copilot-cli).

### Step 2: Run the integration skill

After installing the plugin, finish setup by running the guided integration skill:

```
/sonar-integrate
```

The skill installs or updates the SonarQube CLI, authenticates it, and runs `sonar integrate` to set up context augmentation and agentic analysis for the current project.

### Step 3: Restart your agent

If your agent is running, restart it so the integration is loaded for the current project.

### Step 4: Verify your setup

[Verify the setup](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup): ask your agent *"What is the current architecture of the project? Limit the answer to the top-level blocks."*

## Installing Vortex for GitHub Copilot CLI using the SonarQube CLI

### Step 1: Install the SonarQube CLI

[Install the SonarQube CLI](https://github.com/SonarSource/sonarqube-documentation/tree/main/content-output/cli/default/quickstart-guide.md#step-1-install-the-cli) and [authenticate](https://github.com/SonarSource/sonarqube-documentation/tree/main/content-output/cli/default/quickstart-guide.md#step-2-authenticate).

### Step 2: Integrate your project

Run the following command at the root of your project's repository:

```bash
sonar integrate copilot --project <your_project_key>
```

The CLI asks you questions. Answer "yes" when asked if you want "Context Augmentation" and "Agentic Analysis".

### Step 3: Restart your agent

If your agent is running, restart it so the integration is loaded for the current project.

### Step 4: Verify your setup

[Verify the setup](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup): ask your agent *"What is the current architecture of the project? Limit the answer to the top-level blocks."*


# Vortex for Antigravity

How to install Vortex for Antigravity using the SonarQube plugin or the SonarQube CLI.

You have two ways to install Vortex for Antigravity:

* Using the Antigravity SonarQube plugin
* Using the SonarQube CLI

Once installed, both options result in exactly the same thing, as the plugin installs the SonarQube CLI for you and automates the integration in the agent. We recommend that individual developers use the SonarQube plugin, and teams or organizations use the CLI directly for automated deployments.

## Installing Vortex for Antigravity using the SonarQube plugin

### Step 1: Install the SonarQube plugin for Antigravity

The SonarQube plugin is distributed from the [SonarSource/sonarqube-agent-plugins](https://github.com/SonarSource/sonarqube-agent-plugins) repository. There is no `@vendor` marketplace shorthand, so install by using a git URL, archive, or local path.

From your shell, run:

```bash
agy plugin install https://github.com/SonarSource/sonarqube-agent-plugins
```

This installs the plugin globally under `~/.gemini/config/plugins/sonarqube/`.

For more details, see [Antigravity](/agent-centric-development-cycle/developer-tools/agent-plugins/antigravity).

### Step 2: Run the integration skill

After installing the plugin, finish setup by running the guided integration skill:

```
/sonarqube:sonar-integrate
```

The skill installs or updates the SonarQube CLI, authenticates it, and runs `sonar integrate` to set up context augmentation and agentic analysis for the current project.

### Step 3: Restart your agent

If your agent is running, restart it so the integration is loaded for the current project.

### Step 4: Verify your setup

[Verify the setup](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup): ask your agent *"What is the current architecture of the project? Limit the answer to the top-level blocks."*

## Installing Vortex for Antigravity using the SonarQube CLI

### Step 1: Install the SonarQube CLI

[Install the SonarQube CLI](https://github.com/SonarSource/sonarqube-documentation/tree/main/content-output/cli/default/quickstart-guide.md#step-1-install-the-cli) and [authenticate](https://github.com/SonarSource/sonarqube-documentation/tree/main/content-output/cli/default/quickstart-guide.md#step-2-authenticate).

### Step 2: Integrate your project

Run the following command at the root of your project's repository:

```bash
sonar integrate antigravity --project <your_project_key>
```

The CLI asks you questions. Answer "yes" when asked if you want "Context Augmentation" and "Agentic Analysis".

### Step 3: Restart your agent

If your agent is running, restart it so the integration is loaded for the current project.

### Step 4: Verify your setup

[Verify the setup](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup): ask your agent *"What is the current architecture of the project? Limit the answer to the top-level blocks."*


# Vortex for Kiro

How to install Vortex for Kiro using the SonarQube Power and the SonarQube MCP Server.

For Kiro, Vortex runs through the SonarQube MCP Server. The SonarQube Power installs the MCP Server configuration for you, and you then enable the toolsets Vortex needs.

The SonarQube CLI has no `sonar integrate kiro` command, so the plugin-plus-CLI path available for other agents does not apply here.

## Prerequisites

* The [general prerequisites for Vortex](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/vortex-prerequisites).
* The requirements for running Vortex through MCP, including a Docker-compatible installation. See [Prerequisites](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/install-vortex-with-mcp#prerequisites) on the MCP page.

## Step 1: Install the SonarQube Power for Kiro

The SonarQube Power is published on the [Kiro Powers marketplace](https://kiro.dev/powers/). Find **SonarQube** and click **Add to Kiro**. The MCP Server configuration is applied automatically.

For more details, see [Kiro](/agent-centric-development-cycle/developer-tools/agent-plugins/kiro).

## Step 2: Authenticate

Log in so the MCP Server can connect:

```bash
sonar auth login
```

## Step 3: Enable the Vortex toolsets

The Power does not enable the toolsets Vortex needs. Edit your MCP configuration to add them, as described in [Add or edit your MCP configuration file](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/install-vortex-with-mcp#step-2-add-or-edit-your-mcp-configuration-file).

## Step 4: Restart your agent

If Kiro is already running, restart it so the configuration is loaded for the current project.

## Step 5: Verify your setup

Ask your agent *"What is the current architecture of the project? Limit the answer to the top-level blocks."* For the expected response, see [Checking your setup](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup).


# Vortex with the MCP server

How to install Vortex by configuring the SonarQube MCP server into any agent

Vortex can be used through the SonarQube MCP server if the CLI does not offer a specific integration for your agent.

## Prerequisites

* Vortex can only be used through MCP with the local (stdio) version of the SonarQube MCP server, because it needs access to local files to perform the analysis. The SonarQube-hosted MCP server, reached over HTTP, cannot be used for Vortex.
* The SonarQube MCP Server requires a Docker-compatible installation, for example Docker Desktop or Colima on macOS.

## Step 1: Export the SonarQube token environment variable

Export the `SONARQUBE_TOKEN` [Environment variables](/sonarqube-mcp-server/reference/environment-variables#common-variables) with a valid [Personal Access Token (PAT)](/sonarqube-cloud/managing-your-account/managing-tokens) for your project.

```bash
# macOS/Linux (Bash/Zsh)
export SONARQUBE_TOKEN="{<YourUserToken>}"
```

## Step 2: Add or edit your MCP configuration file

MCP settings files are located at the following paths:

* `.cursor/mcp.json` for Cursor IDE
* `.mcp.json` for Claude Code
* `~/.gemini/config/mcp_config.json` for Antigravity
* `.codex/config.toml` for Codex
  * use a TOML config instead of JSON
* `.vscode/mcp.json` for Copilot in Visual Studio Code

> **Note:** Replace the placeholders above with appropriate values. ⚠️ The path format is critical:
>
> * Paths must be absolute. Relative paths like `./` or `../` are not accepted.
> * On Windows, use forward slashes, for example `C:/Users/john/projects/myapp`. Don't use back slashes, for example `C:\\Users\\john\\projects\\myapp`.

The `SONARQUBE_TOOLSETS` value determines which [MCP toolsets](/sonarqube-mcp-server/reference/tools) are enabled. The configuration below enables the `analysis`, `cag` and `projects` toolsets required for Sonar Vortex.

```json
{
  "mcpServers": {
    "sonarqube-mcp-server": {
      "command": "docker",
      "args": [
        "run", "-i", "--rm", "--pull=always",
        "-e", "SONARQUBE_URL",
        "-e", "SONARQUBE_TOKEN",
        "-e", "SONARQUBE_ORG",
        "-e", "SONARQUBE_PROJECT_KEY",
        "-e", "SONARQUBE_TOOLSETS",
        "-v", "/ABSOLUTE/PATH/TO/YOUR/PROJECT:/app/mcp-workspace:rw",
        "sonarsource/sonarqube-mcp"
      ],
      "env": {
        "SONARQUBE_URL": "https://sonarcloud.io",
        "SONARQUBE_ORG": "<YourOrganizationKey>",
        "SONARQUBE_PROJECT_KEY": "<YourProjectKey>",
        "SONARQUBE_TOOLSETS": "analysis,projects,cag"
      }
    }
  }
}
```

> **Note:** Optional configurations:
>
> * **Include default SonarQube MCP tools**: To include the default SonarQube MCP tools in addition to the Agentic Workflow tools, change the `SONARQUBE_TOOLSETS` value to: `"analysis,issues,projects,quality-gates,rules,duplications,measures,security-hotspots,dependency-risks,coverage,cag"`.
> * **Read-only volume mounting of the project workspace**: The project workspace can be mounted in read-only mode by specifying `ro` instead of `rw`. Some tools may work in degraded mode.

## Step 3: Configure agent operational constraints (recommended)

Tool usage can be inconsistent depending on available tools, context, and agent behavior. To ensure the agent follows the Guide-and-Verify workflow consistently, explicitly guide your AI agent to use the Sonar Vortex tools appropriately.

Add the directive to your agent's system prompt or instructions file.

**Example directive:**

```
# SonarQube Agentic Workflow - Usage Directive (MUST FOLLOW)

**Always use the Guide-and-Verify workflow** for writing and modifying code.

## GUIDE Phase - Before Writing or Editing Code

**Before writing or editing code** you MUST:
1. Call `get_guidelines` for project context and coding standards
2. Locate existing code with `search_by_signature_patterns` or `search_by_body_patterns`
3. Read implementation with `get_source_code`

**When changing architecture or dependencies** you MUST:
- Check `get_current_architecture` and `get_intended_architecture`
- Analyze impact using:
  - `get_upstream_call_flow` / `get_downstream_call_flow` - trace method calls
  - `get_references` - find all usages
  - `get_type_hierarchy` - check inheritance

**Before adding or updating a third-party dependency** you MUST:
- Call `check_dependency` with the package URL (purl) to check for vulnerabilities, malware, and license compliance

## VERIFY Phase - After Writing or Editing Code

You must strictly follow this Analyze-Then-Commit workflow for every code modification. No code is considered complete until it has passed the following SonarQube validation loop:

1. **Read Phase:** After any modification or before commit, use the `Read` tool to load the current state of all relevant source files.
2. **Analysis Phase:** For every new or modified file, you must call `run_advanced_code_analysis` using:
   - `filePath`: The project-relative path to the file (e.g., `src/main/java/MyClass.java`)
   - `branchName`: The active development branch
   - `fileScope`: `["MAIN"]` or `["TEST"]` depending on the code type
3. **Evaluation & Remediation:**
   - **Rule Lookup:** For every issue flagged, call `show_rule` with the specific rule key (e.g., `java:S1874`)
   - **Mandatory Fixes:** You are prohibited from committing code with **CRITICAL** or **HIGH** issues. Implement fixes based on the rule's rationale and recommended guidance immediately.
4. **Verification:** After applying fixes, re-run the analysis to ensure issues are resolved and no regressions were introduced.
```

## Step 4: Restart your agent

Restart your agent and make sure that your MCP configuration is taken into account and applied correctly.

## Step 5: Verify your setup

1. Ask your agent "What is Guide and Verify?" You should see a description of the SonarQube Agentic workflow as configured in step 3.

**Example response**

```
 "Guide & Verify" is a workflow defined in your project's CLAUDE.md file for writing and modifying code. It has two phases:
                                                                                                                                                                                                                                                 
  GUIDE Phase (before writing code):                                                                                                                                                                                                             
  - Fetch project guidelines and coding standards via get_guidelines                                                                                                                                                                             
  - Locate existing code using search tools                                                                                                                                                                                                      
  - Read the relevant implementation via get_source_code                                                                                                                                                                                       
  - For architectural changes: check current/intended architecture, trace call flows, find usages, inspect type hierarchies

  VERIFY Phase (after writing code):
  1. Read — reload all modified source files
  2. Analyze — run run_advanced_code_analysis on each changed file against the active branch
  3. Evaluate & Fix — look up flagged rules with show_rule, and mandatory fix any CRITICAL or HIGH severity issues before committing
  4. Re-verify — re-run analysis to confirm fixes and check for regressions

  In short, it's a SonarQube-backed quality gate that requires you to understand existing code before touching it and validate every change with static analysis before considering it done.
```

2. Ask your agent "Verify the file `path/to/file.java`." You should see it invoke the `run_advanced_analysis` tool (it might ask for confirmation). You should see a report of which issues are currently present in the file, broken down by severity.

**Example response**

```
Here is a summary of the 21 issues found:                                                                                                                                                                                                      
                                                                                                                                                                                                                                                 
  ---                                                                                                                                                                                                                                            
  Analysis Results                                                                                                                                                                                                                               
                                                                                                                                                                                                                                                 
  CRITICAL / HIGH — None
                                                                                                                                                                                                                                                 
  No blocking issues were found. The file is safe to commit as-is from a severity standpoint.                                                                                                                                                    
                                                                                                                                                                                                                                                 
  ---                                                                                                                                                                                                                                            
  Medium Issues                                                                                                                                                                                                                                  

  java:S107 — Too many constructor parameters (line 137)
  The private OrderSequence(...) constructor has 14 parameters, exceeding the limit of 7. This is a common pattern for immutable value objects using the "wither" pattern, but SonarQube flags it nonetheless. Refactoring would require
  introducing a builder, which is a non-trivial API change.

  java:S3358 — Nested ternary (line 720)
  ref == null ? List.of("") : List.of(ref.getName())
  Inside an already-ternary expression. Should be extracted into a variable or helper method.

  ---
  Low / Info Issues

  java:S1133 — Deprecated code not yet removed (lines 66, 256, 269)
  The type field and the getType() / withType() methods are annotated @Deprecated with a scheduled removal at 8.0. SonarQube reminds you to eventually remove them.

  java:S1123 — Missing @deprecated Javadoc tag (line 66)
  The type field is annotated with @Deprecated but its Javadoc comment does not include a @deprecated tag explaining the migration path.

  java:S1874 — Use of deprecated type field (lines 124, 154, 173, 193, 213, 233, 351, 389, 449, 485, 523, 560, 600, 637, 673) — 15 occurrences
  Every internal usage of the deprecated type field triggers this rule. These will all be resolved once type is removed in 8.0.

  ---
  Summary

  ┌───────────────┬───────┬───────────────────────┐
  │   Severity    │ Count │        Action         │
  ├───────────────┼───────┼───────────────────────┤
  │ CRITICAL/HIGH │ 0     │ None required         │
  ├───────────────┼───────┼───────────────────────┤
  │ Medium        │ 2     │ Optional improvement  │
  ├───────────────┼───────┼───────────────────────┤
  │ Low/Info      │ 19    │ Track for 8.0 cleanup │
  └───────────────┴───────┴───────────────────────┘

  The file is clean from a blocking-issue perspective. The medium-severity nested ternary at line 720 is the only quick improvement worth considering now. Everything else is tracked for the 8.0 deprecation removal cycle.
```


# Checking your setup

How to check that Sonar Vortex is installed correctly and can reach SonarQube Cloud for your project.

After you install Vortex, confirm that your agent can reach it. Vortex gives your agent two capabilities, so run both checks: one for the context it receives before writing code, and one for the analysis of the code it produces.

## Check the context: ask about the project's architecture

Ask your agent "What is the current architecture of the project? Limit the answer to the top-level blocks." The agent uses Vortex to retrieve the current architecture (it might ask for your confirmation), then presents a high-level overview of the current project.

Example response:

```
The architecture has 19 top-level modules with 35 dependencies between them:

  ---
  Foundation (no dependencies)

  ┌──────────────────┬──────────────────────┐
  │      Module      │      Depended on by    │
  ├──────────────────┼──────────────────────┤
  │ proj-api-base    │ All 18 other modules │
  └──────────────────┴──────────────────────┘

  ---
  Core layer (depend only on api-base)

  ┌────────────────────────────────────────────────┬────────────────────────────────────────┐
  │                     Module                     │                Purpose                 │
  ├────────────────────────────────────────────────┼────────────────────────────────────────┤
  │ proj-api-injection                             │ DI configuration interfaces            │
  │ proj-common                                    │ Shared utilities                       │
  │ proj-documentation                             │ Documentation                          │
  │ proj-impl-configuration-gestalt                │ Gestalt config implementation          │
  │ proj-peripheralcommadapter-loopback            │ Peripheral loopback driver             │
  │ proj-plantoverview-base                        │ Base UI components                     │
  │ proj-plantoverview-panel-loadgenerator         │ Load generator panel                   │
  │ proj-plantoverview-panel-resourceallocation    │ Resource allocation panel              │
  │ proj-plantoverview-themes-default              │ Default UI themes                      │
  │ proj-strategies-default                        │ Default routing/dispatching strategies │
  └────────────────────────────────────────────────┴────────────────────────────────────────┘

  ---
  Mid layer (depend on api-base + common)

  ┌────────────────────────────────────────┬────────────────────────────┐
  │                 Module                 │      Also depends on       │
  ├────────────────────────────────────────┼────────────────────────────┤
  │ proj-commadapter-loopback              │ common                     │
  │ proj-kernel-extension-http-services    │ common                     │
  │ proj-kernel-extension-rmi-services     │ common                     │
  │ proj-plantoverview-common              │ common, plantoverview-base │
  └────────────────────────────────────────┴────────────────────────────┘

  ---
  Application layer (leaf modules, nothing depends on them)

  ┌─────────────────────────────┬────────────────────────────────────────────────────────────┐
  │           Module            │                         Depends on                         │
  ├─────────────────────────────┼────────────────────────────────────────────────────────────┤
  │ proj-kernel                 │ api-base, common, commadapter-loopback                     │
  │ proj-kernelcontrolcenter    │ api-base, common, commadapter-loopback                     │
  │ proj-modeleditor            │ api-base, common, plantoverview-base, plantoverview-common │
  │ proj-operationsdesk         │ api-base, common, plantoverview-base, plantoverview-common │
  └─────────────────────────────┴────────────────────────────────────────────────────────────┘

  ---
  Dependency flow (simplified)

  proj-api-base
    └── proj-common
          └── proj-commadapter-loopback
          │     ├── proj-kernel
          │     └── proj-kernelcontrolcenter
          └── proj-plantoverview-base
                └── proj-plantoverview-common
                      ├── proj-modeleditor
                      └── proj-operationsdesk

  proj-api-base is the clear foundation — every module depends on it and nothing depends on the four application-layer modules (kernel, kernelcontrolcenter, modeleditor, operationsdesk).
```

## Check the analysis: ask your agent to edit a file

Ask your agent to edit a file in your project. After it applies the change, Vortex analyzes the modified code and surfaces any new findings. How the findings reach you depends on your agent:

* Claude Code and Codex run a hook after the edit and feed the findings back into the session, so the agent can fix new issues before ending its turn.
* Cursor runs an always-applied rule after the edit.
* Antigravity and GitHub Copilot CLI check the files they edit and return the findings in their response.

If you installed Vortex through the SonarQube MCP server, including for Kiro, your agent has no post-edit hook and runs the analysis on request instead. Ask it to analyze a file, for example *"Verify the file `path/to/file.java`."* Your agent invokes the analysis (it might ask for your confirmation) and reports the issues currently present in that file, grouped by severity.=

## If a check fails

1. Confirm your authentication with `sonar auth status`.
2. Restart your agent so the integration is loaded for the current project.

If the checks still fail, re-run the installation for your agent. See [How to install Vortex for your agent](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides).


# What is the CI verification loop?

Learn how SonarQube analysis and Gitar keep low-quality code out of your main branch.

Once a human or an agent has pushed code to the repository and opened a pull request, the pipeline and all verifications run to detect problems, trigger quality gates, and prevent merging low-quality code into the main branch.

Verification is zero-trust and multi-layered, which means no single check is trusted on its own. Two layers work together on your pull request:

* SonarQube analysis runs on the new code, raises issues as inline comments on the pull request, and computes the [quality gate](/sonarqube-cloud/standards/managing-quality-gates/introduction-to-quality-gates) that decides whether the code is fit to merge. See [Pull request analysis](/sonarqube-cloud/analyzing-source-code/pull-request-analysis).
* [Gitar](https://docs.gitar.ai/introduction) adds AI-powered code review to your pull requests: inline comments, summaries, walkthroughs, and diagrams.


# What is the code maintenance loop?

Learn how to discover and solve issues already in your main codebase with the SonarQube Hunter Agent and Remediation Agent.

Code that lives in the main branch of your repository, or in any long-living branch, is certainly not free of issues today. It is completely normal to have a backlog of existing issues that need some attention. It is also good practice to leverage dedicated agents with specific capabilities to find complex issues that static analysis cannot. This is part of what we call a "multi-layer verification system".

Find out how the [Remediation Agent](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/remediation-agent) can help you reduce your technical debt in an automated, pain-free way. Discover how the [Hunter Agent](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/hunter-agent) can find high impact security issues that could result in serious vulnerabilities if released in the wild.

## How-to guides

* [Get backlog fix suggestions](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/backlog-fix-suggestions)
* [Get individual issue fix suggestions](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/individual-issues-fix-suggestions)
* [Administer AI CodeFix](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/administer-ai-codefix)
* [Administer Remediation Agent](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/administer-remediation-agent)
* [Uncover complex vulnerabilities with AI](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/uncover-complex-vulnerabilities-with-ai)


# Remediation Agent

This page outlines the SonarQube Remediation Agent, built to help you fix and manage code issues and SCA dependency vulnerabilities found by SonarQube.

The Remediation Agent is part of Sonar Agent Essentials, a product that requires a separate subscription to your SonarQube Cloud Team (annual) or Enterprise plan.

## Overview

The SonarQube Remediation Agent runs an independent review and analysis to help you fix reliability, maintainability, and security issues found in your latest code, and to remediate dependency vulnerabilities found by Software Composition Analysis (SCA). It focuses on issues in your SonarQube Cloud backlog (discovered in your main branch analysis) and on issues found in your latest pull request (PR).

The agent works with projects bound to GitHub or Azure DevOps. Automated and manual backlog remediation are available on both platforms; pull request remediation is available for GitHub-bound projects only.

The agent generates fix suggestions in the background and checks that the new code doesn't introduce new issues before offering the suggestion. Using the agent requires your own LLM provider API key. See [Configure your LLM provider key](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/administer-remediation-agent#configure-your-llm-provider-key) for more information.

After issues from your analysis are assigned, the agent proposes fixes and creates new PRs for your review. Enable it per project, then review and approve code suggestions for each issue.

The SonarQube Remediation Agent can suggest fixes in three ways:

* **Automated backlog remediation**: The agent runs on a schedule you set, automatically proposing fixes for eligible issues in your main branch without manual assignment. A SonarQube Cloud organization admin enables the scheduler and sets the frequency (daily or weekly), time, and timezone. The agent then opens pull requests in your repository on that schedule, grouped by rule key and file type, the same way it does for manual backlog remediation. Project admins can override or disable the schedule for individual projects.
* **Manual backlog remediation**: The agent fixes issues you select from your backlog and assign with the **Assign to Agent** button on the **Issues** page.
* **Pull request remediation** (GitHub only): The agent is triggered from a pull request analysis when your quality gate fails.

## Supported languages

The Remediation Agent works with your most common languages (C#, Java, JavaScript/TypeScript, and Python) by providing feedback on maintainability, reliability, and select security issues. In addition, it also offers fix suggestions for [Secrets](https://docs.sonarsource.com/sonarqube-cloud/analyzing-source-code/languages/secrets). It can also remediate dependency vulnerabilities found by Software Composition Analysis (SCA); see [SCA basic remediation](#sca-basic-remediation) below. See the [Requirements and limitations](https://docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/ai-features/sonarqube-remediation-agent#requirements-and-limitations) article for complete details.

## Sharing your code with Sonar <a href="#sharing-your-code-with-sonar" id="sharing-your-code-with-sonar"></a>

If you use the SonarQube Remediation Agent, the affected code is processed by Sonar to generate and verify a fix suggestion. Sonar’s remediation service sends the affected code snippet to your provider’s LLM to generate the suggestion, then verifies the generated code.

Because you bring your own [provider key](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/administer-remediation-agent#configure-your-llm-provider-key), the request is made under your own provider account, so your provider’s usage agreement governs how your data is handled.

For Sonar terms and conditions, see [Early Access terms](https://www.sonarsource.com/legal/early-access/) in our [Legal documentation](https://www.sonarsource.com/legal/).

## Setup

To enable and install the agent, see [Administer the Remediation Agent](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/administer-remediation-agent).

To understand the agent's behavior and learn how to engage with the agent in your pull request, follow the [Pull request fix suggestions](/sonarqube-cloud/managing-your-projects/issues/with-ai-features#pull-request-fix-suggestions) and [Backlog fix suggestions](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/backlog-fix-suggestions) guides.

## SCA basic remediation

The Remediation Agent can fix Software Composition Analysis (SCA) vulnerabilities by bumping the dependency version suggested by the SCA analysis. Triggered by a SonarQube Cloud [Dependency risks](https://docs.sonarsource.com/sonarqube-cloud/advanced-security/reviewing-and-fixing-dependency-risks) analysis, the agent generates a PR for your review.

The following package managers are supported:

* **NPM** — covers npm and yarn
* **PyPI** — covers pip
* **Maven** — covers Maven and Gradle

## Related products

For AI-powered pull request review automation, see [Gitar](https://docs.gitar.ai), a separate Sonar product.


# Hunter Agent

SonarQube Hunter Agent is an AI-powered agent that finds broken access control, business logic, and authentication flaws that traditional analysis misses.

> SonarQube Hunter Agent is available as a beta feature in the SonarQube Cloud Enterprise plan. For more information on release stages, see [Product release lifecycle](https://docs.sonarsource.com/sonarqube-cloud/appendices/product-release-lifecycle).

## Overview

SonarQube Hunter Agent performs deep verification inside the [code maintenance loop](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/code-maintenance-loop) of the [Agent Centric Development Cycle](/agent-centric-development-cycle). It runs a deep analysis of your projects to find vulnerabilities that require human-like understanding of the code, then raises them as issues you can triage in SonarQube Cloud.

Broken access control and business-logic flaws don't show up as code patterns. They live in the gap between what your code is meant to do and what it actually does. Static analysis cannot see that gap, so these flaws usually surface only in manual security review. SonarQube Hunter Agent brings that type of review to your projects.

With SonarQube Hunter Agent, you:

* find high-impact security flaws that static analysis misses, such as broken access control and business-logic errors
* work with findings as regular issues you triage, assign, and track like any other, with no new tool to learn
* run the analysis on Sonar's infrastructure, with nothing to install or run locally

The agent works through playbooks: structured, multi-step sequences of specialized prompts that reason through your code the way a security researcher works through a manual code audit.

Each run works in stages: the agent identifies the threat model for the security-relevant parts of your codebase, detects candidate issues, tests them to rule out false positives, and pins each confirmed finding to an exact location in the code.

```mermaid
%%{init: {'theme': 'base', 'themeVariables': {
  'primaryColor': '#E6F2FF',
  'primaryBorderColor': '#126ED3',
  'primaryTextColor': '#111827',
  'lineColor': '#126ED3'
}}}%%
flowchart TD
    D["Discover
---
Identify the threat model"] --> I1["Detect issues
---
Broken access control"]
    D --> I2["Detect issues
---
Business logic"]
    D --> I3["Detect issues
---
Authentication and session"]
    I1 --> C1["Verify candidates
---
Broken access control"]
    I2 --> C2["Verify candidates
---
Business logic"]
    I3 --> C3["Verify candidates
---
Authentication and session"]
    C1 --> S["Consolidate
---
Merge findings across categories"]
    C2 --> S
    C3 --> S
    S --> L["Locate
---
Pin each finding to a file and line"]
    L --> R["Report
---
Raise findings as issues in SonarQube Cloud"]
```

## What it detects

SonarQube Hunter Agent runs a single application security playbook that covers three categories of vulnerability. Note that the following lists of CWEs are not exhaustive.

**Broken access control**: insecure direct object references (IDOR), missing or incorrect authorization checks, privilege escalation, sensitive data exposure, and cross-site request forgery (CSRF)

* CWE-639: Authorization Bypass Through User-Controlled Key (IDOR)
* CWE-285: Improper Authorization
* CWE-862: Missing Authorization
* CWE-863: Incorrect Authorization
* CWE-269: Improper Privilege Management
* CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
* CWE-352: Cross-Site Request Forgery

**Business logic vulnerabilities**: skipping required workflow steps, abusing repeatable actions, and missing rate limits

* CWE-840: Business Logic Errors (parent category)
* CWE-841: Improper Enforcement of Behavioral Workflow
* CWE-799: Improper Control of Interaction Frequency
* CWE-837: Improper Enforcement of a Single, Unique Action
* CWE-770: Allocation of Resources Without Limits or Throttling

**Authentication and session management flaws**: broken authentication, session fixation, non-expiring sessions, weak password recovery, missing multi-factor authentication (MFA), and brute-force gaps

* CWE-287: Improper Authentication
* CWE-384: Session Fixation
* CWE-613: Insufficient Session Expiration
* CWE-640: Weak Password Recovery Mechanism for Forgotten Password
* CWE-308: Use of Single-factor Authentication
* CWE-294: Authentication Bypass by Capture-replay
* CWE-307: Improper Restriction of Excessive Authentication Attempts

SonarQube Hunter Agent works with any language supported by SonarQube Cloud.

## Reviewing findings

SonarQube Hunter Agent findings appear in your project's regular issue list, alongside your other issues, so you can filter, assign, comment on, and change their status like any other issue. Each enabled project also has a **Hunter Agent** page that summarizes findings.

## Setup

To enable SonarQube Hunter Agent for your organization and projects, see [Uncover complex vulnerabilities with AI](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/uncover-complex-vulnerabilities-with-ai).

## FAQ

#### Does SonarQube Hunter Agent replace static analysis?

No. It complements Sonar's static analysis. Static analysis handles the vulnerability classes it's built for, such as SQL injection and cross-site scripting (XSS), and SonarQube Hunter Agent adds a layer for logic-level flaws that don't show up as code patterns.

#### How is it different from runtime tools or pentesting agents?

Runtime tools and AI-assisted pentesting agents probe a running application after deployment. SonarQube Hunter Agent works at the code level, before the code ships, applying the same attacker-perspective reasoning earlier, when a fix costs far less.

#### Does it run my application?

No. SonarQube Hunter Agent only reads your source code. It doesn't run or attack a running application.

#### How is it different from Gitar?

Gitar reviews individual pull requests as they're opened. SonarQube Hunter Agent analyzes your projects in depth.

#### How is it different from the Remediation Agent?

Both are agents, but they work at opposite ends of the cycle. SonarQube Hunter Agent is a *Verify* feature that finds new vulnerabilities. The [Remediation Agent](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/remediation-agent) is a *Solve* feature that proposes fixes for issues you already have. SonarQube Hunter Agent doesn't fix the issues it finds.

#### Which large language model does it use?

SonarQube Hunter Agent is model-agnostic. It runs on Sonar's Foundation Agent, which currently uses Claude Sonnet and Opus, and Sonar can qualify other models over time. The Foundation Agent keeps results consistent and auditable, whichever model is in use.

#### Are the results consistent from run to run?

Yes. Consistency is a core design goal. Rather than producing different results on the same project each run, SonarQube Hunter Agent aims for reproducible, auditable output that you can triage, escalate, and report on.

#### What happens to my code and findings?

Your code and findings stay within your SonarQube Cloud environment. SonarQube Hunter Agent doesn't send your source code to external services beyond the model inference call, which is subject to the same data-handling terms as the rest of the platform. Contact your account team for the full data-handling documentation.

## Related pages

* [About the Agent Centric Development Cycle](/agent-centric-development-cycle)
* [Uncover complex vulnerabilities with AI](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/uncover-complex-vulnerabilities-with-ai)


# AI CodeFix

SonarQube's AI CodeFix feature offers AI-generated fix suggestions for issues found during your analysis.

## Overview

AI CodeFix solves issues in the [code maintenance loop](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/code-maintenance-loop) of the [Agent Centric Development Cycle](/agent-centric-development-cycle).

Sonar’s AI CodeFix uses a large language model (LLM) to automatically generate AI-driven code fixes for the issues discovered by SonarQube Cloud or SonarQube Server.

The feature is available with:

* SonarQube Cloud Team and Enterprise plans.
* SonarQube Server Enterprise and Data Center editions.

When the feature is enabled, a **Generate AI fix** button appears in the SonarQube Server or SonarQube Cloud UI for the selected issue. Clicking the button sends the affected code and issue description to an LLM. AI CodeFix then proposes an edit that resolves the problem without changing the code’s functionality.

In SonarQube Cloud, fixes can also be [opened as a pull request in Azure DevOps](/sonarqube-cloud/managing-your-projects/issues/fixing#opening-a-pull-request-in-azure-devops).

## Sharing your code with Sonar <a href="#sharing-your-code-with-sonar" id="sharing-your-code-with-sonar"></a>

For fully self-hosted SonarQube Server configurations, AI CodeFix is designed to operate without outbound internet access. All necessary prompts and rule descriptions for AI CodeFix are provided with the SonarQube product installation.

* Requirement: The SonarQube Server instance must be able to reach your configured LLM endpoint.

If you use Sonar’s AI CodeFix LLM, the affected code snippet will be sent by the AI CodeFix service to the selected LLM. Service agreements with Sonar’s LLMs prevent your code from being used to train those models.

For terms and conditions, see [AI CodeFix terms](https://www.sonarsource.com/legal/ai-codefix-terms/) in our [Legal Documentation](https://www.sonarsource.com/legal/).

## Setup

### Use the feature

* SonarQube Cloud: [Getting AI-generated fix suggestions](/sonarqube-cloud/managing-your-projects/issues/fixing#getting-ai-generated-fix-suggestions).
* SonarQube Server: [Getting AI-generated fix suggestions](/sonarqube-server/2026.1/user-guide/issues/fixing#getting-ai-generated-fix-suggestions).

In SonarQube Cloud, you can also open a pull request in Azure DevOps directly from a generated fix when your organization and project are bound to Azure DevOps. See [Opening a pull request in Azure DevOps](/sonarqube-cloud/managing-your-projects/issues/fixing#opening-a-pull-request-in-azure-devops) for details.

### Use the feature in your IDE

After enabling AI CodeFix, users can select **Generate AI Fix** on eligible issues and copy the fix into their IDE with the **Open in IDE** feature in connected mode. If your engineers use SonarQube for [VS Code](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-for-vs-code/) or SonarQube for [IntelliJ](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-for-intellij/), AI CodeFix is available in the IDE and follows the settings defined in your quality profile.

* See the IntelliJ page for [AI CodeFix in your IDE](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-for-intellij/ai-capabilities/ai-codefix/)
* See the VS Code page for [AI CodeFix in your IDE](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-for-vs-code/ai-capabilities/ai-codefix/)

### Enable the feature

To learn how to enable the feature, see:

* SonarQube Cloud: [Enable AI CodeFix](/sonarqube-cloud/administering-sonarcloud/ai-features/enable-ai-codefix).
* SonarQube Server: [Enable AI CodeFix](/sonarqube-server/2026.1/instance-administration/ai-features/enable-ai-codefix).

## Usage limits

Usage limits protect the AI CodeFix feature from abuse. Developers are notified directly when your organization reaches its monthly allocation. If the instance is blocked due to reaching the allowance, users attempting to generate a fix will see an error message. Usage quotas are reset on the first day of each month.

SonarQube Server instances using a self-hosted LLM aren’t subject to Sonar’s limits; however, you may encounter rate limits from your LLM provider.


# How-to guides

Learn how to fix SonarQube issues with backlog fixes and AI CodeFix suggestions, and how to administer AI CodeFix and the Remediation Agent.

Get AI-generated fix suggestions for issues detected during analysis.

* [Backlog fix suggestions](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/backlog-fix-suggestions)
* [Individual issue fix suggestions](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/individual-issues-fix-suggestions)
* [Uncover complex vulnerabilities with AI](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/uncover-complex-vulnerabilities-with-ai)

Administer features:

* [Administer AI CodeFix](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/administer-ai-codefix)
* [Administer Remediation Agent](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/administer-remediation-agent)


# Get backlog fix suggestions

Assign issues to the SonarQube Remediation Agent and generate AI CodeFix suggestions in SonarQube Cloud.

Assign issues to the SonarQube Remediation Agent and generate AI CodeFix suggestions in SonarQube Cloud.

The Remediation Agent is part of Sonar Agent Essentials, a product that requires a separate subscription to your SonarQube Cloud Team (annual) or Enterprise plan.

## Prerequisites

An organization admin must enable the SonarQube Remediation Agent and add an LLM provider key for your organization before the agent can run. See [Enable your agent](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/administer-remediation-agent#enable-your-agent) and [Configure your LLM provider key](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/administer-remediation-agent#configure-your-llm-provider-key).

## Automated backlog remediation

The SonarQube Remediation Agent can run on a schedule, automatically proposing fixes for eligible issues in your main branch without manual assignment. When triggered, the agent opens pull requests in your repository on your configured schedule, grouped by rule key and file type, the same way it does for issues you assign manually. Each scheduled run opens one pull request for up to five issues in every selected repository.

An organization admin enables scheduled runs by selecting **Automated backlog remediation** when enabling the Remediation Agent on the **AI capabilities** page. For step-by-step instructions, see the [Enable your agent](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/administer-remediation-agent#enable-your-agent) article on the SonarQube Remediation Agent page. Once enabled, set the frequency (daily or weekly), the time, and the timezone at which the agent runs. To cap how many open pull requests the agent keeps active, set a limit under **Pause when open PRs reach**, or select **Don't pause**. These organization-level settings apply to all projects where the agent is enabled.

![The Automated backlog remediation settings: a project selection, a run schedule with frequency, time, and timezone, and a limit for the number of open pull requests.](/files/P04WjNIiNmZeV5aZcSRn)

Project admins have the same controls and can override or disable scheduled runs for individual projects. Navigate to *Your Organization* > *Your Project* > **AI capabilities** to manage project-level settings. Project settings take precedence over the organization settings.

Scheduled runs are visible on the **Agent activity** page.

## Assigning issues to the agent

Reduce technical debt by selecting issues from your main branch and letting the SonarQube Remediation Agent propose fixes in new pull requests (PR). The **Assign to Agent** button on the **Issues** page lets you send selected issues to the agent so it can generate a fix proposal for you to review.

The **Backlog fixes** feature runs *only on the main branch*. It must be enabled by selecting **Backlog fixes** from the **AI capabilities** page in SonarQube Cloud. For step-by-step instructions to enable the **Backlog fixes**, see the [Enable your agent](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/administer-remediation-agent#enable-your-agent) article on the SonarQube Remediation Agent page.

Only eligible issues in your main branch can be assigned to the agent. If you select a mix of eligible and non-eligible issues, a warning appears and you are reminded that only eligible issues will be sent to the service. The **Assign to Agent** button stays greyed out until at least one eligible issue is selected, and you can't assign more than 20 issues at one time. For a list of unsupported rules, see the [Requirements and limitations](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/administer-remediation-agent#requirements-and-limitations) article on the SonarQube Remediation Agent page.

When you select **Assign to Agent**, the agent opens a new pull request in your repository, authored by the SonarQube Remediation Agent. Fix suggestions are grouped together in PRs, organized by rule key and file type; one PR will be opened for each rule key and/or file type. An estimated time to fix notification will pop up and the agent's activity will be visible on the **Agent activity** page when the PR is available.

1. Navigate to your project’s **Issues** page.
2. Check that you are on the `main` branch.
3. Select issues from your backlog that you want the agent to fix.
4. Select **Assign to Agent** to send eligible issues to the SonarQube Remediation Agent.

![Select one or more issues to fix using the SonarQube Remediation Agent to fix issues in your backlog.](https://docs.sonarsource.com/~gitbook/image?url=https%3A%2F%2F2223713658-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FB4UT2GNiZKjtxFtcFAL7%252Fuploads%252Fc35RXVsNgqGeykXVTvu1%252Fsonarqube-cloud-assign-to-agent-steps.png%3Falt%3Dmedia%26token%3D702ab688-35d6-4a54-8971-5bcbee7bbeb2\&width=768\&dpr=3\&quality=100\&sign=23509ec6\&sv=2)

**Backlog fixes** are only available when addressing issues in your main branch. See the [Main branch analysis](https://docs.sonarsource.com/sonarqube-cloud/analyzing-source-code/branch-analysis/main-branch-analysis) page for information about the main branch **Summary** page.

## Reviewing agent fixes

The PR summary includes issue information in the same format you expect to see in an issue’s rule description from any SonarQube product. The agent’s fix proposal is delivered in a unique commit for each issue, ready for an engineer to review.

The SonarQube Remediation Agent's PR comment will have a list of **Fixed Issues** with information that includes the issue's rule description and the accompanying information as found with every SonarQube rule.

> **Note:** Azure DevOps limits pull request descriptions to 4,000 characters. When the agent fixes several issues in one pull request and the full description would exceed that limit, it shortens the description: each issue keeps its rule, title, and a **View issue** link, while the detailed explanation is dropped to conserve characters. An indicator marks that more issues were fixed than the description lists in full.

If CI fails on the agent's PR, the agent automatically reads the build logs and pushes a new commit to fix the failures. This applies to PRs created by both manual and automated backlog remediation. The agent retries up to three times and tracks progress in the PR description. For details on how CI/CD failure recovery works, see [CI/CD failure recovery](/sonarqube-cloud/managing-your-projects/issues/with-ai-features#cicd-failure-recovery) on the Pull request fix suggestions page.

> **Note:** CI/CD failure recovery works only for GitHub Actions workflows. If your CI uses another provider, SonarQube Cloud detects the failure but can't retrieve the logs needed to generate a fix.

## Agent activity <a href="#agent-activity" id="agent-activity"></a>

To review the SonarQube Remediation Agent's activity, go to *Your SonarQube Cloud Project* > **Agent activity**. From there you'll see the agent's:

* Status/duration: Time the agent spent to generate fixes.
* Started: When the agent is triggered by the **Automated backlog remediation** schedule, by selecting **Assign to Agent** on the **Issues** page, or by selecting **Fix automatically** in the **Quality Gate failed** comment on a pull request.
* Source: Where the agent is working. *Backlog fixes* means that the agent is working on issues found in your main branch; or a link will be provided to the branch where you first called the agent.
* Outcome: A link to the agent's PR.
  * PRs made for *Backlog fixes* will be on your `main` branch.
  * PRs made for *Pull request fixes* will be made on your branch. See [Engage with the agent](/sonarqube-cloud/managing-your-projects/issues/with-ai-features#engage-with-the-agent) for details.

![The SonarQube Cloud Agent activity page lists each of the agent's event moments on your pull request analyses.](https://docs.sonarsource.com/~gitbook/image?url=https%3A%2F%2F2223713658-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FB4UT2GNiZKjtxFtcFAL7%252Fuploads%252Fzo0hYjsJKgxztCAKN7rG%252Fsonarqube-cloud-agent-activity.png%3Falt%3Dmedia%26token%3D84d47193-c5c7-486e-98d9-0c59d420da1d\&width=768\&dpr=3\&quality=100\&sign=98c996d1\&sv=2)

## Agents in your pull request <a href="#agents-in-your-pull-request" id="agents-in-your-pull-request"></a>

Get AI-generated fix suggestions in your pull request for C#, Java, JavaScript/TypeScript, and Python projects when the quality gate fails with new issues introduced. See the [Pull request fix suggestions](/sonarqube-cloud/managing-your-projects/issues/with-ai-features#pull-request-fix-suggestions) page for the full details.

## Related products

For AI-powered pull request review automation, see [Gitar](https://docs.gitar.ai), a separate Sonar product.


# Get individual issue fix suggestions

SonarQube Cloud’s AI CodeFix feature offers AI-generated fix suggestions for issues found during your analysis.

In the code maintenance loop of the Agent Centric Development Cycle, use AI CodeFix to get code fix suggestions for individual issues detected during analysis.

Find instructions for getting individual issue fix suggestions in the following product documentation:

* SonarQube Cloud: [Fixing issues #Getting AI-generated fix suggestions](/sonarqube-cloud/managing-your-projects/issues/fixing#getting-ai-generated-fix-suggestions)
* SonarQube Server: [Getting AI-generated fix suggestions](https://docs.sonarsource.com/sonarqube-server/user-guide/issues/fixing#getting-ai-generated-fix-suggestions)

To learn how AI CodeFix generates fix suggestions, see [AI CodeFix](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/ai-codefix).


# Administer AI CodeFix

How to administer AI CodeFix in SonarQube Cloud and SonarQube Server.

To administer AI CodeFix, see:

* SonarQube Cloud: [Enabling AI CodeFix](/sonarqube-cloud/administering-sonarcloud/ai-features/enable-ai-codefix)
* SonarQube Server: [Enabling AI CodeFix](/sonarqube-server/2026.1/instance-administration/ai-features/enable-ai-codefix)

To learn how AI CodeFix generates fix suggestions, see [AI CodeFix](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/ai-codefix).


# Administer Remediation Agent

Information on how to administer the SonarQube Remediation Agent.

## Overview

The SonarQube Remediation Agent helps you fix issues found by SonarQube Cloud in pull requests and in your backlog. It generates fix suggestions for eligible issues and verifies the proposed changes before offering them to you.

This page explains how to enable the agent, manage repository access, and control how it operates in GitHub, Azure DevOps, and SonarQube Cloud.

The Remediation Agent is part of Sonar Agent Essentials, a product that requires a separate subscription to your SonarQube Cloud Team (annual) or Enterprise plan.

## Requirements and limitations

* The SonarQube Remediation Agent, when enabled, can make automated and manual backlog fix suggestions on private projects bound to GitHub or Azure DevOps. It can also make fix suggestions in new pull requests on private GitHub-bound projects.
* Analysis must be enabled on your repository, either automatic analysis or CI-based analysis.
* Your GitHub or Azure DevOps organization and repository must be bound to your SonarQube Cloud organization and project.
* Pull request remediation, available for GitHub-bound projects only, fixes new issues in a pull request when the quality gate fails. Azure DevOps-bound projects can use automated and manual backlog remediation.
* The agent can suggest code fixes in the main branch of your backlog and on your pull request for maintainability, reliability, and a select set of security issues found in C#, Java, JavaScript/TypeScript, and Python code. The agent can also suggest fixes for secrets detected in your code.
* The agent can also fix dependency vulnerabilities found by Software Composition Analysis (SCA). See [Reviewing and fixing dependency risks](https://docs.sonarsource.com/sonarqube-cloud/advanced-security/reviewing-and-fixing-dependency-risks) for details.

To keep the agent's output manageable, the number of issues it handles at once is limited:

* Automated backlog remediation: each scheduled run opens one pull request for up to five issues in every selected repository.
* Manual backlog remediation: you can't select more than 20 issues to assign at one time.
* Pull request remediation: if a pull request introduces more than 20 new issues, the agent isn't offered.

> **Warning:** The SonarQube Remediation Agent will only work with issues found in one of the supported language types.
>
> Once enabled in SonarQube Cloud, any of your GitHub repositories can add the SonarQube Remediation Agent as a GitHub App, regardless of the language type.
>
> SonarQube Cloud may find issues in a repository with an unsupported language (for example, C++), but the agent won't be triggered in a pull request because C++ isn't a supported language.

## Sharing your code with Sonar

If you use the SonarQube Remediation Agent, the affected code is processed by Sonar to generate and verify a fix suggestion. Sonar's remediation service sends the affected code snippet to your provider's LLM to generate the suggestion, then verifies the generated code.

Because you bring your own [provider key](#configure-your-llm-provider-key), the request is made under your own provider account, so your provider's usage agreement governs how your data is handled.

For Sonar terms and conditions, see [Early Access terms](https://www.sonarsource.com/legal/early-access/) in our [Legal documentation](https://www.sonarsource.com/legal/).

## Enable your agent

Before you connect the agent, bind your project to its GitHub or Azure DevOps repository and enable analysis, using either automatic analysis or CI-based analysis. Then navigate to *Your SonarQube Cloud organization* > **Administration** > **AI capabilities** > **Remediation Agent**.

How you connect the agent depends on your DevOps platform.

### GitHub: install the SonarQube Agent app

A GitHub administrator needs to install the [SonarQube Agent GitHub app](https://github.com/apps/sonarqube-agent). Under **Install app**, select **GitHub**. The administrator will be prompted to install the app on the GitHub organization already linked to your SonarQube Cloud organization. If installed, the agent will be granted:

* Read and write access to code and pull requests
* Read-only access to Actions
* Read-only access to issues and metadata

Choose either **All repositories** or **Only select repositories** to control which repositories the agent can access. Once you've made your selection, select **Install & Authorize** to finish the setup. The installation may take a few seconds to complete.

### Azure DevOps: reuse your platform connection

Azure DevOps doesn't use a separate app. The agent reuses the personal access token (PAT) captured when your Azure DevOps organization was imported into SonarQube Cloud, so there's no app to install and no install-time repository picker. If your organization isn't imported yet, see [Importing an Azure DevOps organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-azure-devops-organization#create-pat) and [Azure DevOps project binding](/sonarqube-cloud/managing-your-projects/administering-your-projects/devops-platform-integration/azure-devops).

### Select flows and projects

After you connect the agent, **Pull request fixes** (GitHub only) and **Backlog fixes** are selected automatically under **Enable agent**. You'll be able to commit the agent's suggestions directly from your PRs, and the **Assign to Agent** button will be available on the **Issues** page for selected projects. Choose whether the agent runs on **All projects** or **Only selected projects**.

To have the agent fix backlog issues on a schedule, an organization admin selects **Automated backlog remediation** at the bottom of the **Enable agent** list. Set the frequency (daily or weekly), the time, and the timezone for the scheduled runs. To cap how many open pull requests the agent keeps active, set a limit under **Pause when open PRs reach**, or select **Don't pause**. These organization-level settings apply to all projects where the agent is enabled, and project admins have the same controls to override or disable the schedule for individual projects.

## Configure your LLM provider key

The SonarQube Remediation Agent runs on a large language model (LLM) from an external provider. You bring your own provider API key: add an OpenAI or Anthropic API key to your organization, and the agent uses it to generate fix suggestions.

Because you provide the key, agent usage is billed to your provider account. You need an OpenAI or Anthropic account to use the agent.

### Add a provider key

Adding keys is an organization-level task. Navigate to *Your SonarQube Cloud organization* > **Administration** > **AI capabilities** > **Configuration**, then:

1. Select **Add key**.
2. Choose a provider: **OpenAI** or **Anthropic**.
3. Enter the API key from your provider account.
4. Enter a name to identify the key in SonarQube Cloud.
5. Select **Save**.

When you save, SonarQube Cloud verifies the key with the provider. If the key is valid, it's accepted; if it can't be verified, SonarQube Cloud reports the error and the key isn't saved.

You can add up to three keys per organization. Once you reach that limit, the **Add key** option is disabled until you delete a key.

> **Note:** You choose the provider, not the model. SonarQube Cloud uses Claude Opus 4.6 for Anthropic and GPT-5.5 for OpenAI.

### How your key is handled

* **Encrypted at rest**: keys are encrypted with AWS Key Management Service (KMS) before they're stored.
* **Never logged**: the key value isn't written to logs.
* **Masked when displayed**: after you save a key, SonarQube Cloud only ever shows a masked hint, a few characters from the start and end of the key. The full key is never shown again and is never sent back to the browser, so keep your own copy if you need it elsewhere.

### Select the key for the agent

After you add a key, choose which one the agent uses. Navigate to *Your organization* > **Administration** > **AI capabilities** > **Remediation Agent**, and select your key in the agent setup steps. The agent can't be enabled until a key is selected, so the later setup steps stay disabled until you complete this step.

### Manage and delete keys

To review or remove keys, go to *Your SonarQube Cloud organization* > **Administration** > **AI capabilities** > **Configuration**. Each saved key shows its name, provider, and masked hint.

To delete a key, select it and confirm. If you delete the key currently selected for the agent, the agent is disabled until you select another key.

## Manage agent access

### GitHub

The SonarQube Remediation Agent only has access to the bound repositories defined in GitHub. To change repository access, a GitHub administrator who is also a SonarQube Cloud Administrator can navigate in SonarQube Cloud to *Your organization* > **Administration** > **AI capabilities** > **Remediation Agent**. Under Install app, select **Manage Permissions** which takes you to your GitHub Apps page.

Alternatively, a GitHub administrator can navigate in GitHub to *Your GitHub organization* > **Settings** > **Third-party Access** > **GitHub Apps**. Under **Installed GitHub Apps** > **SonarQube Agent**, select **Configure**.

* In GitHub, under **SonarQube Agent** > **Repository access**, add or remove your repositories from the list. When finished, select **Save** to confirm your selection.

### Azure DevOps

The agent's access comes from your Azure DevOps organization binding rather than a separate app. To change which projects the agent works on, switch between **All projects** and **Only selected projects** under *Your organization* > **Administration** > **AI capabilities** > **Remediation Agent**. To change repository-level access, update the personal access token or organization binding in Azure DevOps. See [Azure DevOps project binding](/sonarqube-cloud/managing-your-projects/administering-your-projects/devops-platform-integration/azure-devops).

### Disable or suspend agent access

A SonarQube Cloud Administrator can disable the agent for any platform: navigate to *Your organization* > **Administration** > **AI capabilities** > **Remediation Agent** > **Enable agent** and unselect the remediation type you want to suspend. After you select **Save**, the agent won't be triggered.

On GitHub, you can also suspend or uninstall the SonarQube Agent app completely. Navigate in GitHub to *Your GitHub organization* > **Third-party Access** > **GitHub Apps** > **SonarQube Agent** > **Danger zone** and select **Suspend** or **Uninstall**.

* **Suspend** will block the agent's access to your repositories. This is the easiest way to restart the agent when you're ready.
* If you select and confirm **Uninstall**, the SonarQube Agent will be removed from all of your repositories and from your SonarQube Cloud organization. The agent's activity will remain in your PR history, but if you want to use the agent again, you must return to [Enable your agent](#enable-your-agent).

On Azure DevOps, there's no app to suspend or uninstall. Disable the agent in SonarQube Cloud as described above, or revoke or rescope the personal access token in Azure DevOps to remove access.

## Agent behavior

The SonarQube Remediation Agent proposes fixes in four ways: automatically on a schedule, for issues you assign from your backlog, for new issues in a pull request when its quality gate fails, and by retrying after CI failures on its own PRs.

* **Automated backlog remediation**: The agent runs on a schedule you set, automatically proposing fixes for eligible issues in your main branch without manual assignment. For configuration details, see [Backlog fix suggestions](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/backlog-fix-suggestions#automated-backlog-remediation).
* **Manual backlog remediation**: Select issues from your main branch and assign them to the agent. It opens a new pull request in your repository and groups the fixes you assign by rule key and file type. For details, see [Backlog fix suggestions](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/backlog-fix-suggestions).
* **Pull request remediation** (GitHub only): When your quality gate fails during PR analysis, the **Quality Gate failed** comment includes a **Fix automatically** checkbox. Select it to trigger the agent, which generates fixes and opens a separate PR targeting your branch. Its behavior and how to engage with it are described on [Pull request fix suggestions](/sonarqube-cloud/managing-your-projects/issues/with-ai-features#pull-request-fix-suggestions).
* **CI/CD failure recovery** (GitHub Actions only): If CI fails on an agent-created PR, the agent automatically reads the build logs, pushes a new commit to address the failures, and waits for CI to run again. The agent retries up to three times. If CI passes, the PR is ready for your review. If CI still fails after three attempts, the agent stops and leaves the PR open for you to fix manually. Recovery applies to PRs created from both pull request remediation and backlog remediation flows.

  > **Note:** CI/CD failure recovery works only for GitHub Actions workflows. The agent detects CI failures from any provider, but can only read build logs through the GitHub API, which exposes logs for GitHub Actions jobs only.

## Unsupported rules

A small number of rules aren't supported because they're too complex for an LLM to solve.

### Unsupported C# rules

csharpsquid:S1133

csharpsquid:S1134

csharpsquid:S1135

csharpsquid:S1144

csharpsquid:S3776

### Unsupported Java rules

java:S120

java:S1133

java:S1134

java:S1135

java:S1144

java:S1228

java:S3776

### Unsupported JavaScript rules

javascript:S1134

javascript:S1135

javascript:S1144

javascript:S1874

javascript:S3776

### Unsupported Python rules

python:S1134

python:S1135

python:S1144

python:S3776

### Unsupported TypeScript rules

typescript:S1134

typescript:S1135

typescript:S1144

typescript:S1874

typescript:S3776

### Secrets rules

All Secrets rules are supported


# Uncover complex vulnerabilities with AI

How to enable the SonarQube Hunter Agent for your organization and projects so it runs an AI-powered analysis that uncovers complex broken access control, business logic, and authentication flaws.

This guide walks you through enabling the [SonarQube Hunter Agent](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/hunter-agent) so it runs an AI-powered analysis that uncovers complex, logic-level security vulnerabilities that pattern-based analysis misses.

> SonarQube Hunter Agent is available as a beta feature in the Enterprise plan. For more information on release stages, see [Product release lifecycle](https://docs.sonarsource.com/sonarqube-cloud/appendices/product-release-lifecycle).

## Prerequisites

* A SonarQube Cloud organization on the Enterprise plan
* Your organization bound to a supported DevOps platform (GitHub, GitLab, or Azure DevOps)
* The project you want to scan bound to its DevOps platform
* The Administer Organization permission (to enable the agent) and the Administer Project permission (to turn it on)

## Enable Hunter Agent for your organization

You need to be an organization administrator.

1. In SonarQube Cloud, go to *your organization* > **Administration** > **AI capabilities**.
2. Enroll your organization in the SonarQube Hunter Agent beta.
3. If your organization is not yet bound to a DevOps platform, follow the prompt to bind it. The agent cannot be enabled until the organization is bound.
4. Activate the **Allow project admins to enable scheduled scans** option.

Once enabled, the **Hunter Agent** section lists the projects that have the agent turned on, so you can see which projects are covered.

## Running analyses with Hunter Agent

> If you're running the first Hunter Agent analysis for your project, see [First analysis recommendations](#first-analysis-recommendations) to avoid failing your quality gate on the main branch.

As a project administrator, you can run Hunter Agent analyses manually or set up scheduled analyses.

1. Open the project you want to scan.
2. Go to **Administration** > **AI capabilities** and open the **Hunter Agent** tab.
3. If you see a message that the agent isn't enabled for the organization, ask an organization administrator to enable it first, using the link in the message.
4. If the project isn't bound to its DevOps platform, bind it first, following the prompt.
5. Run a Hunter Agent analysis manually or schedule analyses:
   * Manually: on the **Hunter Agent** page, select **Run now**, choose the branch to scan, and start an analysis immediately.
   * On a schedule: the agent scans the project automatically each day. The project's **Hunter Agent** page shows the last scan and the next scheduled scan.

## First analysis recommendations

SonarQube Hunter Agent raises its findings as regular issues. Running your first analysis directly on the main branch can cause a passing quality gate to fail and block your team before you've had a chance to work through the findings.

To roll out the agent without disrupting your main branch:

1. Start on a dedicated branch. For your first analysis, select **Run now** and choose a dedicated branch instead of your main branch. The findings surface as issues on that branch, so they don't affect your main branch's quality gate.
2. Work through the backlog. Triage, assign, and resolve the findings the agent raises, the same way you handle any other issue.
3. Schedule analyses on the main branch. After your fixes are merged into the main branch and the number of open findings is under control, set up scheduled analyses so the agent keeps covering it.

This approach keeps the first wave of findings off your main branch. It gives your team time to clear the backlog and brings the agent into your main-branch quality gate only once the results are manageable.

## Viewing agent activity

Track SonarQube Hunter Agent runs on the **Activity** tab of the project's **Hunter Agent** page. The table lists each run with the time it started, the branch it ran on, and its outcome. It shows SonarQube Hunter Agent runs only.

## Viewing findings

Each project with the agent enabled has a **Hunter Agent** page in its navigation. This page gives you a results overview: the total number of findings, a breakdown by vulnerability category (broken access control, business logic, and authentication and session management), and the count at each severity within a category.

Select the issues in one of the findings tiles on the **Hunter Agent** page to open the project's **Issues** page filtered to SonarQube Hunter Agent findings. Each category count links to the issues for that category. On the **Issues** page, you can also filter by the `hunter-agent` tag to see all agent findings, or by a per-category tag such as `hunter-broken-access-control` to focus on one category.

Each finding is raised as a vulnerability with a security software quality and an estimated severity, and includes an explanation with **Why is this an issue?** and **How to fix it?** sections. You review, assign, comment on, and resolve these findings like any other issue. See [Managing code issues](https://docs.sonarsource.com/sonarqube-cloud/managing-your-projects/issues/) to learn how to review issues in SonarQube Cloud.

## Related pages

* [Hunter Agent](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/hunter-agent)
* [About the Agent Centric Development Cycle](/agent-centric-development-cycle)
* [Reviewing issues](/sonarqube-cloud/managing-your-projects/issues/reviewing)


# AI Code Assurance

This section explains how to manage standards for AI-generated code, including the use of tools for Sonar’s AI Code Assurance in your SonarQube project.

AI Code Assurance features in SonarQube Server and SonarQube Cloud help you set appropriate standards for projects containing AI-generated code. A combination of tools—project labels, a default quality gate, and externally published project badges—helps ensure your AI projects meet security and code quality standards.

For more information, see [Set your AI standards](https://docs.sonarsource.com/sonarqube-cloud/standards/ai-code-assurance/overview) for SonarQube Cloud and the [AI Code Assurance overview](https://docs.sonarsource.com/sonarqube-server/quality-standards-administration/ai-code-assurance/overview) for SonarQube Server.


# Autodetect AI Code

SonarQube can autodetect the likelihood of AI-generated code in your projects on GitHub using GitHub Copilot.

> **Deprecated:** Autodetect AI Code is still available in SonarQube Cloud and SonarQube Server 2026.1 LTA and it will be removed in a future release. See the deprecation policy for [SonarQube Cloud](https://docs.sonarsource.com/sonarqube-cloud/deprecations-and-removals#deprecation-policy) and [SonarQube Server](https://docs.sonarsource.com/sonarqube-server/server-update-and-maintenance/maintenance/deprecations/deprecation-policy) for more information. Manual labeling of projects containing AI code remains available in both [SonarQube Cloud](https://docs.sonarsource.com/sonarqube-cloud/standards/ai-code-assurance/overview#label-projects-with-ai-code) and [SonarQube Server](https://docs.sonarsource.com/sonarqube-server/quality-standards-administration/ai-code-assurance/overview#label-projects-with-ai-code).

Knowing if your project contains AI-generated code helps raise awareness of code ownership and code security. To help build this awareness, SonarQube Cloud can autodetect AI-generated code in projects using GitHub Copilot.

* If turned on, the feature alerts Project Admins when project contributors recently used GitHub Copilot.
* If Copilot usage is detected, Project Admins can apply the tags and quality gates associated with your team’s *AI Code Assurance profile* to flag projects that contain AI-generated code.

**Autodetect AI-Generated Code** is on by default in SonarQube Cloud, but your GitHub App must have the appropriate permissions to allow communication with SonarQube Cloud.

For full details about the feature, including instructions and requirements, see [Autodetect AI code](https://docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/ai-features/autodetect-ai-code) for SonarQube Cloud and [Autodetect AI code](https://docs.sonarsource.com/sonarqube-server/instance-administration/ai-features/autodetect-ai-code) for SonarQube Server.


# SonarQube CLI in agentic workflows

Use SonarQube CLI with agents to perform various actions.

The [SonarQube CLI](https://docs.sonarsource.com/sonarqube-cli/) supports every loop of the Agent Centric Development Cycle. `sonar integrate` connects the CLI with your AI coding agent in one command, installing secrets-detection hooks, the SonarQube MCP server, [Sonar Vortex analysis](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-analysis), and [Sonar Vortex context](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-context). Individual CLI commands let you and your agent run analyses, query issues, and request fixes directly from the terminal.

## Supported agents

The following integrations are available:

| Agent              | Command                       |
| ------------------ | ----------------------------- |
| Claude Code        | `sonar integrate claude`      |
| Codex CLI          | `sonar integrate codex`       |
| GitHub Copilot CLI | `sonar integrate copilot`     |
| Cursor             | `sonar integrate cursor`      |
| Antigravity        | `sonar integrate antigravity` |

For detailed setup instructions, see the corresponding agent plugin page in [agent-plugins/](/agent-centric-development-cycle/developer-tools/agent-plugins).

## What the integration installs

For each supported agent, `sonar integrate` installs:

* Secrets detection: Hooks, instructions, or both that prevent the agent from reading files containing secrets or including them in prompts. The exact mechanism varies by agent.
* [Sonar Vortex analysis](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-analysis): Instructions or hooks that tell the agent to run `sonar analyze agentic` after edits.
* [Sonar Vortex context](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-context): A skill that lets the agent pull project guidelines, architecture, semantic navigation, and dependency context as it works.
* [SonarQube MCP server](https://docs.sonarsource.com/sonarqube-mcp-server/): Configured so the agent can fetch projects, issues, and rules directly.

To install the Vortex features, see [Installing Vortex](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides).

## Analyzing local changes

Beyond the automatic hooks installed by `sonar integrate`, run [Sonar Vortex analysis](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-analysis) directly from the terminal at any time:

```
sonar analyze agentic            # analyze uncommitted changes
sonar analyze agentic --staged   # analyze only staged changes
sonar analyze --staged           # secrets scan plus agentic analysis
```

This is the same command the integration runs automatically. Call it directly to trigger a check on demand or pass different flags. See [Analyzing local changes](/sonarqube-cli/analysis/analyzing-local-changes) in the SonarQube CLI docs for the full reference.

> **Note:** Agentic analysis requires a SonarQube Cloud organization with agentic analysis enabled.

## Listing and remediating issues

`sonar list issues` fetches issues from your SonarQube project with filters for severity, type, and status. Pass `--format toon` for a token-efficient format to pass to an AI agent:

```
sonar list issues --project <YourProjectKey> --format toon
```

`sonar remediate` sends eligible issues to the Remediation Agent and returns a proposed fix:

```
sonar remediate --project <YourProjectKey>
```

See [AI remediation](/sonarqube-cli/analysis/ai-remediation) in the SonarQube CLI docs.

> **Note:** `sonar remediate` requires a SonarQube Cloud organization entitled to the Remediation Agent. `sonar list issues` works with both SonarQube Cloud and SonarQube Server.

## For AI agents

If you're an AI agent reading these docs, machine-readable references for the SonarQube CLI are available at:

* Command reference (LLM-friendly text): `sonarsource.com/sonarqube/cli/llms.txt`
* Structured JSON schema: `sonarsource.com/sonarqube/cli/data/commands.json`

## List of commands

For the full list of SonarQube CLI commands, see [Commands](https://www.sonarsource.com/sonarqube/cli/commands#sonar-auth-login) on the SonarQube CLI website, an interactive reference where you can browse every command with its arguments, options, and examples.

If you prefer the documentation, see the [Commands reference](/sonarqube-cli/using-sonarqube-cli/commands) page.


# Agent plugins

Install and use SonarQube agent plugins for Claude Code, Codex CLI, Cursor, GitHub Copilot CLI, Kiro, and GitHub agent apps to bring SonarQube into your AI coding workflow.

The SonarQube agent plugins bring SonarQube code quality and security analysis directly into AI coding workflows, whether you run an agent locally in Antigravity, Claude Code, Codex CLI, Cursor, GitHub Copilot CLI, or Kiro, or through GitHub agent apps. Each plugin wires up the [About the MCP Server](/sonarqube-mcp-server/about-the-mcp-server) and exposes SonarQube features through the commands and skills appropriate to that surface.

Choose your agent for installation and usage details:

{% content-ref url="/pages/1zkUmtFOJvHDLcr1uTnp" %}
[Agent apps for GitHub](/agent-centric-development-cycle/developer-tools/agent-plugins/agent-apps-for-github)
{% endcontent-ref %}

{% content-ref url="/pages/WJd869gaVl4nHBZ1XfFo" %}
[Antigravity](/agent-centric-development-cycle/developer-tools/agent-plugins/antigravity)
{% endcontent-ref %}

{% content-ref url="/pages/46k0jZiwh7flw9LJSPRX" %}
[Claude Code](/agent-centric-development-cycle/developer-tools/agent-plugins/claude-code)
{% endcontent-ref %}

{% content-ref url="/pages/KIbLQLsXmcLmJKUvT6HI" %}
[Codex CLI](/agent-centric-development-cycle/developer-tools/agent-plugins/codex-cli)
{% endcontent-ref %}

{% content-ref url="/pages/FfdmhJXiUjZW77iekLjL" %}
[Cursor](/agent-centric-development-cycle/developer-tools/agent-plugins/cursor)
{% endcontent-ref %}

{% content-ref url="/pages/RXvplWpKvM1ooYCwhrj7" %}
[GitHub Copilot CLI](/agent-centric-development-cycle/developer-tools/agent-plugins/github-copilot-cli)
{% endcontent-ref %}

{% content-ref url="/pages/JuTYgNypwedH1IqYnfTc" %}
[Kiro](/agent-centric-development-cycle/developer-tools/agent-plugins/kiro)
{% endcontent-ref %}


# Agent apps for GitHub

Install the SonarQube agent GitHub app to bring SonarQube into your AI coding workflow through GitHub agent apps.

> **Available only with SonarQube Cloud.**

The SonarQube agent is a GitHub agent app that connects your repositories to SonarQube Cloud through the [SonarQube MCP Server](https://docs.sonarsource.com/sonarqube-mcp-server/). From a pull request comment or your repository's **Agents** view, ask it about quality gates, issues, coverage, and dependency risks.

## Features

* Check whether the SonarQube quality gate passes for a pull request, branch, or project.
* List and filter bugs, vulnerabilities, and code smells flagged by SonarQube.
* Apply fixes for specific SonarQube findings by rule key and file location.
* Inspect test coverage and find duplicated code blocks.
* Surface dependency risks (SCA) on pull requests, when SonarQube Advanced Security is available.

## Prerequisites

* A working SonarQube Cloud account ([sonarcloud.io](https://sonarcloud.io) or [sonarqube.us](https://sonarqube.us)) using GitHub as the selected DevOps platform. For setup instructions, see the [Getting started with GitHub](/sonarqube-cloud/getting-started/github) page in the SonarQube Cloud documentation.
* Access to [GitHub agent apps](https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-agent-apps).
* Ability to install apps in your GitHub organization or repository (including personal repositories).

## Getting started

1. Install the [SonarQube agent](https://github.com/apps/sonarqube-agent) GitHub app in your GitHub organization or repository. Use the [SonarQube agent US](https://github.com/apps/sonarqube-agent-us) app instead if your SonarQube Cloud organization is in the US region ([sonarqube.us](https://sonarqube.us)).
   * Select **Allow as Agent** before selecting **Install & Authorize**.
2. Every user who wants to use the SonarQube agent app must authorize the access tokens in SonarQube Cloud.

   * If you are installing the GitHub app, you are automatically redirected to the consent page during installation.
   * Otherwise, navigate to **My account** > **Access Tokens**, select the [**Agent Apps** tab](https://sonarcloud.io/account/access-tokens?tab=github_agent_hq), and toggle the **Allow Agent Apps for GitHub to create personal access tokens** option. See [Managing your access tokens](/sonarqube-cloud/managing-your-account/managing-tokens#agent-apps) in the SonarQube Cloud documentation.

   <div align="left"><figure><img src="/files/iFXcvSPP896GfnBqHChb" alt="The SonarQube Cloud Access tokens page, showing the Agent Apps tab with the &#x27;Allow Agent Apps for GitHub to create personal access tokens&#x27; toggle highlighted." width="563"><figcaption></figcaption></figure></div>
3. If you already had the SonarQube agent installed, you will need to configure the GitHub app to allow it as an Agent. Go to the organization or repository where the app was installed, open the app page from step 1, and select **Configure**. In the **Agent features** section, select **Allow as Agent**.

   <div align="left"><figure><img src="/files/KYLtTnL4BB4EvqwHJMrQ" alt="A screenshot demonstrating how to allow SonarQube agent as an Agent, with the &#x27;Allow as Agent&#x27; button highlighted to emphasize the action." width="563"><figcaption></figcaption></figure></div>
4. In GitHub, go to your repository or organization **Settings** > **Secrets and variables** > **Agents**.
5. On the **Agent secrets and variables** page, switch to the **Variables** tab. Create the following variables, copying the names exactly. Your option depends on the level: select **New organization variable** at the organization level, or **New repository variable** at the repository level:

   > **Important:** Use these exact variable names.

   <br>

   | Name                                | Value                                                                                                                                                                                           | Description                                                                                                                                                                     |
   | ----------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | `COPILOT_MCP_SONARQUBE_ORG`         | Your SonarQube Cloud [organization key](/sonarqube-cloud/managing-your-projects/retrieving-projects#viewing-project-information).                                                               | Required. If your GitHub organization corresponds to a single SonarQube Cloud organization, set this once in organization agent variables and reuse it across all repositories. |
   | `COPILOT_MCP_SONARQUBE_PROJECT_KEY` | The [project key](/sonarqube-cloud/managing-your-projects/retrieving-projects#viewing-project-information) inside your SonarQube Cloud organization that is linked with your GitHub repository. | Optional but recommended. Set this under repository agent variables.                                                                                                            |

   > **Note:** When `COPILOT_MCP_SONARQUBE_ORG` is set at both the GitHub organization and repository levels, the repository-level value overrides the organization-level value.

   <br>

   <div align="left"><figure><img src="/files/X3YFBXufbMTnLGLd439T" alt="The Variables tab on the GitHub Agent secrets and variables page, showing COPILOT_MCP_SONARQUBE_ORG and COPILOT_MCP_SONARQUBE_PROJECT_KEY listed as repository variables." width="563"><figcaption></figcaption></figure></div>
6. You are ready to use the SonarQube agent through agent apps. Go to your GitHub repository > **Agents**, select **SonarQube Agent** in the dropdown, and submit a prompt.

   <div align="left"><figure><img src="/files/qDU4IwGADPezx5FYKF2i" alt="The Agents dropdown in a GitHub repository showing SonarQube Agent alongside Copilot." width="563"><figcaption></figcaption></figure></div>

   You can also mention the agent in your pull request comments.

## Verify that it works

From your repository's **Agents** view, ask the agent: "Which projects can I see?" It should respond with the SonarQube projects accessible from your organization. If it doesn't, check that the `COPILOT_MCP_SONARQUBE_ORG` variable is set correctly and that the SonarQube agent app is allowed as an Agent on your repository or organization.

## Usage

Interact with the SonarQube agent in natural language from your repository's **Agents** view, or by mentioning the SonarQube agent app in a pull request comment.

The agent picks up the project and pull request context automatically, so you don't usually need to specify a project, branch, or pull request.

### Quality gate

* "Is the quality gate passing?"
* "Did this PR pass SonarQube analysis?"
* "What conditions are failing?"

### List issues

* "List the issues."
* "Show me bugs and vulnerabilities."
* "What's flagged on this PR?"
* "Issues in `src/auth/login.py`."

### Fix an issue

* "Fix `python:S2077` at `src/auth/login.py:34`."
* "Resolve this SonarQube finding."
* "Apply the suggested fix."

> **Note:** After a fix is applied, the SonarQube analysis doesn't refresh immediately. The new state appears after the next CI analysis of the branch or pull request.

### Analyze a code snippet

* "Analyze this file."
* "Run Sonar on `src/auth/login.py`."
* "Scan this snippet."

### Coverage

* "What's the test coverage?"
* "Which files have low coverage?"
* "Which lines aren't covered in `src/auth/login.py`?"

### Duplication

* "Show duplicated code."
* "Where is this block duplicated?"

### Dependency risks

Dependency risks require SonarQube Advanced Security on the connected organization (SonarQube Cloud Enterprise plan).

* "Any vulnerable dependencies?"
* "Check for CVEs in dependencies."

### List projects

* "Which projects can I see?"
* "Find the key for project `my-project`."

### What else the agent can do

Beyond the skills listed above, the SonarQube agent calls the SonarQube MCP Server directly to handle related requests. Ask it in natural language to:

* Explain a rule and how to fix violations.
* Look up project metrics, or list the quality gates configured in your organization.
* Search, review, and update security hotspots.
* Change the status of an issue: accept it, mark it as a false positive, or reopen it.


# Antigravity

Install the SonarQube plugin in Antigravity to bring code analysis, issue management, and secrets detection into your AI coding sessions.

The SonarQube plugin for Antigravity connects your AI coding agent to SonarQube's code quality and security data through the [About the MCP Server](/sonarqube-mcp-server/about-the-mcp-server). SonarQube does the analysis; Antigravity calls the MCP tools and acts on the results. Once installed and configured, Antigravity can run SonarQube analysis on your code, list and fix issues, check quality gates, inspect coverage and duplication, and run [Sonar Vortex analysis](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-analysis). The plugin also configures the SonarQube CLI to detect secrets, keeping credentials out of your prompts and the files the agent reads or writes.

The plugin works with SonarQube Cloud or SonarQube Server.

## Features

The plugin gives Antigravity access to the full set of [Tools](/sonarqube-mcp-server/reference/tools) exposed by the SonarQube MCP Server, including:

* Code analysis: analyze code snippets and files in the agent context.
* Issues: search, review, and update code issues.
* Quality gates: check the quality gate status for a project.
* Security hotspots: search and review security hotspots.
* Coverage: find under-covered files and review line-by-line coverage.
* Dependencies: check third-party dependencies for SCA issues.

Through the SonarQube CLI integration it sets up, the plugin also adds:

* Secrets detection: a hook that blocks file reads exposing secrets, plus managed instructions that warn the agent before it sends a prompt containing a secret.
* Agentic analysis (SonarQube Cloud only, project-level installs): instructions that tell Antigravity to verify the files it edits.
* Context augmentation (SonarQube Cloud only, project-level installs): a skill that tells Antigravity to pull project guidelines before editing code, check dependencies before changing a manifest, and use SonarQube's architecture and semantic-navigation context as it works.

## Prerequisites

* A SonarQube Cloud organization or SonarQube Server instance.
* [Antigravity](https://antigravity.google/) installed.
* The SonarQube CLI installed. The plugin's MCP Server uses your `sonar auth login` session.
* A container runtime (Docker, Podman, or nerdctl) to run the SonarQube MCP Server image.

## Install

The SonarQube plugin is distributed from the [SonarSource/sonarqube-agent-plugins](https://github.com/SonarSource/sonarqube-agent-plugins) repository. There is no `@vendor` marketplace shorthand—install via a git URL, archive, or local path.

From your shell, run:

```bash
agy plugin install https://github.com/SonarSource/sonarqube-agent-plugins
```

This installs the plugin globally under `~/.gemini/config/plugins/sonarqube/`. To install it for a single workspace only, copy the plugin files into `<YourProjectRoot>/.agents/plugins/sonarqube/` instead.

## Configuration

After installing the plugin, finish setup by running the guided integration skill:

```
/sonarqube:sonar-integrate
```

The skill does the following:

1. Install the SonarQube CLI if not already present, or update it with `sonar self-update`.
2. Authenticate with SonarQube Cloud or your SonarQube Server instance via `sonar auth login`. Your browser opens to complete login; the token is stored in your system keychain.
3. Run `sonar integrate antigravity`, which prompts you to install each component: the secrets-detection hook, the prompt-secrets instructions, the SonarQube MCP Server, and, for SonarQube Cloud project installs, the agentic analysis instructions and context augmentation skill.

Restart the Antigravity session after setup if MCP tools don't appear.

> **Important:** `--project` and `--global` are mutually exclusive. Passing both causes the command to fail with an "invalid options" error (exit code `2`).

## Sonar Vortex: agentic analysis and context augmentation features

When you run `sonar integrate antigravity`, the command configures Antigravity to use the [What is Sonar Vortex?](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex) features. They run through the SonarQube CLI:

* Agentic analysis: instructions tell Antigravity to check the files it edits and return any findings in its response. Unlike the Claude Code and Codex hooks, Antigravity can't inject findings back into the conversation.
* Context augmentation: gives Antigravity your project's coding guidelines, dependency health, architecture, and semantic-navigation context as it works.

Both features are project-scoped and skipped on a global install. Run `sonar integrate antigravity --project <YourProjectKey>` from a project directory to install them, or pass `--skip-context` to opt out of context augmentation.

## Migrate from Gemini CLI

Antigravity replaces Gemini CLI. If you previously used the SonarQube Gemini extension, migrate your platform configuration first, then run:

```bash
agy plugin import gemini       # converts legacy extensions and MCP config to native Antigravity format
sonar integrate antigravity    # adds hooks, instructions, and CAG (new vs. Gemini)
```

`agy plugin import gemini` scans your existing Gemini directories and migrates the SonarQube MCP entry into `mcp_config.json`. After verifying Antigravity works, remove any duplicate legacy extension install if the import created a copy.

For a fresh install on a machine that never had Gemini, use the steps in [Install](#install) and [Configuration](#configuration) above.

## Verify that it works

### Test the secrets hook

1. Create a file with a fake-looking but secret-shaped value:

   ```javascript
   // secrets.js
   const API_KEY = "sqp_1aa323ae0689cd4a1abd062a2ad0a224ae8a1d13";
   ```
2. Ask Antigravity to read it: *"Read secrets.js."*
3. Antigravity should block the read and explain that the file contains a secret.

Once you've confirmed the hook is active, delete the test file.

Run `sonar system status` to confirm the Antigravity integration reports **Secrets Hook: CONFIGURED**. If the hook entry exists but the backing script is missing or malformed, status shows **CONFIGURED / INVALID CONFIG** and recommends re-running `sonar integrate antigravity`.

### Test the MCP server

In Antigravity, ask: *"List my SonarQube projects."* Antigravity should call the SonarQube MCP server and return your project list. If it doesn't, run `sonar auth status` to confirm the underlying token is healthy and restart the session.

### Test Sonar Vortex

Vortex adds context augmentation and agentic analysis. To confirm both are working, see [Checking that Vortex works properly](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup).

## Non-interactive install

For provisioning scripts and onboarding automation, skip the interactive skill and run the SonarQube CLI directly:

```bash
sonar integrate antigravity --global --non-interactive
```

In non-interactive mode the CLI doesn't prompt. A `--global` install wires up the SonarQube MCP Server, the secrets-detection hook, and the prompt-secrets instructions, but skips the project-scoped agentic analysis instructions and context augmentation skill. When you authenticate with [Environment variables](/sonarqube-cli/using-sonarqube-cli/environment-variables), integrate commands also run in non-interactive mode even without the flag. Run `sonar auth status` afterward to confirm the integration is wired up. See [Google Antigravity](/sonarqube-cli/integrations/antigravity) in the SonarQube CLI docs for full details.

## Usage

After setup, invoke SonarQube skills in Antigravity using slash commands or natural language. Both options are shown for each skill.

### List projects

```
/sonarqube:sonar-list-projects                    # all accessible projects
/sonarqube:sonar-list-projects my-project         # search by name or key
```

Or in natural language:

* "List my SonarQube projects."
* "Search for projects with `auth` in the name."

### List issues

```
/sonarqube:sonar-list-issues                                        # issues in the current project
/sonarqube:sonar-list-issues my-project --severity CRITICAL
```

Or in natural language:

* "List the issues in `my-project`."
* "Show me critical issues in `my-project`."
* "Search issues in `my-project` on branch `main`."

### Fix an issue

```
/sonarqube:sonar-fix-issue java:S1481 src/main/java/MyClass.java
/sonarqube:sonar-fix-issue python:S2077 src/auth/login.py:34
```

Or in natural language:

* "Fix the issue `java:S1481` in `src/main/java/MyClass.java`."
* "Help me fix `python:S2077` on line 34 of `src/auth/login.py`."

### Quality gate

```
/sonarqube:sonar-quality-gate
/sonarqube:sonar-quality-gate my-project --branch main
```

Or in natural language:

* "Check the quality gate status for `my-project`."
* "Show me the quality gate for `my-project` on pull request 42."

### Analyze a file

```
/sonarqube:sonar-analyze
/sonarqube:sonar-analyze src/auth/login.py
```

Or in natural language:

* "Analyze `src/auth/login.py` for code quality and security issues."
* "Run analysis on the current file."

### Coverage

```
/sonarqube:sonar-coverage
/sonarqube:sonar-coverage my-project --max 50
/sonarqube:sonar-coverage my-project --file src/auth/login.py
```

Or in natural language:

* "What files in `my-project` have less than 50% coverage?"
* "Show me line-by-line coverage for `src/auth/login.py`."

### Duplication

```
/sonarqube:sonar-duplication
/sonarqube:sonar-duplication my-project --pr 42
/sonarqube:sonar-duplication my-project --file src/auth/login.py
```

Or in natural language:

* "Find duplicated files in `my-project`."
* "Show duplications in `my-project` on pull request 42."

### Dependency risks

Dependency risks require SonarQube Advanced Security.

```
/sonarqube:sonar-dependency-risks
/sonarqube:sonar-dependency-risks my-project --pr 42
```

Or in natural language:

* "List dependency risks in `my-project`."
* "Show me SCA issues on pull request 42."

### Security hotspots

Access security hotspots through the same `sonar-list-issues` skill:

```
/sonarqube:sonar-list-issues my-project
```

Or in natural language:

* "Search security hotspots in `my-project`."
* "Show hotspots in `my-project` that are still to review."

## Uninstall

To remove the SonarQube plugin from Antigravity, run:

```bash
agy plugin uninstall sonarqube
```

Uninstalling the plugin removes the skills, rules, and MCP wiring it registered. To also remove the underlying CLI integration files written by `sonar integrate antigravity` (the secrets-detection hook, prompt-secrets instructions, agentic analysis instructions, and context augmentation skill), see [Google Antigravity](/sonarqube-cli/integrations/antigravity) in the SonarQube CLI docs.

## Related pages

* [SonarQube CLI integration with Antigravity](/sonarqube-cli/integrations/antigravity)
* Set up the [SonarQube MCP Server in Antigravity](/sonarqube-mcp-server/setup/quickstart-guides/antigravity)


# Claude Code

Install the SonarQube plugin in Claude Code to enable code analysis, issue management, and secrets detection skills directly from your AI coding sessions.

The SonarQube plugin for Claude Code connects your AI coding agent to SonarQube's code quality and security data. Once installed and configured, Claude Code can analyze code, list and fix issues, check quality gates, inspect coverage and duplication, and run [Sonar Vortex analysis](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-analysis) through the [About the MCP Server](/sonarqube-mcp-server/about-the-mcp-server). The plugin's secrets-detection capabilities keep credentials out of your prompts and the files the agent reads or writes.

The plugin works with SonarQube Cloud or SonarQube Server.

## Features

The plugin gives Claude Code's agent access to the full set of [Tools](/sonarqube-mcp-server/reference/tools) exposed by the SonarQube MCP Server, including:

* Code analysis: analyze code snippets and files in the agent context.
* Issues: search, review, and update code issues.
* Quality gates: check the quality gate status for a project.
* Security hotspots: search and review security hotspots.
* Coverage: find under-covered files and review line-by-line coverage.
* Dependencies: check third-party dependencies for SCA issues.

Through the SonarQube CLI integration set up by `/sonarqube:sonar-integrate`, the plugin also adds:

* Secrets detection: hooks that run before the agent executes a tool or receives a prompt, keeping credentials out of the files the agent reads and out of prompts sent to Claude Code.
* Agentic Analysis (SonarQube Cloud only, project-level installs): hooks that run `sonar verify --staged` after Claude Code edits files.

It also adds SonarQube skills that you can invoke as slash commands in Claude Code. See the [Usage](#usage) article for more details.

## Prerequisites

* A SonarQube Cloud organization or SonarQube Server instance.
* Node.js, required to run the hook that checks the integration when a session starts.
* A container runtime (Docker, Podman, or nerdctl) to run the SonarQube MCP Server image.

## Install

Install the SonarQube plugin from the `claude-plugins-official` marketplace:

* From your shell, run `claude plugin install sonarqube@claude-plugins-official`.
* Or inside Claude Code, run `/plugin install sonarqube@claude-plugins-official`.

Then reload SonarQube's skills and hooks in Claude Code:

* Either restart Claude Code, or
* Run `/reload-plugins` if your version supports it.

## Configuration

After installing the plugin, finish setup by running the guided integration skill:

```
/sonarqube:sonar-integrate
```

The skill does the following:

1. Install the SonarQube CLI if not already present, or update it with `sonar self-update`.
2. Authenticate with SonarQube Cloud or your SonarQube Server instance via `sonar auth login`. Your browser opens to complete login; the token is stored in your system keychain.
3. Run `sonar integrate claude` to register the SonarQube MCP Server and install the secrets-detection hooks. On a SonarQube Cloud project install, it also sets up the agentic analysis hook and the context augmentation skill.

## Sonar Vortex: agentic analysis and context augmentation features

When you run `sonar integrate claude`, the command configures Claude to use the [What is Sonar Vortex?](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex) features. They run through the SonarQube CLI:

* Agentic analysis: a hook runs after Claude edits files and feeds findings back into the session, so Claude can fix new issues before ending the turn.
* Context augmentation: gives Claude your project's coding guidelines, dependency health, architecture, and semantic-navigation context as it works.

Both features are project-scoped and skipped on a global install. Run `sonar integrate claude --project <YourProjectKey>` from a project directory to install them, or pass `--skip-context` to opt out of context augmentation.

## Verify that it works

### Test the secrets hook

1. Create a file with a fake-looking but secret-shaped value:

   ```javascript
   // secrets.js
   const API_KEY = "sqp_1aa323ae0689cd4a1abd062a2ad0a224ae8a1d13";
   ```
2. Ask Claude to read it: *"Read secrets.js."*
3. Claude Code should block the read and explain that the file contains a secret.

Once you've confirmed the hook is active, delete the test file.

### Test the MCP server

In Claude Code, ask: *"Use the SonarQube MCP server to list my open projects."* Claude should call SonarQube and return your project list. If it doesn't, run `sonar auth status` to confirm the underlying token is healthy and restart Claude.

### Test Sonar Vortex

Vortex adds context augmentation and agentic analysis. To confirm both are working, see [Checking that Vortex works properly](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup).

## Non-interactive install

For provisioning scripts and onboarding automation, skip the interactive skill and run the SonarQube CLI directly:

```bash
sonar integrate claude --global --non-interactive
```

In non-interactive mode, the CLI doesn't prompt for confirmation or token repair. Run `sonar auth status` afterward to confirm the integration is wired up. See [Claude Code](/sonarqube-cli/integrations/claude-code) in the SonarQube CLI docs for full details.

## Usage

After setup, invoke SonarQube skills in Claude Code using explicit slash commands or natural language. Both options are shown for each skill.

### List projects

```
/sonarqube:sonar-list-projects                    # all accessible projects
/sonarqube:sonar-list-projects my-project         # search by name or key
```

Or in natural language:

* "List my SonarQube projects."
* "Search for projects with `auth` in the name."

### List issues

```
/sonarqube:sonar-list-issues                                        # issues in the current project
/sonarqube:sonar-list-issues my-project --severity CRITICAL
```

Or in natural language:

* "List the issues in `my-project`."
* "Show me critical issues in `my-project`."
* "Search issues in `my-project` on branch `main`."

### Fix an issue

```
/sonarqube:sonar-fix-issue java:S1481 src/main/java/MyClass.java
/sonarqube:sonar-fix-issue python:S2077 src/auth/login.py:34
```

Or in natural language:

* "Fix the issue `java:S1481` in `src/main/java/MyClass.java`."
* "Help me fix `python:S2077` on line 34 of `src/auth/login.py`."

### Quality gate

```
/sonarqube:sonar-quality-gate
/sonarqube:sonar-quality-gate my-project --branch main
```

Or in natural language:

* "Check the quality gate status for `my-project`."
* "Show me the quality gate for `my-project` on pull request 42."

### Analyze a file

```
/sonarqube:sonar-analyze
/sonarqube:sonar-analyze src/auth/login.py
```

Or in natural language:

* "Analyze `src/auth/login.py` for code quality and security issues."
* "Run analysis on the current file."

### Coverage

```
/sonarqube:sonar-coverage
/sonarqube:sonar-coverage my-project --max 50
/sonarqube:sonar-coverage my-project --file src/auth/login.py
```

Or in natural language:

* "What files in `my-project` have less than 50% coverage?"
* "Show me line-by-line coverage for `src/auth/login.py`."

### Duplication

```
/sonarqube:sonar-duplication
/sonarqube:sonar-duplication my-project --pr 42
/sonarqube:sonar-duplication my-project --file src/auth/login.py
```

Or in natural language:

* "Find duplicated files in `my-project`."
* "Show duplications in `my-project` on pull request 42."

### Dependency risks

Dependency risks require SonarQube Advanced Security.

```
/sonarqube:sonar-dependency-risks
/sonarqube:sonar-dependency-risks my-project --pr 42
```

Or in natural language:

* "List dependency risks in `my-project`."
* "Show me SCA issues on pull request 42."

### Security hotspots

Access security hotspots through the same `sonar-list-issues` skill:

```
/sonarqube:sonar-list-issues my-project
```

Or in natural language:

* "Search security hotspots in `my-project`."
* "Show hotspots in `my-project` that are still to review."

## Uninstall

To remove the SonarQube plugin from Claude Code:

* From your shell, run `claude plugin uninstall sonarqube`.
* Or inside Claude Code, run `/plugin` to open the **Manage plugins** window and remove the SonarQube plugin.

Uninstalling the plugin removes the SonarQube skills and hooks the plugin registered. To also remove the underlying CLI integration files written by `/sonarqube:sonar-integrate` (the SonarQube MCP server entry, secrets-detection hook configuration, state record), see [Uninstall](/sonarqube-cli/integrations/claude-code#uninstall) on the SonarQube CLI integration page.

## Related pages

* [SonarQube CLI integration with Claude Code](/sonarqube-cli/integrations/claude-code)
* Set up the [SonarQube MCP Server in Claude Code](/sonarqube-mcp-server/setup/quickstart-guides/claude-code)


# Codex CLI

Install the SonarQube plugin for the Codex CLI or Codex IDE extension to bring code analysis, issue management, and secrets detection into your AI coding sessions.

The SonarQube plugin for Codex CLI connects your AI coding agent to SonarQube's code quality and security data through the [About the MCP Server](/sonarqube-mcp-server/about-the-mcp-server). SonarQube does the analysis; Codex calls the MCP tools and acts on the results. Once installed and configured, Codex can run SonarQube analysis on your code, list and fix issues, check quality gates, inspect coverage and duplication, and run [Sonar Vortex analysis](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-analysis). The plugin also configures the SonarQube CLI to detect secrets, keeping credentials out of your prompts and the files the agent reads or writes.

The plugin works with SonarQube Cloud or SonarQube Server.

Use the plugin from both the Codex CLI and the Codex IDE extension.

## Features

The plugin gives the Codex agent access to the full set of [Tools](/sonarqube-mcp-server/reference/tools) exposed by the SonarQube MCP Server, including:

* Code analysis: analyze code snippets and files in the agent context.
* Issues: search, review, and update code issues.
* Quality gates: check the quality gate status for a project.
* Security hotspots: search and review security hotspots.
* Coverage: find under-covered files and review line-by-line coverage.
* Dependencies: check third-party dependencies for SCA issues.

Through the SonarQube CLI integration it sets up, the plugin also adds:

* Secrets detection: a hook that scans prompts for secrets before they are sent to Codex, plus secrets-on-read instructions in `.codex/AGENTS.md` that tell Codex to refuse working with exposed tokens when it reads files.
* Agentic analysis (SonarQube Cloud only, project-level installs): a hook that runs after Codex edits files.
* Context augmentation (SonarQube Cloud only, project-level installs): a skill that tells Codex to pull project guidelines before editing code, check dependencies before changing a manifest, and use SonarQube's architecture and semantic-navigation context as it works.

## Prerequisites

* A SonarQube Cloud organization or SonarQube Server instance.
* [OpenAI Codex](https://developers.openai.com/codex/) installed.
* A container runtime (Docker, Podman, or nerdctl) to run the SonarQube MCP Server image.

## Install

The SonarQube plugin is distributed through SonarSource's Codex plugin marketplace. Add that marketplace as a source in Codex, then install the plugin:

* From your shell, register the marketplace:

  ```bash
  codex plugin marketplace add SonarSource/sonarqube-agent-plugins
  ```
* Start a Codex session, run `/plugins`, search for `sonarqube`, and install it.

## Configuration

After installing the plugin, finish setup by running the guided integration skill:

```
$sonar-integrate
```

The skill does the following:

1. Install the SonarQube CLI if not already present, or update it with `sonar self-update`.
2. Authenticate with SonarQube Cloud or your SonarQube Server instance via `sonar auth login`. Your browser opens to complete login; the token is stored in your system keychain.
3. Run `sonar integrate codex`, which prompts you to install each component: the secrets-detection hook, the secrets-on-read instructions in `.codex/AGENTS.md`, the SonarQube MCP Server, and, for SonarQube Cloud project installs, the agentic analysis hook and context augmentation skill.

## Sonar Vortex: agentic analysis and context augmentation features

When you run `sonar integrate codex`, the command configures Codex to use the [What is Sonar Vortex?](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex) features. They run through the SonarQube CLI:

* Analysis: a hook runs after Codex edits files and surfaces findings inline.
* Context augmentation: gives Codex your project's coding guidelines, dependency health, architecture, and semantic-navigation context as it works.

Both features are project-scoped and skipped on a global install. Run `sonar integrate codex --project <YourProjectKey>` from a project directory to install them, or pass `--skip-context` to opt out of context augmentation.

## Verify that it works

### Test the secrets hook

1. Restart Codex so the newly installed secrets-detection hook is active.
2. Compose a prompt to Codex that contains a fake-looking but secret-shaped value:

   ```
   Here is my key: sqp_1aa323ae0689cd4a1abd062a2ad0a224ae8a1d13
   ```
3. Send the prompt.
4. Codex should block or refuse the operation and explain that the prompt contains a secret.

### Test the MCP server

In Codex, ask: *"List my SonarQube projects."* Codex should call the SonarQube MCP server and return your project list. If it doesn't, run `sonar auth status` to confirm the underlying token is healthy and restart Codex.

### Test Sonar Vortex

Vortex adds context augmentation and agentic analysis. To confirm both are working, see [Checking that Vortex works properly](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup).

## Non-interactive install

For provisioning scripts and onboarding automation, skip the interactive skill and run the SonarQube CLI directly:

```bash
sonar integrate codex --global --non-interactive
```

In non-interactive mode the CLI doesn't prompt. A `--global` install wires up the SonarQube MCP Server, the secrets-detection hook, and the secrets-on-read instructions, but skips the project-scoped agentic analysis hook and context augmentation skill. Run `sonar auth status` afterward to confirm the integration is wired up. See [OpenAI Codex](/sonarqube-cli/integrations/codex) in the SonarQube CLI docs for full details.

## Usage

After setup, invoke SonarQube skills in Codex with `$` commands or in natural language. Both options are shown for each skill.

### List projects

```
$sonar-list-projects                    # all accessible projects
$sonar-list-projects my-project         # search by name or key
```

Or in natural language:

* "List my SonarQube projects."
* "Search for projects with `auth` in the name."

### List issues

```
$sonar-list-issues                                        # issues in the current project
$sonar-list-issues my-project --severity CRITICAL
```

Or in natural language:

* "List the issues in `my-project`."
* "Show me critical issues in `my-project`."
* "Search issues in `my-project` on branch `main`."

### Fix an issue

```
$sonar-fix-issue java:S1481 src/main/java/MyClass.java
$sonar-fix-issue python:S2077 src/auth/login.py:34
```

Or in natural language:

* "Fix the issue `java:S1481` in `src/main/java/MyClass.java`."
* "Help me fix `python:S2077` on line 34 of `src/auth/login.py`."

### Quality gate

```
$sonar-quality-gate
$sonar-quality-gate my-project --branch main
```

Or in natural language:

* "Check the quality gate status for `my-project`."
* "Show me the quality gate for `my-project` on pull request 42."

### Analyze a file

```
$sonar-analyze
$sonar-analyze src/auth/login.py
```

Or in natural language:

* "Analyze `src/auth/login.py` for code quality and security issues."
* "Run analysis on the current file."

### Coverage

```
$sonar-coverage
$sonar-coverage my-project --max 50
$sonar-coverage my-project --file src/auth/login.py
```

Or in natural language:

* "What files in `my-project` have less than 50% coverage?"
* "Show me line-by-line coverage for `src/auth/login.py`."

### Duplication

```
$sonar-duplication
$sonar-duplication my-project --pr 42
$sonar-duplication my-project --file src/auth/login.py
```

Or in natural language:

* "Find duplicated files in `my-project`."
* "Show duplications in `my-project` on pull request 42."

### Dependency risks

Dependency risks require SonarQube Advanced Security.

```
$sonar-dependency-risks
$sonar-dependency-risks my-project --pr 42
```

Or in natural language:

* "List dependency risks in `my-project`."
* "Show me SCA issues on pull request 42."

### Security hotspots

Access security hotspots through the same `sonar-list-issues` skill:

```
$sonar-list-issues my-project
```

Or in natural language:

* "Search security hotspots in `my-project`."
* "Show hotspots in `my-project` that are still to review."

## Uninstall

To remove the SonarQube plugin from Codex CLI, start a Codex session, run `/plugins`, and remove the SonarQube plugin.

Uninstalling the plugin removes the skills and MCP wiring it registered. To also remove the underlying CLI integration files written by `sonar integrate codex` (the SonarQube MCP server entry, secrets-detection hook, and agentic analysis hook), see [OpenAI Codex](/sonarqube-cli/integrations/codex) in the SonarQube CLI docs.

## Related pages

* [SonarQube CLI integration with Codex](/sonarqube-cli/integrations/codex)
* Set up the [SonarQube MCP Server in Codex](/sonarqube-mcp-server/setup/quickstart-guides/codex-cli)


# Cursor

Install the SonarQube plugin in the Cursor IDE, Cursor CLI, or Agent Window to bring SonarQube code quality and security analysis, secrets detection, and agentic verification into your AI coding sessi

The SonarQube plugin for Cursor connects your AI coding agent to SonarQube's code quality and security data through the [About the MCP Server](/sonarqube-mcp-server/about-the-mcp-server). SonarQube does the analysis; Cursor calls the MCP tools and acts on the results. Once installed and configured, Cursor's agent can run SonarQube analysis on your code, list and fix issues, check quality gates, inspect coverage and duplication, and review dependency risks. Running `sonar integrate cursor` after the plugin install adds secrets detection, agentic analysis, and context augmentation.

The plugin works with SonarQube Cloud or SonarQube Server.

Use the plugin from the Cursor IDE, the Cursor CLI, and the Cursor Agent Window.

## Features

The plugin gives Cursor's agent access to the full set of [Tools](/sonarqube-mcp-server/reference/tools) exposed by the SonarQube MCP Server, including:

* Code analysis: analyze code snippets and files in the agent context.
* Issues: search, review, and update code issues.
* Quality gates: check the quality gate status for a project.
* Security hotspots: search and review security hotspots.
* Coverage: find under-covered files and review line-by-line coverage.
* Dependencies: check third-party dependencies for SCA issues.

Through the SonarQube CLI integration set up by `sonar integrate cursor`, the plugin also adds:

* Secrets detection: three hooks that keep credentials out of the files the agent reads and the prompts sent to Cursor. One hook runs before the agent uses a tool, one before it reads a file, and one when you submit a prompt.
* Agentic analysis (SonarQube Cloud only, project-level installs): an always-applied rule that runs after Cursor edits files.
* Context augmentation (SonarQube Cloud only, project-level installs): a skill that tells Cursor to pull project guidelines before editing code, check dependencies before changing a manifest, and use SonarQube's architecture and semantic-navigation context as it works.

It also adds SonarQube skills that you can invoke as slash commands in Cursor's chat. See [Usage](#usage).

## Prerequisites

* A SonarQube Cloud organization or SonarQube Server instance.
* [Cursor](https://cursor.com/) installed.
* The SonarQube CLI installed. The plugin's MCP Server uses your `sonar auth login` session.
* A container runtime (Docker, Podman, or nerdctl) to run the SonarQube MCP Server image.

## Install

The SonarQube plugin is published in the `sonar` marketplace catalog on the [Cursor marketplace](https://cursor.com/marketplace/sonarsource), sourced from the [SonarSource/sonarqube-agent-plugins](https://github.com/SonarSource/sonarqube-agent-plugins) repository.

In Cursor's chat, install the plugin:

```
/add-plugin sonarqube
```

You can also install it from Cursor's marketplace panel. For more on plugin marketplaces and installation, see Cursor's [Plugins documentation](https://cursor.com/docs/plugins).

## Configuration

After installing the plugin, finish setup in two steps.

### Step 1 — Authenticate

Log in so the MCP Server can connect:

```bash
sonar auth login
```

Use the command for your scenario:

| Scenario             | Command                                                             |
| -------------------- | ------------------------------------------------------------------- |
| SonarQube Cloud (EU) | `sonar auth login -o <YourOrganizationKey>`                         |
| SonarQube Cloud (US) | `sonar auth login -o <YourOrganizationKey> -s https://sonarqube.us` |
| SonarQube Server     | `sonar auth login -s <YourServerURL>`                               |

Your browser opens to complete login, and the token is stored in your system keychain. Check your authentication anytime with `sonar auth status`.

### Step 2—Install secrets hooks, agentic analysis, and context augmentation

Run the integration command from your project directory:

```bash
sonar integrate cursor
```

In an interactive terminal, the command prompts you to install each component: secrets-detection hooks, the SonarQube MCP server configuration, and, for SonarQube Cloud project installs, the agentic analysis rule and the context augmentation skill.

Use `--global` to install the secrets hooks for all projects on your machine:

```bash
sonar integrate cursor --global
```

> **Note:** Cursor's cloud and background agents only pick up project-level hooks, not global ones. A global install wires up the secrets hooks and skips agentic analysis and context augmentation.

## Sonar Vortex: agentic analysis and context augmentation features

When you run `sonar integrate cursor`, the command configures Cursor to use the [What is Sonar Vortex?](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex) features. They run through the SonarQube CLI:

* Agentic analysis: an always-applied rule runs after Cursor edits files.
* Context augmentation: gives Cursor your project's coding guidelines, dependency health, architecture, and semantic-navigation context as it works.

Both features are project-scoped and skipped on a global install. Run `sonar integrate cursor --project <YourProjectKey>` from a project directory to install them, or pass `--skip-context` to opt out of context augmentation.

## Verify that it works

### Test the secrets hook

1. Create a file with a fake-looking but secret-shaped value:

   ```javascript
   // secrets.js
   const API_KEY = "sqp_1aa323ae0689cd4a1abd062a2ad0a224ae8a1d13";
   ```
2. Ask Cursor's agent to read it: *"Read secrets.js."*
3. Cursor should block the read and explain that the file contains a secret.

Once you've confirmed the hook is active, delete the test file.

### Test the MCP server

In Cursor's chat, ask: *"List my SonarQube projects."* Cursor should call the SonarQube MCP server and return your project list. If it doesn't, open Cursor Settings → MCP, confirm the sonarqube entry is enabled, then run `sonar auth status` to confirm the underlying token is healthy and restart Cursor.

### Test Sonar Vortex

Vortex adds context augmentation and agentic analysis. To confirm both are working, see [Checking that Vortex works properly](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup).

## Non-interactive install

For provisioning scripts and onboarding automation, skip the interactive prompts and run the SonarQube CLI directly:

```bash
sonar integrate cursor --global --non-interactive
```

In non-interactive mode the CLI doesn't prompt. A `--global` install wires up the SonarQube MCP Server and the secrets-detection hooks, but skips the project-scoped agentic analysis rule and context augmentation skill. Run `sonar auth status` afterward to confirm the integration is wired up. See [Cursor](/sonarqube-cli/integrations/cursor) in the SonarQube CLI docs for full details.

## Usage

After setup, invoke SonarQube skills in Cursor using slash commands or natural language. Both options are shown for each skill.

### List projects

```
/sonar-list-projects                    # all accessible projects
/sonar-list-projects my-project         # search by name or key
```

Or in natural language:

* "List my SonarQube projects."
* "Search for projects with `auth` in the name."

### List issues

```
/sonar-list-issues                                        # issues in the current project
/sonar-list-issues my-project --severity CRITICAL
```

Or in natural language:

* "List the issues in `my-project`."
* "Show me critical issues in `my-project`."
* "Search issues in `my-project` on branch `main`."

### Fix an issue

```
/sonar-fix-issue java:S1481 src/main/java/MyClass.java
/sonar-fix-issue python:S2077 src/auth/login.py:34
```

Or in natural language:

* "Fix the issue `java:S1481` in `src/main/java/MyClass.java`."
* "Help me fix `python:S2077` on line 34 of `src/auth/login.py`."

### Quality gate

```
/sonar-quality-gate
/sonar-quality-gate my-project --branch main
```

Or in natural language:

* "Check the quality gate status for `my-project`."
* "Show me the quality gate for `my-project` on pull request 42."

### Analyze a file

```
/sonar-analyze
/sonar-analyze src/auth/login.py
```

Or in natural language:

* "Analyze `src/auth/login.py` for code quality and security issues."
* "Run analysis on the current file."

### Coverage

```
/sonar-coverage
/sonar-coverage my-project --max 50
/sonar-coverage my-project --file src/auth/login.py
```

Or in natural language:

* "What files in `my-project` have less than 50% coverage?"
* "Show me line-by-line coverage for `src/auth/login.py`."

### Duplication

```
/sonar-duplication
/sonar-duplication my-project --pr 42
/sonar-duplication my-project --file src/auth/login.py
```

Or in natural language:

* "Find duplicated files in `my-project`."
* "Show duplications in `my-project` on pull request 42."

### Dependency risks

Dependency risks require SonarQube Advanced Security.

```
/sonar-dependency-risks
/sonar-dependency-risks my-project --pr 42
```

Or in natural language:

* "List dependency risks in `my-project`."
* "Show me SCA issues on pull request 42."

### Security hotspots

Access security hotspots through the same `sonar-list-issues` skill:

```
/sonar-list-issues my-project
```

Or in natural language:

* "Search security hotspots in `my-project`."
* "Show hotspots in `my-project` that are still to review."

For the full reference of what the agent can call, see the [Tools](/sonarqube-mcp-server/reference/tools) page.

## Manual MCP setup

If you prefer to configure the MCP Server directly in Cursor's `mcp.json` instead of installing the plugin, for example to use HTTPS transport or the SonarQube Cloud-hosted server, see the [Cursor](/sonarqube-mcp-server/setup/quickstart-guides/cursor).

## Uninstall

To remove the SonarQube plugin from Cursor, open Cursor's plugins panel and remove the SonarQube plugin. For details, see Cursor's [Plugins documentation](https://cursor.com/docs/plugins).

Uninstalling the plugin removes the skills and MCP wiring it registered. To also remove the underlying CLI integration files written by `sonar integrate cursor` (the secrets-detection hooks, agentic analysis rule, and context augmentation skill), see [Cursor](/sonarqube-cli/integrations/cursor) in the SonarQube CLI docs.

## Related pages

* [SonarQube CLI integration with Cursor](/sonarqube-cli/integrations/cursor)
* Set up the [SonarQube MCP Server in Cursor](/sonarqube-mcp-server/setup/quickstart-guides/cursor)


# GitHub Copilot CLI

Install the SonarQube plugin in GitHub Copilot CLI to bring SonarQube code quality and security analysis into your AI coding sessions, powered by the SonarQube MCP Server.

The SonarQube plugin for GitHub Copilot CLI connects your AI coding agent to SonarQube's code quality and security data. Once installed and configured, Copilot CLI can analyze code, list and fix issues, check quality gates, inspect coverage and duplication, and run [Sonar Vortex analysis](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-analysis) through the SonarQube CLI. The plugin's secrets-detection capabilities keep credentials out of your prompts and the files the agent reads or writes.

The plugin works with SonarQube Cloud or SonarQube Server.

This page covers the GitHub Copilot CLI terminal agent. For GitHub Copilot Chat in VS Code, see [GitHub Copilot in VS Code](#github-copilot-in-vs-code).

## Features

The plugin gives the Copilot CLI agent access to the full set of [Tools](/sonarqube-mcp-server/reference/tools) exposed by the SonarQube MCP Server, including:

* Code analysis: analyze code snippets and files in the agent context.
* Issues: search, review, and update code issues.
* Quality gates: check the quality gate status for a project.
* Security hotspots: search and review security hotspots.
* Coverage: find under-covered files and review line-by-line coverage.
* Dependencies: check third-party dependencies for SCA issues.

The plugin also installs:

* Secrets detection: a secrets detection hook that blocks Copilot CLI from reading or writing files containing exposed credentials. The plugin also installs custom instructions that tell the agent to refuse working with exposed tokens, since GitHub Copilot CLI doesn't currently support a prompt-time hook.
* Agentic analysis (SonarQube Cloud only, project-level installs): instructions that tell Copilot CLI to verify the files it edits.
* Context augmentation (SonarQube Cloud only, project-level installs): a skill that tells Copilot CLI to pull project guidelines before editing code, check dependencies before changing a manifest, and use SonarQube's architecture and semantic-navigation context as it works.

## Prerequisites

* A SonarQube Cloud organization or SonarQube Server instance.
* A container runtime (Docker, Podman, or nerdctl) to run the SonarQube MCP Server image.

## Install

Install the SonarQube plugin from the `awesome-copilot` marketplace, which is registered by default in GitHub Copilot CLI:

* From your shell, run `copilot plugin install sonarqube@awesome-copilot`.
* Or inside an interactive Copilot CLI session, run `/plugin install sonarqube@awesome-copilot`.

For details on plugin marketplaces and installation, see [Finding and installing plugins for GitHub Copilot CLI](https://docs.github.com/en/copilot/how-tos/copilot-cli/customize-copilot/plugins-finding-installing).

## Configuration

After installing the plugin, finish setup by running the guided integration skill:

```
/sonar-integrate
```

The skill does the following:

1. Install the SonarQube CLI if not already present, or update it with `sonar self-update`.
2. Authenticate with SonarQube Cloud or your SonarQube Server instance via `sonar auth login`. Your browser opens to complete login; the token is stored in your system keychain.
3. Run `sonar integrate copilot`, which prompts you to install each component: the secrets-detection hook, the prompt-secrets instructions, the SonarQube MCP Server, and, for SonarQube Cloud project installs, the agentic analysis instructions and context augmentation skill.

## Sonar Vortex: agentic analysis and context augmentation features

When you run `sonar integrate copilot`, the command configures Copilot CLI to use the [What is Sonar Vortex?](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex) features. They run through the SonarQube CLI:

* Agentic analysis: instructions tell Copilot CLI to check the files it edits and return any findings in its response. Unlike the Claude Code and Codex hooks, Copilot CLI can't inject findings back into the conversation.
* Context augmentation: gives Copilot CLI your project's coding guidelines, dependency health, architecture, and semantic-navigation context as it works.

Both features are project-scoped and skipped on a global install. Run `sonar integrate copilot --project <YourProjectKey>` from a project directory to install them, or pass `--skip-context` to opt out of context augmentation.

## Verify that it works

### Test the secrets hook

1. Create a file with a fake-looking but secret-shaped value:

   ```javascript
   // secrets.js
   const API_KEY = "sqp_1aa323ae0689cd4a1abd062a2ad0a224ae8a1d13";
   ```
2. Ask Copilot CLI to read it: *"Read secrets.js."*
3. Copilot CLI should block the read and explain that the file contains a secret.

Once you've confirmed the hook is active, delete the test file.

### Test the MCP server

Ask Copilot CLI to list your SonarQube projects via the MCP server. If the call fails, run `sonar auth status` to confirm the underlying token is healthy and restart Copilot CLI.

### Test Sonar Vortex

Vortex adds context augmentation and agentic analysis. To confirm both are working, see [Checking that Vortex works properly](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup).

## Non-interactive install

For provisioning scripts and onboarding automation, skip the interactive skill and run the SonarQube CLI directly:

```bash
sonar integrate copilot --global --non-interactive
```

In non-interactive mode the CLI does not prompt. A `--global` install wires up the SonarQube MCP Server and the secrets-detection hook, but skips the project-scoped agentic analysis instructions and context augmentation skill. Run `sonar auth status` afterward to confirm the integration is wired up. See [GitHub Copilot CLI](/sonarqube-cli/integrations/github-copilot-cli) in the SonarQube CLI docs for full details.

## Usage

After setup, invoke SonarQube skills in GitHub Copilot CLI using slash commands or natural language. Both options are shown for each skill.

### List projects

```
/sonar-list-projects                    # all accessible projects
/sonar-list-projects my-project         # search by name or key
```

Or in natural language:

* "List my SonarQube projects."
* "Search for projects with `auth` in the name."

### List issues

```
/sonar-list-issues                                        # issues in the current project
/sonar-list-issues my-project --severity CRITICAL
```

Or in natural language:

* "List the issues in `my-project`."
* "Show me critical issues in `my-project`."
* "Search issues in `my-project` on branch `main`."

### Fix an issue

```
/sonar-fix-issue java:S1481 src/main/java/MyClass.java
/sonar-fix-issue python:S2077 src/auth/login.py:34
```

Or in natural language:

* "Fix the issue `java:S1481` in `src/main/java/MyClass.java`."
* "Help me fix `python:S2077` on line 34 of `src/auth/login.py`."

### Quality gate

```
/sonar-quality-gate
/sonar-quality-gate my-project --branch main
```

Or in natural language:

* "Check the quality gate status for `my-project`."
* "Show me the quality gate for `my-project` on pull request 42."

### Analyze a file

```
/sonar-analyze
/sonar-analyze src/auth/login.py
```

Or in natural language:

* "Analyze `src/auth/login.py` for code quality and security issues."
* "Run analysis on the current file."

### Coverage

```
/sonar-coverage
/sonar-coverage my-project --max 50
/sonar-coverage my-project --file src/auth/login.py
```

Or in natural language:

* "What files in `my-project` have less than 50% coverage?"
* "Show me line-by-line coverage for `src/auth/login.py`."

### Duplication

```
/sonar-duplication
/sonar-duplication my-project --pr 42
/sonar-duplication my-project --file src/auth/login.py
```

Or in natural language:

* "Find duplicated files in `my-project`."
* "Show duplications in `my-project` on pull request 42."

### Dependency risks

Dependency risks require SonarQube Advanced Security.

```
/sonar-dependency-risks
/sonar-dependency-risks my-project --pr 42
```

Or in natural language:

* "List dependency risks in `my-project`."
* "Show me SCA issues on pull request 42."

### Security hotspots

Security hotspots are surfaced through the same `sonar-list-issues` skill:

```
/sonar-list-issues my-project
```

Or in natural language:

* "Search security hotspots in `my-project`."
* "Show hotspots in `my-project` that are still to review."

For the full reference of what the agent can call, see the [Tools](/sonarqube-mcp-server/reference/tools) page.

## Uninstall

To remove the SonarQube plugin from GitHub Copilot CLI:

* From your shell, run `copilot plugin uninstall sonarqube`.
* Or inside an interactive Copilot CLI session, run `/plugin uninstall sonarqube`.

Uninstalling the plugin removes the MCP wiring the plugin registered with Copilot CLI. To also remove the underlying CLI integration files written by the `sonar-integrate` skill (the SonarQube MCP server entry, state record), see [Uninstall](/sonarqube-cli/integrations/github-copilot-cli#uninstall) on the SonarQube CLI integration page.

## GitHub Copilot in VS Code

GitHub Copilot Chat in VS Code is a separate product from GitHub Copilot CLI. The GitHub Copilot Chat extension runs inside VS Code and integrates directly with the SonarQube VS Code extension, with no plugin installation, MCP server, or Docker required. For the full SonarQube MCP Server integration with Copilot in Agent mode, see [VS Code with GitHub Copilot](/sonarqube-mcp-server/setup/quickstart-guides/vs-code) in the MCP Server docs.

The SonarQube VS Code extension exposes Copilot tools that give Copilot Chat per-file diagnostic access in agent mode:

* `#sonarqube_analyzeFile`: analyze a file for code quality and security issues
* `#sonarqube_getPotentialSecurityIssues`: list security issues and taint vulnerabilities in a file
* `#sonarqube_setUpConnectedMode`: guided connected mode setup with SonarQube Server or Cloud
* `#sonarqube_excludeFiles`: exclude files and folders from analysis

To add instruction-file-based guidance on top of these tools (secrets scanning rules, issue querying, and SonarQube CLI commands), run `sonar integrate copilot` inside your project. This generates instruction files similar to those installed by the SonarQube plugin for GitHub Copilot CLI. Note that the [pre-tool secrets-scanning hook](/sonarqube-cli/analysis/secrets-detection) does not fire in Copilot Chat; it is wired for the Copilot CLI terminal agent only.

More information about using the [AI agents](/sonarqube-for-vs-code/ai-capabilities/agents#github-copilot) is available in the SonarQube for VS Code documentation.

## Related pages

* [SonarQube CLI integration with GitHub Copilot CLI](/sonarqube-cli/integrations/github-copilot-cli)
* Set up the [SonarQube MCP Server in GitHub Copilot CLI](/sonarqube-mcp-server/setup/quickstart-guides/github-copilot-cli)


# Kiro

Install the SonarQube Power in Kiro to bring SonarQube code quality and security analysis into your AI coding sessions.

The SonarQube Power for Kiro connects Amazon's AI coding IDE to SonarQube's code quality and security data through the [About the MCP Server](/sonarqube-mcp-server/about-the-mcp-server). SonarQube does the analysis; Kiro calls the MCP tools and acts on the results. Once installed and configured, Kiro's agent can run SonarQube analysis on code snippets, retrieve information about issues, check quality gates, fetch coverage and duplication information, pull dependency risks, and synchronize project context for better-informed code changes.

The Power works with SonarQube Cloud or SonarQube Server.

## Features

The Power gives Kiro's agent access to the full set of [Tools](/sonarqube-mcp-server/reference/tools) exposed by the SonarQube MCP Server, including:

* Code analysis: analyze code snippets and files in the agent context.
* Issues: search, review, and update code issues.
* Quality gates: check the quality gate status for a project.
* Security hotspots: search and review security hotspots.
* Coverage: find under-covered files and review line-by-line coverage.
* Dependencies: check third-party dependencies for SCA issues.

> **Note:** The Kiro Power doesn't install hooks, so secrets detection, agentic analysis, and context augmentation aren't configured automatically. You can still access each one:
>
> * **Secrets detection**: Secrets detection is built into the SonarQube CLI. After installing the CLI as directed during Power setup, run `sonar analyze secrets <path>` from your terminal.
> * **Agentic analysis**: Available through the SonarQube MCP Server with the `analysis` toolset enabled. See [Vortex with the MCP server](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/install-vortex-with-mcp#step-2-add-or-edit-your-mcp-configuration-file) for toolset setup steps.
> * **Context augmentation**: Requires a local MCP Server running in a container runtime with a volume mount and the `cag` toolset. See [Vortex with the MCP server](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/install-vortex-with-mcp#step-2-add-or-edit-your-mcp-configuration-file) for toolset setup steps.

## Prerequisites

* A SonarQube Cloud organization or SonarQube Server instance.
* [Kiro](https://kiro.dev/) installed.
* The SonarQube CLI. Kiro will guide you through the installation as part of your Power setup. The MCP Server uses your `sonar auth login` session to connect.

## Install

The SonarQube Power is published on the [Kiro Powers marketplace](https://kiro.dev/powers/). Find **SonarQube** and click **Add to Kiro** — the MCP Server configuration is applied automatically.

## Configuration

Log in so the MCP Server can connect:

```bash
sonar auth login
```

Use the command for your scenario:

| Scenario             | Command                                                             |
| -------------------- | ------------------------------------------------------------------- |
| SonarQube Cloud (EU) | `sonar auth login -o <YourOrganizationKey>`                         |
| SonarQube Cloud (US) | `sonar auth login -o <YourOrganizationKey> -s https://sonarqube.us` |
| SonarQube Server     | `sonar auth login -s <YourServerURL>`                               |

Your browser opens to complete login, and the token is stored in your system keychain. Check your authentication anytime with `sonar auth status`.

## Verify that it works

In Kiro's chat, ask: *"List my SonarQube projects."* Kiro should call the SonarQube MCP Server and return your project list. If it doesn't, check Kiro's MCP settings to confirm the SonarQube Power is enabled, then run `sonar auth status` to confirm the underlying token is healthy and restart Kiro.

### Test Sonar Vortex

Vortex adds context augmentation and agentic analysis. To confirm both are working, see [Checking that Vortex works properly](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/check-vortex-setup).

## Related pages

* [Kiro Powers marketplace](https://kiro.dev/powers/)
* [SonarQube MCP Server in Kiro](/sonarqube-mcp-server/setup/quickstart-guides/kiro)
* [Sonar Vortex context](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-context)
* [Sonar Vortex analysis](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-analysis)
* [Vortex for Kiro](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/how-to-guides/install-vortex-kiro)


# Homepage

SonarQube Cloud is a fully managed SaaS code analysis solution for 40+ languages, delivering real-time security verification to reduce outages, improve security, and lower risk.

### What is SonarQube?

The SonarQube platform delivers automated code quality and security analysis for modern development teams. Designed to seamlessly integrate with your CI/CD pipelines and DevOps tooling, it continuously reviews your source code to uncover bugs, security vulnerabilities, security hotspots, code smells, and architecture issues before code is merged or released. With broad support for [40+ programming languages and frameworks](/sonarqube-cloud/discovering-sonarcloud/overview), SonarQube empowers developers and organizations to uphold high standards of code health across web, mobile, embedded, and cloud-native apps. It’s trusted by more than 7 million developers, underscoring its industry leadership as a critical solution for secure, maintainable, and high-quality software development.

Customers can choose between two delivery methods for SonarQube: [SonarQube Cloud](https://docs.sonarsource.com/sonarqube-cloud/), the cloud-based, software-as-a-service (SaaS) offering or [SonarQube Server](https://docs.sonarsource.com/sonarqube-server/2026.1/), the a self-managed, self-hosted server side solution.

\
The SonarQube platform also includes an IDE plugin, [SonarQube for IDE](https://docs.sonarsource.com/sonarqube-for-vs-code/), that brings real-time static analysis, quick-fix guidance, and security issue detection directly into your coding editor.

Additionally, you can explore featured public projects on SonarQube Cloud and experience how other organizations leverage the platform to improve their code. See [Retrieving your organizations](/sonarqube-cloud/getting-started/viewing-organizations#free-organization).

## Achieving high quality code <a href="#achieving-high-quality-code" id="achieving-high-quality-code"></a>

SonarQube sets high standards for all code — ensuring software is secure, reliable, and maintainable. This applies across all code types: source code, test code, infrastructure as code, glue code, scripts, and AI-generated code.

All new code, whether written by a developer or generated by an AI agent, should meet the same quality and security standards. SonarQube achieves this by providing automated code verification that surfaces bugs, vulnerabilities, and maintainability issues in real time, before code is merged or released. This helps teams maintain consistent standards across the entire codebase — and is the foundation for high-performance software engineering.

SonarQube Cloud comes with a built-in quality profile designed for each supported language, called the Sonar way profile. The Sonar way activates a set of rules applicable to most projects and is a starting point for implementing good practices across your organization.

## The SonarQube solution <a href="#the-sonarqube-solution" id="the-sonarqube-solution"></a>

SonarQube is designed to help you achieve a state of high quality, verified code at every stage of development. By linking SonarQube for IDE with SonarQube Cloud or SonarQube Server, automated code analysis runs continuously across the development lifecycle. We call this the SonarQube solution. Your project settings, new code definitions, and quality profiles managed in SonarQube Cloud are applied locally to an analysis in the IDE.

* [SonarQube for IDE](https://docs.sonarsource.com/sonarqube-for-vs-code/) brings automated code verification directly into your development environment, surfacing issues as you write — whether authored by a developer or generated by an AI tool — so problems are caught before code is even committed.
* Then, [SonarQube Server](/sonarqube-server/2025.4/analyzing-source-code/pull-request-analysis) and [SonarQube Cloud](/sonarqube-cloud/analyzing-source-code/pull-request-analysis) deliver powerful static analysis by reviewing each pull request before it’s merged. This adds an essential verification layer, ensuring code quality and preventing issues from entering your codebase.
* Finally, [SonarQube Server](/sonarqube-server/2026.1/quality-standards-administration) and [SonarQube Cloud](/sonarqube-cloud/standards) integrate into your CI/CD pipeline, analyzing code on every build. Using quality profiles and quality gates, they automatically block code with issues from reaching production — ensuring only secure, reliable, and maintainable code makes it through.

The SonarQube solution embodies a clear methodology: Guide your AI tools and developers with the right standards, verify every line of code automatically, and solve issues at the source before they compound. Focusing on quality and verification at the point of creation ensures your codebase improves incrementally over time.

## Connected Mode <a href="#connected-mode" id="connected-mode"></a>

Connected mode joins SonarQube Cloud with SonarQube for IDE to deliver the full SonarQube solution. While in connected mode, SonarQube Cloud sends notifications to SonarQube for IDE when a quality gate changes or a new issue is assigned to the user. Smart notifications can be enabled or disabled from the SonarQube for IDE UI while creating or editing the connection settings. In addition, SonarQube for IDE helps the engineer focus on writing high quality code by using the new code definition on the server.

Be sure to check out all of the [SonarQube for IDE](/sonarqube-cloud/analyzing-source-code/connected-mode#connected-mode-benefits).

## Getting started <a href="#getting-started" id="getting-started"></a>

Now that you’ve heard about how [SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/cloud/) can help you verify and ship secure, reliable code, you are ready to try out SonarQube Cloud for yourself. After signing up for SonarQube Cloud using the login from your DevOps platform account (see [Signing up and onboarding](/sonarqube-cloud/getting-started/sign-up)), you can import your organizations and repositories to set up a [first analysis](/sonarqube-cloud/getting-started/first-analysis).

The [CI-based analysis](/sonarqube-cloud/analyzing-source-code/ci-based-analysis) pages explain how to connect your scanner to your CI pipeline and provides instructions for analyzing your project’s branches and pull requests.

Here's a page with everything you need to learn [What SonarQube Cloud can do](/sonarqube-cloud/discovering-sonarcloud/what-sonarcloud-can-do).

## Learn more <a href="#learn-more" id="learn-more"></a>

Check out the entire suite of Sonar products on the main website: [SonarQube Server](https://www.sonarsource.com/products/sonarqube/), [SonarQube Cloud](https://www.sonarsource.com/products/sonarqube/cloud/), and [SonarQube for IDE](https://www.sonarsource.com/products/sonarqube/ide/).

Then, have a look at how to fix issues detected by SonarQube for [IntelliJ](/sonarqube-for-intellij/using/fixing-issues), [Visual Studio](/sonarqube-for-visual-studio/using/fixing-issues), [VS Code](/sonarqube-for-vs-code/using/fixing-issues), and [Eclipse](/sonarqube-for-eclipse/using/fixing-issues) when combined with managing your code issues in [SonarQube Server](/sonarqube-server/2025.4/user-guide/issues/introduction) and [SonarQube Cloud](/sonarqube-cloud/managing-your-projects/issues/introduction) for static code analysis.

### More getting started resources <a href="#more-getting-started-resources" id="more-getting-started-resources"></a>

* [Signing up and onboarding](/sonarqube-cloud/getting-started/sign-up)
* [Automatic analysis](/sonarqube-cloud/analyzing-source-code/automatic-analysis) and [CI-based analysis](/sonarqube-cloud/analyzing-source-code/ci-based-analysis)
* [Managing quality profiles](/sonarqube-cloud/standards/managing-quality-profiles)
* [Managing portfolios](/sonarqube-cloud/managing-portfolios)

And if you need help, visit our [online community](https://community.sonarsource.com/c/sc/9) to search for answers and reach out with questions!


# AI capabilities

SonarQube Cloud offers a series of AI capabilities to help you produce secure and maintainable code.

SonarQube Cloud comes with a set of AI capabilities that fit in the Agent Centric Development Cycle (AC/DC), a framework that defines a continuous 3-stage loop for every AI-assisted change:

**Guide → Verify → Solve**

* **Guide** provides project context to agents before they write or edit code.
* **Verify** analyzes the resulting code.
* **Solve** fixes issues found during verification.

To learn more about AC/DC and how SonarQube Cloud features fit in the cycle, see [Agent Centric Development Cycle](https://docs.sonarsource.com/agent-centric-development-cycle/).

## AI CodeFix

SonarQube's AI CodeFix uses a large language model (LLM) to suggest fixes for issues found during analysis, the Solve stage of the AC/DC cycle. An Organization Admin enables the feature for the organization's projects.

To turn it on, see the [Enable AI CodeFix](/sonarqube-cloud/administering-sonarcloud/ai-features/enable-ai-codefix) page. To learn how to get fix suggestions for your issues, see the [Fixing issues](/sonarqube-cloud/managing-your-projects/issues/fixing#getting-ai-generated-fix-suggestions) article.

## SonarQube MCP Server

The [SonarQube MCP Server](https://docs.sonarsource.com/sonarqube-mcp-server/) is a [Model Context Protocol](https://modelcontextprotocol.io/introduction) (MCP) server that connects your AI coding agent to SonarQube Cloud. Once connected, your agent can retrieve issue data, project quality status, and more.

SonarQube Cloud includes a hosted MCP server with no local setup required. See the [SonarQube Cloud-hosted](/sonarqube-mcp-server/setup/sonarqube-cloud-hosted) page for setup instructions.

For step-by-step agent setup, see the [IDE/CLI quickstart guides](/sonarqube-mcp-server/setup/quickstart-guides) for the MCP server.

## Related products

[Gitar](https://gitar.ai) is a separate Sonar product that provides AI-powered pull request review automation. Gitar posts review comments directly in your pull requests to help you catch issues earlier in the development cycle.


# Advanced Security

SonarQube Advanced Security extends SonarQube’s capabilities by offering deeper security analysis and features such as Software Composition Analysis (SCA).

*The Advanced Security product is available starting with the Team plan.* See the [Signing up for a plan or product](/sonarqube-cloud/administering-sonarcloud/managing-subscription/signing-up-for-plan#advanced-security) article for signup instructions.

{% content-ref url="/pages/fUlk1Rv2eMt5aP8NVyQw" %}
[Introduction](/sonarqube-cloud/advanced-security/introduction)
{% endcontent-ref %}

{% content-ref url="/pages/Or5ua04ZwEOqm0Vv2eKK" %}
[Analyzing projects for dependencies (SCA)](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca)
{% endcontent-ref %}

{% content-ref url="/pages/8K3874C8xwLRi4l9oASv" %}
[Viewing dependencies](/sonarqube-cloud/advanced-security/viewing-dependencies)
{% endcontent-ref %}

{% content-ref url="/pages/01fNk6sBYZ8kFTHcT7eV" %}
[Reviewing and fixing dependency risks](/sonarqube-cloud/advanced-security/reviewing-and-fixing-dependency-risks)
{% endcontent-ref %}

{% content-ref url="/pages/CJQHUJFh9WYU3vQkg6mT" %}
[Managing license profiles and policies](/sonarqube-cloud/advanced-security/managing-license-profiles-and-policies)
{% endcontent-ref %}

{% content-ref url="/pages/6gUaUf1EfMswBreCOS8c" %}
[Troubleshooting the dependency analysis](/sonarqube-cloud/advanced-security/troubleshooting-the-dependency-analysis)
{% endcontent-ref %}

{% content-ref url="/pages/mh8oGPU2ZAhz5S3zNmi4" %}
[Best practices for managing dependency risks](/sonarqube-cloud/advanced-security/best-practices-for-managing-dependency-risks)
{% endcontent-ref %}


# Introduction

An introduction to SonarQube Advanced Security.

## Overview <a href="#overview" id="overview"></a>

SonarQube Advanced Security extends SonarQube’s capabilities by offering deeper security analysis and compliance-focused features such as Software Composition Analysis (SCA) and advanced SAST.

Designed for organizations that require enterprise-grade application security, it helps developers detect vulnerabilities and risks in open source code early in the software development lifecycle.

Advanced Security is a product that requires a separate subscription to your SonarQube Cloud's [plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features).

*The Advanced Security product is available starting with the Team plan.* See the [Signing up for a plan or product](/sonarqube-cloud/administering-sonarcloud/managing-subscription/signing-up-for-plan#advanced-security) article for signup instructions.

## Software Composition Analysis (SCA) <a href="#sca" id="sca"></a>

SonarQube can identify your open source dependencies and discover issues with them, ensuring security and compliance.

* **Vulnerability identification**: Track, manage, and mitigate vulnerabilities in publicly available third-party dependencies, such as vulnerabilities tracked by the CVE (Common Vulnerabilities and Exposures) project.
* **Malicious package discovery**: Protect against malware compromise by checking your dependencies against known malicious packages.
* **License management**: Ensure projects follow your organization’s policies for allowed software licenses.
* **Software Bills of Materials (SBOM)**: Export an inventory that helps understand, manage, and report on your dependency usage.

The analysis results appear in the **Dependency Risks** and **Dependencies** sections of projects and portfolios. The **Dependencies** tab's location differs if you are in a project or portfolio.

For more information, see [Analyzing projects for dependencies (SCA)](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca).

### Data sources

Sonar uses the following sources of vulnerability data:

* [NIST National Vulnerability Database](https://nvd.nist.gov/)
* [OSV](https://osv.dev), including [OpenSSF Malicious Packages](https://github.com/ossf/malicious-packages)
* [Exploit Prediction Scoring System (EPSS)](https://www.first.org/epss/)
* [CISA Known Exploited Vulnerabilities (KEV)](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)

The Sonar service accesses these sites regularly to get the latest updates, and supplements it with manual research as well as insights from open source maintainers. All data sources are checked, at minimum, hourly.

Sonar uses license data from upstream package managers and source repositories, and supplements it with manual research.

## Advanced SAST <a href="#advanced-sast" id="advanced-sast"></a>

SonarQube Cloud is a Static Application Security Testing (SAST) tool. It examines your project's source code, without executing it, allowing you to find vulnerabilities before they enter your codebase.

The categories of issue types detected through SAST include SQL injection, cross-site scripting, deserialization, secret detection, and more.

[Advanced SAST](https://www.sonarsource.com/solutions/security/sast/) extends code analysis and scanning to cover the unknown parts of the code that are in the open-source dependencies. It helps you identify deeper and more complex vulnerabilities due to the interaction of your application code with third-party (open-source) code.

Advanced SAST is available for the following languages:

* Java
* C# / .NET
* Python

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Viewing dependencies](/sonarqube-cloud/advanced-security/viewing-dependencies)
* [Reviewing and fixing dependency risks](/sonarqube-cloud/advanced-security/reviewing-and-fixing-dependency-risks)
* [Analyzing projects for dependencies](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca)
* [Managing license profiles and policies](/sonarqube-cloud/advanced-security/managing-license-profiles-and-policies)
* [Troubleshooting](/sonarqube-cloud/advanced-security/troubleshooting-the-dependency-analysis)
* [Best practices for managing dependency risks](/sonarqube-cloud/advanced-security/best-practices-for-managing-dependency-risks)
* [Cyber Resilience Act capability mapping](https://docs.sonarsource.com/cyber-resilience-act)

## Related online courses

* <i class="fa-desktop">:desktop:</i> [Introducing SCA: How is modern software built today?](https://www.sonarsource.com/learn/course/advanced-security/edb09c7e-54b0-4c7d-a66e-08bdd57e2fc5/introducing-sca-how-is-modern-software-built-today)
* <i class="fa-desktop">:desktop:</i> [How does SCA work in SonarQube Advanced Security?](https://www.sonarsource.com/learn/course/advanced-security/58f074f4-e16e-4fda-9465-8f6132a9d493/how-does-sca-work-in-sonarqube-advanced-security)


# Analyzing projects for dependencies (SCA)

SonarQube Cloud can analyze your projects for dependencies and identify dependency risks. You can also import SBOM files to analyze containers.

Advanced Security is a product that requires a separate subscription to your [SonarQube Cloud's plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features).

*The Advanced Security product is available starting with the Team plan.* See the [Signing up for a plan or product](/sonarqube-cloud/administering-sonarcloud/managing-subscription/signing-up-for-plan#advanced-security) article for signup instructions.

## Enabling the SCA service

By default, SCA is enabled for your organization when SonarQube [Advanced Security](/sonarqube-cloud/advanced-security/introduction) is active.

You can choose whether all projects will be scanned using SCA by default. To do this, go to your organization and choose **Administration** > **Organization Settings** > **Advanced Security**, where you can adjust the **Enable SCA** checkbox. If you disable dependency analysis by default, you will need to enable analysis on a project-by-project basis at the scanner level by passing `sonar.sca.enabled=true` as an analysis parameter.

## Supported languages and package managers <a href="#supported-languages-and-package-managers" id="supported-languages-and-package-managers"></a>

SonarQube evaluates your third-party open source code usage by matching dependencies defined in your project’s dependency files to known open source code on upstream package managers. It currently supports the following languages, package managers, and package manager files:

| Language                 | <p>Package manager<br>/Build tool</p> | Package repository                             | Manifest file names                                                                                | Lock file names                                                                                               |
| ------------------------ | ------------------------------------- | ---------------------------------------------- | -------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- |
| Java                     | Maven                                 | [Maven Central](https://central.sonatype.com/) | pom.xml                                                                                            | Generated at the time of analysis                                                                             |
| Java                     | Gradle                                | [Maven Central](https://central.sonatype.com/) | <ul><li>build.gradle</li><li>build.gradle.kts</li></ul>                                            | Generated at the time of analysis                                                                             |
| JavaScript               | NPM                                   | [NPM](https://www.npmjs.com/)                  | package.json                                                                                       | <ul><li>package-lock.json</li><li>npm-shrinkwrap.json</li></ul>                                               |
| JavaScript               | Yarn                                  | [NPM](https://www.npmjs.com/)                  | package.json                                                                                       | yarn.lock                                                                                                     |
| JavaScript               | PNPM                                  | [NPM](https://www.npmjs.com/)                  | package.json                                                                                       | pnpm-lock.yaml                                                                                                |
| JavaScript               | Bun                                   | [NPM](https://www.npmjs.com/)                  | package.json                                                                                       | bun.lock                                                                                                      |
| Kotlin                   | Maven                                 | [Maven Central](https://central.sonatype.com/) | pom.xml                                                                                            | Generated at the time of analysis                                                                             |
| Kotlin                   | Gradle                                | [Maven Central](https://central.sonatype.com/) | <ul><li>build.gradle</li><li>build.gradle.kts</li></ul>                                            | Generated at the time of analysis                                                                             |
| PHP                      | Composer                              | [Packagist](https://packagist.org/)            | composer.json                                                                                      | composer.lock                                                                                                 |
| Python                   | Pip                                   | [PyPI](https://pypi.org/)                      | requirements.txt                                                                                   | Generated at the time of analysis                                                                             |
| Python                   | Pipenv                                | [PyPI](https://pypi.org/)                      | Pipfile                                                                                            | Pipfile.lock                                                                                                  |
| Python                   | Poetry                                | [PyPI](https://pypi.org/)                      | pyproject.toml                                                                                     | poetry.lock                                                                                                   |
| Python                   | uv                                    | [PyPI](https://pypi.org/)                      | pyproject.toml                                                                                     | uv.lock                                                                                                       |
| Scala                    | Maven                                 | [Maven Central](https://central.sonatype.com/) | pom.xml                                                                                            | Generated at the time of analysis                                                                             |
| Scala                    | Gradle                                | [Maven Central](https://central.sonatype.com/) | build.gradle                                                                                       | Generated at the time of analysis                                                                             |
| Golang                   | go                                    | [pkg.go.dev](https://pkg.go.dev/)              | go.mod                                                                                             | Generated at the time of analysis                                                                             |
| C#                       | NuGet                                 | [NuGet Gallery](https://www.nuget.org/)        | <ul><li><em>.csproj</em></li><li><em>Project.json</em></li><li>.nuspec</li></ul>                   | <ul><li>packages.lock.json</li><li>project.assets.json</li><li>Project.lock.json</li><li>paket.lock</li></ul> |
| VB.NET                   | NuGet                                 | [NuGet Gallery](https://www.nuget.org/)        | <ul><li><em>.vbproj</em></li><li><em>Project.json</em></li><li>.nuspec</li></ul>                   | <ul><li>packages.lock.json</li><li>project.assets.json</li><li>Project.lock.json</li><li>paket.lock</li></ul> |
| Ruby                     | Rubygems                              | [Rubygems](https://rubygems.org/)              | Gemfile                                                                                            | Gemfile.lock                                                                                                  |
| Rust                     | Cargo                                 | [Crates.io](https://crates.io/)                | Cargo.toml                                                                                         | Cargo.lock                                                                                                    |
| C/C++                    | Conan                                 | [conan.io](https://conan.io/)                  | conanfile.py                                                                                       | conan.lock                                                                                                    |
| C/C++                    | VCPkg                                 | [vcpkg.io](https://vcpkg.io/)                  | vcpkg.json                                                                                         | Generated at the time of analysis                                                                             |
| Generic SBOM (CycloneDX) | N/A                                   | N/A                                            | <ul><li>cyclonedx.json</li><li>cyclonedx.xml</li><li><em>.cdx.json</em></li><li>.cdx.xml</li></ul> | N/A                                                                                                           |
| Generic SBOM (SPDX)      | N/A                                   | N/A                                            | <ul><li><em>.spdx</em></li><li>.spdx.json</li></ul>                                                | N/A                                                                                                           |

## Automatic analysis support

[Automatic analysis](/sonarqube-cloud/analyzing-source-code/automatic-analysis) supports SonarQube Advanced Security's SCA functionality.

To ensure accurate results, commit lockfiles (such as `yarn.lock`) to the project repository.

If lockfiles are not present in the repository, or not supported by the platform, only direct dependencies will be analyzed when using automatic analysis.

## Ensure the analysis is run in an appropriate environment <a href="#appropriate-environment" id="appropriate-environment"></a>

To correctly analyze both your direct and transitive dependencies on projects where there is not a lockfile that contains all dependencies, SonarQube executes commands using your build tools to get a full dependency list.

#### Note on security <a href="#note-on-security" id="note-on-security"></a>

To run a dependency analysis, the SonarQube scanner might install the dependencies required to build your application. This could pull in untrusted artifacts, similar to while you're building the application. Ensure the analysis will run in a secure environment before proceeding.

#### Notes on specific build tools and language ecosystems <a href="#notes-on-specific-build-tools-and-language-ecosystems" id="notes-on-specific-build-tools-and-language-ecosystems"></a>

**Maven**

The Maven binary (`mvn`) or maven wrapper (`mvnw`) must be located in the project directory, the manifest file’s directory, or in the execution path.

**Gradle**

The Gradle binary (`gradle`) or Gradle wrapper (`gradlew`) must be in the project directory, the manifest file’s directory, or in the execution path.

**pip**

The analysis must be run with the same Python runtime that your application is built on. The SonarQube analysis will create a virtual environment to resolve dependencies, and a C compiler and development libraries may be required, based on your python dependencies.

**Go**

The go runtime that matches the version in `go.mod` must be present.

**Internal artifact repositories**

If your application build configuration includes internal or private artifacts, the analysis process must have network access to your artifact server.

If the analysis is not run in the proper environment, it will cause degraded analysis results and potential analysis failures. You can see more information in analysis warnings in the UI and in the scanner log. See [Troubleshooting](https://github.com/SonarSource/sonarqube-documentation/blob/main/content-output/advanced-security/.gitbook/includes/troubleshooting-the-dependency-analysis.md) for some common scenarios.

#### Note on pull request analysis <a href="#appropriate-files" id="appropriate-files"></a>

To get valuable results when performing a pull request analysis, the target branch should be analyzed first.

## Ensure the analysis includes the appropriate files <a href="#appropriate-files" id="appropriate-files"></a>

The SCA analysis recursively searches for appropriate package files for your project. In some cases, this may analyze more files than what your project actually uses. Common cases to look out for include:

* Package manager files in test code and data directories

If you have package manager files present in test directories, ensure these locations are properly excluded from analysis. This can be done in multiple ways:

* Add paths to the common `sonar.exclusions` configuration option. Example: `sonar.exclusions="tests/**"`
* Use the specific `sonar.sca.exclusions` configuration option. Example `sonar.sca.exclusions="tests/**"`
* As long as SonarQube's SCM support is enabled (the default), add the paths to a source control ignore file, such as `.gitignore`

## Customizing the dependency analysis <a href="#customizing-the-dependency-analysis" id="customizing-the-dependency-analysis"></a>

The following parameters influence the results of the dependency analysis.

| Parameter                              | Type    | Default         | Description                                                                                                                                                                                                                                                                                                                                     |
| -------------------------------------- | ------- | --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `sonar.sca.enabled`                    | Boolean | true            | Indicates whether to perform Software Composition Analysis (SCA) on this project. Set it to false to disable SCA for this project.                                                                                                                                                                                                              |
| `sonar.sca.exclusions`                 | String  | <p><br></p>     | <p>A comma-separated list of global patterns of paths to exclude as part of analysis.</p><p>For example, to ignore all manifests under the tests/ and fixtures/ directories, set:</p><p><code>sonar.sca.exclusions = "tests/</code><strong><code>, fixtures/</code></strong><code>"</code></p>                                                  |
| `sonar.sca.allowManifestFailures`      | Boolean | true            | <p>When performing analysis, SonarQube attempts to run your build tools (such as Maven or Gradle) to create a full dependency graph.</p><p>By default, SonarQube does not fail the analysis if these tools fail, and returns information on a limited set of dependencies. Set this parameter to false to force a failure in this scenario.</p> |
| `sonar.sca.goNoResolve`                | Boolean | false           | Disables automatic generation of a Go lock file. This results in degraded dependency information.                                                                                                                                                                                                                                               |
| `sonar.sca.mavenNoResolve`             | Boolean | false           | <p>Disables automatic generation of a Maven lock file and dependency graph file.</p><p>This results in degraded dependency information.</p>                                                                                                                                                                                                     |
| `sonar.sca.mavenForceDepPlugin`        | Boolean | true            | Ensures Maven Dependency Plugin is installed even when it’s not available in the environment.                                                                                                                                                                                                                                                   |
| `sonar.sca.mavenIgnoreWrapper`         | Boolean | false           | Disables a search for a Maven wrapper script `mvnw.` Set this to true if the default Maven wrapper in your `PATH` is not functioning.                                                                                                                                                                                                           |
| `sonar.sca.mavenOptions`               | String  | <p><br></p>     | Sends additional options to any Maven commands used to generate the lock file and dependency graph file.                                                                                                                                                                                                                                        |
| `sonar.sca.gradleNoResolve`            | Boolean | false           | Disables automatic generation of a Gradle dependencies lock file. This results in degraded dependency information.                                                                                                                                                                                                                              |
| `sonar.sca.gradleConfigurationPattern` | String  | <p><br></p>     | Java regex of configurations to include. This is passed to gradle via `-PconfigurationPattern`. When unset, all configurations will be resolved.                                                                                                                                                                                                |
| `sonar.sca.pythonBinary`               | String  | /usr/bin/python | Path to a specific Python binary that should be used if lock files need to be generated.                                                                                                                                                                                                                                                        |
| `sonar.sca.pythonNoResolve`            | Boolean | false           | Disables automatic generation of a Python lock file. This results in degraded dependency information.                                                                                                                                                                                                                                           |
| `sonar.sca.pythonResolveLocal`         | Boolean | false           | When generating a python lockfile, dependency resolution is done in a temporary virtual environment. Set this to true to skip creation of the virtual environment and resolve against the local python environment.                                                                                                                             |
| `sonar.sca.npmNoResolve`               | Boolean | false           | Disables automatic generation of a lock file for an NPM project when a supported lockfile (`yarn.lock`, `package-lock.json`, `pnpm-lock.yaml`, `bun.lock`) is not present.                                                                                                                                                                      |
| `sonar.sca.npmEnableScripts`           | Boolean | false           | By default, when generating a lockfile, the `--ignore-scripts NPM/Yarn` option is passed to ignore any lifecycle scripts. If lifecycle scripts are needed to properly generate dependencies, enable this option.                                                                                                                                |
| `sonar.sca.nugetNoResolve`             | Boolean | false           | Disables automatic generation of a lock file for a Nuget project.                                                                                                                                                                                                                                                                               |
| `sonar.scanner.keepReport`             | Boolean | false           | Not specific to SCA. Keeps the scanner work directory after analysis, including the `dependency-files.tar.xz` that contains dependency files to analyze. Useful if you have access to [commercial support](https://www.sonarsource.com/support/), as the Sonar support team may ask for this file to assist with resolving issues.              |
| `sonar.sca.cfamily`                    | Boolean | false           | When set to true, enables support for C/C++ dependency analysis (beta)                                                                                                                                                                                                                                                                          |
| `sonar.sca.sbomImportPaths`            | String  |                 | Comma-separated list of SBOM files to import and analyze. See “Supported languages and package managers” for supported file types and required file naming.                                                                                                                                                                                     |

## Import SBOM files to analyze containers <a href="#sbom-import" id="sbom-import"></a>

You can use the Software Bill of Materials (SBOM) import feature of SonarQube Advanced Security to analyze a container image.

1. Generate an SBOM of the container. Several freely available tools can do this. For example, given a potential `test/example` container, version 1.2:

   **Using Syft**

   To generate the SBOM of the container using [Syft](https://github.com/anchore/syft):

   ```bash
   syft -o cyclonedx-json=container.cdx.json test/example:1.2
   ```

   **Using CycloneDX Generator**

   To generate the SBOM of the container using [CycloneDX Generator](https://github.com/cdxgen/cdxgen):

   ```bash
   cdxgen test/example:1.2 -o container.cdx.json -t docker
   ```
2. Use the SBOM import feature to analyze the resulting SBOM by passing the following in `sonar-project.properties` or on the scanner command line:

   ```properties
   sonar.sca.sbomImportPaths=container.cdx.json
   ```

### SBOM import requirements

SonarQube Advanced Security has specific requirements for imported Software Bills of Materials.

SBOMs imported into SonarQube must:

* Be in the CycloneDX (JSON or XML) or SPDX (JSON or plaintext) formats
* Be appropriately named (cyclonedx.xml, cyclonedx.json, \*.cdx.json, \*.spdx, \*.spdx.json)
* Contain dependency entries ('components' in CycloneDX, 'packages' in SPDX) that reference items in the [Package URL](https://github.com/package-url) format

Identification of items by [CPE](https://nvd.nist.gov/products/cpe) is not currently supported.

For operating system (Linux) vulnerabilities, they will be returned for the following Linux distributions:

* Red Hat Enterprise Linux
* Debian (11 and higher)
* Rocky Linux
* AlmaLinux
* Ubuntu

Downstream or vendor packages may return inconsistent results for vulnerabilities.

## Continual analysis

Once SCA analysis has been performed on a branch, Sonar automatically re-analyzes your branch for new dependency risks. This analysis runs once per day. Any newly discovered vulnerability or license risks will be added to the list of dependency risks for your project, any changes to risk factors and scoring will cause any needed severity updates, and any quality gate will be recomputed.

You can configure the branch rescan frequency by going to **Administration** > **Advanced Security** > **Configure branch rescanning**.

From there, you can set the following:

* **Branch rescan frequency**: Daily, weekly, or never
* **Target branch types**: Main branch only, kept branches only, or all branches. When set to **Kept branches only**, continual analysis targets [long-lived branches](/sonarqube-cloud/analyzing-source-code/branch-analysis/branch-analysis-setup#longlived-branches).

You can see the last analysis or reanalysis time on the **Dependency Risks** screen. If you have the **Administer projects** permission, you can also trigger a manual reanalysis from that screen.

## What data is collected

Whenever you run an analysis, data is sent to a Sonar cloud service for analysis. The Sonar scanner collects the manifests of your projects. Manifests are language-specific files that define your projects’ dependencies, such as `pom.xml` for Java, or `requirements.txt` for Python. The scanner also collects any relevant lockfiles that describe the fully-resolved set of dependencies, such as `package-lock.json` for a JavaScript project.

These manifests and lockfiles are assembled into an archive file and sent to a Sonar cloud service for analysis. All data is sent over a secure HTTPS connection. Information on your dependencies and their issues is returned to your SonarQube Server instance. No source code is sent to Sonar.

Manifests and lockfiles are not stored persistently in Sonar. Sonar may collect aggregate data, and other service telemetry on open source package usage in an anonymized way.

The manifest and lockfiles that are processed contain a list of all dependencies of your project, which could include internally-developed library names. The Sonar service compares dependency names against a set of known open source components; any internally-developed library name would not match, and therefore would not have any license or vulnerability data returned for that library.

## Troubleshooting the dependency analysis <a href="#troubleshooting-the-dependency-analysis" id="troubleshooting-the-dependency-analysis"></a>

See [Advanced security troubleshooting](https://docs.sonarsource.com/sonarqube-cloud/advanced-security/troubleshooting/) for guidance on how to troubleshoot the dependency analysis.

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Viewing dependencies](/sonarqube-cloud/advanced-security/viewing-dependencies)
* [Reviewing and fixing dependency risks](/sonarqube-cloud/advanced-security/reviewing-and-fixing-dependency-risks)
* [Managing license profiles and policies](/sonarqube-cloud/advanced-security/managing-license-profiles-and-policies)
* [Troubleshooting](/sonarqube-cloud/appendices/troubleshooting)
* [Best practices for managing dependency risks](/sonarqube-cloud/advanced-security/best-practices-for-managing-dependency-risks)

## Related online courses

* <i class="fa-desktop">:desktop:</i> [Configuring SonarQube Advanced Security](https://www.sonarsource.com/learn/course/advanced-security/7160987d-7e9b-4223-a434-8dfba3beb34a/configuring-sonarqube-advanced-security)


# Viewing dependencies

How to view the dependencies in your SonarQube Cloud projects and export the software bill of materials (SBOM).

Advanced Security is a product that requires a separate subscription to your SonarQube Cloud's [plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features).

*The Advanced Security product is available starting with the Team plan.* See the [Signing up for a plan or product](/sonarqube-cloud/administering-sonarcloud/managing-subscription/signing-up-for-plan#advanced-security) article for signup instructions.

During project analysis, SonarQube Advanced Security conducts software composition analysis (SCA) to identify and list project dependencies and associated risks. It's also possible to export the software bill of materials (SBOM) for your project.

## Viewing the list of dependencies <a href="#viewing-the-list-of-dependencies" id="viewing-the-list-of-dependencies"></a>

You must build, or rebuild your project's main branch to see the SCA results. After an analysis, a list of dependencies becomes available on the **Dependencies** page for projects and portfolios. It is updated with each analysis. You need the **Browse** permission to view dependencies on private projects and portfolios.

<figure><img src="/files/lzwHp7IAofy7x0blPC4z" alt="Dependencies page under projects"><figcaption></figcaption></figure>

You can use **Filters** to narrow down the results. Dependencies can be filtered by:

* **Dependency type**: Direct or Transitive.
* **Dependency scope**: Production or Development.
* **Package manager**: A list of package managers. See [Analyzing projects for dependencies](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca) for supported package managers and languages.

Use the search feature to find specific dependencies.

The following information is displayed for each dependency card in the list:

<figure><img src="https://assets-eu-01.kc-usercontent.com/b1eeb429-d9e0-0100-be87-468f6802040a/ded013f1-73f7-490d-bd02-c352dc49636e/dependency-info.png?w=512&#x26;h=151&#x26;auto=format&#x26;fit=crop" alt="Information on a dependency in SonarQube Cloud." height="151" width="512"><figcaption></figcaption></figure>

1. Dependency name
2. Dependency version
3. Dependency type
4. Dependency scope
5. Files where the dependency was identified
6. Package manager
7. License

Click on the dependency name to open a detailed view.

## Detailed view <a href="#detailed-view" id="detailed-view"></a>

<figure><img src="/files/iXZD1FxoiiWFIUZvay7T" alt="The detailed view of a dependency in SonarQube Cloud"><figcaption></figcaption></figure>

The detailed view of a dependency provides the following information:

* Details of the dependency, including **Dependency type**, **Dependency scope**, **Identified using**, **Package manager** and **License**. Click on the info icon for **Identify using** to reveal all the files where the dependency was identified.
* Dependency chains: A list of direct and transitive dependency chains, if available.

### About dependency chains <a href="#about-dependency-chains" id="about-dependency-chains"></a>

Dependency chains show how a dependency is brought into your project.

Project components often rely on other components, creating dependencies. These dependencies can be direct, where one component immediately uses another, or transitive, where a component relies on another component which, in turn, depends on yet another.

For example In a Project > Component 1 > Component 2 scenario:

* The dependency between Project and Component 1 is direct.
* The dependency between Project and Component 2 is transitive because Component 1 is built using Component 2.

The detailed view indicates whether a dependency has direct and transitive dependency chains and displays the complete path for transitive dependencies.

## Getting a high-level view of your dependency usage <a href="#global-view-dependency-usage" id="global-view-dependency-usage"></a>

You can also view dependencies for portfolios to get a higher-level view of your dependency usage. For example, to get a list, or bill of materials, for all software in use by your organization, you can create a [portfolio](/sonarqube-cloud/managing-portfolios) of **All Projects**.

After you create and refresh a portfolio, you can view **Dependencies** and **Dependency Risks**. Searching Dependencies by name allows you to see where a dependency is used in your organization. Searching Dependency Risks by a CVE name allows you to discover where your in organization you may be affected by a newly reported CVE.

## Software Bill of Materials (SBOM) <a href="#software-bill-of-materials" id="software-bill-of-materials"></a>

Note: Software Bill of Materials export is only available on the Enterprise [plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features).

A software bill of materials (SBOM) is an inventory of components your project is built with, including details such as the component name, version, and license.

Because your project depends on these components to build and run your software, getting the SBOM for a project is a key element to track all the items that you depend on for both internal use in the remediation of dependency risks, and external use for compliance with regulations.

Compliance teams can use SBOMs as an index to keep an inventory of licenses in use. Developers can use SBOMs to manage dependencies. All of this creates greater interoperability and efficiency within an organization. It is a shared language for all of these teams that can be passively generated and maintained based on application builds.

Sonar supports exporting an SBOM in two major SBOM formats: Software Package Data Exchange (SPDX) and CycloneDX.

### Exporting the SBOM <a href="#exporting-the-sbom" id="exporting-the-sbom"></a>

You can export the SBOM from the **Dependencies** page of **Projects** and **Portfolios**. SBOMs are available in the CycloneDX and SPDX, in both XML and JSON formats.

<figure><img src="/files/ZTRXgXLETk6kbq8TPEo8" alt="The Export SBOM button on the SonarQube Cloud UI"><figcaption></figcaption></figure>

By default, a SonarQube-generated SBOM only includes 'production' dependencies - dependencies that end up in your released application. If you need to include all dependencies, including development dependencies, you can generate a SBOM via the API by passing `onlyProductionScope=false`.

SBOMs are generated when requested in the UI or API; there is no storage or history for SBOMs in SonarQube. If your needs require storing SBOMs for particular released versions of your projects or portfolios, you should export a SBOM at release time and save it somewhere outside of SonarQube for later use.

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Reviewing and fixing dependency risks](/sonarqube-cloud/advanced-security/reviewing-and-fixing-dependency-risks)
* [Analyzing projects for dependencies](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca)
* [Managing license profiles and policies](/sonarqube-cloud/advanced-security/managing-license-profiles-and-policies)
* [Troubleshooting](/sonarqube-cloud/appendices/troubleshooting)
* [Best practices for managing dependency risks](/sonarqube-cloud/advanced-security/best-practices-for-managing-dependency-risks)
* [Cyber Resilience Act capability mapping](https://docs.sonarsource.com/cyber-resilience-act)


# Reviewing and fixing dependency risks

SonarQube Cloud lets you manage the dependency risks detected during analysis and provides insights on how to fix them.

Advanced Security is a product that requires a separate subscription to your SonarQube Cloud's [plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features).

*The Advanced Security product is available starting with the Team plan.* See the [Signing up for a plan or product](/sonarqube-cloud/administering-sonarcloud/managing-subscription/signing-up-for-plan#advanced-security) article for signup instructions.

SonarQube Advanced Security lets you manage dependency risks, mark them as safe, confirmed, or accepted, and assign them to other members of your team. For Remediation Agent subscribers, you can let the agent fix a vulnerability for you by opening a pull request that bumps the affected dependency version; see [SCA basic remediation](https://docs.sonarsource.com/agent-centric-development-cycle/solve/remediation-agent#sca-basic-remediation).

## Reviewing and fixing dependency risks <a href="#reviewing-and-fixing-dependency-risks" id="reviewing-and-fixing-dependency-risks"></a>

Navigate to the **Dependency Risks** tab of your project or portfolio.

Use **Filters** in the left side bar to narrow down the results. You can filter the results by:

* **Risk type**: Vulnerability, Malicious package, and Prohibited license
* **Risk severity**: Blocker, High, Medium, Low, or Info
* **Software quality**: Security, Maintainability
* **Reachability**: Show only confirmed reachable vulnerabilities
* **Dependency type**: Direct or Transitive
* **Dependency scope**: Production or Development
* **Package manager**: See [Analyzing project for dependencies](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca) for a list of supported package managers and languages.
* **Status**: Accepted, Confirmed, Open, Fixed, Safe
* **Assignee**: Type in the name of the person assigned and select it from the list.

From there, you can sort the list of results:

* by choosing the sorting criteria from the **Sort by** dropdown menu
* by vulnerability name by entering a vulnerability ID (such as CVE-2022-38392) into the search box

The following information is displayed for each dependency risk in the list:

<div align="center"><figure><img src="https://assets-eu-01.kc-usercontent.com/b1eeb429-d9e0-0100-be87-468f6802040a/128422bc-f650-4fce-aa68-92a22004b833/dependency-risk-card.png?w=1028&#x26;h=369&#x26;auto=format&#x26;fit=crop" alt="Information on each dependency risk card."><figcaption></figcaption></figure></div>

1. Descriptive title of the dependency risk. Click on the title to open a detailed view.
2. Software quality, risk type, and severity
3. Status: Open, Confirmed, Accepted, Safe
4. Assignee of the risk
5. Amount of time that has passed since the risk was first detected
6. Affected dependency and version
7. If it is confirmed to be reachable by your code, a Reachable badge is displayed

## Understanding the risk types <a href="#understanding-the-risk-types" id="understanding-the-risk-types"></a>

Each dependency risk has an assigned risk type:

* **Vulnerability**: When a third-party dependency is affected by a publicly reported vulnerability, such as a record on [CVE.org](http://cve.org/)
* **Malicious package**: When a third-party dependency is known to be malicious
* **Prohibited license**: When a third-party dependency has a software license not allowed by the project's associated [license profile and policy](/sonarqube-cloud/advanced-security/managing-license-profiles-and-policies). Note that license risks are only available on the Enterprise [plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features).

## Changing dependency status and assigning risks <a href="#changing-dependency-status-and-assigning-risks" id="changing-dependency-status-and-assigning-risks"></a>

### Dependency risk lifecycle <a href="#dependency-risk-lifecycle" id="dependency-risk-lifecycle"></a>

A dependency risk can have the following statuses:

* **Open**: Initial state of a dependency risk after analysis. The risk has not been yet reviewed.
* **Confirmed**: Indicates that the dependency risk has been reviewed and the risk is valid.
* **Accepted**: The risk is valid but it may not be fixed for a while.
* **Safe**: Indicates that the dependency risk does not compromise the security of the software. A mandatory justification must be provided.

To change the status of the dependency risk, click the **Change Status** button to open a modal. From the **Status** dropdown list select a new status for the risk and enter a description for the change in the **Explain your decision** text box.

If a release is updated without fixing a risk (such as to a new version that is under the same prohibited license), any manual status changes and comments are copied to the new risk.

### Assigning a dependency risk <a href="#assigning-a-dependency-risk" id="assigning-a-dependency-risk"></a>

You can delegate a review of dependency risks to other team members by clicking the **Unassigned** dropdown menu and entering a name. You can also assign the risk to yourself.

### Email notifications <a href="#email-notifications" id="email-notifications"></a>

If you have subscribed to [email notifications](/sonarqube-cloud/managing-your-account/notifications) for a project, note that the notifications that apply to issues also apply to dependency risks.

## Detailed view <a href="#detailed-view" id="detailed-view"></a>

Clicking the title of the dependency risk in the list of results opens its detailed view page:

<figure><img src="/files/4yor5gJo3SYEroZeAmMX" alt="The detailed view of a dependency risks in SonarQube Cloud"><figcaption></figcaption></figure>

1. Details of the dependency risk, including **Risk type**, **Risk Severity**, **First detected**, **Assignee**, and **Status**.
2. **What’s the Risk?** and **How can I fix it?** allow you to review information about the dependency risk, the factors affecting the risk’s severity, and information about currently used dependency versions and fixes.
3. **Affected dependencies** shows the dependency version that raised the risk, dependency type, package manager and the associated risks. Click the **View all risks for this dependency** for a full list.

## What’s the risk? <a href="#whats-the-risk" id="whats-the-risk"></a>

Sonar uses a holistic approach to determine the severity of a dependency risk. The methods used depend on the associated risk type.

<div align="left"><figure><img src="https://assets-eu-01.kc-usercontent.com/b1eeb429-d9e0-0100-be87-468f6802040a/5789f5e3-7835-4203-99a2-5ce64a0eaf24/whats-the-risk-tab.png?w=512&#x26;h=230&#x26;auto=format&#x26;fit=crop" alt="The &#x22;What&#x27;s the risk&#x22; tab in the UI." width="563"><figcaption></figcaption></figure></div>

### Vulnerability risk <a href="#vulnerability-risk" id="vulnerability-risk"></a>

Sonar partners with select open source maintainers to uphold their software to secure development practices. As part of this partnership, Sonar-partnered maintainers provide guidance on vulnerabilities. This guidance includes:

* Whether the vulnerability is real, or a false positive
* How likely it is that the vulnerability will affect typical usage
* Whether the vulnerability affects development or test usage, or only production usage
* What workarounds, if any, are available
* What specific functions or methods are affected

<figure><img src="/files/8B5PEkrckk2fGfMmtDZL" alt="The Insights from the maintainer tab in the SonarQube UI."><figcaption></figcaption></figure>

This guidance ensures that developers have comprehensive information to speed up remediation times.

**Risk evaluation**

The risk evaluation is based on the following factors:

* **Severity**: Evaluates the technical severity of a vulnerability based on an assessment by [CVSS](https://www.first.org/cvss/).
* **Known exploited**: Shows if the risk has been actively exploited in the wild. It’s measured by [KEV](https://www.cisa.gov/known-exploited-vulnerabilities-catalog).
* **Chance of future exploitation**: Estimates the likelihood (percentage) of a software vulnerability being exploited in the wild over the next 30 days. It’s measured by [EPSS](http://first.org/epss).

Sonar combines these factors to assign a severity to a discovered vulnerability to ensure that developers are prioritizing the most urgent risk in their applications.

#### Vulnerability reachability <a href="#vulnerability-reachability" id="vulnerability-reachability"></a>

SonarQube performs reachability analysis of vulnerabilities to determine whether your code calls the vulnerable code in your third party dependencies.

Three possible values are shown for the reachable status of a vulnerability:

* Reachable: SonarQube found your code calling functions associated with the vulnerability
* Unreachable: SonarQube found no instances of your code directly calling functions associated with the vulnerability. You may still be affected due to transitive calls from other dependencies, or other ways of exploiting the vulnerability.
* Not analyzed: SonarQube did not analyze this vulnerability for reachability

Reachable vulnerabilities should be prioritized for immediate remediation.

Vulnerabilities may not be analyzed for reachability for a number of reasons. The vulnerability could be in an unsupported language, the vulnerable package may be a transitive dependency, or no deep vulnerability analysis has yet been performed.

Reachability is only calculated for a full analysis (either in CI, or via automatic analysis), as it requires a call graph analysis of your code. Vulnerabilities detected via [continual analysis](https://docs.sonarsource.com/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca#continual-analysis) will be analyzed for reachability at the next full analysis.

Reachability analysis is currently only supported for vulnerabilities in Java code. Sonar will add additional language support over time.

### Malicious package risk <a href="#malicious-package-risk" id="malicious-package-risk"></a>

Malicious package risks are always BLOCKER severity. They should be remediated immediately.

### Prohibited license risk <a href="#prohibited-license-risk" id="prohibited-license-risk"></a>

The dependency risk for prohibited license risk type depends on the configuration of your instance's license profile and policy. The **What's the risk?** tab provides information about the risk associated with the license and links to relevant resources. For more information, see [Managing license profiles and policies](/sonarqube-cloud/advanced-security/managing-license-profiles-and-policies). License risks are only available on the Enterprise plan.

## Dependency risk severities <a href="#risk-severities" id="risk-severities"></a>

The table below lists the dependency risk severities used for vulnerability risks and their definition.

| **Risk severity** | **Definition**                                                                                                                                                                                                                                                                                                                                                                         |
| ----------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Blocker           | A vulnerability is on the CISA KEV list.                                                                                                                                                                                                                                                                                                                                               |
| High              | <p>Vulnerability has both:</p><ul><li>High exploitability (an EPSS probability greater than 5%)</li><li>High risk (a CVSS score over 7.0)</li></ul>                                                                                                                                                                                                                                    |
| Medium            | <p>Any other vulnerability that has both:</p><ul><li>Moderate or unknown exploitability (an EPSS probability greater than 0.5%, or no EPSS scoring)</li><li>Moderate risk (a CVSS score over 4.0)</li></ul>                                                                                                                                                                            |
| Low               | Any remaining vulnerability that does not fit into another category.                                                                                                                                                                                                                                                                                                                   |
| Info              | <p>Any of the following is true:</p><ul><li>A Tidelift or Sonar partnered maintainer has declared the vulnerability a false positive</li><li>The vulnerability has been declared as <em>withdrawn</em> by a vulnerability source (NIST, OSV)</li></ul><p>Note: this categorization for Info overrides any criteria that would place the risk into Critical, High, or Low severity.</p> |

**Editing risk severities**

If you decide that a different level is more appropriate for a given risk, you can manually set a new severity level. Keep in mind that doing so may impact your quality gates.

To customize the risk severity level for **Software qualities impacted**:

1. Select a risk from the search results list.
2. Click on the quality: **Security**, **Reliability**, or **Maintainability**.
3. Select the severity level you wish to apply from the dropdown list. You can also change the severity level from the risk's details page.

Note that if you manually update the severity level for a risk, it will no longer be updated automatically by Sonar, even if the data used in the severity calculation changes.

## How can I fix it? <a href="#how-can-i-fix-it" id="how-can-i-fix-it"></a>

### Vulnerability <a href="#vulnerability" id="vulnerability"></a>

The **How can I fix it?** tab displays information about dependency versions, starting with the latest, and available fixes.

<div align="left"><figure><img src="https://assets-eu-01.kc-usercontent.com/b1eeb429-d9e0-0100-be87-468f6802040a/9ae308e9-c13f-468b-b7a8-babb41abf82e/how-can-i-fix-it-tab.png?w=512&#x26;h=445&#x26;auto=format&#x26;fit=crop" alt="The &#x22;How can I fix it&#x22; tab for dependency risks in the SonarQube UI." height="444.99999999999994" width="512"><figcaption></figcaption></figure></div>

The following options are available:

* **Complete fix**: A dependency version that fixes all associated vulnerabilities.
* **Partial fix**: A dependency version that fixes the vulnerability but not all other vulnerabilities associated with the dependency.
* **Affected version**: A dependency version for which the vulnerability was detected.

The SonarQube Remediation Agent can apply the suggested version bump for you by opening a pull request. See [SCA basic remediation](https://docs.sonarsource.com/agent-centric-development-cycle/features/remediation-agent#sca-basic-remediation) for the supported package managers.

### Malicious package <a href="#malicious-package" id="malicious-package"></a>

Any machine that has an installed a malicious piece of software should be considered compromised and remediated immediately. The How can I fix it? tab provides steps that should be followed when malware is detected, including informing your information security team.

### Prohibited license <a href="#prohibited-license" id="prohibited-license"></a>

The dependency risk for prohibited license risk type depends on the configuration of your instance’s license profile and policy. The How can I fix it? tab provides information about different license categories and links to relevant resources. In general, resolving a license risk will require choosing a different software package to use instead. For more information, see [Managing license profiles and policies](/sonarqube-cloud/advanced-security/managing-license-profiles-and-policies).

## Setting a license profile and policy <a href="#setting-a-license-profile-and-policy" id="setting-a-license-profile-and-policy"></a>

Instance admins can configure a license profile and policy to define which licenses are allowed or prohibited for the dependencies used in your projects or the whole instance. For more information, see Managing license profiles and policies.

## Dependency risks in quality gates <a href="#dependency-risks-in-quality-gates" id="dependency-risks-in-quality-gates"></a>

The **Project overview** page displays dependency risks and indicates whether they pass or fail the associated quality gate.

As a quality gate administrator, you can configure quality gate conditions for **Prohibited license**, **Malicious package**, and **Vulnerability** types for new and overall code, or set limits on the number or severity of dependency risks that will cause the quality gate to fail. See [Managing custom quality gates](/sonarqube-cloud/standards/managing-quality-gates/managing-custom-quality-gates) for more information.

If your organization has recently purchased the Advanced Security package, you will have to create a custom quality gate to make sure no new dependency risks are introduced in your projects.

See [Understanding measures and metrics](/sonarqube-cloud/managing-your-projects/metric-definitions) for more information about Advanced Security metrics used in quality gates.

## Tracking risks via reports <a href="#tracking-risks-via-reports" id="tracking-risks-via-reports"></a>

In addition to the existing SonarQube [enterprise reports](https://docs.sonarsource.com/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports), you can download a specific report of your third party dependency risks for your project, applications, and portfolios from the project overview page, or by calling a [SonarQube Cloud API endpoint](https://api-docs.sonarsource.com/sonarqube-cloud/default/public-dependencyservice-v1-4).

The report lists dependency risks based on the latest scan for the default branch of your project or portfolio. It can help managers identify:

* What violations exist in their team’s projects
* What patterns of risk are associated with higher-level dependencies, and how to use the information to guide developers effectively
* What specific upgrades developers can perform to remove multiple violations.

The report is downloadable in JSON or CSV format and contains information on:

* Project or portfolio name
  * Branch of project, if the report is for a project
* Project or portfolio key
* Package URL (purl) of the dependency
* Link to the risk in the SonarQube interface
* Dependency chain(s)
* Risk title (a short description of the risk)
* Risk type
* Risk severity
* Risk status, including comments when status was changed
* Scope of the dependency, including whether it is considered a production dependency
* Vulnerability specific fields
  * Risk identifier (e.g., the CVE id)
  * CVSS and EPSS scoring for the risk
  * KEV status of the risk
  * Associated CWE weakness ids
  * Date the vulnerability was published
  * Reachability status of the risk
* Date when Sonar assigned the Risk to the project

Additionally, you can download a machine-readable vulnerability risk report in [VEX format](https://cyclonedx.org/capabilities/vex/), which can be used to attest to the vulnerability posture of your products. The VEX report includes raw vulnerability detail, and also justifications based on comments made when marking vulnerabilities as SAFE in your projects.

All reports require an Enterprise-level subscription.

## Required permissions <a href="#required-permissions" id="required-permissions"></a>

On private projects, and portfolios, the following permissions apply:

* **Browse**: access, browse, confirm dependency risks, change assignee.
* **Administer issues**: change risk severity, resolve risks as **Accepted** or **Safe**.

Anyone within an organization is allowed to browse dependency risks on public projects and portfolios.

Changing the status of a dependency risk requires the **Administer Issues** permission.

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Viewing dependencies](/sonarqube-cloud/advanced-security/viewing-dependencies)
* [Analyzing projects for dependencies](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca)
* [Managing license profiles and policies](/sonarqube-cloud/advanced-security/managing-license-profiles-and-policies)
* [Troubleshooting](/sonarqube-cloud/advanced-security/troubleshooting-the-dependency-analysis)
* [Best practices for managing dependency risks](/sonarqube-cloud/advanced-security/best-practices-for-managing-dependency-risks)
* [SCA basic remediation](https://docs.sonarsource.com/agent-centric-development-cycle/features/remediation-agent#sca-basic-remediation)


# Managing license profiles and policies

As an administrator, SonarQube Cloud allows you to define license policies to warn developers about the use of prohibited licenses in their projects.

Advanced Security is a product that requires a separate subscription to your SonarQube Cloud's [plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features). License profiles are only available on the Enterprise plan.

*The Advanced Security product is available starting with the Team plan.* See the [Signing up for a plan or product](/sonarqube-cloud/administering-sonarcloud/managing-subscription/signing-up-for-plan#advanced-security) article for signup instructions.

To reduce legal risk and maintain a high level of security for your software, it’s important to ensure your project’s dependencies use licenses that comply with your organization’s policies.

## About license profiles <a href="#about-license-profiles" id="about-license-profiles"></a>

A license profile is a collection of policies that define which licenses are allowed or prohibited for the dependencies used in your projects.

Once configured, analysis will raise a dependency risk when a dependency with a prohibited license is detected in your projects.

Depending on how your software is built, deployed, and delivered to your users, you may have different licensing requirements for different projects in your organization. You can create multiple license profiles based on the needs of your applications, and assign projects to each individual profile as needed.

### How Sonar analyzes license combinations <a href="#how-sonar-analyzes-license-combinations" id="how-sonar-analyzes-license-combinations"></a>

Sonar proactively analyzes license combinations to give you the most accurate results according to your policy.

For example, if your policy allows MIT, but disallows LGPL-2.0:

* software that is licensed as "MIT AND LGPL-2.0" will generate a dependency risk, as a portion of it uses a license that you have not allowed.
* software that is licensed as "MIT OR LGPL-2.0" will *not* generate a dependency risk, as you can use it under the MIT license.

## Creating a license profile <a href="#creating-a-license-profile" id="creating-a-license-profile"></a>

To define which licenses are allowed or prohibited, you must create a license profile. Note that you need the **Administer Quality Profiles** permission to perform this task.

When you create a license profile, you choose if it applies:

* to only the projects you select
* to all the existing and future projects of your instance, except the projects already assigned to a different profile.

To create a license profile:

1. Go to *Your organization >* **License profiles** > **Create profile.**
2. Give your license profile a name.
3. Select the scope of your license profile:
   1. To use it only on certain projects, choose **Only the projects I select.**
   2. To create a default profile that applies to all projects, choose **Every project I should use should use this project by default.**

## Managing license profiles <a href="#managing-license-profiles" id="managing-license-profiles"></a>

You can edit your license profiles under **License profiles** > *your license profile.*

If your profile is applied to selected projects only, go to **Projects using this profile** > **Manage** to edit the list of projects that use this license profile.

## Viewing the list of licenses <a href="#viewing-the-list-of-licenses" id="viewing-the-list-of-licenses"></a>

Licenses used in your projects are listed in the **License profiles** > **Licenses** section. You can search for licenses and filter them by category and their 'Allowed' or 'Prohibited' status.

Each license in the list has a display name and an SPDX identifier based on the [SPDX License List](https://spdx.org/licenses/), a listing of common open source licenses.

By default, all the licenses are prohibited, see “Configuring license policies” below for more information.

## Downloading a license profile

If you would like to export your license profile to review in another tool, you can download the profile in JSON format via the more actions menu on the top right of the license profile screen.

### About license categories <a href="#about-license-categories" id="about-license-categories"></a>

Each license has a category determined by Sonar based on [Blue Oak Council’s](https://blueoakcouncil.org/copyleft) categorization of licenses. The categories are as follows:

| **License category**    | **Description**                                                                                                                                                                                                                                                                                                                                                                                     |
| ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Standard permissive     | <p>The most commonly used permissive licenses. They grant broad permissions to use and modify with very minimal obligations (primarily attribution) and have all the essential elements of permissive open source licenses.<br><br>Examples: MIT and Apache software licenses.</p>                                                                                                                  |
| Non-standard permissive | <p>Permissive licenses that lack one or more essential elements of modern permissive open source licenses, or impose complex or confusing requirements.</p><p>Many use unclear, jocular, or incomplete language and can be considered less legally predictable to use.<br><br>Examples: Artistic 1.0 and the WTFPL software licenses.</p>                                                           |
| Weak copyleft           | <p>Weak copyleft licenses require sharing your changes and additions to the licensed software when you give copies to others.</p><p>Examples: GNU LGPL and the Mozilla Public License software licenses.</p>                                                                                                                                                                                        |
| Strong copyleft         | <p>In addition to the requirements of the weak copyleft licenses, strong copyleft licenses require you to share larger programs that you build with the licensed software when you give copies to others.</p><p>Example: the GNU GPL license.</p>                                                                                                                                                   |
| Network copyleft        | <p>In addition to the requirements of strong copyleft licenses, network copyleft licenses require you to share larger programs that you build with the licensed software not just when you give copies to others, but also when you run the software for others to use over the Internet or another network.</p><p>Examples: the GNU AGPL and the Server-Side-Public License software licenses.</p> |
| Maximal copyleft        | <p>Maximal copyleft licenses answer the question “When does the license require you to share?” differently than other families. Maximal copyleft licenses require you to share software you make with others, and to license that software alike when you do.</p><p>Example: the Parity and Reciprocal software licenses.</p>                                                                       |
| Other                   | <p>Many detectable licenses do not fall into one of the standard categories, usually because they have non-standard requirements.</p><p>Any license in the ‘Other’ category needs to be individually reviewed and configured based on the specific license terms and use case.</p>                                                                                                                  |

For licenses that exist in the [SPDX License List](https://spdx.org/licenses/), you can click on the license identifier to view the license text.

## Configuring license policies <a href="#configuring-license-policies" id="configuring-license-policies"></a>

Once your license profile is created, you can configure license policies to define which licenses are allowed or prohibited in your license profile.

By default, all licenses are prohibited.

From the **Licenses** section, you can configure:

* *individual policies,* by assigning the **Allowed** or **Prohibited** policy to each license.
* *default policies*, by mapping each license category to the **Allowed** or **Prohibited** policy. Default policies don’t apply to 'Other' licenses.

To set default policies, go to **Default policies** > **Manage** and select **Allowed** or **Prohibited** for each license category.

It’s possible to override default policies with individual policies for each license.

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Reviewing and fixing dependency risks](/sonarqube-cloud/advanced-security/reviewing-and-fixing-dependency-risks)
* [Analyzing projects for dependencies](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca)
* [Troubleshooting](/sonarqube-cloud/advanced-security/troubleshooting-the-dependency-analysis)
* [Best practices for managing dependency risks](/sonarqube-cloud/advanced-security/best-practices-for-managing-dependency-risks)


# Troubleshooting the dependency analysis

Troubleshooting guidelines for SonarQube Cloud issues related to dependency analysis.

Advanced Security is a product that requires a separate subscription to your SonarQube Cloud's [plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features).

*The Advanced Security product is available starting with the Team plan.* See the [Signing up for a plan or product](/sonarqube-cloud/administering-sonarcloud/managing-subscription/signing-up-for-plan#advanced-security) article for signup instructions.

## Errors from the dependency service <a href="#errors-from-the-dependency-service" id="errors-from-the-dependency-service"></a>

There may be errors from the dependency service if the files sent are invalid or corrupted.

Additionally, there are size limits to software composition analysis

| File type              | Size limit                  |
| ---------------------- | --------------------------- |
| Single dependency file | 50 megabytes (uncompressed) |
| All files combined     | 10 megabytes (compressed)   |

## Issues with analysis results <a href="#issues-with-analysis-results" id="issues-with-analysis-results"></a>

Guidelines for troubleshooting analysis result issues.

### Only direct dependencies shown when using automatic analysis

Automatic analysis relies on lockfiles being present in the repository to determine transitive dependencies and dependency graphs.

For projects where lockfiles are not committed to the project, or where lockfiles are not supported (such as maven projects), only direct dependencies will be shown, and a warning will be raised.

### I don't see any issues on my first PR analysis <a href="#i-dont-see-any-issues-on-my-first-pr-analysis" id="i-dont-see-any-issues-on-my-first-pr-analysis"></a>

If the first analysis for your project is on a pull request, the analysis will be unable to determine what dependencies and risks are new in your pull request, so you may not see the results you expect. We recommend running at least one analysis on the main branch before running analyses on pull requests.

### I don't see any dependencies analyzed (No packages were found.)

Make sure that you have a supported manifest and lockfile (shown in the [Supported languages and package managers](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca#supported-languages-and-package-managers) section) available, not excluded from analysis, and not excluded by SCM exclusions (such as `.gitignore`). For example, if you exclude XML files (e.g. `sonar.exclusions=**/*.xml` ) for a Maven Java project or JSON files (e.g. `sonar.exclusions=**/*.json`) in JavaScript/TypeScript projects, then Sonar scanner will not find `pom.xml`, `package.json`, etc.

### My SCA analysis takes too long <a href="#my-sca-analysis-takes-too-long" id="my-sca-analysis-takes-too-long"></a>

A properly configured analysis with a lockfile should take minimal time. Common causes of extended analysis time are:

**JavaScript**

Ensure the directory is excluded via `sonar.exclusions` or `sonar.sca.exclusions`. See [Analyzing projects for dependencies](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca) for more information.

**Pip / requirements.txt**

The Sonar analysis will run `pip install -r requirements.txt` in a temporary virtual environment for any discovered `requirements.txt`file. This may take significant memory or time if the installation process requires building core Python wheels.

**Maven/Gradle**

The Sonar analysis will run Maven or Gradle to resolve the dependencies of your project. If a wrapper is used, it will use the specified JVM memory configuration for maven/gradle, which may be more than what your analysis previously required.

Ensure that the memory parameters are set appropriately, or that your analysis runners have enough memory for your configured JVM memory parameters.

### How do I see what the SCA analysis is doing? <a href="#how-do-i-see-what-the-sca-analysis-is-doing" id="how-do-i-see-what-the-sca-analysis-is-doing"></a>

You can see the commands being run by examining the scanner log and looking for `Running…` lines after the `----- Gather SCA dependencies on project` line. Running the scanner in debug mode `sonar.verbose`, or passing `-X` provides additional detail.

## Unknown lifecycle phase error <a href="#unknown-lifecycle-phase-error" id="unknown-lifecycle-phase-error"></a>

When analyzing some java projects, you may get an error that says "there was a problem running `mvn dependency:tree”`, and the following message in the details of the error:

`[ERROR] Unknown lifecycle phase "/some/path/.m2"`

This is due to a conflict between a `MAVEN_CONFIG` environment variable that was present during analysis and the `mvnw` maven wrapper in your project directory. You can solve this by doing one of the following:

* unset the `MAVEN_CONFIG` environment variable
* update the maven wrapper in your repository by running `./mvnw wrapper:wrapper`, and commit the result
* force the use of `mvn` instead of the wrapper by setting the `sonar.sca.mavenIgnoreWrapper` property to `true`

## No dependency chains found <a href="#no-dependency-chains-found" id="no-dependency-chains-found"></a>

Sonar uses lockfiles that contain a full dependency graph to determine how dependencies are used by your project. If a lockfile is missing, or cannot be generated, dependency chains will be missing.

You can fix this error by ensuring a lockfile is present when analysis is run. Sonar recommends committing the lockfile to your source control system. For examples, you can see the documentation for the [python dependency manager poetry](https://python-poetry.org/docs/basic-usage/#committing-your-poetrylock-file-to-version-control) and the [JavaScript dependency manager yarn](https://classic.yarnpkg.com/lang/en/docs/yarn-lock/).

## Errors in the dependency analysis <a href="#errors-in-dependency-analysis" id="errors-in-dependency-analysis"></a>

The scanner will warn you of any errors when processing your dependency files.

| **Error message**                                          | **Recommendation**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ---------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| No packages were found.                                    | Make sure that you have a supported manifest and lockfile shown in [Analyzing project for dependencies](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca) (see the "Supported languages and package managers" section).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| There was a problem parsing the manifests.                 | Same as above.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| This type of file is not supported.                        | Same as above.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| \<name> (\<platform>) has inexact version '\<requirement>' | <p>Certain manifest files (such as a NPM package.json file) list a range of allowable dependencies. When a dependency is specified as a range, Sonar uses a lockfile to determine the exact dependency in use.</p><p>When a lockfile is either not present, or cannot be properly generated, the scanner raises an error that the version specified is not exact and cannot be resolved to a specific software version.</p><p>You can fix this error by ensuring a lockfile is present when analysis is run.</p><p>For examples, see the documentation for the <a href="https://python-poetry.org/docs/basic-usage/#committing-your-poetrylock-file-to-version-control">python dependency manager poetry</a> and the <a href="https://classic.yarnpkg.com/lang/en/docs/yarn-lock/">JavaScript dependency manager yarn</a>.</p> |

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Reviewing and fixing dependency risks](/sonarqube-cloud/advanced-security/reviewing-and-fixing-dependency-risks)
* [Analyzing projects for dependencies](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca)
* [Managing license profiles and policies](/sonarqube-cloud/advanced-security/managing-license-profiles-and-policies)
* [Best practices for managing dependency risks](/sonarqube-cloud/advanced-security/best-practices-for-managing-dependency-risks)


# Best practices for managing dependency risks

A list of best practices for managing dependency risks in SonarQube Cloud.

Advanced Security is a product that requires a separate subscription to your SonarQube Cloud's [plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features).

*The Advanced Security product is available starting with the Team plan.* See the [Signing up for a plan or product](/sonarqube-cloud/administering-sonarcloud/managing-subscription/signing-up-for-plan#advanced-security) article for signup instructions.

Managing dependency risks from SCA is differs from fixing issues in first-party code in a number of ways. Here are some recommendations.

## How dependency risks differ from issues <a href="#how-dependency-risks-differ-from-issues" id="how-dependency-risks-differ-from-issues"></a>

First-party code issues can be fixed entirely by your developers. Even where they may require some internal refactoring, 95% of the time a developer can fix a first-party Sonar code without leaving their codebase, and without having to adjust other code in their application.

That isn’t the case with dependency risks. Dependency risks require updating your open source dependencies to new versions. Moving to a new version of a dependency could require any or all of the following larger changes:

* Adjusting code throughout your application to call new or changed APIs.
* Data migration to new file formats if the new dependency version requires it.
* Moving to entirely an entirely new version of your language runtime (such as Java 21) if the new version of the dependency requires it.

Because of this, the typical dependency risk takes significantly longer to fix than a typical Sonar code issue. Oftentimes development teams will need to schedule explicit technical debt work to perform needed dependency upgrades.

### Some risks require replacing the entire package <a href="#some-risks-require-replacing-the-entire-package" id="some-risks-require-replacing-the-entire-package"></a>

Open source packages do not change licenses often. If a risk is found where you are using a third-party dependency with a license that is unfit for your organization, in the overwhelming majority of cases, the only available fix is to move to a different dependency entirely. This can be an effort of hours, weeks, or even months in the case of major framework migrations.

### The initial work can be large <a href="#the-initial-work-can-be-large" id="the-initial-work-can-be-large"></a>

If you have not previously had good dependency management practices, you may be surprised by the number of direct and transitive issues that are discovered for your projects. The scope of burning down this initial backlog of risk is usually larger than can be added to your developers’ plates to be handled in an ad-hoc manner while they do their normal day-to-day work.

Because of the differences in how dependency risks are resolved by developers, Sonar recommends the following practices for successful onboarding of the SCA features of Advanced Security in a large organization.

## Best practices <a href="#best-practices" id="best-practices"></a>

### Start small <a href="#start-small" id="start-small"></a>

The initial [SCA analyses](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca) will likely create a backlog of issues that need to be triaged and addressed, especially if you had no prior SCA process in place.

* Start with one developer team to refine rollout processes.
* Choose a team committed to refining the process and willing to be a reference.
* The team should have time to spend working through a backlog of initially discovered risks.

### Determine how you want to handle license compliance <a href="#determine-how-you-want-to-handle-license-compliance" id="determine-how-you-want-to-handle-license-compliance"></a>

The appropriate [license policy](/sonarqube-cloud/advanced-security/managing-license-profiles-and-policies) for a piece of software in your organization can depend on:

* what the license of your own code is
* where and how the application is deployed (internal only, network facing, delivered as an artifact to customers)
* how it uses and invokes those dependencies
* your own organization’s level of risk tolerance

There is no one-size-fits-all approach to license compliance. Work with your legal contact to create an appropriate license profile for the applications produced by your first developer team. Create multiple profiles as necessary based on the characteristics of your applications.

### Only enforce a quality gate on new code <a href="#only-enforce-a-quality-gate-on-new-code" id="only-enforce-a-quality-gate-on-new-code"></a>

To avoid shutting down ongoing development due to a tightly configured [quality gate](/sonarqube-cloud/standards/quality-gates) when tackling dependency risks, start enforcement by only enforcing quality on [newly added code](/sonarqube-cloud/standards/about-new-code) / on pull requests.

To ensures no new, real, risk is added to your codebase, a good first start is by adding the “Severity of a dependency risk is greater than Info” condition for new code.

### Begin reducing existing risk outside of a quality gate <a href="#begin-reducing-existing-risk-outside-of-a-quality-gate" id="begin-reducing-existing-risk-outside-of-a-quality-gate"></a>

Once you are no longer bringing in new risks into your codebase, you can then address the backlog of initial risks.

Start by addressing the most severe (any Blocker or High risks). Work with your development team to:

* evaluate how the risk applies to your code. You may be able to mark them as safe as you research how it affects your environment.
* perform any necessary dependency upgrades or implement any workarounds.

Once you have worked with your development team to understand how quickly they can remediate these risks and perform these upgrades, you can then determine how strict of a quality gate is appropriate for overall code.

### When ready, enforce a quality gate on overall code <a href="#when-ready-enforce-a-quality-gate-on-overall-code" id="when-ready-enforce-a-quality-gate-on-overall-code"></a>

A quality gate on overall code means that *merging of new code will be broken for any new publicly disclosed vulnerability*. Before you enable such a quality gate, you need to ensure that your development team is able to handle these risks when they arise.

Once you are comfortable that your development team is able to quickly remediate new public issues, you can add a quality gate condition such as “Severity of a dependency risk is greater than Medium”

This ensures that production code drops will stop whenever a newly discovered High or Blocker issue, forcing the development team to address it.

### Track your work <a href="#track-your-work" id="track-your-work"></a>

You can measure your success in dependency risk management by tracking the risk over time in your applications.

Track how over time the number of risks, and their severity, drops across your applications. This shows you how your developers are reducing risk in your organization, and how fast they are eliminating risks as they appear.

### Expand the circle <a href="#expand-the-circle" id="expand-the-circle"></a>

Once you have gone through these steps with one development team in your organization, you can expand the circle. Take your notes and processes that you have developed, and repeat the steps with another team. Use your first team as a reference to help onboard subsequent teams. As you expand, you will be able to build a culture of dependency management practices throughout your organization.

## Related pages

* [Cyber Resilience Act capability mapping](https://docs.sonarsource.com/cyber-resilience-act)

## Related online courses

* <i class="fa-video">:video:</i> [Best practices for managing dependency risks](https://www.sonarsource.com/learn/course/advanced-security/990efa06-7255-4a83-986b-d09ff9f8fed3/best-practices-for-sca-rollout-and-adoption)


# Discovering SonarQube Cloud

Discover how SonarQube Cloud can help you achieve a state of high-quality code.

{% content-ref url="/pages/ojQTjluMTCGUBYjGY0hn" %}
[Developing with Sonar](/sonarqube-cloud/discovering-sonarcloud/developing-with-sonar)
{% endcontent-ref %}

{% content-ref url="/pages/SYtYWoa6H1HmJNC7mkFT" %}
[What SonarQube Cloud can do](/sonarqube-cloud/discovering-sonarcloud/what-sonarcloud-can-do)
{% endcontent-ref %}

{% content-ref url="/pages/Y8pjU7Rc5CXbRdy4Igui" %}
[SonarQube analysis overview](/sonarqube-cloud/discovering-sonarcloud/analysis-process-overview)
{% endcontent-ref %}

{% content-ref url="/pages/V5pxHmN6oMkekBIB8mcC" %}
[Supported languages](/sonarqube-cloud/discovering-sonarcloud/overview)
{% endcontent-ref %}

{% content-ref url="/pages/pNkCoKThLDv35abOfIDz" %}
[DevOps platforms](/sonarqube-cloud/discovering-sonarcloud/integration-with-devops-platforms)
{% endcontent-ref %}

{% content-ref url="/pages/MnIzl7DZPByKgZTJ99fj" %}
[Integrations](/sonarqube-cloud/discovering-sonarcloud/integrations)
{% endcontent-ref %}


# Developing with Sonar

The Sonar solution helps developers find address issues effectively, so code is only promoted when the code is secure and passes the quality gate.

The SonarQube solution helps developers perform automated code analysis and reviews at every stage of the development process:

* SonarQube for IDE provides immediate feedback in your IDE as you write code so you can find, focus on, and fix anticipated issues before a commit.
* SonarQube Cloud’s PR analysis fits into your cloud-based CI/CD workflows so that you merge high-quality code every time.
* Quality gates keep code with issues from being released to production. See [Quality standards and new code](/sonarqube-cloud/standards/about-new-code) for more details.

Organizations start with a set of default rules called the Sonar Way Quality Profile. Quality profiles define the set of [SonarQube rules](/sonarqube-cloud/standards/managing-rules/rules) to be applied during code review and analysis. The Sonar Way can be customized per project to satisfy different technical requirements. See [Understanding quality profiles](/sonarqube-cloud/standards/managing-quality-profiles/understanding-quality-profiles) for more information.

A quality gate is an indicator of code quality that can be configured to give a green or red light on the current release-worthiness of your code. It indicates whether your code complies with the quality standards and can move forward. See [Understanding quality gates](/sonarqube-cloud/standards/managing-quality-gates/introduction-to-quality-gates) for more information.

* A **Passed** (green) quality gate means the code meets your standard and is ready to be merged.
* A **Failed** (red) quality gate means there are issues to address.

SonarQube Cloud provides feedback through its UI, email, and in decorations on pull or merge requests to notify your team that there are issues to address. SonarQube Cloud also provides in-depth guidance on the issues telling you why each issue is a problem and how to fix it, adding a valuable layer of education for developers of all experience levels.

Feedback can also be obtained during automated code review in [SonarQube for IDE](/sonarqube-cloud/analyzing-source-code/connected-mode) when running in Connected Mode. SonarQube for IDE helps developers find, focus on, and fix anticipated issues before a commit. Together, SonarQube for IDE and SonarQube Cloud help developers address issues effectively, so only high-quality code that passes the quality gate is promoted.

Explore featured public projects on SonarQube Cloud and experience how other organizations leverage the platform to improve their code. See [Retrieving your organizations](/sonarqube-cloud/getting-started/viewing-organizations#free-organization).


# What SonarQube Cloud can do

SonarQube Cloud uses static analysis to help you reliable, maintainable, and secure software.

SonarQube Cloud’s code review and analysis is designed to help you achieve a state of high-quality code, that is, code with attributes that contribute to making your software reliable, maintainable, and secure.

To do this, SonarQube Cloud identifies both *issues* and *security hotspots* in your code.

Explore [featured public projects](https://sonarcloud.io/explore/projects) on SonarQube Cloud and experience how other organizations leverage the platform to improve their code.

## Issues <a href="#what-sonar-can-do" id="what-sonar-can-do"></a>

In SonarQube Cloud terminology, an issue is a problem in your code that requires fixing. When scanning for issues, the automated code review algorithms are purposely conservative. They are designed to minimize the number of false positives, that is, things wrongly identified as problems. If the code analysis identifies an issue, you can be quite confident that it really is something that should be fixed. SonarQube Cloud will not overwhelm the developer with false alarms concerning issues.

For details, see the Issues [Introduction](/sonarqube-cloud/managing-your-projects/issues/introduction) page.

## Security hotspots <a href="#security-hotspots" id="security-hotspots"></a>

Security hotspots are areas of the code that may cause security issues and therefore need to be reviewed. By design, automated code review is more permissive when identifying security hotspots than when identifying vulnerabilities and other issues. An issue is almost always a real problem, while a security hotspot can often be a false alarm (but it is still worth checking). By separating hotspots from issues, SonarQube Cloud maintains the accuracy of its issue detection while still providing developers with useful warnings under the less stringent criteria of the hotspot

## Where SonarQube Cloud fits In <a href="#where-sonarcloud-fits-in" id="where-sonarcloud-fits-in"></a>

SonarQube Cloud is designed to be integrated into your CI/CD workflow in order to intervene early when coding, allowing you to remediate fresh issues rapidly and prevent them from reaching production. It does so in three different places: In the IDE, in the pull request, and in the codebase.

### In the IDE <a href="#in-the-ide" id="in-the-ide"></a>

SonarQube Cloud’s companion product, [SonarQube for IDE](/sonarqube-cloud/analyzing-source-code/connected-mode), provides developers with immediate feedback through its automated code review, right in the IDE, catching issues before they even get to the repository. SonarQube for IDE is the first line of defense to find and fix issues in real time, ensuring the quality of the code and enhancing productivity.

Supporting 25 languages and the most popular IDEs, SonarQube for IDE leverages over 5,000 language-specific rules to instantly highlight common coding mistakes and vulnerabilities. In parallel, SonarQube for IDE provides rich contextual educational guidance to help developers improve their skills while resolving the issue.

Sonar’s IDE extensions are available for IntelliJ (and other JetBrains IDEs including IntelliJ IDEA, CLion, WebStorm, PHPStorm, PyCharm, Rider, Android Studio & RubyMine), Visual Studio, VS Code, and Eclipse, and can be installed directly from your IDE’s plugin marketplace.

Much like a spellchecker, automated code review in SonarQube for IDE highlights problems in your code using error squiggles, provides quick fixes, and gives you detailed information about issues found in your code.

In Connected Mode, SonarQube for IDE becomes part of the full SonarQube solution that integrates code review and analysis throughout your development process from IDE to CI pipeline to DevOps platform, helping to make sure that only high-quality code makes it into your project. For more information, see the Connected Mode pages in the SonarQube for IDE docs:

* [Connected mode](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-for-intellij/connect-your-ide/connected-mode) - SonarQube for IntelliJ
* [Connected mode](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-for-visual-studio/connect-your-ide/connected-mode) - SonarQube for Visual Studio
* [Connected mode](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-for-vs-code/connect-your-ide/connected-mode) - SonarQube for VS Code
* [Connected mode](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-for-eclipse/connect-your-ide/connected-mode) - SonarQube for Eclipse

### In the pull request <a href="#in-the-pull-request" id="in-the-pull-request"></a>

Pull requests (on some platforms, called "merge requests") are a mechanism to allow developers to collaborate more effectively. They enable a developer to ask others to review their work (usually their *personal feature branch*) prior to it being merged into the main body of the code, or *main branch*. In the DevOps platform, the pull request is displayed in a dedicated interface that allows the reviewer to see the changes proposed and to either approve or deny the merge.

SonarQube Cloud annotates the pull requst interface of the repository service, providing the results of its code review and analysis on the pull request branch right in the interface and granting or denying approval of the pull request depending on quality gate criteria. In effect, this augments human code review with automatic code review. This feature is often called pull request decoration because it "decorates" the pull request interface with additional information.

### In the codebase <a href="#in-the-codebase" id="in-the-codebase"></a>

Code review and analysis at the IDE and pull request level helps to identify problems before they are merged into the main codebase. However, there are some types of issues and hotspots that can only be found after the code is merged. To find these types of problems, SonarQube Cloud needs to analyze the entire codebase as a single unit and (in the case of some languages) also analyze the results of compiling the code. To do this, SonarQube Cloud offers two approaches: *automatic analysis* and *CI-based analysis*.

## Automatic analysis <a href="#automatic-analysis" id="automatic-analysis"></a>

With automatic analysis, SonarQube Cloud detects every change to your pull requests or main branch and analyzes the new state of the code in your repository. It uses the same set of analysis methods as CI-based analysis (see below) but it is subject to the following restrictions:

* It only works with GitHub and Azure DevOps.
* It does not work on repositories that were imported as monorepos into SonarQube Cloud.
* It does not work on all SonarQube Cloud supported languages.

However, if you're using GitHub or Azure DevOps and the project you imported is in a language that's supported by automatic analysis, no configuration is needed—analysis starts automatically. For details, see the [Automatic analysis](/sonarqube-cloud/analyzing-source-code/automatic-analysis) page.

Because automatic analysis is only available for GitHub and Azure DevOps and doesn't work with certain compiled languages, there are many cases where you'll need to configure CI-based analysis instead.

## CI-based analysis <a href="#ci-based-analysis" id="ci-based-analysis"></a>

A CI-based analysis refers to the configuration of SonarQube Cloud so that it performs code review and analysis as part of your regular continuous integration (CI) process, in other words, your build process.

To enable CI-based analysis you have to install and configure a piece of software called a *scanner*. SonarQube Cloud offers scanner extensions and integrations for all of the leading *continuous integration* (CI) systems used today.

Typically, the scanner is configured to run as part of your continuous integration pipeline so that whenever you push changes to your repository, the scanner is invoked and performs a scan on the code.

The details of how SonarQube Cloud is integrated with your CI/CD process depend on which build tools and the continuous integration system you use. SonarQube Cloud provides custom integrations for the following:

* GitHub Actions
* Bitbucket Pipelines
* Azure Pipelines
* make
* npm
* Maven
* Gradle
* .NET
* Jenkins
* TravisCI
* CircleCI

Additionally, SonarQube Cloud also offers a stand-alone command-line tool (called SonarScanner) that you can install and integrate into your build process manually. For an overview on the SonarScanner, see the [Overview of integrated CIs](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/overview-of-integrated-cis) page.

The results of the scan are sent automatically to SonarQube Cloud where they are processed and made available in the dashboard, that is, the SonarQube Cloud interface itself. There you will find all the results of all code analyzed in your repositories. You can sort and filter the results according to a wide range of criteria in order to get a clear picture of the state of your code.

Additionally, the outcome of the SonarQube Cloud analysis (in both automatic and CI-based analyses) can be used to control subsequent build actions such as automatic deployment, etc.


# SonarQube analysis overview

Understanding how SonarQube Cloud analysis works.

{% content-ref url="/pages/hC3OzmWEph90cprNuRSi" %}
[Basic principles of SonarQube analysis](/sonarqube-cloud/discovering-sonarcloud/analysis-process-overview/basic-principles)
{% endcontent-ref %}

{% content-ref url="/pages/9eNc6tXwusSWLz5xKyCL" %}
[SonarQube analysis process](/sonarqube-cloud/discovering-sonarcloud/analysis-process-overview/analysis-process)
{% endcontent-ref %}


# Basic principles of SonarQube analysis

For an introduction to SonarQube analysis solution, consider the analysis main steps and the concept definitions below.

The SonarQube code analysis process unfolds as follows:

1. **Commit and trigger**: A developer commits changes to their repository, which triggers the Continuous Integration (CI) pipeline.
2. **Analysis start**: The CI pipeline initiates the code analysis.
3. **Scanning and setup**: The SonarScanner scans the repository. It uses the analysis parameters configured for the bound SonarQube project to determine the code to be analyzed. It then instructs the language analyzer(s) to perform their analyses.
4. **Analysis execution**: Each analyzer executes its analysis based on the configured language-specific quality profile, which is a set of defined rules. The analyzer sends the results (issues and measures) back to the SonarScanner, which forwards this information to SonarQube.
5. **Result processing**: SonarQube processes the analysis results, distinguishing between new code and overall code.
   * It identifies, assigns, and surfaces new issues within the uploaded code. (SonarQube uploads the code during analysis to show users where issues are raised; unanalyzed changes are not visible.)
   * It calculates metrics and determines the quality gate status.
   * It generates reports.
6. **Review and fix**: Developers can review the raised issues in SonarQube. Using connected mode, they have the option to fix these issues directly within their Integrated Development Environment (IDE).

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/22TOfGGYyvyBtnLR0TSi" alt="An analysis is started on a developer&#x27;s commit. The SonarScanner analyzes the code and sends the results to SonarQube."><figcaption></figcaption></figure>

## SonarScanner

Stand-alone program running on the CI/CD host that orchestrates the code analysis. It scans the code to retrieve the files to be analyzed according to the configured analysis parameters, sends these files to the analyzers for analysis; sends the analysis results to SonarQube.

The Sonar Solution offers SonarScanners that integrate with the following build systems: Gradle, Maven, .NET, NPM, and Python. For other project types, the SonarScanner CLI which requires more manual configuration is used.

To learn more, see [SonarScanner for Maven](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-maven), [SonarScanner for Gradle](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-gradle), [SonarScanner for .NET](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-dotnet), [SonarScanner for NPM](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-npm), [SonarScanner for Python](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-python), [SonarScanner CLI](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-cli).

## Analysis parameters

Parameters processed by the SonarScanner to manage the code analysis.

To learn more, see [Configuration overview](/sonarqube-cloud/analyzing-source-code/analysis-parameters/configuration-overview).

## Project

Analyzing code with SonarQube involves creating a project in SonarQube. A project corresponds to a repository on your DevOps platform.

To learn more, see [Organization's projects](/sonarqube-cloud/administering-sonarcloud/about-sonarqube-cloud-solution/resources-structure/projects).

## Language analyzer

Program running on the CI/CD host that executes code analysis. An analyzer is specific to a language or language family.

To learn more, see [Supported languages](/sonarqube-cloud/discovering-sonarcloud/overview).

## Quality profile

A quality profile defines the set of rules to be applied by a given language analyzer during code analysis.

To learn more, see [Understanding quality profiles](/sonarqube-cloud/standards/managing-quality-profiles/understanding-quality-profiles).

## Rule

Coding rules define how code should be written, formatted, and organized to ensure security, reliability, and maintainability.

To learn more, see [SonarQube rules](/sonarqube-cloud/standards/managing-rules/rules).

## Issue

When a rule is broken, an issue is raised.

To learn more, see [SonarQube analysis process](/sonarqube-cloud/discovering-sonarcloud/analysis-process-overview/analysis-process#identification-and-assignment).

## New code

New code is code that you’ve recently added or modified. It is identified based on the New Code Definition.

SonarQube differentiates the analysis results on new code from overall code (overall code includes new and old code) to allow focusing your efforts on new code.

To learn more, see [Quality standards and new code](/sonarqube-cloud/standards/about-new-code#focus-on-new-code).

## New Code Definition

The New Code Definition tells SonarQube which part of the code is considered new during analysis. It can be configured at the global, project, or branch level and several definition options are available.

To learn more, see [Quality standards and new code](/sonarqube-cloud/standards/about-new-code#new-code-definitions).

## Quality gate

A quality gate consists of a set of conditions against which the code is measured during analysis. A condition is defined on either new code or overall code. Depending on the result, the code will pass or fail the quality gate, giving developers indications on whether to fix issues or merge the code.

To learn more, see [Understanding quality gates](/sonarqube-cloud/standards/managing-quality-gates/introduction-to-quality-gates).

## Metric

Quantitative, measurable indicators used by SonarQube Cloud to assess the quality, complexity, and security of your code.

To learn more, see [Understanding measures and metrics](/sonarqube-cloud/managing-your-projects/metric-definitions).

## Connected mode

Connected mode binds your SonarQube project to your IDE project through SonarQube for IDE. This way, issues detected by SonarQube are also raised in your IDE.

To learn more, see [SonarQube for IDE](/sonarqube-cloud/analyzing-source-code/connected-mode).

## Related pages

* [SonarQube analysis process](/sonarqube-cloud/discovering-sonarcloud/analysis-process-overview/analysis-process)
* [DevOps platforms](/sonarqube-cloud/discovering-sonarcloud/integration-with-devops-platforms)
* [Integrations](/sonarqube-cloud/discovering-sonarcloud/integrations)

## Related online learning

* <i class="fa-desktop">:desktop:</i> [SonarQube analysis: From local scans to CI/CD automation](https://www.sonarsource.com/learn/course/core-concepts/f16bd24c-2a61-490d-9040-0e90039d14c0/sonarqube-analysis-from-local-scans-to-cicd-automation)


# SonarQube analysis process

This page explains how SonarQube Cloud integrates with your CI pipeline and the main analysis steps.

## Integration into your CI pipeline <a href="#integration-into-ci-pipeline" id="integration-into-ci-pipeline"></a>

Integrating SonarQube into your CI pipeline brings powerful code review capabilities to your projects. Key features include main branch analysis, pull request analysis, and multiple branch analysis, ensuring comprehensive code quality checks at every stage of development.

The following steps outline the integration of the SonarQube analysis into your continuous integration (CI) pipeline for code analysis:

1. **Code commit**: A developer pushes code changes on a branch to the remote repository.
2. **Pipeline trigger**: A CI pipeline is initiated for the specific branch. This is often accomplished using webhooks, which are triggered by events in the Source Control Management (SCM) system, or through monitoring by a CI/CD tool like Jenkins.
3. **Code checkout**: The pipeline clones the remote repository, checking out the relevant branch to the local CI/CD host, thereby copying both the code and the SCM metadata.
4. **Code build** (if necessary): For compiled programming languages, the code is built by the pipeline.
5. **Code analysis**: The appropriate SonarScanner is executed by the pipeline to analyze the code.
6. **Results submission**: The SonarScanner transmits the analysis results to SonarQube for computation.
7. **Quality Gate check** (optional): SonarQube sends the result of the Quality Gate computation back to the CI pipeline.
8. **Pipeline continuation**: The pipeline either proceeds (if the Quality Gate passes) or stops (if the Quality Gate fails).

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/QpyaKjZj1SUEujjmAotH" alt="An overview of the SonarQube Server analysis process."><figcaption></figcaption></figure>

## Scanner engine and analyzers download at analysis time <a href="#scanner-engine-and-analyzers-download" id="scanner-engine-and-analyzers-download"></a>

A SonarScanner is a scanner bootstrapper that downloads the scanner engine and language analyzers from SonarQube at analysis time. This way:

* It ensures that the scanner engine and analyzer versions are compatible with SonarQube.
* Only the analyzers necessary to analyze the detected languages are downloaded.

The figure below shows a simplified view of the download process of the scanner engine and language analyzers. For each analysis run:

1. The CI or build pipeline starts the SonarScanner.
2. The SonarScanner connects to SonarQube to retrieve the scanner engine version to be used. It checks the scanner cache for the scanner engine version. If it doesn’t find it, it downloads it from SonarQube and stores it in the cache.
3. The scanner engine scans the code to identify the different languages used in the project to be analyzed.
4. The scanner engine checks the scanner cache for the required language analyzers. If it doesn’t find them, it downloads them from SonarQube and stores them in the cache.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/oJthldzyS4ZLw8V3dhNi" alt="The SonarScanner downloads the Scanner engine which downloads the language analyzers"><figcaption></figcaption></figure>

## Issue identification and assignment by SonarQube <a href="#identification-and-assignment" id="identification-and-assignment"></a>

For each code file:

1. SonarQube checks if the file has been renamed.
2. SonarQube determines:
   * Whether an issue found during the current analysis is new or existed previously.
   * If an issue found during the previous analysis has been fixed.
3. For each new issue:
   * SonarQube determines and sets the issue date. The issue date is the analysis date except in some cases where issue backdating to the line commit date is necessary.
   * SonarQube tries to automatically assign the issue to an appropriate SonarQube user.

### Method used to identify if an issue is new <a href="#new-issue-identification-method" id="new-issue-identification-method"></a>

SonarQube use the same algorithm to determine whether an issue is new or existed previously:

* For each issue found in the file from the previous analysis, it compares it to each issue found in this file during the current analysis:
  * If there is no match then it considers the issue as Fixed.
  * If there is a match and the issue status is Fixed in the previous analysis then it reopens the issue.
* For each issue found in the file during the current analysis, if there is no matching issue in the file from the previous analysis then it is considered new.

This algorithm relies on the issue’s line hash. The line hash is calculated based on the content of the first line the issue is reported on, excluding the white spaces.

The figure below shows the comparison process between two issues.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/lNwPORlgzp3WivWkUTjo" alt="Questions used by SonarQube to identify whether an issue is new or not"><figcaption></figcaption></figure>

* If the issue is on the same rule, with the same line hash (but not necessarily with the same message) : MATCH
* If the issue is on the same rule, on the same line number with the same message (but not necessarily with the same line hash): MATCH
* If the issue is on the same rule but the detected block moved inside the file, then if the issue is on the same line within the moved block, and has the same message: MATCH

### Issue backdating (new issues raised on old code) <a href="#issue-backdating" id="issue-backdating"></a>

In some corner cases, new issues or issues that didn’t exist in the previous analysis, may be detected on old code or code outside of the new code definition period. This may be the case, for instance, if the issue has existed in code for a long time but was only found in the most recent analysis because new rules were added to the quality profile. In such cases, SonarQube doesn’t apply the analysis date as the issue date but uses backdating so that it can correctly identify whether the new issue is to be reported on new code or old code (overall code).

If the date of the last change to the line is available then SonarQube will backdate to this date an issue identified as new in the following cases:

* On the first analysis of a project or branch.
* When the rule is new in the quality profile (a brand new rule activated or a rule that was deactivated and is now activated) or when a rule parameter was changed.
* When SonarQube has just been upgraded because rule implementations could be smarter now.
* When the rule is external, rule managed and applied by an external, third-party analyzer.
* Previously excluded files are now analyzed.

{% hint style="warning" %}
During a pull request analysis, new issues on old code are not reported since only new code issues are reported. It means that the first analysis on the target branch after the merge may report new issues on old code that were not reported by the pull request analysis.
{% endhint %}

### Automatic issue assignment <a href="#automatic-issue-assignment" id="automatic-issue-assignment"></a>

SonarQube automatically assigns an issue during analysis to the last committer on the issue line - called issue author - if the author can be correlated to a SonarQube user.

Login and email correlations between SCM account and SonarQube user are made automatically. For example, if the user commits with their email address and that email address is part of their SonarQube user profile, then new issues raised on lines where the user was the last committer will be automatically assigned to the user.

{% hint style="info" %}

* Currently, issues on any level above a file, for example, issues reported at a directory or project level, cannot be automatically assigned.
* If the SCM login associated with an issue is longer than 255 characters including the characters for an issue author, the author will be left blank.
  {% endhint %}

## Issue triaging

An issue can have one of the following statuses:

* **Open**: initial value after the first analysis. A user can reopen an **Accepted** or **False positive** issue. 
* **Accepted**: set by an authorized user if they decide to fix the issue later or not fix the issue.  SonarQube ignores **Accepted** issues in the ratings of the code but displays the number of **Accepted** issues in the various analysis snapshots.
* **False positive:** set by an authorized user if the analysis is mistaken.  SonarQube ignores **False positive** issues in the quality reports and the ratings of the code.
* **Fixed**: set by SonarQube after a subsequent analysis if the previously open issue has been fixed in the code (is no longer being detected). SonarQube purges **Fixed** issues after 30 days.

{% hint style="info" %}
If users tend to mark a lot of issues as **False positive**, it means that some coding rules are not appropriate for the project. In that case, rules can be deactivated in quality profiles or the analysis scope of the project can be adjusted to exclude files. See [Editing a quality profile](/sonarqube-cloud/standards/managing-quality-profiles/editing-a-custom-quality-profile) and [Analysis scope](/sonarqube-cloud/managing-your-projects/project-analysis/setting-analysis-scope) for more information.
{% endhint %}

The figure below shows the issue life cycle.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/6Vg4cOGird3Ulax8HGD2" alt="The different statuses an issue can have during its lifecycle in SonarQube"><figcaption></figcaption></figure>

## Related pages

* [Basic principles of SonarQube analysis](/sonarqube-cloud/discovering-sonarcloud/analysis-process-overview/basic-principles)
* [DevOps platforms](/sonarqube-cloud/discovering-sonarcloud/integration-with-devops-platforms)
* [Integrations](/sonarqube-cloud/discovering-sonarcloud/integrations)

## Related online learning

* <i class="fa-desktop">:desktop:</i> [SonarQube analysis: From local scans to CI/CD automation](https://www.sonarsource.com/learn/course/core-concepts/f16bd24c-2a61-490d-9040-0e90039d14c0/sonarqube-analysis-from-local-scans-to-cicd-automation)


# Supported languages

A full list of programming languages supported by SonarQube Cloud analysis.

SonarQube Cloud is an automated code review and static code analysis solution for several languages to satisfy your unique needs. Some languages are available only with the [Enterprise plan](/sonarqube-cloud/getting-started-with-enterprise/introduction).

The table below lists the supported languages. For the supported versions and language-specific properties, refer to each language page directly. See *Related pages* below.

Infrastructure as Code (IaC) analysis is supported for the following languages listed in the table below: Ansible, Azure Resource Manager, CloudFormation, Docker, Kubernetes, Terraform.

<table><thead><tr><th>Language</th><th width="187">SonarQube Community Build</th><th>SonarQube Cloud</th><th>SonarQube Server</th></tr></thead><tbody><tr><td>ABAP</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"><br>Enterprise Plan</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Ansible</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Apex</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"><br>Enterprise Plan</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"><br>From Enterprise</td></tr><tr><td>Azure Resource Manager</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>C</td><td><p><br></p><p><br></p></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>C++</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>CloudFormation</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>COBOL</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"><br>Enterprise Plan</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"><br>From Enterprise</td></tr><tr><td>C#</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>CSS</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Dart</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Docker</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Flex</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>GitHub Actions</td><td></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Go</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Gosu</td><td></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"><br>From Enterprise</td></tr><tr><td>Groovy</td><td></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>HTML</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Java</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>JavaScript</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>JCL</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"><br>Enterprise Plan</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"><br>From Enterprise</td></tr><tr><td>JSON</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Kotlin</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Kubernetes/Helm</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Objective-C</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>PHP</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>PL/I</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"><br>Enterprise Plan</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"><br>From Enterprise</td></tr><tr><td>PL/SQL</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Powershell (in beta)</td><td></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Python</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>RPG</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"><br>Enterprise Plan</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"><br>From Enterprise</td></tr><tr><td>Ruby</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Rust</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Scala</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Secrets</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Shell</td><td></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Swift</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>Terraform</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>TypeScript</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>TSQL</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>VB.NET</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>VB6</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"><br>From Enterprise</td></tr><tr><td>XML</td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr><tr><td>YAML</td><td><br></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td><td><img src="/spaces/KXW79zfYFiA8incTvwZK/files/EIEIaB8tMCJU7EyKfkBK" alt="Checkmark icon"></td></tr></tbody></table>

## Related pages <a href="#related-pages" id="related-pages"></a>

* [ABAP](/sonarqube-cloud/analyzing-source-code/languages/abap)
* [Ansible](/sonarqube-cloud/analyzing-source-code/languages/ansible)
* [Apex](/sonarqube-cloud/analyzing-source-code/languages/apex)
* [Azure Resource Manager](/sonarqube-cloud/analyzing-source-code/languages/azure-resource-manager)
* [C/C++/Objective-C analysis overview](/sonarqube-cloud/analyzing-source-code/languages/c-family/overview)
* [C#](/sonarqube-cloud/analyzing-source-code/languages/csharp)
* [CloudFormation](/sonarqube-cloud/analyzing-source-code/languages/cloudformation)
* [COBOL](/sonarqube-cloud/analyzing-source-code/languages/cobol)
* [Dart](/sonarqube-cloud/analyzing-source-code/languages/dart)
* [Docker](/sonarqube-cloud/analyzing-source-code/languages/docker)
* [Flex](/sonarqube-cloud/analyzing-source-code/languages/flex)
* [GitHub Actions](/sonarqube-cloud/analyzing-source-code/languages/github-actions)
* [Go](/sonarqube-cloud/analyzing-source-code/languages/go)
* [Groovy](/sonarqube-cloud/analyzing-source-code/languages/groovy)
* [HTML](/sonarqube-cloud/analyzing-source-code/languages/html)
* [Java](/sonarqube-cloud/analyzing-source-code/languages/java)
* [JavaScript/TypeScript/CSS](/sonarqube-cloud/analyzing-source-code/languages/javascript-typescript-css)
* [JCL](/sonarqube-cloud/analyzing-source-code/languages/jcl)
* [JSON](/sonarqube-cloud/analyzing-source-code/languages/json)
* [Kotlin](/sonarqube-cloud/analyzing-source-code/languages/kotlin)
* [Kubernetes/Helm](/sonarqube-cloud/analyzing-source-code/languages/kubernetes)
* [PHP](/sonarqube-cloud/analyzing-source-code/languages/php)
* [PL/I](/sonarqube-cloud/analyzing-source-code/languages/pl-i)
* [PL/SQL](/sonarqube-cloud/analyzing-source-code/languages/pl-sql)
* [PowerShell](/sonarqube-cloud/analyzing-source-code/languages/powershell)
* [Python](/sonarqube-cloud/analyzing-source-code/languages/python)
* [RPG](/sonarqube-cloud/analyzing-source-code/languages/rpg)
* [Ruby](/sonarqube-cloud/analyzing-source-code/languages/ruby)
* [Rust](/sonarqube-cloud/analyzing-source-code/languages/rust)
* [Scala](/sonarqube-cloud/analyzing-source-code/languages/scala)
* [Secrets](/sonarqube-cloud/analyzing-source-code/languages/secrets)
* [Shell](/sonarqube-cloud/analyzing-source-code/languages/shell)
* [Swift](/sonarqube-cloud/analyzing-source-code/languages/swift)
* [Terraform](/sonarqube-cloud/analyzing-source-code/languages/terraform)
* [T-SQL](/sonarqube-cloud/analyzing-source-code/languages/t-sql)
* [VB.NET](/sonarqube-cloud/analyzing-source-code/languages/vb-net)
* [VB6](/sonarqube-cloud/analyzing-source-code/languages/vb6)
* [XML](/sonarqube-cloud/analyzing-source-code/languages/xml)
* [YAML](/sonarqube-cloud/analyzing-source-code/languages/yaml)


# DevOps platforms

SonarQube Cloud integrates with Azure DevOps, GitHub, Bitbucket Cloud, and GitLab to streamline code quality analysis and security into your DevOps pipelines.

This integration allows you to import your DevOps platform organization and its repositories into SonarQube Cloud, automatically binding SonarQube Cloud projects to their corresponding DevOps platform repositories. The integration also enables features like automatically triggering analysis in your CI/CD pipeline, displaying quality gate status in your DevOps pipeline, and preventing merges when the quality gate fails.

By default, users can authenticate to SonarQube Cloud with their existing credentials on their DevOps platform service (no additional setup is required). With the DevOps platform service authentication, Just-in-Time user provisioning is used.

{% hint style="info" %}
With the Enterprise plan, you can use Single Sign On authentication. See [Subscription plans](/sonarqube-cloud/administering-sonarcloud/managing-subscription/subscription-plans) for more information.
{% endhint %}

{% content-ref url="/pages/0s9avdl3qbWbG1Hhf9Ok" %}
[GitHub](/sonarqube-cloud/discovering-sonarcloud/integration-with-devops-platforms/github)
{% endcontent-ref %}

{% content-ref url="/pages/odaHCyL8gAbKBSbGZTuv" %}
[Bitbucket Cloud](/sonarqube-cloud/discovering-sonarcloud/integration-with-devops-platforms/bitbucket-cloud)
{% endcontent-ref %}

{% content-ref url="/pages/uPFTRqAcNx6oSpNn694p" %}
[GitLab](/sonarqube-cloud/discovering-sonarcloud/integration-with-devops-platforms/gitlab)
{% endcontent-ref %}

{% content-ref url="/pages/8Dk9vRN7zA40BSwD1vbo" %}
[Azure DevOps](/sonarqube-cloud/discovering-sonarcloud/integration-with-devops-platforms/azure-devops)
{% endcontent-ref %}


# GitHub

SonarQube Cloud's integration with GitHub allows you to maintain code quality and security in your GitHub repositories.

{% hint style="success" %}
To get started analyzing your GitHub projects with SonarQube Cloud, see [Getting started with GitHub](/sonarqube-cloud/getting-started/github).
{% endhint %}

SonarQube Cloud’s integration is supported with GitHub plans running on the [github.com](https://github.com/) domain and on the ghe.com domain used for GitHub Enterprise Cloud with Data Residency.

## Key features <a href="#key-features" id="key-features"></a>

With this integration, you’ll be able to:

* Authenticate with GitHub (through the SonarQube Cloud GitHub application).\
  Automatic member synchronization is supported.
* Import your GitHub organization and its repositories into SonarQube Cloud to easily set up SonarQube Cloud projects.\
  The following additional features are supported:
  * The auto-import of new GitHub repositories.
  * The bulk import of all existing repositories.
  * The automatic analysis of the projects’ main branch.
* Analyze projects with GitHub Actions.\
  SonarScanners running in GitHub Actions jobs can automatically detect branches or pull requests being built.\
  You can fail the job if the SonarQube quality gate fails.
* Report your quality gate status to your branches and pull requests.\
  You can see your quality gate and code metric results right in GitHub so you know if it’s safe to merge your changes. You can prevent pull request merges when the quality gate fails.
* Display security issues found by SonarQube Cloud as code scanning alerts in the GitHub interface (not yet supported with GHE.com Cloud).
* Import your monorepo into SonarQube Cloud to easily manage the related projects.

## Related pages

* [Getting started with GitHub](/sonarqube-cloud/getting-started/github)
* [Github Actions](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/github-actions-for-sonarcloud)
* [Importing GitHub.com organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-github-organization)
* [Importing GHE.com Cloud organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-ghecom-cloud-organization)
* [Creating your project](/sonarqube-cloud/managing-your-projects/administering-your-projects/setting-up-project#creating-manually)


# Bitbucket Cloud

SonarQube Cloud's integration with Bitbucket Cloud allows you to maintain code quality and security in your Bitbucket Cloud repositories.

{% hint style="success" %}
To get started analyzing your Bitbucket Cloud projects with SonarQube Cloud, see [Getting started with Bitbucket Cloud](/sonarqube-cloud/getting-started/bitbucket-cloud).
{% endhint %}

## Key features <a href="#key-features" id="key-features"></a>

With SonarQube Cloud’s integration with Bitbucket Cloud, you’ll be able to:

* Authenticate with Bitbucket Cloud (through OAuth authentication).
* Import your Bitbucket workspace and its repositories into SonarQube Cloud to easily set up SonarQube Cloud projects.
* Analyze projects with Bitbucket Pipelines.\
  SonarScanners running in Bitbucket Pipelines can automatically detect branches or pull requests being built.\
  You can fail the pipeline if the SonarQube quality gate fails.
* Report your quality gate status to your branches and pull requests.\
  You can see your quality gate and code metric results right in Bitbucket Cloud so you know if it’s safe to merge your changes. You can prevent pull request merges when the quality gate fails.
* Import your monorepo into SonarQube Cloud to easily manage the related projects.

## Related pages

* [Getting started with Bitbucket Cloud](/sonarqube-cloud/getting-started/bitbucket-cloud)
* [Importing Bitbucket workspace](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-bitbucket-workspace)
* [Bitbucket Pipelines](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/bitbucket-pipelines-for-sonarcloud)


# GitLab

SonarQube Cloud's integration with GitLab allows you to maintain code quality and security in your GitLab projects.

{% hint style="success" %}
To get started analyzing your GitLab projects with SonarQube Cloud, see [Getting started with GitLab](/sonarqube-cloud/getting-started/gitlab).
{% endhint %}

## Key features <a href="#key-features" id="key-features"></a>

With SonarQube Cloud’s integration with GitLab, you’ll be able to:

* Authenticate with GitLab (through OAuth authentication).
* Import your GitLab group and its projects into SonarQube Cloud to easily set up SonarQube Cloud projects.\
  The bulk import of all existing repositories is supported.
* Analyze projects with GitLab CI/CD.\
  SonarScanners running in GitLab CI/CD jobs can automatically detect branches or merge requests being built.\
  You can fail the job if the SonarQube quality gate fails.
* Report your quality gate status to your branches and merge requests (merge request decoration).\
  You can see your quality gate and code metric results right in GitLab so you know if it’s safe to merge your changes. You can prevent merges when the quality gate fails.
* Import your monorepo into SonarQube Cloud to easily manage the related projects.

{% hint style="info" %}
You can use CI-based analysis from Self-hosted GitLab CI pipelines. However, since there is no native DevOps binding to Self-hosted GitLab in SonarQube Cloud (only to gitlab.com), the following features are not supported:

* Direct sign-up to SonarQube Cloud using Self-hosted GitLab OAuth.\
  Note that you can integrate your Self-hosted GitLab authentication indirectly by using [Single Sign-On](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning).
* GitLab group and repositories import.
* Merge request decoration.
  {% endhint %}

## Related pages

* [Getting started with GitLab](/sonarqube-cloud/getting-started/gitlab)
* [Importing GitLab group](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-gitlab-group)
* [GitLab CI](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/gitlab-ci)
* [Creating your project](/sonarqube-cloud/managing-your-projects/administering-your-projects/setting-up-project#creating-manually)


# Azure DevOps

SonarQube Cloud’s integration with Azure DevOps allows you to maintain code quality and security in your Azure DevOps repositories. It is compatible with Azure DevOps Services.

{% hint style="success" %}
To get started analyzing your Azure DevOps projects with SonarQube Cloud, see [Getting started with Azure DevOps](/sonarqube-cloud/getting-started/azure-devops).
{% endhint %}

## Key features <a href="#key-features" id="key-features"></a>

With this integration, you’ll be able to:

* Sign in to SonarQube Cloud with your Azure DevOps credentials.
* Import your Azure DevOps repositories into SonarQube Cloud to easily set up SonarQube Cloud projects.
* Use Automatic analysis to quickly analyze your code without configuring the need to configure a CI-based analysis. This lets you analyze the main branch and any pull request.
* Use the Azure DevOps extension for SonarQube to integrate SonarQube Cloud analyses into your Azure build pipeline. This includes multi-branch analysis features.
* Report the analysis’ quality gate status right in Azure Pipeline’s Build Summary page.
* Prevent pull request merges when the quality gate fails.
* View issues detected on a pull request in Azure DevOps.\
  Each issue will be a comment on the Azure DevOps pull request. If you change the status of an issue in SonarQube Cloud, that status change is immediately reflected in the Azure DevOps interface.
* Import your monorepo into SonarQube Cloud to easily manage the related projects.

<div align="left"><figure><img src="/files/gQMeoNyiABRZtna1GIqz" alt="SonarQube Cloud and Azure DevOps integration overview."><figcaption><p>How the Azure DevOps extension for SonarQube integrates with SonarQube Cloud</p></figcaption></figure></div>

## Related pages

* [Automatic analysis](/sonarqube-cloud/analyzing-source-code/automatic-analysis)
* [Azure Pipelines integration overview](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/azure-pipelines/azure-pipelines-integration-overview)
* [Getting started with Azure DevOps](/sonarqube-cloud/getting-started/azure-devops)
* [Importing Azure DevOps organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-azure-devops-organization)
* [Azure DevOps Extension](/sonarqube-cloud/analyzing-source-code/scanners/sonarcloud-extension-for-azure-devops)
* [Azure pipelines](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/azure-pipelines)
* [Adding analysis to build pipeline](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/azure-pipelines/adding-analysis-to-build-pipeline)
* [Checking quality gate in release pipeline](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/azure-pipelines/quality-gate-status-in-release-pipeline)


# Integrations

SonarQube Cloud supports webhooks and integrates with applications across various domains.

{% content-ref url="/pages/PFPFVu2nKhVxLSxYp9kj" %}
[Slack](/sonarqube-cloud/discovering-sonarcloud/integrations/integration-overview)
{% endcontent-ref %}

{% content-ref url="/pages/QvvdBASw36JnZJSBwKfd" %}
[Jira Cloud](/sonarqube-cloud/discovering-sonarcloud/integrations/jira-cloud)
{% endcontent-ref %}

{% content-ref url="/pages/sGaLgPcRHiptlKGYqktw" %}
[JFrog Evidence Collection](/sonarqube-cloud/discovering-sonarcloud/integrations/jfrog)
{% endcontent-ref %}

{% content-ref url="/pages/zRYJWia4t0pDfOIrRjIX" %}
[Webhooks](/sonarqube-cloud/discovering-sonarcloud/integrations/webhooks)
{% endcontent-ref %}


# Slack

Understanding how the SonarQube Cloud integration with Slack works.

{% hint style="success" %}
To set up the SonarQube Cloud integration with Slack, see [Connecting SonarQube Cloud to Slack](/sonarqube-cloud/administering-sonarcloud/integrations/setup).
{% endhint %}

With the SonarQube Cloud integration with Slack, users can receive real-time notifications on analysis results directly in Slack. Currently, a notification is triggered when the quality gate status of a project’s main branch analysis transitions from Passed to Failed or from Failed to Passed.

The Slack messages contain context-rich notifications for immediate action, significantly cutting context-switching and improving code review feedback loop efficiency. Check out this [video](https://www.youtube.com/watch?v=oW-pp4LN9r0) on how to benefit from the Slack integration.

{% hint style="info" %}
Read our [privacy notice](https://www.sonarsource.com/company/privacy/) to learn how your personal data is collected, processed and stored.
{% endhint %}

{% hint style="warning" %}
The Slack integration is currently not supported in the SonarQube Cloud's US instance.
{% endhint %}

## Overview

The SonarQube App for Slack, installed in your Slack workspace, allows the integration of SonarQube Cloud with Slack:

* SonarQube Cloud is connected at the global level to your Slack workspace.\
  A Slack workspace admin connects the Slack workspace to SonarQube Cloud. This process links their Slack account with their SonarQube Cloud account.
* Users log in to the SonarQube App for Slack by connecting their SonarQube Cloud and Slack accounts.
* Any Slack channel can be subscribed to notifications on one or several SonarQube Cloud projects distributed across different organizations:
  * The channel’s member who performs the subscription must have Browse access to the project in SonarQube Cloud.
  * All channel members receive the notifications.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/c7TqT8uwkNea94LT8FmO" alt="The SonarQube App for Slack, installed in your Slack workspace, allows the integration of SonarQube Cloud with Slack"><figcaption></figcaption></figure>

## Security <a href="#security" id="security"></a>

SonarQube Cloud and Slack utilize OAuth 2.0 for their integration, ensuring secure data transfer. This is achieved through secure token handling, encryption, and robust access controls, all contributing to the highest security standards.

## Notification process <a href="#notification-process" id="notification-process"></a>

The notification process is as follows:

1. When an event to be notified occurs in SonarQube Cloud following the analysis of Project\_abc, SonarQube Cloud sends the event notification to the SonarQube App for Slack to be sent to each Slack channel subscribed to this project.
2. The SonarQube App for Slack forwards the messages to all subscribed channels. All channel members receive the message.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/0VP8mtWVPOrFHKCBHJkZ" alt="An event in SonarQube Cloud is notified in a Slack channel subscribed to the respective SonarQube Cloud project."><figcaption></figcaption></figure>

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Connecting SonarQube Cloud to Slack](/sonarqube-cloud/administering-sonarcloud/integrations/setup)
* [Subscribing to Slack notifications](/sonarqube-cloud/managing-your-account/subscribing-to-slack-notifications)


# Jira Cloud

Understanding and using the SonarQube Cloud integration with Jira Cloud.

*The Jira Cloud integration is available in the Team and Enterprise plans.*

{% hint style="success" %}
To set up the SonarQube Cloud integration with Jira Cloud, see [Connecting your organization to Jira Cloud](/sonarqube-cloud/administering-sonarcloud/integrations/jira-cloud).
{% endhint %}

Push any SonarQube finding into your Jira sprint in two clicks. The work item is pre-filled with the file path, code lines, commit, rule, and severity. Your team tracks it on their board like any other work item — no copy-pasting, no context switching, no findings lost between tools.

* **Push to Jira** — Create a Jira work item from any issue without leaving SonarQube. All context transfers automatically.
* **Bulk push** — Select up to 500 issues and group them into a single Jira work item, useful for batching a sprint's worth of debt or security findings.
* **Release widget** — A widget on your main branch Summary page shows open Jira items in your upcoming release, so you know what's tracked before you ship.
* **No new workflow** — Issues appear as standard Jira work items on your existing boards with your existing work types.

## What's in the Jira work item <a href="#work-item-contents" id="work-item-contents"></a>

A Jira work item includes the following information for each connected issue:

* Title of the connected SonarQube issue.
* SonarQube issue link.
* Location of the issue.
* File path.
* Code lines.
* Commit hash.
* Date the issue was introduced.
* Information about why this is an issue and how to fix it with the rule name and link.
* Impact on software quality and severity.

The reporter for each Jira work item is the Atlassian account used for the org connection — see [#how-it-works](#how-it-works "mention") for why this matters.

You can navigate from the Jira work item back to the SonarQube issue and vice versa. To disconnect the link, click the close icon on the Jira badge in SonarQube. This removes the connection in SonarQube but does not delete the work item in Jira.

{% hint style="info" %}

* It is not possible to push a SonarQube issue to an existing Jira work item.
* A user cannot push the same issue to multiple Jira work items.
  {% endhint %}

{% hint style="warning" %}
**When to push to Jira, and when not to.** SonarQube has built-in issue assignment — you can assign any issue to a developer directly. Push to Jira when the fix needs to enter sprint planning, requires cross-team visibility, or must appear on your Jira board. Do not push every issue to Jira. It creates noise in both tools and makes neither the source of truth.
{% endhint %}

## For AI agents <a href="#for-ai-agents" id="for-ai-agents"></a>

{% hint style="info" %}
**Product:** SonarQube Cloud only (not SonarQube Server) · **Plan:** Team or Enterprise required

**Setup sequence — must follow in this order:**

1. Org admin: **Your Organization → Administration → Organization settings → Jira → Connect** (OAuth 2.0 3LO authorization flow)
2. Project admin: **Your Project → Administration → General Settings → Jira** (select Jira space and enable work types)
3. Developer: Push to Jira button appears automatically on all issues in bound projects

**If Push to Jira button is not visible:**

* Org not connected to Jira → org admin must complete step 1
* Org connected but project not bound → project admin must complete step 2
* Both configured but all work types greyed out → mandatory Jira fields blocking

See [#troubleshooting](#troubleshooting "mention") for full details and fixes.

**Critical:** reporter = Atlassian account from step 1 (see [#how-it-works](#how-it-works "mention") warning). Use a team or service account, not a personal account.

**Hard limits:** 500 issues max per bulk push · new work items only (cannot push to existing) · Jira Cloud only, not Data Center or Server · connection expires after 3 months of inactivity · only Summary, Description, and Reporter fields are populated
{% endhint %}

## Who needs to do what <a href="#who-needs-to-do-what" id="who-needs-to-do-what"></a>

Three roles, three different jobs. You only need to do yours.

* **Organization admin** — Connect SonarQube Cloud to your Jira Cloud instance once. This unlocks the integration for your entire organization. See [Connecting your organization to Jira Cloud](/sonarqube-cloud/administering-sonarcloud/integrations/jira-cloud).
* **Project admin** — Bind this project to a Jira space and choose which work types developers can create. See [Connecting your project to Jira Cloud](/sonarqube-cloud/managing-your-projects/administering-your-projects/integrations/jira-cloud).
* **Developer** — Once both setup steps are done, the Push to Jira button appears on every issue. See [Pushing issues to Jira](/sonarqube-cloud/managing-your-projects/issues/pushing-issues-to-jira).

{% hint style="info" %}
Not sure if your org is already connected? Check **Your Organization → Administration → Organization settings → Jira**. If a Jira site URL appears with a green "Connected" badge, skip straight to project-level setup.
{% endhint %}

## Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* SonarQube Cloud organization on **Team or Enterprise** plan
* **Organization admin** access in SonarQube Cloud (for the org connection)
* An Atlassian account that is a member of the Jira Cloud instance and all Jira projects you want to connect (the OAuth app requests `read:jira-work`, `manage:jira-configuration`, and `write:jira-work` during the connection flow)
* A **Jira Cloud** instance — Jira Data Center and Jira Server are not supported
* **Project admin** access in SonarQube Cloud on the specific project (for project binding)
* No additional access required for developers — any org member can push issues once the project is bound

## How it works <a href="#how-it-works" id="how-it-works"></a>

The integration runs at three levels. They happen in order, once each, then get out of the way.

1. **Organization admin connects once.** They authorize SonarQube Cloud to access your Jira Cloud instance via OAuth 2.0 3LO.
2. **Project admins bind their projects.** Each project connects to a specific Jira space and picks which work types developers can create from it.
3. **Developers push issues.** The Push to Jira button appears on every issue in a bound project. One click to push, one more to pick a work type if there is more than one.

{% hint style="warning" %}
**One decision before step 1 that is hard to change later.** The Atlassian account used for the org connection becomes the reporter on every Jira work item this integration ever creates, regardless of who clicks Push to Jira. Use a shared team account or service account. You can reauthorize later with a different account, but that changes the reporter on all future work items.
{% endhint %}

## Jira release widget <a href="#jira-widget" id="jira-widget"></a>

<div align="left"><figure><img src="/files/qGAfojDTPvTUDNeDE0K9" alt="The Jira widget on the main branch Summary page shows open work items in the upcoming release."><figcaption></figcaption></figure></div>

The main branch Summary page of each bound project shows the count of open Jira work items in the earliest unreleased version of your connected Jira space.

Two things to know before you expect this widget to work:

1. **Your Jira space must use the Jira Releases concept.** If it does not, the widget shows a warning instead of a count. Enable Releases in Jira first, or accept that this widget will not show data for your project. The Push to Jira button on individual issues works regardless.
2. **The widget counts all open items in that version, not just those created from SonarQube.** If your team tracks other work in the same Jira version, those items appear in the count too. This is expected.

{% hint style="info" %}
If two or more unreleased versions share the same date or have no assigned date, the widget selects the version with the lowest release ID, which is the release that was created first.
{% endhint %}

Click the count to navigate to those open items in Jira Cloud.

## Troubleshooting <a href="#troubleshooting" id="troubleshooting"></a>

### "Push to Jira" button is not visible <a href="#push-button-not-visible" id="push-button-not-visible"></a>

Work through these causes in order:

1. **The organization is not connected to Jira.** Check **Your Organization → Administration → Organization settings → Jira**. If no Jira instance is listed, an org admin must complete the connection. See [Connecting your organization to Jira Cloud](/sonarqube-cloud/administering-sonarcloud/integrations/jira-cloud).
2. **This project is not bound to a Jira space.** Check **Your Project → Administration → General Settings → Jira**. If no Jira space is listed, a project admin must bind this project. See [Connecting your project to Jira Cloud](/sonarqube-cloud/managing-your-projects/administering-your-projects/integrations/jira-cloud).
3. **All work types are greyed out.** See [#all-work-types-greyed-out](#all-work-types-greyed-out "mention") below.

### All Jira work types are greyed out <a href="#all-work-types-greyed-out" id="all-work-types-greyed-out"></a>

Every available work type has at least one mandatory custom field with no default value that SonarQube Cloud cannot fill. SonarQube Cloud fills only the Summary, Description, and Reporter fields. Any work type with additional mandatory fields is disabled.

**Fix:** In Jira, open the affected work type's field configuration and either remove the mandatory requirement or set a default value. Return to SonarQube Cloud project settings — the work type should now be selectable.

{% hint style="info" %}
If the Reporter field itself is mandatory in a way that conflicts with how SonarQube sets the reporter, set a default value for Reporter in Jira.
{% endhint %}

At least one supported Jira work type is required to save the configuration.

### Jira connection expired <a href="#connection-expired" id="connection-expired"></a>

If the integration is not used for more than three months, its access authorization will expire. The org admin must reauthorize:

1. Go to **Your Organization → Administration → Organization settings → Jira → Reauthorize**.
2. Reauthorizing is non-destructive — existing project bindings and issue-to-work-item connections remain intact.
3. Always select the same Jira instance during reauthorization.

If the admin who originally connected the integration has left, a new org admin must reauthorize with their own Atlassian account.

### Jira widget shows a warning instead of a count <a href="#widget-warning" id="widget-warning"></a>

The connected Jira space does not use the Jira Releases concept, or has no unreleased versions defined. Enable Releases in Jira Cloud and create at least one unreleased version. The Push to Jira button on individual issues works regardless.

## Limits <a href="#limits" id="limits"></a>

| Limit                              | Value                                                   |
| ---------------------------------- | ------------------------------------------------------- |
| Issues per bulk push               | Up to 500, grouped into a single work item              |
| Push to an existing Jira work item | Not supported                                           |
| Jira Data Center or Server         | Not supported — Jira Cloud only                         |
| Custom field population            | Not supported — only Summary, Description, and Reporter |
| Connection expiry on inactivity    | 3 months                                                |

## Quick reference <a href="#quick-reference" id="quick-reference"></a>

| Task                                | Navigation path                                                                 |
| ----------------------------------- | ------------------------------------------------------------------------------- |
| Connect org to Jira                 | Your Organization → Administration → Organization settings → Jira → Connect     |
| Grant project admins binding access | Organization settings → Jira → Grant project administrators binding permissions |
| Bind project to a Jira space        | Your Project → Administration → General Settings → Jira                         |
| Push a single issue                 | Issue detail page → Push to Jira → select work type                             |
| Push multiple issues                | Issues page → select issues (up to 500) → Push to Jira                          |
| Reauthorize expired connection      | Organization settings → Jira → Reauthorize                                      |

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Connecting your organization to Jira Cloud](/sonarqube-cloud/administering-sonarcloud/integrations/jira-cloud)
* [Connecting your project to Jira Cloud](/sonarqube-cloud/managing-your-projects/administering-your-projects/integrations/jira-cloud)
* [Pushing issues to Jira](/sonarqube-cloud/managing-your-projects/issues/pushing-issues-to-jira)


# JFrog Evidence Collection

Understanding the SonarQube Cloud integration with JFrog Evidence Collection.

*This integration requires the SonarQube Cloud Enterprise license.*

{% hint style="success" %}
To set up your pipeline to use the JFrog CLI to create the Sonar evidence, see the [JFrog pipelines documentation](https://jfrog.com/help/r/jfrog-pipelines-documentation/jfrog-pipelines).
{% endhint %}

The [JFrog Evidence Collection](https://jfrog.com/evidence/) expands JFrog’s Release Lifecycle Management capabilities to enrich artifacts, builds, and release bundles with signed attestation metadata that can be easily tracked and verified for governance and compliance.

SonarQube Cloud integrates with JFrog Evidence Collection to provide trusted auditing for software packages.

## Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* SonarQube Cloud Enterprise license
* JFrog Artifactory Enterprise+ license
* Minimum JFrog CLI version: 2.78.9

## Integration overview <a href="#integration-overview" id="integration-overview"></a>

The [JFrog CLI](https://docs.jfrog-applications.jfrog.io/jfrog-applications/jfrog-cli) is used within the CI pipeline to create the Sonar evidence that will be displayed on the JFrog platform. This evidence contains the quality gate status computed by SonarQube Cloud and made accessible via its API.

The figure below shows the process:

1. The CI pipeline starts the SonarQube analysis.
2. The SonarScanner performs the analysis and sends the results to SonarQube Cloud.
3. SonarQube Cloud processes the analysis results and computes the quality gate status.
4. The CI pipeline asks JFrog CLI to create the Sonar evidence for the analysis.
5. The JFrog CLI, which waits for the analysis completion, retrieves SonarQube analysis evidence payload from SonarQube Cloud's endpoint: [api.sonarcloud.io/dop-translation/jfrog-evidence](https://api.sonarcloud.io/dop-translation/jfrog-evidence/%7BtaskId%7D) (see [#example-of-a-sonar-endpoint-response](#example-of-a-sonar-endpoint-response "mention") below).

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/C12AVUaNIQfBCBNaEcS0" alt="The JFrog CLI waits for the SonarQube Cloud analysis completion, retrieves SonarQube analysis evidence payload from SonarQube Cloud&#x27;s endpoint, creates the Sonar evidence, and sends it to JFrog Evidence Collection."><figcaption></figcaption></figure>

## Example of a Sonar endpoint response <a href="#endpoint-response" id="endpoint-response"></a>

The endpoint response contains the evidence payload in JSON format with a markdown section.

```json
{
   "predicateType":"https://jfrog.com/evidence/sonarqube/v1",
   "predicate":{
      "projectStatus":{
         "status":"ERROR",
         "ignoredConditions":false,
         "caycStatus":"non-compliant",
         "conditions":[
            {
               "status":"ERROR",
               "metricKey":"new_coverage",
               "comparator":"LT",
               "errorThreshold":"85",
               "actualValue":"82.50562381034781"
            },
            {
               "status":"OK",
               "metricKey":"skipped_tests",
               "comparator":"GT",
               "actualValue":"0"
            }
         ],
         "period":{
            "mode":"last_version",
            "date":"2000-04-27T00:45:23+0200",
            "parameter":"2015-12-07"
         }
      }
   },
    "createdAt": "2222-01-01T00:00:00.000Z",
    "createdBy": "SonarQube",
    "markdown": "# SVG in Markdown example\n\n## Details\n\n- **Type**: svg examples\n\nThis demonstrates the syntax for embedding an SVG without a separate file.\n\n!"
}
```


# Webhooks

Understanding webhooks in SonarQube Cloud.

*This feature is only available in the Team and Enterprise plans.*

{% hint style="success" %}
To configure your webhooks, see:

* [Configuring webhooks for your organization](/sonarqube-cloud/administering-sonarcloud/integrations/webhooks)
* [Configuring webhooks for your project](/sonarqube-cloud/managing-your-projects/administering-your-projects/integrations/webhooks)
  {% endhint %}

Webhooks notify external services when:

* A project analysis is complete.\
  This is done regardless of the status of the background task or of the quality gate.
* An issue type, severity, or status is updated, and this update changes the quality gate status.\
  For example:
  * A user marks an issue as False Positive and the quality gate status turns green.
  * The severity of an issue is increased and the quality gate status turns red.

An HTTP(S) call including a JSON payload is sent to each configured URL. URLs may be specified at both the project and global levels. The project-level specification does not replace global-level webhooks. All hooks at both levels are called.

## HTTP(S) call <a href="#https-call" id="https-call"></a>

The HTTP(S) call:

* Has an HTTP header `X-SonarQube-Project` with the project key to allow quick identification of the project involved.
* Includes a JSON document as payload, using the POST method. See below.
* Has a content type of `application/json`, with UTF-8 encoding.

## Payload <a href="#payload" id="payload"></a>

The payload is a JSON document that includes:

* `analysedAt`: when the analysis was performed.
* `project`: the identification of the project analyzed.
* `qualityGate`: each quality gate criterion checked and its status.
* `qualityGate.status`: the quality gate status of the analysis.
* `status` and `taskID`: the status and the identifier of the background task.
* `properties`: user-specified properties.

{% hint style="info" %}
You can define project parameters to be added to the payload.
{% endhint %}

<details>

<summary>Payload example</summary>

```json
{
    "serverUrl": "<mySonarqubeURL>",
    "taskId": "AVh21JS2JepAEhwQ-b3u",
    "status": "SUCCESS",
    "analysedAt": "2016-11-18T10:46:28+0100",
    "revision": "c739069ec7105e01303e8b3065a81141aad9f129",
    "project": {
        "key": "myProject",
        "name": "My Project",
        "url": "https://mycompany.com/sonarqube/project/overview?id=myproject"
    },
    "properties": {
    },
    "qualityGate": {
        "conditions": [
            {
                "errorThreshold": "1",
                "metric": "new_security_rating",
                "onLeakPeriod": true,
                "operator": "GREATER_THAN",
                "status": "OK",
                "value": "1"
            },
            {
                "errorThreshold": "1",
                "metric": "new_reliability_rating",
                "onLeakPeriod": true,
                "operator": "GREATER_THAN",
                "status": "OK",
                "value": "1"
            },
            {
                "errorThreshold": "1",
                "metric": "new_maintainability_rating",
                "onLeakPeriod": true,
                "operator": "GREATER_THAN",
                "status": "OK",
                "value": "1"
            },
            {
                "errorThreshold": "80",
                "metric": "new_coverage",
                "onLeakPeriod": true,
                "operator": "LESS_THAN",
                "status": "NO_VALUE"
            }
        ],
        "name": "SonarQube way",
        "status": "OK"
    }
}
```

</details>

## Webhook protection with HMAC <a href="#webhook-protection-with-hmac" id="webhook-protection-with-hmac"></a>

SonarQube can generate an HMAC to allow the third party service to verify the integrity and authenticity of the webhook they receive. To do so, it uses the HMAC-SHA256 algorithm and the secret stored in the webhook configuration.

## Related pages

* [Configuring webhooks for your organization](/sonarqube-cloud/administering-sonarcloud/integrations/webhooks)
* [Configuring webhooks for your project](/sonarqube-cloud/managing-your-projects/administering-your-projects/integrations/webhooks)


# Quickstart Guides

{% content-ref url="/pages/yIV11N22DBsI3ebW9PRN" %}
[Quickstart guide](/sonarqube-cloud/quickstart-guides/quickstart-guide)
{% endcontent-ref %}

{% content-ref url="/pages/pEV3otQaFkGlZYVhXIWD" %}
[Quickstart guide for Enterprises](/sonarqube-cloud/quickstart-guides/quickstart-guide-enterprises)
{% endcontent-ref %}


# Quickstart guide

A checklist for administrators completing the initial setup of SonarQube Cloud.

By completing this guide you will:

1. [Set up your SonarQube Cloud account](#set-up-your-sonarqube-cloud-account)
   1. Set up your Organization
   2. Upgrade to Enterprise
      1. SSO via SAML
2. [Onboard projects](#onboard-your-projects)
3. [Configure CI analysis](#configure-your-ci-analysis)
4. [Integrate with SonarQube for IDE](#connect-with-sonarqube-for-ide)
5. [Review quality gates](#review-your-quality-gates)
   1. Review pull/merge request analysis for failed quality gates.
   2. Configure pull request decoration on your DevOps platform

## Set up your SonarQube Cloud account

We use an [organization-based structure](/sonarqube-cloud/administering-sonarcloud/about-sonarqube-cloud-solution/resources-structure/organization) that mirrors the structure on your chosen DevOps platforms.

Create an organization based on:

* [GitHub](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-github-organization)
* [BitBucket Cloud](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-bitbucket-workspace)
* [GitLab](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-gitlab-group)
* [Azure DevOps](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-azure-devops-organization)

Consider upgrading to [Enterprise](/sonarqube-cloud/administering-sonarcloud/managing-subscription/subscription-plans) so you can begin [Setting up SSO](/sonarqube-cloud/getting-started-with-enterprise/setting-up-sso).

## Onboard your projects

Import repositories from your DevOps platform to create projects:

* [GitHub](/sonarqube-cloud/getting-started/github)
* [Bitbucket Cloud](/sonarqube-cloud/getting-started/bitbucket-cloud)
* [GitLab](/sonarqube-cloud/getting-started/gitlab)
* [Azure DevOps](/sonarqube-cloud/getting-started/azure-devops)

## Configure your CI analysis

Set up analysis for your imported projects:

* [GitHub](/sonarqube-cloud/getting-started/github#set-up-your-analysis)
* [Bitbucket Cloud](/sonarqube-cloud/getting-started/bitbucket-cloud#set-up-your-analysis)
* [GitLab](/sonarqube-cloud/getting-started/gitlab#set-up-your-analysis)
* [Azure DevOps](/sonarqube-cloud/getting-started/azure-devops#set-up-your-analysis)

Now that you can review the [main branch’s analysis](/sonarqube-cloud/analyzing-source-code/branch-analysis/main-branch-analysis) on any of your imported projects.

## Connect with SonarQube for IDE

Have your developers install [SonarQube for IDE](/sonarqube-cloud/analyzing-source-code/connected-mode) to leverage the power of SonarQube in their IDE.

## Review your quality gates

The purpose of [Quality gates](/sonarqube-cloud/standards/quality-gates) is to tell you whether your code is good enough to be pushed to the next step:

* For the main branch and other long-lived branches, the quality gate answers the question: "Can I release my code today?"
* For pull requests (and short-lived branches), the quality gate answers the question: "Can I merge this pull request?"

By setting up [Pull request analysis](/sonarqube-cloud/analyzing-source-code/pull-request-analysis), you ensure pull requests are analyzed when they are opened and every time a change is pushed to the pull request branch. You can also configure [pull request decoration](/sonarqube-cloud/analyzing-source-code/pull-request-analysis#pull-request-decoration) to allow your developers to view the analysis from SonarQube Cloud directly on the PRs they submit.

By keeping an eye on the quality gates, the decision makers can quickly judge the status of code and decide what to do next.

## Develop with Sonar

Now that you have seen the benefits of using [SonarQube Cloud](/sonarqube-cloud/discovering-sonarcloud/what-sonarcloud-can-do) with your DevOPs platforms, managers and tech leads can check out the [security reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports) and [portfolios](/sonarqube-cloud/managing-portfolios) features to begin monitoring the security and releasability of projects.

## Related pages

* [Networking requirements](/sonarqube-cloud/appendices/networking-requirements)


# Quickstart guide for Enterprises

Set up SonarQube Cloud Enterprise from prerequisites through organization onboarding, enterprise creation, SSO, Advanced Security, and developer enablement.

If you're setting up SonarQube Cloud on the Team plan, use the [Quickstart guide](/sonarqube-cloud/quickstart-guides/quickstart-guide).

By completing this guide you will:

1. [Confirm your prerequisites](#confirm-your-prerequisites)
   1. [Choose your hosted region](#choose-your-hosted-region)
   2. [Prepare networking](#prepare-networking)
   3. [Prepare software and build agents](#prepare-software-and-build-agents)
   4. [Prepare authentication](#prepare-authentication)
   5. [Review trust and compliance documentation](#review-trust-and-compliance-documentation)
2. [Create your SonarQube Cloud organizations](#create-your-sonarqube-cloud-organizations)
3. [Create your enterprise](#create-your-enterprise)
4. [Enable enterprise capabilities](#enable-enterprise-capabilities)
   1. [Enable Advanced Security](#enable-advanced-security)
   2. [Configure SAML SSO and provisioning](#configure-saml-sso-and-provisioning)
5. [Roll out SonarQube for IDE and AI tooling](#roll-out-sonarqube-for-ide-and-ai-tooling)
6. [Review trust and compliance resources](#review-trust-and-compliance-resources)

## At a glance

| Area               | What to do                                                                                          |
| ------------------ | --------------------------------------------------------------------------------------------------- |
| Region             | Use the EU region by default, or complete the [US region](#us-region) prerequisites before rollout. |
| Networking         | Allow communication between SonarQube Cloud, DevOps platforms, CI runners, and IDEs.                |
| Software           | Prepare Java 21, SonarScanners, stack-specific build tools, and any Azure or SCA dependencies.      |
| Authentication     | Start with a DevOps administrator account and move to SSO after the enterprise exists.              |
| Organization model | Create one SonarQube Cloud organization per DevOps organization or workspace.                       |
| Enterprise setup   | Create the enterprise with your license key and attach the organization or organizations.           |
| Optional products  | Enable Advanced Security through the Sonar team, then configure SSO and provisioning if needed.     |
| Developer rollout  | Install SonarQube for IDE and optionally the SonarQube MCP Server for AI-assisted workflows.        |

## Confirm your prerequisites

### Choose your hosted region

By default, SonarQube Cloud uses the EU region.

#### US region

If the US region is mandatory, contact the [Sales team](mailto:contact@sonarsource.com) before rollout so your domain can authenticate to the US region. After approval, follow the same process described in this guide, but replace `sonarcloud.io` with `sonarqube.us`. For details, see [Choosing your server region](/sonarqube-cloud/getting-started/choosing-your-region).

### Prepare networking

SonarQube Cloud requires bidirectional communication between your DevOps platform, CI pipelines or runners, and developer IDEs.

Before rollout:

* Review the required URLs and IP addresses in [Networking requirements](/sonarqube-cloud/appendices/networking-requirements).
* Allowlist the endpoints needed by SonarQube Cloud, your DevOps platform, your CI infrastructure, and developer workstations.
* If you plan to restrict enterprise access with an IP allow list after SSO is enabled, include the IPs used by enterprise admins, developers, CI runners, and token-based integrations. See [IP allow lists](/sonarqube-cloud/administering-sonarcloud/enterprise-security/ip-allow-lists).

### Prepare software and build agents

Make sure your build and analysis environment is ready before you onboard projects:

* Ensure all build agents support Java 21. It is the recommended runtime for the latest SonarScanners.
* Identify the scanner or scanners required by your primary technology stacks:
  * [SonarScanner for Maven](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-maven)
  * [SonarScanner for Gradle](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-gradle)
  * [SonarScanner CLI](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-cli)
  * [SonarScanner for .NET](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-dotnet/introduction)
  * [SonarScanner for NPM](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-npm)
  * [Introduction](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-npm/introduction)
  * [SonarScanner for Python](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-python)
  * [Sonar's Build Wrapper](/sonarqube-cloud/analyzing-source-code/languages/c-family/prerequisites) or analyzing C/C++/Objective-C code
* Verify the supporting build tools on your agents:
  * [JavaScript/TypeScript/CSS](/sonarqube-cloud/analyzing-source-code/languages/javascript-typescript-css#nodejs) for JavaScript and TypeScript analysis
  * [SonarScanner for Maven](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-maven) or [SonarScanner for Gradle](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-gradle) for Java builds
  * [Installing the scanner](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-dotnet/installing) for C# analysis
* If you use Azure DevOps Pipelines, install the [SonarQube extension for Azure DevOps](https://marketplace.visualstudio.com/items?itemName=SonarSource.sonarcloud).
* If you plan to use Advanced Security, review [Analyzing projects for dependencies (SCA)](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca) to confirm any additional build tool, lockfile, or package manager requirements.

### Prepare authentication

The DevOps administrator who performs the setup should sign in with an administrator account from the chosen DevOps platform: GitHub, Azure DevOps, GitLab, or Bitbucket Cloud.

Before rollout:

* Confirm that the account can administer the DevOps organization or workspace you plan to import.
* If needed, install the SonarQube Cloud marketplace application or grant the required access described in [Default authentication through DevOps platform](/sonarqube-cloud/administering-sonarcloud/about-sonarqube-cloud-solution/user-management/devops-platform-authentication).
* Plan to configure [Setting up SSO](/sonarqube-cloud/getting-started-with-enterprise/setting-up-sso) after the enterprise is created. Enterprise users still start by signing up with their DevOps platform account.

## Create your SonarQube Cloud organizations

SonarQube Cloud uses a one-to-one model: one SonarQube Cloud organization is bound to one DevOps organization or workspace. If you need to connect multiple DevOps platforms or multiple organizations, create a separate SonarQube Cloud organization for each one. For background, see [Binding with the DevOps platform](/sonarqube-cloud/administering-sonarcloud/about-sonarqube-cloud-solution/resources-structure/binding-with-dop) and [Organization](/sonarqube-cloud/administering-sonarcloud/about-sonarqube-cloud-solution/resources-structure/organization).

When you create an organization that will be added to an enterprise, select the Free plan during the organization import flow. The organization will move to the Enterprise plan when you add it to the enterprise.

Use the import path that matches your DevOps platform:

* [Importing GitHub.com organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-github-organization): grant the SonarQube Cloud application access to the organization.
* [Importing GHE.com Cloud organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-ghecom-cloud-organization): only available from within an existing enterprise, not the **+** menu > **Create new organization** flow.
* [Importing Bitbucket workspace](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-bitbucket-workspace): grant the SonarQube Cloud application access to the workspace.
* [Importing GitLab group](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-gitlab-group): create and provide a Personal Access Token from an owner or dedicated technical account.
* [Importing Azure DevOps organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-azure-devops-organization): create and provide a Personal Access Token from an administrator or dedicated technical account.

## Create your enterprise

You do not need an organization to already exist first, you can create or add one in the same flow as the enterprise:

1. In SonarQube Cloud, select the **+** menu in the top-right corner.
2. Select **Create new enterprise**.
3. Enter the license key provided by Sonar.
4. Enter the enterprise name and enterprise key.
5. Create, import, or add the organization or organizations you want to include.
6. Create the enterprise.

For the full workflow, see [Setting up your enterprise](/sonarqube-cloud/getting-started-with-enterprise/setting-up-your-enterprise#create-enterprise).

After creation, review [Managing the enterprise-related permissions](/sonarqube-cloud/administering-sonarcloud/managing-enterprise/managing-the-enterprise-related-permissions) and make sure the right users can administer the enterprise and create portfolios.

## Enable enterprise capabilities

### Enable Advanced Security

Advanced Security is enabled by the Sonar team.

To request it:

1. Open the enterprise in SonarQube Cloud.
2. Copy the enterprise ID from the browser URL, for example `https://sonarcloud.io/enterprise/<your-enterprise-id>`.
3. Provide that ID to your Sonar contact or Sonar team.
4. Wait for confirmation that Advanced Security has been enabled.

Once enabled, use [Analyzing projects for dependencies (SCA)](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca) to configure dependency analysis.

### Configure SAML SSO and provisioning

After the enterprise exists, you can transition from DevOps-platform authentication to SAML SSO.

Use this rollout order:

1. Review [Setting up SSO](/sonarqube-cloud/getting-started-with-enterprise/setting-up-sso) for the enterprise-level flow.
2. Configure SAML in [Set up SSO](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning/set-up-sso).
3. Decide whether you will provision users with [Set up SCIM](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning/set-up-scim) or [About SSO and provisioning](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning/about#just-in-time).
4. Map IdP groups to SonarQube Cloud organizations with [Set up SCIM](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning/set-up-scim#map-groups).
5. Complete the setup with [Invite users to sign in](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning/complete-setup).
6. Verify the resulting organization access with [Managing user groups](/sonarqube-cloud/administering-sonarcloud/managing-organization/users-and-permissions/user-groups), [Setting your project's permissions](/sonarqube-cloud/managing-your-projects/administering-your-projects/setting-permissions), and [Using permission templates](/sonarqube-cloud/administering-sonarcloud/managing-organization/manage-org-projects/manage-project-permissions/templates).

If you're rolling out SSO with Okta, Microsoft Entra ID, or another SAML-compatible identity provider, the SSO assistant guides you through the provider-specific configuration.

## Roll out SonarQube for IDE and AI tooling

Make sure developers can reach `sonarcloud.io` or `sonarqube.us`, depending on your hosted region.

For local analysis and issue remediation, install SonarQube for IDE in the supported IDEs and bind projects with [SonarQube for IDE](/sonarqube-cloud/analyzing-source-code/connected-mode). Connected mode lets SonarQube for IDE use the quality profiles, rule selections, file exclusions, and issue states configured in SonarQube Cloud.

* [VS Code](https://docs.sonarsource.com/sonarqube-for-vs-code/)
* [IntelliJ](https://docs.sonarsource.com/sonarqube-for-intellij/)
* [Visual Studio](https://docs.sonarsource.com/sonarqube-for-visual-studio/)
* [Eclipse](https://docs.sonarsource.com/sonarqube-for-eclipse/)

If your organization manages VS Code extensions through a [VS Code Private Marketplace](https://code.visualstudio.com/blogs/2025/11/18/PrivateMarketplace), make SonarQube for VS Code available through that private catalog before onboarding developers. Developers in managed environments may not be able to install the extension from the public Visual Studio Marketplace.

If your teams use AI-assisted development, you can also roll out the [https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-mcp-server/about-the-mcp-server](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-mcp-server/about-the-mcp-server "mention"):

* Use SonarQube Cloud's embedded MCP server for the simplest setup.
* Run a local MCP server via Docker when you need local filesystem access or Sonar Vortex's context augmentation and agentic analysis tooling.
* If you use the US region, review the US-specific MCP configuration notes on the MCP server page before rollout.

## Review trust and compliance resources

Review the [Trust Center](https://trust.sonarsource.com/) for security attestations and SaaS security documentation. For ongoing enterprise administration after setup, the [Getting started with Enterprise](/sonarqube-cloud/getting-started-with-enterprise) section is the best next stop.


# Getting started with SonarQube Cloud

When you first sign up for SonarQube Cloud, you have to choose which DevOps platform you want to connect to. Then sign in to SonarQube Cloud with your existing credentials on that service.

{% content-ref url="/pages/tgaKQpsfJyIPrnahzJun" %}
[Signing up and onboarding](/sonarqube-cloud/getting-started/sign-up)
{% endcontent-ref %}

{% content-ref url="/pages/RyxE6TfgRO0CRHvUAOAy" %}
[Getting started with GitHub](/sonarqube-cloud/getting-started/github)
{% endcontent-ref %}

{% content-ref url="/pages/AmcejQNAJV7EVAznLifW" %}
[Getting started with Bitbucket Cloud](/sonarqube-cloud/getting-started/bitbucket-cloud)
{% endcontent-ref %}

{% content-ref url="/pages/X1NpTayDd2HcZIKc65cV" %}
[Getting started with GitLab](/sonarqube-cloud/getting-started/gitlab)
{% endcontent-ref %}

{% content-ref url="/pages/mwCkGnbQAS35dwmm2hvi" %}
[Getting started with Azure DevOps](/sonarqube-cloud/getting-started/azure-devops)
{% endcontent-ref %}

{% content-ref url="/pages/8fjzrst5Y0DGj6gbOC2G" %}
[Viewing your first analysis' results](/sonarqube-cloud/getting-started/first-analysis)
{% endcontent-ref %}

{% content-ref url="/pages/wMxtTmOWt71LBJ4j7o4z" %}
[Retrieving your organizations](/sonarqube-cloud/getting-started/viewing-organizations)
{% endcontent-ref %}

{% content-ref url="/pages/VUuUQ2UXOjPEauSBJJsZ" %}
[Choosing your server region](/sonarqube-cloud/getting-started/choosing-your-region)
{% endcontent-ref %}


# Signing up and onboarding

Learn how to connect and import organizations and projects from your DevOps platform into SonarQube Cloud.

This page is directed at administrators when onboarding their first DevOps platform organization. For sign-in instructions, see [Signing in to SonarQube Cloud](/sonarqube-cloud/managing-your-account/signing-in).

If you want to use the US region, you’ll have to sign up for the SonarQube Cloud’s US instance. For more information, see [Choosing your server region](/sonarqube-cloud/getting-started/choosing-your-region).

When you first sign up for SonarQube Cloud, you have to choose which DevOps platform you want to connect to. Then sign in to SonarQube Cloud with your existing credentials on that service (there is no such thing as a SonarQube Cloud-only account). Your SonarQube Cloud account will be created and bound to your account on the DevOps platform. For more information, see [Authentication](https://www.sonarsource.com/trust-center/#authentication) in the Trust Center.

At this point, you can import organizations from your DevOps platform to SonarQube Cloud and then import repositories from those organizations. Each imported organization becomes a SonarQube Cloud organization and each imported repository becomes a SonarQube Cloud project. Once you import a project, it appears on your **My Projects** page.

## Related pages

* [Getting started with GitHub](/sonarqube-cloud/getting-started/github)
* [Getting started with Bitbucket Cloud](/sonarqube-cloud/getting-started/bitbucket-cloud)
* [Getting started with GitLab](/sonarqube-cloud/getting-started/gitlab)
* [Getting started with Azure DevOps](/sonarqube-cloud/getting-started/azure-devops)


# Getting started with GitHub

Everything you need to know to get started analyzing your GitHub projects on SonarQube Cloud.

SonarQube Cloud's integration is supported with GitHub.com and GHE.com Cloud. For more information about the integration features, see [GitHub](/sonarqube-cloud/discovering-sonarcloud/integration-with-devops-platforms/github).

The getting started journey described below refers to [GitHub.com](https://github.com/).

## Step 1: Sign up

1. Go to [SonarQube Cloud product page](https://www.sonarsource.com/products/sonarqube/cloud/) and select **Start now**. The Get started page opens.\
   If you want to use the [US region](/sonarqube-cloud/getting-started/choosing-your-region), go to [sonarqube.us](http://sonarqube.us/) instead.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/BVLOH9q8iM546Pt17rOq" alt="Select your DevOps platform."><figcaption></figcaption></figure>

2. Select **GitHub** from the list of DevOps platforms. You will be taken to the GitHub login page.
3. Sign in using your GitHub credentials.\
   For prerequisites on your DevOps account’s email address, see [Signing in to SonarQube Cloud](/sonarqube-cloud/managing-your-account/signing-in#via-devops-platform).

Your SonarQube Cloud account is created and bound to your GitHub account. For more information, see [Authentication](https://www.sonarsource.com/trust-center/#authentication) in the Trust Center.

Once you have successfully logged in, you will be prompted to connect your GitHub organization with SonarQube Cloud and create your SonarQube Cloud organization.

## Step 2: Create your organization

We use an [organization-based structure](/sonarqube-cloud/administering-sonarcloud/about-sonarqube-cloud-solution/resources-structure/organization) that mirrors the structure on your chosen DevOps platforms: each SonarQube Cloud organization corresponds one-to-one with a GitHub organization or personal account. A subscription plan is associated one-to-one with a SonarQube Cloud organization. See [Subscription plans](/sonarqube-cloud/administering-sonarcloud/managing-subscription/subscription-plans) for a comparison between the different plans.

To create your SonarQube Cloud organization, you’ll import your GitHub organization or personal account to SonarQube Cloud.

Proceed as follows. For detailed prerequisites and instructions, see [Importing GitHub.com organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-github-organization).

1. You will be presented with a step-by-step tutorial to install the SonarQube Cloud application on GitHub. This allows SonarQube Cloud to access your GitHub organization or personal account. Once this is done, you’ll be redirected to the subscription page.
2. Select a plan for your organization. For a plan comparison, select **Available plans** in the top right corner.
3. Check the organization details. You can see the organization name and key at the bottom of the page.
4. If you selected the Team plan, follow the instructions.
5. Select **Create organiziation**.

{% hint style="info" %}

* The organization creator becomes the organization admin. To set up the organization permissions, see [Managing organization permissions](/sonarqube-cloud/administering-sonarcloud/managing-organization/users-and-permissions/organization-permissions).
* Consider upgrading to [Enterprise](https://docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/managing-subscription/subscription-plans) so you can benefit from many features, in particular SSO and SCIM. See [About SSO and provisioning](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning/about).
  {% endhint %}

## Step 3: Select your projects

You can now import the existing projects (that is, individual Git repositories) that you want to analyze from your GitHub organization into your newly created SonarQube Cloud organization. A corresponding, one-to-one SonarQube Cloud project will be created for each imported repository.

Proceed as follows (you need the Create Projects permission in your organization):

1. You have two options for importing repositories:
   * To import all repositories from your GitHub organization, select the **Bulk import all** button (Option **a** in the figure below). For more details, see [Creating your project](/sonarqube-cloud/managing-your-projects/administering-your-projects/setting-up-project#bulk-import).
   * To select specific repositories to import, choose the ones you want (Option **b** in the figure). Note that you can only import up to 25 repositories at a time.
2. Select the **Auto-import new GitHub repositories** option (Option **c** in the figure) if you want that new GitHub repositories be automatically imported as soon as they are created in your GitHub organization, skipping the manual new project analysis flow. For more information, see [Auto-importing new repositories](/sonarqube-cloud/administering-sonarcloud/managing-organization/manage-org-projects/auto-import-new-repos).

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/VlySSnY8Z7kH3Xrww971" alt="You must chose between option a and option b to import your repositories to SonarQube Cloud. You can use option c in addition to enable the auto-import of new repos."><figcaption></figcaption></figure>

3. Select the **Analyze \<n> projects** button or the **Bulk import all projects** button if you have selected the bulk import option.\
   The projects are created.

{% hint style="info" %}
The project creator becomes the project admin. To set up the project permissions, see [Setting your project's permissions](/sonarqube-cloud/managing-your-projects/administering-your-projects/setting-permissions).
{% endhint %}

If a project qualifies for Automatic analysis, SonarQube Cloud will start the analysis of the project’s main branch automatically, and of the most recent active pull requests. See [Automatic analysis](/sonarqube-cloud/analyzing-source-code/automatic-analysis) for more information.

If the Automatic analysis is not supported or not used for your project, you’ll need to configure the analysis. For more information, see [#setting-up-a-ci-based-analysis](#setting-up-a-ci-based-analysis "mention").

{% hint style="info" %}
With the [Enterprise](https://www.sonarsource.com/plans-and-pricing/) plan, you can disable the Automatic analysis for the entire organization. See [Turning off automatic analysis](/sonarqube-cloud/administering-sonarcloud/managing-organization/setting-config-at-org-level/disabling-automatic-analysis).
{% endhint %}

## Step 4: Connect with SonarQube for IDE

SonarQube for IDE is a free IDE extension that integrates with SonarQube Cloud. Like a spell checker, SonarQube for IDE highlights issues as you type.

Install SonarQube for IDE to leverage the power of SonarQube in your IDE. To do so, see [SonarQube for IDE](/sonarqube-cloud/analyzing-source-code/connected-mode).

## Step 5: View your analysis results

Once your analysis is completed a project Overview page opens, displaying the **Project health dashboard**, a built-in Sonar dashboard available in all plans. Custom dashboards and other built-in dashboard views are available in the [Enterprise](https://www.sonarsource.com/plans-and-pricing/) plan.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/HZgBQbZwvctb7V1bsaPp" alt="The Project Overview page."><figcaption></figcaption></figure>

### Review your project’s quality gate

The purpose of Quality gates is to tell you whether your code is good enough to be pushed to the next step:

* For the main branch and other long-lived branches, the quality gate answers the question: "Can I release my code today?"
* For pull requests (and short-lived branches), the quality gate answers the question: "Can I merge this pull request?"

By keeping an eye on the quality gates, the decision makers can quickly judge the status of code and decide what to do next.

For more information, see [Quality gates](/sonarqube-cloud/standards/quality-gates).

### Review your issues

An analysis detects an issue as a problem in your code. When a coding rule is broken, an issue is raised. Each issue affects one or more software qualities with a varying impact level, called severity, as inherited from the rule. For more information about rules, see [Viewing and managing rules](/sonarqube-cloud/standards/managing-rules).

To review your issues, see [Managing code issues](/sonarqube-cloud/managing-your-projects/issues).

## Step 6: Adjust your project setup

The analysis performed by the SonarScanner is configured through analysis parameters. The following applies:

* A few analysis parameters are mandatory.
* Many analysis parameters, such as those defining the analysis scope, have a default value and can be adjusted.
* Analysis parameters allow you to include the code and test coverage in your analysis, or to import issues generated by a third-party analyzer, etc.

SonarQube Server manages the analysis parameters through sonar properties (The sonar property key has the following syntax: `sonar.<property>`.).

You can configure the analysis parameters in different places. For more information, see [Configuration overview](/sonarqube-cloud/analyzing-source-code/analysis-parameters/configuration-overview).

You can:

* Adjust your analysis scope, see [Analysis scope](/sonarqube-cloud/managing-your-projects/project-analysis/setting-analysis-scope).
* Implement test coverage, see [Test coverage](/sonarqube-cloud/analyzing-source-code/test-coverage).
* Import external analyzer reports, see [External analyzer reports](/sonarqube-cloud/analyzing-source-code/importing-external-issues/external-analyzer-reports).
* Define a Long-lived branch pattern, see [Long-lived branch pattern](/sonarqube-cloud/managing-your-projects/project-analysis/long-lived-branch-pattern).
* Change the new code definition applied to your project, see [New code definition](/sonarqube-cloud/managing-your-projects/project-analysis/configuring-new-code-calculation).
* Change the quality gate assigned to your project, see [Quality gate](/sonarqube-cloud/managing-your-projects/project-analysis/changing-quality-gate).
* Change the quality profiles assigned to your project, see [Quality profile](/sonarqube-cloud/managing-your-projects/project-analysis/quality-profile-association)

## Step 7: Check out security reports and portfolios

Managers and tech leads can check out the security reports and portfolios features to begin monitoring the security and releasability of projects. For more information, see [Viewing the enterprise reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports).

## Setting up a CI-based analysis

If the Automatic analysis is not supported for your project or you don't want to use it, you’ll need to set up the analysis. The actual analysis is performed in your build environment (for example, on a cloud CI or your local machine). This means you have to configure your build process to perform the analysis on each build and communicate the results up to SonarQube Cloud. We refer to this analysis method as CI-based analysis in contrast with the automatic analysis.

To understand the SonarQube analysis principles, see [SonarQube analysis overview](/sonarqube-cloud/discovering-sonarcloud/analysis-process-overview).

To integrate SonarQube Cloud analysis into your GitHub Actions workflow, see [Github Actions](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/github-actions-for-sonarcloud).

### About the SonarQube Cloud analysis

The SonarScanner performs the automated source code analysis as part of your code review process. This stand-alone program runs on the CI/CD host and sends the analysis results to SonarQube Server, which computes them, calculates the quality gate, and generates reports.

To perform the analysis, the SonarScanner uses the [Sonar analyzers](/sonarqube-cloud/discovering-sonarcloud/overview) that it downloads from SonarQube Cloud at installation.

The Sonar Solution offers SonarScanners that integrate with the following build systems: Gradle, Maven, .NET, NPM, and Python. For other project types, the SonarScanner CLI which requires more manual configuration is used.

For more information about integrated CI tools and SonarScanners, see [CI-based analysis](/sonarqube-cloud/analyzing-source-code/ci-based-analysis)

### Setting up the pull request analysis

By setting up pull request analysis, you ensure pull requests are analyzed when they are opened and every time a change is pushed to the pull request branch. To do so, you must add the SonarQube Cloud analysis to your CI pipeline.

* To learn more about pull request analysis, see [Pull request analysis](/sonarqube-cloud/analyzing-source-code/pull-request-analysis).
* To integrate SonarQube Cloud analysis into your GitHub Actions workflow, see [Github Actions](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/github-actions-for-sonarcloud).

## Related pages <a href="#related-pages" id="related-pages"></a>

* [GitHub](/sonarqube-cloud/discovering-sonarcloud/integration-with-devops-platforms/github) (integration solution overview)
* [Organization setup overview](/sonarqube-cloud/administering-sonarcloud/managing-organization/setup-overview)
* [Importing GitHub.com organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-github-organization)
* [Project administration overview](/sonarqube-cloud/managing-your-projects/administering-your-projects/introduction)
* [Creating your project](/sonarqube-cloud/managing-your-projects/administering-your-projects/setting-up-project)
* [Configuring GitHub project binding](/sonarqube-cloud/managing-your-projects/administering-your-projects/devops-platform-integration/github)
* [Github Actions](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/github-actions-for-sonarcloud)
* [Choosing your server region](/sonarqube-cloud/getting-started/choosing-your-region)

## Related online learning

* <i class="fa-desktop">:desktop:</i> [Initial SonarQube Cloud set up with GitHub](https://www.sonarsource.com/learn/course/sonarqube-cloud/e598e92a-7788-44a2-81c3-399432a52892/initial-sonarqube-cloud-set-up-with-github)


# Getting started with Bitbucket Cloud

Everything you need to know to get started analyzing your Bitbucket Cloud projects on SonarQube Cloud.

{% hint style="info" %}
You can take a look at these various projects: [Sample projects analyzed on SonarQube Cloud](https://bitbucket.org/account/user/sonarsource/projects/SAMPLES).
{% endhint %}

## Step 1: Sign up

1. Go to [SonarQube Cloud product page](https://www.sonarsource.com/products/sonarqube/cloud/) and select **Start now**. The Get started page opens.\
   If you want to use the [US region](/sonarqube-cloud/getting-started/choosing-your-region), go to [sonarqube.us](http://sonarqube.us/) instead.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/BVLOH9q8iM546Pt17rOq" alt="Select your DevOps platform."><figcaption></figcaption></figure>

2. Select **Bitbucket** from the list of DevOps platforms. You will be taken to the Bitbucket login page.
3. Sign in using your Bitbucket credentials.\
   For prerequisites on your DevOps account’s email address, see [Signing in to SonarQube Cloud](/sonarqube-cloud/managing-your-account/signing-in#via-devops-platform).

Your SonarQube Cloud account is created and bound to your Bitbucket account. For more information, see [Authentication](https://www.sonarsource.com/trust-center/#authentication) in the Trust Center.

Once you have successfully logged in, you will be prompted to connect your Bitbucket workspace with SonarQube Cloud and create your SonarQube Cloud organization.

## Step 2: Create your organization

We use an [organization-based structure](/sonarqube-cloud/administering-sonarcloud/about-sonarqube-cloud-solution/resources-structure/organization) that mirrors the structure on your chosen DevOps platforms: each SonarQube Cloud organization corresponds one-to-one with a Bitbucket Cloud organization or personal account. A subscription plan is associated one-to-one with a SonarQube Cloud organization. See [Subscription plans](/sonarqube-cloud/administering-sonarcloud/managing-subscription/subscription-plans) for a comparison between the different plans.

To create your SonarQube Cloud organization, you’ll import your Bitbucket Cloud workspace to SonarQube Cloud.

Proceed as follows. For detailed prerequisites and instructions, see [Importing Bitbucket workspace](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-bitbucket-workspace).

1. Select **Import an organization from Bitbucket**.
2. When prompted, grant access to the SonarQube Cloud application to read your Bitbucket Cloud workspace. SonarQube Cloud requests access for:
   * Reading your account information.
   * Reading your repositories and their pull requests.
   * Reading your team membership information.
3. Check the organization details.
4. Select the subscription plan
5. Create your organization. A new page opens.
6. Select **Analyze a new project** and go to the next step below.

{% hint style="info" %}

* The organization creator becomes the organization admin. To set up the organization permissions, see [Managing organization permissions](/sonarqube-cloud/administering-sonarcloud/managing-organization/users-and-permissions/organization-permissions).
* Consider upgrading to [Enterprise](https://docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/managing-subscription/subscription-plans) so you can benefit from many features, in particular SSO and SCIM. See [About SSO and provisioning](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning/about).
  {% endhint %}

## Step 3: Import your repositories

You can now import the existing projects (that is, individual Git repositories) that you want to analyze from your Bitbucket workspace into your newly created SonarQube Cloud organization. A corresponding, one-to-one SonarQube Cloud project will be created for each imported repository.

Proceed as follows (you need the Create Projects permission in your organization):

1. Select the repositories you want to import and select the **Set up** button.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/Dw2Pa0vEqSPL0110rGD4" alt="Select your repository(ies) and select the Set up button."><figcaption></figcaption></figure>

2. Select the new code definition for your new project(s). For more information about this definition, see [Quality standards and new code](/sonarqube-cloud/standards/about-new-code).\
   Note that the new code definition you apply at this stage will apply to all of the projects you have selected for import. You can change your new code definition later on a per-project basis (see [New code definition](/sonarqube-cloud/managing-your-projects/project-analysis/configuring-new-code-calculation)).

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/bDXgcK90altZWukE5AwK" alt="Select a new code definition option for your project."><figcaption></figcaption></figure>

3. Create your project(s).

{% hint style="info" %}
The project creator becomes the project admin. To set up the project permissions, see [Setting your project's permissions](/sonarqube-cloud/managing-your-projects/administering-your-projects/setting-permissions).
{% endhint %}

## Step 4: Set up your project analysis

With Bitbucket projects, the actual analysis is performed in your build environment (for example, on a cloud CI or your local machine). This means you have to configure your build process to perform the analysis on each build and communicate the results up to SonarQube Cloud.

We refer to this analysis method as CI-based analysis (though it may take place in a cloud CI or a manually configured build environment) to contrast it with automatic analysis which works by SonarQube Cloud directly accessing your repository and performing the analysis itself. However, automatic analysis is currently not available only for BitBucket Cloud projects.

SonarQube Cloud will guide you through a tutorial on how to set up your build environment to run your analysis. The first step is to select your build environment. If you have no particular preference and are setting up a new project on Bitbucket, we recommend using Bitbucket Pipelines as your CI. See [Bitbucket Pipelines](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/bitbucket-pipelines-for-sonarcloud).

To understand the SonarQube analysis principles, see [SonarQube analysis overview](/sonarqube-cloud/discovering-sonarcloud/analysis-process-overview).

### About the SonarQube Cloud analysis

The SonarScanner performs the automated source code analysis as part of your code review process. This stand-alone program runs on the CI/CD host and sends the analysis results to SonarQube Server, which computes them, calculates the quality gate, and generates reports.

To perform the analysis, the SonarScanner uses the [Sonar analyzers](/sonarqube-cloud/discovering-sonarcloud/overview) that it downloads from SonarQube Cloud at installation.

The Sonar Solution offers SonarScanners that integrate with the following build systems: Gradle, Maven, .NET, NPM, and Python. For other project types, the SonarScanner CLI which requires more manual configuration is used.

For more information about integrated CI tools and SonarScanners, see [CI-based analysis](/sonarqube-cloud/analyzing-source-code/ci-based-analysis)

### Setting up the pull request analysis

By setting up pull request analysis, you ensure pull requests are analyzed when they are opened and every time a change is pushed to the pull request branch. To do so, you must add the SonarQube Cloud analysis to your CI pipeline.

* To learn more about pull request analysis, see [Pull request analysis](/sonarqube-cloud/analyzing-source-code/pull-request-analysis).
* To integrate SonarQube Cloud analysis into your Bitbucket pipeline, see [Bitbucket Pipelines](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/bitbucket-pipelines-for-sonarcloud).

You can also configure pull request decoration to allow your developers to view the analysis from SonarQube Cloud directly on the pull requests they submit.

* To learn more about the Bitbucket integration features, see [Issues reported in Bitbucket Cloud](/sonarqube-cloud/managing-your-projects/issues/in-devops-platform/bitbucket-cloud).
* To set up your project integration with Bitbucket Cloud, see [Configuring Bitbucket Cloud project binding](/sonarqube-cloud/managing-your-projects/administering-your-projects/devops-platform-integration/bitbucket-cloud).

## Step 5: Connect with SonarQube for IDE

SonarQube for IDE is a free IDE extension that integrates with SonarQube Cloud. Like a spell checker, SonarQube for IDE highlights issues as you type.

Install SonarQube for IDE to leverage the power of SonarQube in your IDE. To do so, see [SonarQube for IDE](/sonarqube-cloud/analyzing-source-code/connected-mode).

## Step 6: View your analysis results

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/HZgBQbZwvctb7V1bsaPp" alt="The Project Overview page."><figcaption></figcaption></figure>

### Review your project’s quality gate

The purpose of Quality gates is to tell you whether your code is good enough to be pushed to the next step:

* For the main branch and other long-lived branches, the quality gate answers the question: "Can I release my code today?"
* For pull requests (and short-lived branches), the quality gate answers the question: "Can I merge this pull request?"

By keeping an eye on the quality gates, the decision makers can quickly judge the status of code and decide what to do next.

For more information, see [Quality gates](/sonarqube-cloud/standards/quality-gates).

### Review your issues

An analysis detects an issue as a problem in your code. When a coding rule is broken, an issue is raised. Each issue affects one or more software qualities with a varying impact level, called severity, as inherited from the rule. For more information about rules, see [Viewing and managing rules](/sonarqube-cloud/standards/managing-rules).

To review your issues, see [Managing code issues](/sonarqube-cloud/managing-your-projects/issues).

## Step 7: Adjust your project setup

The analysis performed by the SonarScanner is configured through analysis parameters. The following applies:

* A few analysis parameters are mandatory.
* Many analysis parameters, such as those defining the analysis scope, have a default value and can be adjusted.
* Analysis parameters allow you to include the code and test coverage in your analysis, or to import issues generated by a third-party analyzer, etc.

SonarQube Server manages the analysis parameters through sonar properties (The sonar property key has the following syntax: `sonar.<property>`.).

You can configure the analysis parameters in different places. For more information, see [Configuration overview](/sonarqube-cloud/analyzing-source-code/analysis-parameters/configuration-overview).

You can:

* Adjust your analysis scope, see [Analysis scope](/sonarqube-cloud/managing-your-projects/project-analysis/setting-analysis-scope).
* Implement test coverage, see [Test coverage](/sonarqube-cloud/analyzing-source-code/test-coverage).
* Import external analyzer reports, see [External analyzer reports](/sonarqube-cloud/analyzing-source-code/importing-external-issues/external-analyzer-reports).
* Define a Long-lived branch pattern, see [Long-lived branch pattern](/sonarqube-cloud/managing-your-projects/project-analysis/long-lived-branch-pattern).
* Change the new code definition applied to your project, see [New code definition](/sonarqube-cloud/managing-your-projects/project-analysis/configuring-new-code-calculation).
* Change the quality gate assigned to your project, see [Quality gate](/sonarqube-cloud/managing-your-projects/project-analysis/changing-quality-gate).
* Change the quality profiles assigned to your project, see [Quality profile](/sonarqube-cloud/managing-your-projects/project-analysis/quality-profile-association)

## Step 8: Check out security reports and portfolios

Managers and tech leads can check out the security reports and portfolios features to begin monitoring the security and releasability of projects. For more information, see [Viewing the enterprise reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports).

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Bitbucket Cloud](/sonarqube-cloud/discovering-sonarcloud/integration-with-devops-platforms/bitbucket-cloud) (integration solution overview)
* [Importing Bitbucket workspace](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-bitbucket-workspace)
* [Creating your project](/sonarqube-cloud/managing-your-projects/administering-your-projects/setting-up-project)
* [Configuring Bitbucket Cloud project binding](/sonarqube-cloud/managing-your-projects/administering-your-projects/devops-platform-integration/bitbucket-cloud)
* [Bitbucket Pipelines](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/bitbucket-pipelines-for-sonarcloud)
* [Choosing your server region](/sonarqube-cloud/getting-started/choosing-your-region)

## Related online courses

* <i class="fa-desktop">:desktop:</i> [Initial SonarQube Cloud set up with Bitbucket](https://www.sonarsource.com/learn/course/sonarqube-cloud/6026e0b7-1566-44d6-95b9-1fab00c0848a/initial-sonarqube-cloud-set-up-with-bitbucket)


# Getting started with GitLab

Everything you need to know to get started analyzing your GitLab projects on SonarQube Cloud.

## Step 1: Sign up

1. Go to [SonarQube Cloud product page](https://www.sonarsource.com/products/sonarqube/cloud/) and select **Start now**. The Get started page opens.\
   If you want to use the [US region](/sonarqube-cloud/getting-started/choosing-your-region), go to [sonarqube.us](http://sonarqube.us/) instead.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/BVLOH9q8iM546Pt17rOq" alt="Select your DevOps platform."><figcaption></figcaption></figure>

2. Select **GitLab** from the list of DevOps platforms. You will be taken to the GitLab login page.
3. Sign in using your GitLab credentials.

   For prerequisites on your DevOps account’s email address, see [Signing in to SonarQube Cloud](/sonarqube-cloud/managing-your-account/signing-in#via-devops-platform).

Your SonarQube Cloud account is created and bound to your GitLab account. For more information, see [Authentication](https://www.sonarsource.com/trust-center/#authentication) in the Trust Center.

Once you have successfully logged in, you will be prompted to connect your GitLab group with SonarQube Cloud and create your SonarQube Cloud organization.

## Step 2: Create your organization

We use an [organization-based structure](/sonarqube-cloud/administering-sonarcloud/about-sonarqube-cloud-solution/resources-structure/organization) that mirrors the structure on your chosen DevOps platforms: each SonarQube Cloud organization corresponds one-to-one with a GitLab group. A subscription plan is associated one-to-one with a SonarQube Cloud organization. See [Subscription plans](/sonarqube-cloud/administering-sonarcloud/managing-subscription/subscription-plans) for a comparison between the different plans.

To create your SonarQube Cloud organization, you’ll import to SonarQube Cloud either a GitLab group or your personal namespace. If you select the first option, you will need your GitLab group key and a GitLab personal access token. If you select the second option, you will just need a personal access token. For more information, see [Importing GitLab group](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-gitlab-group#create-personal-access-token) and [Importing GitLab group](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-gitlab-group#retrieve-group-key).

Proceed as follows. For detailed instructions, see [Importing GitLab group](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-gitlab-group).

1. Select **Import an organization from GitLab**.
2. Select your import option and provide the group key and/or your GitLab personal access token.
3. Select **Continue**.
4. Check the organization details.
5. Select the subscription plan.
6. Create your organization. A new page opens.
7. Select **Analyze a new project** and go to the next step below.

{% hint style="info" %}

* The organization creator becomes the organization admin. To set up the organization permissions, see [Managing organization permissions](/sonarqube-cloud/administering-sonarcloud/managing-organization/users-and-permissions/organization-permissions).
* Consider upgrading to [Enterprise](https://docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/managing-subscription/subscription-plans) so you can benefit from many features, in particular SSO and SCIM. See [About SSO and provisioning](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning/about).
  {% endhint %}

## Step 3: Import your projects

You can now import the existing projects that you want to analyze from your GitLab group into your newly created SonarQube Cloud organization. A corresponding, one-to-one SonarQube Cloud project will be created for each imported project.

Proceed as follows (you need the Create Projects permission in your organization):

1. You have two options for importing projects:
   * To import all projects from your GitLab group, select the **Import all repositories** button (Option **b** in the figure below). For more details, see [Creating your project](/sonarqube-cloud/managing-your-projects/administering-your-projects/setting-up-project#bulk-import).
   * To select specific projects to import, choose the ones you want (Option **a** in the figure below). The **Import all repositories** button will then change to the **Set up** button. Select the **Set up** button to continue.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/27bh83RHFSvt6vHbWNY6" alt="You must chose between option a and option b to import your repositories to SonarQube Cloud."><figcaption></figcaption></figure>

1. Select the new code definition for your new SonarQube Cloud project(s). For more information about this definition, see [Quality standards and new code](/sonarqube-cloud/standards/about-new-code).\
   Note that the new code definition you apply at this stage will apply to all of the projects you have selected for import. You can change your new code definition later on a per-project basis (see [New code definition](/sonarqube-cloud/managing-your-projects/project-analysis/configuring-new-code-calculation)).

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/bDXgcK90altZWukE5AwK" alt="Select a new code definition option for your project."><figcaption></figcaption></figure>

3. Create your project(s).

{% hint style="info" %}
The project creator becomes the project admin. To set up the project permissions, see [Setting your project's permissions](/sonarqube-cloud/managing-your-projects/administering-your-projects/setting-permissions).
{% endhint %}

## Step 4: Set up your project analysis

With GitLab projects, the actual analysis is performed in your build environment (for example, on a cloud CI or your local machine). This means you have to configure your build process to perform the analysis on each build and communicate the results up to SonarQube Cloud.

We refer to this analysis method as CI-based analysis (though it may take place in a cloud CI or a manually configured build environment) to contrast it with automatic analysis which works by SonarQube Cloud directly accessing your GitLab project and performing the analysis itself. However, automatic analysis is currently not available only for GitLab projects.

SonarQube Cloud will guide you through a tutorial on how to set up your build environment to run your analysis. The first step is to select your build environment. If you have no particular preference and are setting up a new project on GitLab, we recommend using GitLab CI/CD as your CI. See [GitLab CI](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/gitlab-ci).

To understand the SonarQube analysis principles, see [SonarQube analysis overview](/sonarqube-cloud/discovering-sonarcloud/analysis-process-overview).

### About the SonarQube Cloud analysis

The SonarScanner performs the automated source code analysis as part of your code review process. This stand-alone program runs on the CI/CD host and sends the analysis results to SonarQube Server, which computes them, calculates the quality gate, and generates reports.

To perform the analysis, the SonarScanner uses the [Sonar analyzers](/sonarqube-cloud/discovering-sonarcloud/overview) that it downloads from SonarQube Cloud at installation.

The Sonar Solution offers SonarScanners that integrate with the following build systems: Gradle, Maven, .NET, NPM, and Python. For other project types, the SonarScanner CLI which requires more manual configuration is used.

For more information about integrated CI tools and SonarScanners, see [CI-based analysis](/sonarqube-cloud/analyzing-source-code/ci-based-analysis)

### Setting up the pull request analysis

By setting up pull request analysis, you ensure pull requests are analyzed when they are opened and every time a change is pushed to the pull request branch. To do so, you must add the SonarQube Cloud analysis to your CI pipeline.

* To learn more about pull request analysis, see [Pull request analysis](/sonarqube-cloud/analyzing-source-code/pull-request-analysis).
* To integrate SonarQube Cloud analysis into your GitLab CI pipeline, see [GitLab CI](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/gitlab-ci).

You can also configure pull request decoration to allow your developers to view the analysis from SonarQube Cloud directly on the pull requests they submit.

* To learn more about the GitLab integration features, see [Issues reported in GitLab](/sonarqube-cloud/managing-your-projects/issues/in-devops-platform/gitlab).
* To set up your project integration with GitLab, see [Configuring GitLab project binding](/sonarqube-cloud/managing-your-projects/administering-your-projects/devops-platform-integration/gitlab).

## Step 5: Connect with SonarQube for IDE

SonarQube for IDE is a free IDE extension that integrates with SonarQube Cloud. Like a spell checker, SonarQube for IDE highlights issues as you type.

Install SonarQube for IDE to leverage the power of SonarQube in your IDE. To do so, see [SonarQube for IDE](/sonarqube-cloud/analyzing-source-code/connected-mode).

## Step 6: View your analysis results

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/HZgBQbZwvctb7V1bsaPp" alt="The Project Overview page."><figcaption></figcaption></figure>

### Review your project’s quality gate

The purpose of Quality gates is to tell you whether your code is good enough to be pushed to the next step:

* For the main branch and other long-lived branches, the quality gate answers the question: "Can I release my code today?"
* For pull requests (and short-lived branches), the quality gate answers the question: "Can I merge this pull request?"

By keeping an eye on the quality gates, the decision makers can quickly judge the status of code and decide what to do next.

For more information, see [Quality gates](/sonarqube-cloud/standards/quality-gates).

### Review your issues

An analysis detects an issue as a problem in your code. When a coding rule is broken, an issue is raised. Each issue affects one or more software qualities with a varying impact level, called severity, as inherited from the rule. For more information about rules, see [Viewing and managing rules](/sonarqube-cloud/standards/managing-rules).

To review your issues, see [Managing code issues](/sonarqube-cloud/managing-your-projects/issues).

## Step 7: Adjust your project setup

The analysis performed by the SonarScanner is configured through analysis parameters. The following applies:

* A few analysis parameters are mandatory.
* Many analysis parameters, such as those defining the analysis scope, have a default value and can be adjusted.
* Analysis parameters allow you to include the code and test coverage in your analysis, or to import issues generated by a third-party analyzer, etc.

SonarQube Server manages the analysis parameters through sonar properties (The sonar property key has the following syntax: `sonar.<property>`.).

You can configure the analysis parameters in different places. For more information, see [Configuration overview](/sonarqube-cloud/analyzing-source-code/analysis-parameters/configuration-overview).

You can:

* Adjust your analysis scope, see [Analysis scope](/sonarqube-cloud/managing-your-projects/project-analysis/setting-analysis-scope).
* Implement test coverage, see [Test coverage](/sonarqube-cloud/analyzing-source-code/test-coverage).
* Import external analyzer reports, see [External analyzer reports](/sonarqube-cloud/analyzing-source-code/importing-external-issues/external-analyzer-reports).
* Define a Long-lived branch pattern, see [Long-lived branch pattern](/sonarqube-cloud/managing-your-projects/project-analysis/long-lived-branch-pattern).
* Change the new code definition applied to your project, see [New code definition](/sonarqube-cloud/managing-your-projects/project-analysis/configuring-new-code-calculation).
* Change the quality gate assigned to your project, see [Quality gate](/sonarqube-cloud/managing-your-projects/project-analysis/changing-quality-gate).
* Change the quality profiles assigned to your project, see [Quality profile](/sonarqube-cloud/managing-your-projects/project-analysis/quality-profile-association)

## Step 8: Check out security reports and portfolios

Managers and tech leads can check out the security reports and portfolios features to begin monitoring the security and releasability of projects. For more information, see [Viewing the enterprise reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports).

## Related pages <a href="#related-pages" id="related-pages"></a>

* [GitLab](/sonarqube-cloud/discovering-sonarcloud/integration-with-devops-platforms/gitlab) (integration solution overview)
* [Organization setup overview](/sonarqube-cloud/administering-sonarcloud/managing-organization/setup-overview)
* [Importing GitLab group](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-gitlab-group)
* [Project administration overview](/sonarqube-cloud/managing-your-projects/administering-your-projects/introduction)
* [Creating your project](/sonarqube-cloud/managing-your-projects/administering-your-projects/setting-up-project)
* [Configuring GitLab project binding](/sonarqube-cloud/managing-your-projects/administering-your-projects/devops-platform-integration/gitlab)
* [GitLab CI](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/gitlab-ci)
* [Choosing your server region](/sonarqube-cloud/getting-started/choosing-your-region)

## Related online learning

* <i class="fa-desktop">:desktop:</i> [Initial SonarQube Cloud set up with GitLab](https://www.sonarsource.com/learn/course/sonarqube-cloud/157cdb9a-5e24-4e93-ad85-fa73548a00e2/initial-sonarqube-cloud-set-up-with-gitlab)
* <i class="fa-desktop">:desktop:</i> [Configuring code analysis for SonarQube Cloud with GitLab CI/CD](https://www.sonarsource.com/learn/course/sonarqube-cloud/829acfc2-7443-4192-b9e9-872dd6757bc0/configuring-code-analysis-for-sonarqube-cloud-with-gitlab-cicd)


# Getting started with Azure DevOps

Everything you need to know to get started analyzing your Azure DevOps projects on SonarQube Cloud.

## Step 1: Sign up

1. Go to [SonarQube Cloud product page](https://www.sonarsource.com/products/sonarqube/cloud/) and select **Start now**. The Get started page opens.\
   If you want to use the [US region](/sonarqube-cloud/getting-started/choosing-your-region), go to [sonarqube.us](http://sonarqube.us/) instead.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/BVLOH9q8iM546Pt17rOq" alt="Select your DevOps platform."><figcaption></figcaption></figure>

2. Select **Azure DevOps** from the list of DevOps platforms. You will be taken to the Azure DevOps login page.
3. Sign in using your Azure DevOps credentials.\
   For prerequisites on your DevOps account’s email address, see [Signing in to SonarQube Cloud](/sonarqube-cloud/managing-your-account/signing-in#via-devops-platform).

Your SonarQube Cloud account is created and bound to your DevOps account. For more information, see [Authentication](https://www.sonarsource.com/trust-center/#authentication) in the Trust Center.

Once you have successfully logged in, you will be prompted to connect your Azure DevOps organization with SonarQube Cloud and create your SonarQube Cloud organization.

## Step 2: Create your organization

We use an [organization-based structure](/sonarqube-cloud/administering-sonarcloud/about-sonarqube-cloud-solution/resources-structure/organization) that mirrors the structure on your chosen DevOps platforms: each SonarQube Cloud organization corresponds one-to-one with an Azure DevOps organization or personal account. A subscription plan is associated one-to-one with a SonarQube Cloud organization. See [Subscription plans](/sonarqube-cloud/administering-sonarcloud/managing-subscription/subscription-plans) for a comparison between the different plans.

Proceed as follows. For detailed prerequisites and instructions, see [Importing Azure DevOps organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-azure-devops-organization).

1. Create the PAT to be used for the organization binding.\
   SonarQube Cloud uses an Azure DevOps user account to import your Azure DevOps organization and repositories. You must provide a [Personal Access Token](https://docs.microsoft.com/en-us/azure/devops/organizations/accounts/use-personal-access-tokens-to-authenticate?view=tfs-2017\&tabs=preview-page) (PAT) from this account. The token should have the following permissions:
   * **Code** > **Read & write**
   * **Analytics** > **Read** (used for automatic analysis, found under **Show all scopes** at the bottom of the dialog)
2. Select **Import an organization from Azure DevOps**.
3. Paste the PAT you created to **Personal Access Token**.
4. Check the organization details.
5. Select the subscription plan
6. Create your organization. A new page opens.
7. Select **Analyze a new project** and go to the next step below.

{% hint style="info" %}

* The organization creator becomes the organization admin. To set up the organization permissions, see [Managing organization permissions](/sonarqube-cloud/administering-sonarcloud/managing-organization/users-and-permissions/organization-permissions).
* Consider upgrading to [Enterprise](https://docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/managing-subscription/subscription-plans) so you can benefit from many features, in particular SSO and SCIM. See [About SSO and provisioning](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning/about).
  {% endhint %}

## Step 3: Import your repositories

You can now import the existing projects (that is, individual Git repositories) that you want to analyze from your Azure DevOps organization into your newly created SonarQube Cloud organization. A corresponding, one-to-one SonarQube Cloud project will be created for each imported repository.

Proceed as follows (you need the Create Projects permission in your organization):

1. Select the repositories you want to import and select the **Set up** button.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/Dw2Pa0vEqSPL0110rGD4" alt="Select your repository(ies) and select the Set up button."><figcaption></figcaption></figure>

2. Select the new code definition for your new project(s). For more information about this definition, see [Quality standards and new code](/sonarqube-cloud/standards/about-new-code).\
   Note that the new code definition you apply at this stage will apply to all of the projects you have selected for import. You can change your new code definition later on a per-project basis (see [New code definition](/sonarqube-cloud/managing-your-projects/project-analysis/configuring-new-code-calculation)).

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/bDXgcK90altZWukE5AwK" alt="Select a new code definition option for your project."><figcaption></figcaption></figure>

3. Create your project(s).

{% hint style="info" %}
The project creator becomes the project admin. To set up the project permissions, see [Setting your project's permissions](/sonarqube-cloud/managing-your-projects/administering-your-projects/setting-permissions).
{% endhint %}

{% hint style="info" %}
When you import a project that is eligible for automatic analysis, SonarQube Cloud automatically creates a set of webhooks for your Azure DevOps repository. These webhooks are used to trigger [automatic analysis](/sonarqube-cloud/analyzing-source-code/automatic-analysis) in the repository whenever code is pushed, or pull requests are created, and are visible in your Azure DevOps project settings, under **Service hooks**.
{% endhint %}

## Step 4: Set up your project analysis

For Azure DevOps repositories, there are two analysis methods available: Automatic analysis and CI-based analysis.

### Automatic analysis

If a project qualifies for automatic analysis, SonarQube Cloud will start the analysis of the project’s main branch and of the most recent active pull requests automatically, and the results will appear shortly after. See [Automatic analysis](/sonarqube-cloud/analyzing-source-code/automatic-analysis) for more information.

### CI-based analysis

If automatic analysis is not supported for your project or you don't want to use it, you’ll need to set up CI-based analysis. The actual analysis is performed in your build environment (for example, on a cloud CI or your local machine). This means that you must configure your build process to perform the analysis on each build and communicate the results to SonarQube Cloud.

SonarQube Cloud will guide you through a tutorial on how to set up your build environment to perform analysis. For more information, see [Azure pipelines](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/azure-pipelines).

To understand the SonarQube analysis principles, see [SonarQube analysis overview](/sonarqube-cloud/discovering-sonarcloud/analysis-process-overview).

### About the SonarQube Cloud analysis

The SonarScanner performs the automated source code analysis as part of your code review process. This stand-alone program runs on the CI/CD host and sends the analysis results to SonarQube Server, which computes them, calculates the quality gate, and generates reports.

To perform the analysis, the SonarScanner uses the [Sonar analyzers](/sonarqube-cloud/discovering-sonarcloud/overview) that it downloads from SonarQube Cloud at installation.

The Sonar Solution offers SonarScanners that integrate with the following build systems: Gradle, Maven, .NET, NPM, and Python. For other project types, the SonarScanner CLI which requires more manual configuration is used.

For more information about integrated CI tools and SonarScanners, see [CI-based analysis](/sonarqube-cloud/analyzing-source-code/ci-based-analysis)

### Setting up the pull request analysis

By setting up pull request analysis, you ensure pull requests are analyzed when they are opened and every time a change is pushed to the pull request branch. To do so, you must add the SonarQube Cloud analysis to your CI pipeline.

* To learn more about pull request analysis, see [Pull request analysis](/sonarqube-cloud/analyzing-source-code/pull-request-analysis).
* To integrate SonarQube Cloud analysis into your Azure pipeline, see [Azure pipelines](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/azure-pipelines).

You can also configure pull request decoration to allow your developers to view the analysis from SonarQube Cloud directly on the pull requests they submit.

* To learn more about the Azure DevOps integration features, see [Issues reported in Azure DevOps](/sonarqube-cloud/managing-your-projects/issues/in-devops-platform/azure-devops).
* To set up your project integration with Azure DevOps, see [Configuring Azure DevOps project binding](/sonarqube-cloud/managing-your-projects/administering-your-projects/devops-platform-integration/azure-devops).

## Step 5: Connect with SonarQube for IDE

SonarQube for IDE is a free IDE extension that integrates with SonarQube Cloud. Like a spell checker, SonarQube for IDE highlights issues as you type.

Install SonarQube for IDE to leverage the power of SonarQube in your IDE. To do so, see [SonarQube for IDE](/sonarqube-cloud/analyzing-source-code/connected-mode).

## Step 6: View your analysis results

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/HZgBQbZwvctb7V1bsaPp" alt="The Project Overview page."><figcaption></figcaption></figure>

### Review your project’s quality gate

The purpose of Quality gates is to tell you whether your code is good enough to be pushed to the next step:

* For the main branch and other long-lived branches, the quality gate answers the question: "Can I release my code today?"
* For pull requests (and short-lived branches), the quality gate answers the question: "Can I merge this pull request?"

By keeping an eye on the quality gates, the decision makers can quickly judge the status of code and decide what to do next.

For more information, see [Quality gates](/sonarqube-cloud/standards/quality-gates).

### Review your issues

An analysis detects an issue as a problem in your code. When a coding rule is broken, an issue is raised. Each issue affects one or more software qualities with a varying impact level, called severity, as inherited from the rule. For more information about rules, see [Viewing and managing rules](/sonarqube-cloud/standards/managing-rules).

To review your issues, see [Managing code issues](/sonarqube-cloud/managing-your-projects/issues).

## Step 7: Adjust your project setup

The analysis performed by the SonarScanner is configured through analysis parameters. The following applies:

* A few analysis parameters are mandatory.
* Many analysis parameters, such as those defining the analysis scope, have a default value and can be adjusted.
* Analysis parameters allow you to include the code and test coverage in your analysis, or to import issues generated by a third-party analyzer, etc.

SonarQube Server manages the analysis parameters through sonar properties (The sonar property key has the following syntax: `sonar.<property>`.).

You can configure the analysis parameters in different places. For more information, see [Configuration overview](/sonarqube-cloud/analyzing-source-code/analysis-parameters/configuration-overview).

You can:

* Adjust your analysis scope, see [Analysis scope](/sonarqube-cloud/managing-your-projects/project-analysis/setting-analysis-scope).
* Implement test coverage, see [Test coverage](/sonarqube-cloud/analyzing-source-code/test-coverage).
* Import external analyzer reports, see [External analyzer reports](/sonarqube-cloud/analyzing-source-code/importing-external-issues/external-analyzer-reports).
* Define a Long-lived branch pattern, see [Long-lived branch pattern](/sonarqube-cloud/managing-your-projects/project-analysis/long-lived-branch-pattern).
* Change the new code definition applied to your project, see [New code definition](/sonarqube-cloud/managing-your-projects/project-analysis/configuring-new-code-calculation).
* Change the quality gate assigned to your project, see [Quality gate](/sonarqube-cloud/managing-your-projects/project-analysis/changing-quality-gate).
* Change the quality profiles assigned to your project, see [Quality profile](/sonarqube-cloud/managing-your-projects/project-analysis/quality-profile-association)

## Step 8: Check out security reports and portfolios

Managers and tech leads can check out the security reports and portfolios features to begin monitoring the security and releasability of projects. For more information, see [Viewing the enterprise reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports).

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Azure DevOps](/sonarqube-cloud/discovering-sonarcloud/integration-with-devops-platforms/azure-devops) (integration solution overview)
* [Importing Azure DevOps organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-azure-devops-organization)
* [Creating your project](/sonarqube-cloud/managing-your-projects/administering-your-projects/setting-up-project)
* [Configuring Azure DevOps project binding](/sonarqube-cloud/managing-your-projects/administering-your-projects/devops-platform-integration/azure-devops)
* [Azure pipelines](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/azure-pipelines)
* [Choosing your server region](/sonarqube-cloud/getting-started/choosing-your-region)
* [Remediation Agent](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/solve-issues/administer-remediation-agent) (fix backlog issues with AI)

## Related online learning

* <i class="fa-desktop">:desktop:</i> [Initial SonarQube Cloud set up with Azure DevOps](https://www.sonarsource.com/learn/course/sonarqube-cloud/03584daa-8cd6-4825-be83-4ca3b0e73078/initial-sonarqube-cloud-set-up-with-azure-devops)
* <i class="fa-desktop">:desktop:</i> [Configuring code analysis for SonarQube Cloud with Azure Pipelines](https://www.sonarsource.com/learn/course/sonarqube-cloud/d77cd975-f3c7-4ee9-bda5-9e25447d1c9b/configuring-code-analysis-for-sonarqube-cloud-with-azure-pipelines)
* <i class="fa-desktop">:desktop:</i> [Configuring pull request decoration for SonarQube Cloud using Azure DevOps](https://www.sonarsource.com/learn/course/sonarqube-cloud/4a81488c-81ec-4479-8f93-e7bda1a00351/configuring-pull-request-decoration-for-sonarqube-cloud-using-azure-devops)


# Viewing your first analysis' results

Once you have successfully followed the in-product tutorial, SonarQube Cloud will automatically run its first analysis on your project.

If you have successfully followed the in-product tutorial, SonarQube Cloud will run its first analysis on your project.

The first analysis is always a *main branch analysis,* an analysis of the default branch of your repository.

From now on, a new analysis will be triggered every time you make a change to the main branch by direct push, pull request merge, or branch merge.

## Overview page

Once your analysis is completed a project Overview page opens, displaying the **Project health dashboard**, a built-in Sonar dashboard available in all plans. Custom dashboards and other built-in dashboard views are available in the [Enterprise](https://www.sonarsource.com/plans-and-pricing/sonarcloud/) plan.

<figure><img src="/files/Mjs4qXlPdjzJ7BC93F6a" alt=""><figcaption></figcaption></figure>

The top row of the dashboard shows:

* **Quality gate status**: Passed, Failed or Not Computed.

{% hint style="info" %}
**The quality gate displays Not Computed because it needs to be configured.**

We strongly recommend set a new code definition by goin to *Your project* > **Administration** > **New Code**.

See the [Quality gates](/sonarqube-cloud/standards/quality-gates) and [Quality standards and new code](/sonarqube-cloud/standards/about-new-code) for more details. Once you set it up, push a change to the main branch. A new analysis will run, and the quality gate status will display either **Passed** or **Failed**.
{% endhint %}

* **Open issues**: Displays the number of issues found in the main branch.
* **Duplications:** Displays the percentage of main branch code that is duplicated.
* **Coverage**: Displays the percentage of testable code in the main branch that is covered by your test cases.

{% hint style="info" %}
**Coverage displays zero percent because it needs to be configured.**

Initially, your coverage will display zero percent because it requires configuration. To set it up, see the [Overview](/sonarqube-cloud/analyzing-source-code/test-coverage/overview) section.

Once it’s configured, push a change to the main branch to update the analysis. After the a new analysis is run, the coverage percentage will be displayed.
{% endhint %}

See [Retrieving projects](/sonarqube-cloud/managing-your-projects/retrieving-projects) for more information about the Project health dashboard and other project related information.

## Main branch <a href="#main-branch" id="main-branch"></a>

To view additional information about the most recent main branch analysis. Go to *Your project* > **Summary** page. Alternatively, you can go to *Your project* > **Branches** and select the main branch from the list of all the branches. See [Main branch analysis](/sonarqube-cloud/analyzing-source-code/branch-analysis/main-branch-analysis) for more information.

## Pull Requests <a href="#pull-requests" id="pull-requests"></a>

In addition to analyzing your main branch every time it changes, SonarQube Cloud also analyzes individual pull requests. These analyses run when a pull request is opened and on each change to the pull request branch. This all happens *before* you merge, letting you catch problems before they even get to the main branch.

To view a pull request analysis go to *Your project* > **Pull requests** and select your pull request from the list. See [Pull request analysis](/sonarqube-cloud/analyzing-source-code/pull-request-analysis) for more information.

## Branches <a href="#branches" id="branches"></a>

The **Branches** page displays all the non-pull request branches for which you have set up analysis. Go to *Your project* > **Branches** to view the list. Initially, only the main branch is listed here. But, you can configure other branches to be analyzed. Once a branch is configured, an analysis is run on every change to that branch. See [Branch analysis](/sonarqube-cloud/analyzing-source-code/branch-analysis/branch-analysis) and [Branch analysis setup](/sonarqube-cloud/analyzing-source-code/branch-analysis/branch-analysis-setup) for more information.

## Related pages

* [Retrieving projects](/sonarqube-cloud/managing-your-projects/retrieving-projects)
* [Main branch analysis](/sonarqube-cloud/analyzing-source-code/branch-analysis/main-branch-analysis)
* [Pull request analysis](/sonarqube-cloud/analyzing-source-code/pull-request-analysis)
* [Branch analysis](/sonarqube-cloud/analyzing-source-code/branch-analysis/branch-analysis)
* [Branch analysis setup](/sonarqube-cloud/analyzing-source-code/branch-analysis/branch-analysis-setup)


# Retrieving your organizations

You can view any free plan organization or a paid plan organization if you’re a member.

You can view any free or paid plan organization if you’re a member.

## Listing all your organizations <a href="#listing-organizations" id="listing-organizations"></a>

This procedure explains how to open your account’s **Organizations** page.

{% hint style="info" %}
From the Organizations page, you can leave an organization. With the appropriate permissions, you can also create, delete, or upgrade an organization.
{% endhint %}

To list your organizations:

1. Select your account menu in the top right corner of the SonarQube Cloud interface.
2. In the menu, select **View all** at the bottom of the **My Organizations** section.
3. The **Organizations** page opens with the list of organizations you’re a member of.
4. The `Admin` tag indicates that you're an admin of the organization.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/njJU0zZUcCMdFlSh5w3I" alt="Viewing all organizations your are a member of"><figcaption></figcaption></figure>

## Retrieving and viewing your organization <a href="#viewing" id="viewing"></a>

To retrieve your organization, you can:

1. Select your account menu in the top right corner of the SonarQube Cloud interface. In the menu, under **My Organizations**, select the organization you want to view.
2. Alternatively, open the **My Projects** page and select the organization hyperlink in the projects list.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/GJ9e0cbyhAKj2TDEMFL9" alt="Your organizations are clearly displayed in different parts of the SonarQube Cloud UI, where appropriate."><figcaption></figcaption></figure>

The organization record opens as illustrated below:

1. Organization's avatar and name.\
   The avatar is a small image representing the organization. As an organiziation admin, you can add one, see [Changing organization settings](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/changing-organization-settings#change-details).
2. Organization's navigation bar.
3. Organization key.
4. Organization's subscription plan.
5. Button to navigate to the [bound DevOps organization](/sonarqube-cloud/administering-sonarcloud/about-sonarqube-cloud-solution/resources-structure/binding-with-dop).

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/FkyqumRyjCdIdjHG6ctn" alt="Overview of the organization&#x27;s page"><figcaption></figcaption></figure>

You can navigate through the different pages by using the Organization's navigation bar (some pages require specific access permission) :

* **Projects**: This page lists the [Organization's projects](/sonarqube-cloud/administering-sonarcloud/about-sonarqube-cloud-solution/resources-structure/projects) belonging to the organization and to which you have access.
* **Issues**: This page lists issues belonging to the organization. See [Reviewing issues](/sonarqube-cloud/managing-your-projects/issues/reviewing) for details.

**Policies**

* **License profiles**: This page shows which licenses are allowed or prohibited for the dependences used by your projects. See [Managing license profiles and policies](/sonarqube-cloud/advanced-security/managing-license-profiles-and-policies) for details.
* **Rules**: This page allows you to retrieve [SonarQube rules](/sonarqube-cloud/standards/managing-rules/rules) available in the organization through its quality profiles.
* **Quality Profiles**: This page allows you to manage quality profiles available to your organization’s projects, listed by language. See [Introduction](/sonarqube-cloud/standards/managing-quality-profiles/introduction) for more information.
* **Quality Gates**: This page allows you to manage quality gates available to your organization’s projects. See [Understanding quality gates](/sonarqube-cloud/standards/managing-quality-gates/introduction-to-quality-gates) for more information.

**Access**

* **Billing and usage**: This page allows the organization admins to manage the organization's subscription. See Managing your subscription [Introduction](/sonarqube-cloud/administering-sonarcloud/managing-subscription/introduction) for more information.
* **Members**: This page lists the organization's members and allows the organization admins to manage them. See [Adding organization members](/sonarqube-cloud/administering-sonarcloud/managing-organization/users-and-permissions/organization-members) for more information.
* **Groups:** This page allows you to create and manages groups of users. See [Managing user groups](/sonarqube-cloud/administering-sonarcloud/managing-organization/users-and-permissions/user-groups) for details.
* **Permissions:** This page lists all user and groups permissions for your organization. See [Managing users and permissions](/sonarqube-cloud/administering-sonarcloud/managing-organization/users-and-permissions) for details.
* **Permission templates:** This page lists all permission templates for your organization and lets you manage them. See [Using permission templates](/sonarqube-cloud/administering-sonarcloud/managing-organization/manage-org-projects/manage-project-permissions/templates) for details.
* **Scoped organizations:** This page allows you to manage scoped organization tokens. See [Managing Scoped Organization Tokens](/sonarqube-cloud/administering-sonarcloud/managing-organization/scoped-organization-tokens) for details.
* **Webhooks:** This page lists all webhooks for the organization and allows you to create new ones. See [Webhooks](/sonarqube-cloud/discovering-sonarcloud/integrations/webhooks) for more details.
* **Administration**: This menu allows the organization admins to access various administration menus. See [Managing your organization](/sonarqube-cloud/administering-sonarcloud/managing-organization) for more information.

## Retrieving any free organization <a href="#free-organization" id="free-organization"></a>

* If you know the organization key, go to:
  * In the EU region: `sonarcloud.io/organizations/<YourOrganizationKey>`
  * In the US region: `sonarqube.us/organizations/<YourOrganizationKey>`
* Otherwise, in the top navigation bar of the SonarQube Cloud UI, select **Explore** or go to [`sonarcloud.io/explore/projects`](http://sonarcloud.io/explore/projects) (in the EU region) or `sonarqube.us/explore.projects` (in the US region), and select an organization.


# Choosing your server region

SonarQube Cloud offers accounts in the EU and US server regions. This page outlines the specific prerequisites, limitations, and setup details relevant for choosing your region.

*SonarQube Cloud accounts in the US server region require an Enterprise plan subscription.*

SonarQube Cloud is available in two regions: EU and US. Your choice of region determines where your data is stored and cannot be changed after sign-up. Use the comparison table below to choose the region that's right for you. New accounts are created in the EU region by default. To set up an account in the US region, [contact your Sonar sales representative](https://www.sonarsource.com/plans-and-pricing/contact-sales/).

|                              | EU region       | US region                                                       |
| ---------------------------- | --------------- | --------------------------------------------------------------- |
| Sign-in URL                  | `sonarcloud.io` | `sonarqube.us`                                                  |
| Data location                | European Union  | United States                                                   |
| Scanner version requirements | None            | Minimum versions required (see [Prerequisites](#prerequisites)) |
| Slack integration            | Supported       | Not supported                                                   |

If you already have US region access, you can use the region toggle on the login pages (`sonarcloud.io/login` and `sonarqube.us/login`) to select your region.

{% hint style="info" %}
When you request an enterprise setup within the US region, Sonar authorizes your users to access the US instance. As an end user, if you think you should have access, contact your SonarQube Cloud administrator.
{% endhint %}

## Limitations

Access to the US region requires a SonarQube Cloud Enterprise plan and must be specifically requested from your sales representative.

You currently cannot share or move data between the SonarQube Cloud EU and US instances.

The Slack integration is currently not supported in the SonarQube Cloud US instance.

## Prerequisites

All SonarScanners work with the EU region without any version restrictions. To analyze projects in the US region, you must use at least the following scanner version:

* [SonarScanner for Maven](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-maven): 5.1
* [SonarScanner for Gradle](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-gradle): 6.1
* [SonarScanner for .NET](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-dotnet): 10.2
* [SonarScanner for NPM](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-for-npm): 4.3
* [SonarScanner CLI](/sonarqube-cloud/analyzing-source-code/scanners/sonarscanner-cli): 7.1
* [SonarScanner CLI Docker image](https://hub.docker.com/r/sonarsource/sonar-scanner-cli): 11.3
* [Github Actions](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/github-actions-for-sonarcloud): 5.1.0
* [Bitbucket Pipelines](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/bitbucket-pipelines-for-sonarcloud): 4.1
* [Azure DevOps Extension](/sonarqube-cloud/analyzing-source-code/scanners/sonarcloud-extension-for-azure-devops): 3.2

If you use [CircleCI](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/circleci) with our Orb in the US region, use at least Orb version 3.0.

## Configuring your scanner or extension for your region

If you use the Azure DevOps extension, select your region when [Configuring project for Azure Pipelines](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/azure-pipelines/setting-up-project-integration#adding-sonarqube-service-connection).

For all other scanners, the `sonar.region` analysis parameter determines in which server region a project is hosted. This parameter defaults to the EU server region. For more information about this parameter, see [Parameters not settable in the UI](/sonarqube-cloud/analyzing-source-code/analysis-parameters/parameters-not-settable-in-ui#server-connection). For general guidelines to set your analysis parameters, see [Configuration overview](/sonarqube-cloud/analyzing-source-code/analysis-parameters/configuration-overview).

## Connecting SonarQube for IDE to your region

[SonarQube for IDE](https://www.sonarsource.com/products/sonarqube/ide/) is a free IDE extension that integrates with SonarQube Cloud using connected mode.

The connected mode setup is different depending on whether you use the EU or US region. For more information, see:

* VS Code: [Connected mode setup](/sonarqube-for-vs-code/connect-your-ide/setup#sonarqube-cloud-us-region) · [Connected mode setup](/sonarqube-for-vs-code/connect-your-ide/setup#sonarqube-cloud)
* IntelliJ: [Connected mode setup](/sonarqube-for-intellij/connect-your-ide/setup#sonarqube-cloud-us-region) · [Connected mode setup](/sonarqube-for-intellij/connect-your-ide/setup#sonarqube-cloud)
* Visual Studio: [Connected mode setup](/sonarqube-for-visual-studio/connect-your-ide/setup#sonarqube-cloud-us-region) · [Connected mode setup](/sonarqube-for-visual-studio/connect-your-ide/setup#sonarqube-cloud)
* Eclipse: [Connected mode setup](/sonarqube-for-eclipse/connect-your-ide/setup#sonarqube-cloud-us-region) · [Connected mode setup](/sonarqube-for-eclipse/connect-your-ide/setup#sonarqube-cloud)

## Connecting your MCP server to your region

You can connect your local MCP server to either region. No additional configuration is needed for the EU region. For the US region, set `SONARQUBE_URL=https://sonarqube.us` in your configuration file. For more information, see MCP Server's [Environment considerations](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-mcp-server/setup/environment-considerations#connecting-to-sonarqube-cloud-in-the-us-region) page.

The SonarQube Cloud-hosted MCP server is also available for either region; see the MCP Server's [SonarQube Cloud-hosted](https://docs.sonarsource.com/sonarqube-developer-tools/sonarqube-mcp-server/setup/sonarqube-cloud-hosted) page for setup details.

## Using your region's Web API

See [Web API](/sonarqube-cloud/appendices/web-api).

## Networking requirements for your region

See [Networking requirements](/sonarqube-cloud/appendices/networking-requirements).


# Getting started with Enterprise

SonarQube Cloud's Enterprise plan lets you group together your organizations spread across multiple DevOps platforms into a single subscription.

{% content-ref url="/pages/eZnANnlDuzjbveDD642X" %}
[Introduction](/sonarqube-cloud/getting-started-with-enterprise/introduction)
{% endcontent-ref %}

{% content-ref url="/pages/dDf0YlQO3CYUpNyNzQkF" %}
[Setting up your enterprise](/sonarqube-cloud/getting-started-with-enterprise/setting-up-your-enterprise)
{% endcontent-ref %}

{% content-ref url="/pages/wWUg6drfGO5FK6PwZZX4" %}
[Setting up SSO](/sonarqube-cloud/getting-started-with-enterprise/setting-up-sso)
{% endcontent-ref %}

{% content-ref url="/pages/ZRoauffUkMfyww8lRXBM" %}
[Onboarding a new organization](/sonarqube-cloud/getting-started-with-enterprise/onboarding-new-org)
{% endcontent-ref %}

{% content-ref url="/pages/3lzwT5Z93c1YGcL5vs03" %}
[Administering portfolios](/sonarqube-cloud/getting-started-with-enterprise/administering-portfolios)
{% endcontent-ref %}

{% content-ref url="/pages/GaOa5r6JMhqqg6toRQcu" %}
[Viewing the enterprise reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports)
{% endcontent-ref %}

{% content-ref url="/pages/bN0d9UgphO91vF03VZ8X" %}
[Viewing usage information](/sonarqube-cloud/getting-started-with-enterprise/viewing-billing-usage-info)
{% endcontent-ref %}


# Introduction

With the Enterprise subscription plan, you can group together all of your SonarQube Cloud organizations into an enterprise and benefit from additional features.

With the Enterprise subscription plan, you can group together SonarQube Cloud organizations from different DevOps platforms into an enterprise and benefit from many features. To create an enterprise, you need a license which is priced based on the number of Lines of Code (LOC) of private projects within your enterprise.

See [Subscription plans](/sonarqube-cloud/administering-sonarcloud/managing-subscription/subscription-plans) for more information.

## Related pages <a href="#related-pages" id="related-pages"></a>

**For managers and executive users:**

* [Introduction](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/introduction) to Viewing the Enterprise reports.\
  View management reports available with the Enterprise plan: portfolio, security, and project reports.

**For enterprise administrators:**

* [Setting up your enterprise](/sonarqube-cloud/getting-started-with-enterprise/setting-up-your-enterprise)\
  View the different steps necessary to create and configure an enterprise.
* [Viewing usage information](/sonarqube-cloud/getting-started-with-enterprise/viewing-billing-usage-info)
* [Setting up SSO](/sonarqube-cloud/getting-started-with-enterprise/setting-up-sso)
* [Onboarding a new organization](/sonarqube-cloud/getting-started-with-enterprise/onboarding-new-org)
* [Managing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise)
* Check out SonarQube Cloud's [AI capabilities](/sonarqube-cloud/ai-capabilities)

**For portfolio administrators:**

* [Administering portfolios](/sonarqube-cloud/getting-started-with-enterprise/administering-portfolios)


# Setting up your enterprise

This page explains how to set up your SonarQube Cloud Enterprise as part of the Getting started with Enterprise.

With the Enterprise license, you can group together SonarQube Cloud organizations from different DevOps platforms into an enterprise and benefit from many features. [Contact our team](https://www.sonarsource.com/products/sonarqube/cloud/contact-enterprise-sales/) to request an Enterprise license. Provide the maximum number of Lines of Code (LOC) you want to have in your enterprise. For more information, see [Subscription plans](/sonarqube-cloud/administering-sonarcloud/managing-subscription/subscription-plans#loc-based-pricing) for more information.

This page explains how to set up your enterprise from scratch. Once you’ve created the enterprise, you become an enterprise Admin automatically.

{% hint style="info" %}
Currently, Sonar restricts each enterprise to a maximum of 200 organizations.
{% endhint %}

## Step 1: Enter your enterprise details

1. Log in to SonarQube Cloud with your organization’s administrator account.
2. Select the **+** icon in the top right corner of SonarQube Cloud UI and select **Create new enterprise** in the menu.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/9JthxdmIjL7S6YPJgFrT" alt="Click the plus icon and select Create new enterprise in the menu."><figcaption></figcaption></figure>

3. In **License key**, enter the key you received from Sonar.
4. Enter the name and key of your enterprise.
5. Select **Next**.

## Step 2: Create or add the organizations

First, you must add your first organization. You can import and bind the corresponding DevOps platform organization, create an organization manually, or add an existing organization. Once an organization is added to your enterprise, it’s assigned the Enterprise plan.

<figure><img src="/files/rrKcZzTlcnFZuabB303T" alt="The Create an organization step of enterprise creation, showing options to import from GitHub.com, GHE.com, GitLab.com, Bitbucket.org, or Azure DevOps; create an organization manually; or add an existing organization."><figcaption></figcaption></figure>

* To import the organization from your DevOps platform, select your DevOps platform service in **Import from DevOps platform** and follow the instructions. For more information, see:
  * [Importing GitHub.com organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-github-organization)
  * [Importing GHE.com Cloud organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-ghecom-cloud-organization)
  * [Importing GitLab group](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-gitlab-group)
  * [Importing Bitbucket workspace](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-bitbucket-workspace)
  * [Importing Azure DevOps organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-azure-devops-organization)
* To add an existing organization, select the organization in **Add an existing organization**. For more information, see [Adding organizations to your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise/adding-organizations-to-your-enterprise#add-existing-org).

{% hint style="warning" %}
If you add an existing Team plan organization to your enterprise, the organization’s Team plan subscription will be automatically cancelled and the organization will be moved to the Enterprise plan without a refund. Therefore, we recommend adding your organizations before their next billing date to avoid double charges.
{% endhint %}

At the end of the operation, select **Create Enterprise**.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/olpJ3jfjt6ljTaClqswU" alt="Enter the enterprise details and select Create enterprise."><figcaption></figcaption></figure>

The enterprise is created and you’re redirected to your enterprise’s **Organizations** page. You can now add other organizations to your enterprise. To do so, select **Create organization** to create a new organization, or **Add organization** to add an existing organization.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/zA4EVk2YscKlPp08PzSK" alt="Select Create new organization. Alternatively, select Add organization to add an existing organization."><figcaption></figcaption></figure>

## Step 3: Set the enterprise permissions of users

As an Enterprise Admin, you can grant the Administer Enterprise and Create Portfolios permissions. For more information, check out the [Managing the enterprise-related permissions](/sonarqube-cloud/administering-sonarcloud/managing-enterprise/managing-the-enterprise-related-permissions) page.

To set the enterprise-related permissions of users, follow the instructions to [Retrieving and viewing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise/retrieving-and-viewing-your-enterprise). Once inside of your enterprise:

1. Navigate to **Administration** > **Enterprise Permissions**.
2. Filter the list by **Admins or Creators**, or search for specific users.
3. For each user, toggle the **Administer Enterprise** and **Create Portfolios** permissions.

<div align="left"><figure><img src="/files/Y7BknpTvFMtngmrWevjC" alt="Enterprise permissions"><figcaption></figcaption></figure></div>

## Step 4: Complete the enterprise onboarding

For each organization in your enterprise:

* If not already done, verify the group's default permissions on new projects. See the [Using permission templates](/sonarqube-cloud/administering-sonarcloud/managing-organization/manage-org-projects/manage-project-permissions/templates) page for more information.
* You can set project configurations at the organization level. The details are outlined in the [Performing global analysis setup](/sonarqube-cloud/administering-sonarcloud/managing-organization/setting-config-at-org-level) pages.

By default, all organizations share the enterprise LOC limit. You can allocate an individual LOC limit to one or several organizations within your enterprise; please check the [Managing the lines of code within your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise/managing-the-lines-of-code-within-your-enterprise) page.

With the Enterprise license, you can now set up enterprise security features. For more information, see [Enterprise security](/sonarqube-cloud/administering-sonarcloud/enterprise-security).

## Step 5: Prepare developer IDE access <a href="#prepare-developer-ide-access" id="prepare-developer-ide-access"></a>

After the enterprise is created and organizations are attached, plan how developers will install SonarQube for IDE and bind their projects in [SonarQube for IDE](/sonarqube-cloud/analyzing-source-code/connected-mode). Connected mode applies your SonarQube Cloud quality profiles, rule selections, file exclusions, and issue states in the IDE.

SonarQube for IDE is available for [VS Code](https://docs.sonarsource.com/sonarqube-for-vs-code/), [IntelliJ](https://docs.sonarsource.com/sonarqube-for-intellij/), [Visual Studio](https://docs.sonarsource.com/sonarqube-for-visual-studio/), and [Eclipse](https://docs.sonarsource.com/sonarqube-for-eclipse/). If your organization manages VS Code extensions through a [VS Code Private Marketplace](https://code.visualstudio.com/blogs/2025/11/18/PrivateMarketplace), add SonarQube for VS Code to the private catalog before developer onboarding.

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Viewing usage information](/sonarqube-cloud/getting-started-with-enterprise/viewing-billing-usage-info)
* [Adding organizations to your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise/adding-organizations-to-your-enterprise)
* [Onboarding a new organization](/sonarqube-cloud/getting-started-with-enterprise/onboarding-new-org)
* [Recovering enterprise admin access](/sonarqube-cloud/administering-sonarcloud/managing-enterprise/recovering-enterprise-admin-access)
* [Permissions](/sonarqube-cloud/administering-sonarcloud/permissions)

## Related online learning

* <i class="fa-desktop">:desktop:</i> [Initial SonarQube Cloud Enterprise set up](https://www.sonarsource.com/learn/course/sonarqube-cloud/e390f0fe-64f4-4840-b74c-e63598af72f2/initial-sonarqube-cloud-enterprise-set-up)


# Setting up SSO

Getting started with SSO in SonarQube Cloud.

With the [Enterprise plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features), you can transition from the DevOps platform authentication mode to Single Sign On (SSO) with any identity provider (IdP) that supports SAML. SonarQube Cloud uses the Service Provider (SP) initiated SSO.

With SSO you benefit from:

* Increased security and a single source of truth for user authentication.
* Automatic user and group provisioning through SCIM or JIT provisioning.

For more information, see [About SSO and provisioning](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning/about).

SSO is set up for a given enterprise, see [Setting up your enterprise](/sonarqube-cloud/getting-started-with-enterprise/setting-up-your-enterprise) for more information. At SSO login time, users select the enterprise they want to access.

To set up SSO within your enterprise, see [Set up SSO](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning/set-up-sso). To set up SCIM, see [Set up SCIM](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning/set-up-scim).

{% hint style="warning" %}
When created, SSO accounts will have no history. That means that comments on issues, favorite projects, etc., will not be transferred from the corresponding DOP account’s history.
{% endhint %}

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Setting up your enterprise](/sonarqube-cloud/getting-started-with-enterprise/setting-up-your-enterprise)\
  View the different steps necessary to create and configure an enterprise.
* [Viewing usage information](/sonarqube-cloud/getting-started-with-enterprise/viewing-billing-usage-info)
* [Onboarding a new organization](/sonarqube-cloud/getting-started-with-enterprise/onboarding-new-org)

## Related online learning

* <i class="fa-desktop">:desktop:</i> [Initial SonarQube Cloud Enterprise set up](https://www.sonarsource.com/learn/course/sonarqube-cloud/e390f0fe-64f4-4840-b74c-e63598af72f2/initial-sonarqube-cloud-enterprise-set-up)


# Onboarding a new organization

You can add to your enterprise various organizations from various DevOps platforms.

To onboard a new organization to your enterprise:

1. Log in to SonarQube Cloud with your enterprise admin account.
2. Retrieve your enterprise. See [Retrieving and viewing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise/retrieving-and-viewing-your-enterprise) for more information.
3. Go to **Organizations**.

<figure><img src="/spaces/KXW79zfYFiA8incTvwZK/files/Befi9JuSOYzpjG60V8BR" alt="Select Create new organization."><figcaption></figcaption></figure>

4. Select **Create organization**. The **Create an organization** page opens.
5. Select your DevOps platform service and follow the instructions. For more information, see:
   * [Importing GitHub.com organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-github-organization)
   * [Importing GitLab group](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-gitlab-group)
   * [Importing Bitbucket workspace](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-bitbucket-workspace)
   * [Importing Azure DevOps organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-azure-devops-organization)
6. Optionally, allocate an individual LOC limit to the organization. See [Managing the lines of code within your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise/managing-the-lines-of-code-within-your-enterprise#allocating-loc-limit).
7. Manage the organization's user groups (see [Managing user groups](/sonarqube-cloud/administering-sonarcloud/managing-organization/users-and-permissions/user-groups) for more details):
   * In an SSO-enabled enterprise:
     * With SCIM provisioning: [Map the SCIM groups](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning/set-up-scim#map-groups) to the new organization.
     * Without SCIM: Define the user groups in your organization as described in [Invite users to sign in](/sonarqube-cloud/administering-sonarcloud/enterprise-security/sso-and-provisioning/complete-setup#if-using-jit).
   * If you don't use SSO in your enterprise:
     * Define the users and/or groups that can create projects in the organization. See [Managing organization permissions](/sonarqube-cloud/administering-sonarcloud/managing-organization/users-and-permissions/organization-permissions) for more information.
     * Verify the default permissions on new projects. See [Using permission templates](/sonarqube-cloud/administering-sonarcloud/managing-organization/manage-org-projects/manage-project-permissions/templates) for more details.
8. Set analysis configurations at the organization level. See [Performing global analysis setup](/sonarqube-cloud/administering-sonarcloud/managing-organization/setting-config-at-org-level).
9. Authorized organization members can now create projects or portfolios.

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Setting up your enterprise](/sonarqube-cloud/getting-started-with-enterprise/setting-up-your-enterprise)\
  View the different steps necessary to create and configure an enterprise.
* [Viewing usage information](/sonarqube-cloud/getting-started-with-enterprise/viewing-billing-usage-info)
* [Managing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise)


# Administering portfolios

As a SonarQube Cloud portfolio administrator, you can assign users and groups permission to administer, edit, create, and/or view portfolios.

This feature is only available in the [Enterprise plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features).

A portfolio is a set of projects within an enterprise that enables an aggregate view of its state through various lenses, including releasability, security, reliability, and maintainability.

{% hint style="info" %}
Before you can view the Enterprise-level reports, your organization must be added to an enterprise. For more information, see [Managing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise).
{% endhint %}

## Permissions <a href="#permissions" id="permissions"></a>

* To create a portfolio or a portfolio permission template, you must first be granted the Create Portfolios permission by enterprise administrator. See [Setting up your enterprise](/sonarqube-cloud/getting-started-with-enterprise/setting-up-your-enterprise#set-permissions) for details.
* The permissions to administer, edit, or view a portfolio are granted by the portfolio administrator in the portfolio settings.

### Administer, edit, and view permissions <a href="#administer-edit-and-view-permissions" id="administer-edit-and-view-permissions"></a>

The following permissions are available for a portfolio:

<table><thead><tr><th width="198.82421875">Permission</th><th>Description</th></tr></thead><tbody><tr><td><strong>Administer</strong></td><td>Can change the portfolio’s permissions.</td></tr><tr><td><strong>Edit</strong></td><td><p>Grants the ability to:</p><ul><li>Delete a portfolio.</li><li>Add projects by name (with projects’ Browse permission), by project tags, by organizations, or using regex (without projects’ Browse permission).</li><li>Remove any projects. Projects without the Browse permissions appear as hidden and once removed cannot be added back in.</li></ul></td></tr><tr><td><strong>View</strong></td><td>Can view the portfolio’s Overview, Portfolio Breakdown, and Measures tabs. On the Portfolio Breakdown page, users can only view the projects they have access to (Browse permission).</td></tr></tbody></table>

<div align="left"><figure><img src="/files/whi8OWoWFPBZqGOmaXUC" alt="Portfolio permissions page"><figcaption></figcaption></figure></div>

1. Go to **My Portfolios** in the top navigation and select your enterprise from the drop-down menu.
2. Select the portfolio you want to add the permissions to from the Portfolios home page
3. Go to **Administration** > **Permissions**
4. Assign users and groups the **Administer**, **Edit**, and **View** permissions or select **Apply Permission Template**. The Filters sidebar allows you to find users by **Type**, **Role**, and **Organization**.

## Portfolio permission templates <a href="#permission-templates" id="permission-templates"></a>

Portfolio permission template defines the portfolio-related permissions granted to groups and members of your enterprise. Enterprise administrators can define several permission templates in your organization including a default template. Using permission templates allows you to:

* Grant or revoke different sets of permissions to users or groups.
* Set a default template for new portfolios.

### Creating portfolio permission templates <a href="#creating-permission-templates" id="creating-permission-templates"></a>

The Enterprise administrator permission is required to create permission templates:

1. Retrieve your enterprise. See [Retrieving and viewing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise/retrieving-and-viewing-your-enterprise).
2. Select **Administration** > **Portfolio Permission Templates**.
3. Select **Create new template** at the top right of the page.
4. Enter the **Template Name** and **Description** in the modal.
5. Assign users and groups the **Administer**, **Edit,** and **View** permissions. The Filters sidebar allows you to find users by **Type**, **Role**, and **Organization**.

### Editing portfolio permission templates <a href="#editing-permission-templates" id="editing-permission-templates"></a>

To edit an existing permission template:

1. Retrieve your enterprise. See [Retrieving and viewing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise/retrieving-and-viewing-your-enterprise).
2. Select **Administration** > **Portfolio Permission Templates**.
3. From your permission template’s **Actions** menu you can set the template as default for new portfolios, edit permissions, update name and description or delete the template.

<div align="left"><figure><img src="/files/dLhPPw5BZaGzq9g2ePD6" alt="Options for the portfolio permission template"><figcaption></figcaption></figure></div>

{% hint style="info" %}
If you update a portfolio permission template, the changes are not reflected in any previously created or updated portfolios using that template.
{% endhint %}

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Getting started with Enterprise](/sonarqube-cloud/getting-started-with-enterprise)
* [Viewing portfolios](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-portfolios)
* [Managing portfolios](/sonarqube-cloud/managing-portfolios)
* [Permissions](/sonarqube-cloud/administering-sonarcloud/permissions)


# Viewing the enterprise reports

There are a variety of reports available with the SonarQube Cloud Enterprise plan.

{% content-ref url="/pages/tuaMm3FfiBQIyzj8Slib" %}
[Introduction](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/introduction)
{% endcontent-ref %}

{% content-ref url="/pages/oOJjHCRIJ79IfHgBWyBU" %}
[Viewing project security reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/project-security-reports)
{% endcontent-ref %}

{% content-ref url="/pages/r1JBOYG72aA5wymE4Onc" %}
[Viewing project PDF reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/project-pdf-reports)
{% endcontent-ref %}

{% content-ref url="/pages/VNThMwCxiPeJEFh3VkYd" %}
[Viewing portfolios](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-portfolios)
{% endcontent-ref %}

{% content-ref url="/pages/vax8n2CpOR0soFbvgAd2" %}
[Viewing portfolio security reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/portfolio-security-reports)
{% endcontent-ref %}


# Introduction

Viewing the Enterprise reports in SonarQube Cloud.

With the [Enterprise plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features), you have access to the following reporting features:

* **Project security reports**: Security reports help you understand where you may have issues related to particular security standards. See [Viewing project security reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/project-security-reports) for details.
* **Project regulatory reports**: These are audit‑oriented snapshots of a long‑lived branch (typically the main branch) for compliance and governance use cases. If you have [SonarQube Advanced Security](https://www.sonarsource.com/solutions/security/), the regulatory report ZIP file includes both a risk report and a software bill of materials. See [Viewing project regulatory reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-project-regulatory-reports) for details.
* **Project PDF reports**: PDF reports give a view of a project’s state through a number of lenses, including releasability, security, reliability, and maintainability. See [Viewing project PDF reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/project-pdf-reports) for details.
* **Portfolio security reports**: Portfolio security reports provide an aggregate view of issues related to security standards. See [Viewing portfolio security reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/portfolio-security-reports) for more details.
* **Portfolio PDF reports**: Portfolios give an aggregate view of a set of projects through a number of lenses, including releasability, security, reliability and maintainability. See [Viewing portfolio PDF reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-portfolio-pdf-reports) for more details.

{% hint style="info" %}
Before you can view the Enterprise-level reports, your organization must be added to an enterprise. For more information, see [Managing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise).
{% endhint %}

<figure><img src="/files/iPuMn7GELShESAnXIQYD" alt="Accessing the reports on the project level"><figcaption></figcaption></figure>

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Viewing project security reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/project-security-reports)
* [Viewing project regulatory reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-project-regulatory-reports)
* [Viewing project PDF reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/project-pdf-reports)
* [Viewing portfolios](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-portfolios)
* [Viewing portfolio security reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/portfolio-security-reports)
* [Viewing portfolio PDF reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-portfolio-pdf-reports)


# Viewing project security reports

Security reports provide a big picture overview of your project's security standing in relation to industry standards.

This feature is only available in the [Enterprise plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features).

{% hint style="info" %}
Before you can view the Enterprise-level reports, your organization must be added to an enterprise. For more information, see [Managing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise).
{% endhint %}

## Security standards

Security reports help you understand where you may have issues related to the following security standards:

* [OWASP Top 10](https://owasp.org/Top10/) (versions 2025, 2021, 2017)

<details>

<summary>OWASP Top 10 security standards covered by Sonar for version 2025</summary>

<table><thead><tr><th width="207.765625">Category</th><th width="87.17962646484375">Python</th><th width="92.93603515625">JS/TS</th><th width="78.802490234375">Java</th><th width="78.2628173828125">C#</th><th width="81.49072265625">C/C++</th><th width="80.1341552734375">PHP</th><th width="86.203125">Kotlin</th><th>Go</th></tr></thead><tbody><tr><td>A01:Broken Access Control</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A02: Security Misconfiguration</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A03: Software Supply Chain Failures</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td></td><td></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A04: Cryptographic Failures</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A05: Injection</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A06: Insecure design</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A07: Authentication Failures</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A08: Software and Data Integrity Failures</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A09: Logging and Alerting Failures</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td></td></tr><tr><td>A10: Mishandling of Exceptional Conditions</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr></tbody></table>

</details>

* [OWASP Mobile Top 10 2024](https://owasp.org/www-project-mobile-top-10/)

<details>

<summary>OWASP Mobile Top 10 security standards covered by Sonar for version 2024</summary>

<table><thead><tr><th width="206.4246826171875">Standard</th><th>Java</th><th>Kotlin</th><th>Dart</th><th>Swift</th></tr></thead><tbody><tr><td>M1: Improper Credential Usage</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>M2: Inadequate Supply Chain Security</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>M3: Insecure Authentication/Authorization</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>M4: Insufficient Input/Output Validation</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>M5: Insecure Communication</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>M6: Inadequate Privacy Controls</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>M7: Insufficient Binary Protections</td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td></td><td></td></tr><tr><td>M8: Security Misconfiguration</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>M9: Insecure Data Storage</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td></td></tr><tr><td>M10: Insufficient Cryptography</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr></tbody></table>

</details>

* [CWE Top 25](https://cwe.mitre.org/top25/archive/2024/2024_cwe_top25.html) (versions 2024, 2023, 2022, and 2021)

<details>

<summary>CWE Top 25 security standards covered by Sonar for version 2024</summary>

<table><thead><tr><th width="210.5675048828125">Category</th><th width="83.29473876953125">Python</th><th width="83.7493896484375">JS/TS</th><th width="86.885009765625">Java</th><th width="71.547607421875">C#</th><th width="82.7052001953125">C/C++</th><th width="78.1668701171875">PHP</th><th>Kotlin</th></tr></thead><tbody><tr><td>CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-787 Out-of-bounds Write</td><td><br></td><td><br></td><td><br></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-89 Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-352 Cross-Site Request Forgery (CSRF)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td></tr><tr><td>CWE-22 Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-125 Out-of-bounds Read</td><td><br></td><td><br></td><td><br></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-78 Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-416 Use After Free</td><td><br></td><td><br></td><td><br></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-862 Missing Authorization</td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr><tr><td>CWE-434 Unrestricted Upload of File with Dangerous Type</td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr><tr><td>CWE-94 Improper Control of Generation of Code (‘Code Injection’)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-20 Improper Input Validation</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-77 Improper Neutralization of Special Elements used in a Command (‘Command Injection’)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td></tr><tr><td>CWE-287 Improper Authentication</td><td><br></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-269 Improper Privilege Management</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr><tr><td>CWE-502 Deserialization of Untrusted Data</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-200 Exposure of Sensitive Information to an Unauthorized Actor</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-863 Incorrect Authorization</td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr><tr><td>CWE-918 Server-Side Request Forgery (SSRF)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</td><td><br></td><td><br></td><td><br></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-476 NULL Pointer Dereference</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-798 Use of Hard-coded Credentials</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-190 Integer Overflow or Wraparound</td><td><br></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-400 Uncontrolled Resource Consumption</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-306 Missing Authentication for Critical Function</td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr></tbody></table>

</details>

* [EU Cyber Resilience Act](https://docs.sonarsource.com/cyber-resilience-act)

<details>

<summary>EU Cyber Resilience Act security standards covered by Sonar security features</summary>

<table><thead><tr><th width="420">Requirement</th><th width="140">Security</th><th width="140">Dependency Risks</th></tr></thead><tbody><tr><td>Part I - Cybersecurity requirements relating to the properties of products with digital elements</td><td><img src="/files/Y3YH4JBMORdkKV7Ta6jn" alt="Partial coverage"> (partial)</td><td><img src="/files/Y3YH4JBMORdkKV7Ta6jn" alt="Partial coverage"></td></tr><tr><td>1.1 Risk-Based Security Standards for Digital Products</td><td></td><td></td></tr><tr><td>1.2 Security Obligations Derived from Risk Assessments</td><td><img src="/files/Y3YH4JBMORdkKV7Ta6jn" alt="Partial coverage"></td><td><img src="/files/Y3YH4JBMORdkKV7Ta6jn" alt="Partial coverage"></td></tr><tr><td>1.2.a be made available on the market without known exploitable vulnerabilities</td><td></td><td></td></tr><tr><td>1.2.b be made available on the market with a secure by default configuration, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, including the possibility to reset the product to its original state</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>1.2.c ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic security updates that are installed within an appropriate timeframe enabled as a default setting, with a clear and easy-to-use opt-out mechanism, through the notification of available updates to users, and the option to temporarily postpone them</td><td></td><td></td></tr><tr><td>1.2.d ensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorised access</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>1.2.e protect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by state of the art mechanisms, and by using other technical means</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>1.2.f protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>1.2.g process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended purpose of the product with digital elements (data minimisation)</td><td></td><td></td></tr><tr><td>1.2.h protect the availability of essential and basic functions, also after an incident, including through resilience and mitigation measures against denial-of-service attacks</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>1.2.i minimise the negative impact by the products themselves or connected devices on the availability of services provided by other devices or networks</td><td></td><td></td></tr><tr><td>1.2.j be designed, developed and produced to limit attack surfaces, including external interfaces</td><td></td><td></td></tr><tr><td>1.2.k be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques</td><td></td><td></td></tr><tr><td>1.2.l provide security related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user</td><td></td><td></td></tr><tr><td>1.2.m provide the possibility for users to securely and easily remove on a permanent basis all data and settings and, where such data can be transferred to other products or systems, ensure that this is done in a secure manner</td><td></td><td></td></tr><tr><td>Part II - Vulnerability handling requirements</td><td></td><td></td></tr><tr><td>2.1 identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products</td><td></td><td></td></tr><tr><td>2.2 in relation to the risks posed to products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates</td><td></td><td></td></tr><tr><td>2.3 apply effective and regular tests and reviews of the security of the product with digital elements</td><td></td><td></td></tr><tr><td>2.4 once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch</td><td></td><td></td></tr><tr><td>2.5 put in place and enforce a policy on coordinated vulnerability disclosure</td><td></td><td></td></tr><tr><td>2.6 take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third-party components contained in that product, including by providing a contact address for the reporting of the vulnerabilities discovered in the product with digital elements</td><td></td><td></td></tr><tr><td>2.7 provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner and, where applicable for security updates, in an automatic manner</td><td></td><td></td></tr><tr><td>2.8 ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between a manufacturer and a business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken</td><td></td><td></td></tr></tbody></table>

</details>

* [CASA](https://appdefensealliance.dev/casa)
* [OWASP ASVS](https://owasp.org/www-project-application-security-verification-standard/) (version 4.0 level 1, 2, 3)
* [PCI DSS](https://www.pcisecuritystandards.org/) (versions 4.0 and 3.2.1)
* [STIG ASD](https://www.cyber.mil/stigs/) (version 6 and 5)

### Dependency Risks in security reports

Dependency Risks are the security and compliance problems SonarQube detects in your project's open source and third-party dependencies through [Software Composition Analysis (SCA)](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca). They include known vulnerabilities such as CVEs, malicious packages, and dependencies that use a prohibited license.

Dependency Risks ratings are included in SonarQube security reports in both the SonarQube Cloud UI and exported PDFs. To view Dependency Risks, you need access to SonarQube Advanced Security. See the [Subscribing to the Advanced Security product](/sonarqube-cloud/administering-sonarcloud/managing-subscription/signing-up-for-plan#advanced-security) article for signup instructions.

## Viewing the security reports of a project branch <a href="#viewing-branch-report" id="viewing-branch-report"></a>

<figure><img src="/files/mh8P28T6VGqLs1oOI5cn" alt="A number of details are available on the Security reports overview page."><figcaption></figcaption></figure>

1. Retrieve your project. See [Retrieving projects](/sonarqube-cloud/managing-your-projects/retrieving-projects) for more details.
2. Go to **Security reports.**
3. Select the **main** branch or other long-lived branch.
4. Select the security standards you want to review.
5. View **Project overall Security rating**, **Project overall Security Review rating**, and **Project overall Dependency Security Risks rating** ([Advanced Security](/sonarqube-cloud/advanced-security/introduction) license is required) in the **Security reports overview** section.
6. Select the number displayed in the **Security**, **Security Hotspots**, or **Dependency Risks** ([Advanced Security](/sonarqube-cloud/advanced-security/introduction) license is required) columns to review the issues.
7. Select **Download Security report (PDF)** for a PDF version of the report.

## Checking the security rules included in a project’s quality profile <a href="#checking-security-rules" id="checking-security-rules"></a>

<div align="left"><figure><img src="/files/cwToZ3lHXvm92mRghuzS" alt="The four steps described here will help you manage rules that make up your quality profile."><figcaption></figcaption></figure></div>

1. Retrieve your project. See [Retrieving projects](/sonarqube-cloud/managing-your-projects/retrieving-projects) for more details.
2. Go to **Project information**.
3. Under **Quality profiles used**, select a quality profile to open it.
4. Once on the **Quality Profiles** page, select the active **Security** rules from the **Software qualities** table’s **Active** column. The **Rules** page will open.
5. In the left-side panel of the **Rules** page, scroll to the **Security Category** and filter the results by specific standards to view the security categories covered by code review and analysis.

<figure><img src="/files/6pdBjmHcSTwuXpjCj4yt" alt="The fourth and final step to manage rules that make up your quality profile."><figcaption></figcaption></figure>

## Downloading a project security PDF report for a branch <a href="#downloading-project-security-report" id="downloading-project-security-report"></a>

As a member of a security or compliance team, you can generate and download project security reports in a PDF format for any given branch.

1. Retrieve your project. See [Retrieving projects](/sonarqube-cloud/managing-your-projects/retrieving-projects) for more details.
2. Go to **Security Reports** and select the **main** branch or another long-lived branch.
3. In the top right corner of the page click **Download Security report (PDF)**.

### Download options <a href="#download-options" id="download-options"></a>

The following download options are available:

* **Default**: Includes Sonar, OWASP top 10 2021 and CWE TOP 25 2024 security standards.
* **Custom**: Choose from a list of all security standards used by SonarQube.

### Contents of the PDF Report <a href="#contents-of-the-pdf-report" id="contents-of-the-pdf-report"></a>

A Security Overview page that includes:

* Project and branch information
* The number of open **Security** issues, **Security Hotspots**, and **Accepted Security issues** on new code and overall code.
* Overall code security ratings for **Security** issues and **Security Hotspots**, including the percentage of reviewed **Security Hotspots**

A report for a given standard that includes:

* A list of categories for **Security** issues and **Security Hotspots**
* Number of issues to address and their relevant rating per category
* Breakdown by severity (Blocker, High, Medium, Low, Info)
* Hotspots that need review

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Viewing project PDF reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/project-pdf-reports)
* [Viewing portfolio security reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/portfolio-security-reports)
* [Viewing project regulatory reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-project-regulatory-reports)
* [Cyber Resilience Act capability mapping](https://docs.sonarsource.com/cyber-resilience-act)


# Viewing project regulatory reports

Regulatory reports offer insight into a project's quality gate and quality profile information, ratings, and distribution of issues in new and overall code.

Starting in [Enterprise](https://www.sonarsource.com/plans-and-pricing/enterprise/), you can download a regulatory report for any long-lived branch of a project, typically the main branch. See [Long-lived branch pattern](/sonarqube-cloud/managing-your-projects/project-analysis/long-lived-branch-pattern) if the long-lived branch is other than main.

{% hint style="info" %}
Before you can view the Enterprise-level reports, your organization must be added to an enterprise. For more information, see [Managing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise).
{% endhint %}

## Downloading regulatory reports

To download a regulatory report:

1. Retrieve the project. See [Retrieving projects](/sonarqube-cloud/managing-your-projects/retrieving-projects) for more details.
2. Go to **Summary.**
3. Click **Downloadable reports** and select **Download regulatory report (.zip)** from the drop down menu.

<figure><img src="/files/iPuMn7GELShESAnXIQYD" alt="Retrieving project regulatory reports"><figcaption></figcaption></figure>

Alternatively:

1. Go to **Project information**.
2. In the **Regulatory Report** section, choose the project branch from the drop down menu for which you want to download the report.
3. Click **Download report**.

SonarQube generates the report for download, which may take a few minutes depending on the size of the project.

## Contents of the regulatory report’s ZIP file

The reports are in a ZIP file containing a snapshot of the latest analysis of the selected branch and include TXT, CSV, and PDF files.

The PDF file includes:

* **Project overview**:
  * Project details
  * Quality gates information and status
* **Project rating** **overview** for:
  * New code broken down by new issues, accepted issues, coverage, duplication, and security hotspots.
  * Overall code broken down by security, reliability, maintainability, accepted issues, coverage, duplication, and security hotspots.
* **Distribution of issues in new code** showing open issues and breakdown by severity, based on security, reliability, maintainability.
* **Distribution of issues in overall code** showing open issues and breakdown by severity, based on security, reliability, maintainability.
* **Quality gate and quality profiles** information.
* **Files** lists all relevant files included in the ZIP file.
* **Definitions** lists all the definitions of terms related to the report.

The PDF regulatory report is generated with metrics from software qualities (security, reliability, maintainability). Some CSV files may contain metrics from both software qualities and rule types (vulnerabilities, bugs and code smells) and they are marked accordingly.

If you have [SonarQube Advanced Security](https://www.sonarsource.com/solutions/security/), the regulatory report ZIP file includes both a risk report and a software bill of materials.

## Related pages

* [Viewing project security reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/project-security-reports)
* [Viewing project PDF reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/project-pdf-reports)
* [Cyber Resilience Act capability mapping](https://docs.sonarsource.com/cyber-resilience-act)


# Viewing project PDF reports

SonarQube Cloud's PDF reports give a high-level overview of the code quality and security of your projects. You can subscribe to the monthly report.

This feature is only available in the [Enterprise plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features).

PDF reports give a view of a project’s state through a number of lenses, including releasability, security, reliability, and maintainability. They focus mainly on new code and quality gate conditions. You can subscribe to receive a monthly report by email. A project PDF report is available for the main or other long-lived branches.

{% hint style="info" %}
Before you can view the Enterprise-level reports, your organization must be added to an enterprise. For more information, see [Managing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise).
{% endhint %}

## Viewing the PDF report of a project branch <a href="#viewing-report" id="viewing-report"></a>

1. Retrieve your project. See [Retrieving projects](/sonarqube-cloud/managing-your-projects/retrieving-projects) for more details.
2. Go to **Summary**.
3. Click **Downloadable reports** and select **Download project reports (PDF)**.

## Subscribing to the monthly PDF report <a href="#monthly-report" id="monthly-report"></a>

If you subscribe to the monthly PDF report of a project branch, you’ll receive a report by email during the first portfolio calculation of the month (if any), starting from the first day of the current month.

To subscribe or unsubscribe to the monthly PDF report for a project:

1. Retrieve your project. See [Retrieving projects](/sonarqube-cloud/managing-your-projects/retrieving-projects) for more details.
2. Go to **Summary**.
3. Click **Downloadable reports** and select **Subscribe to monthly reports** from the drop-down menu.

The option to **Unsubscribe from monthly reports** is under the same **Downloadable reports** drop-down menu.

## Related pages

* [Viewing project security reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/project-security-reports)
* [Viewing project regulatory reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-project-regulatory-reports)


# Viewing portfolios

Your SonarQube Cloud portfolio includes a set of projects within your enterprise that enables an aggregate view of each project's metrics and risks.

This feature is only available in the [Enterprise plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features).

A portfolio is a set of projects within your enterprise that enables an aggregate view of the project metrics and risks. More precisely, a portfolio consists of project branches and for each project, you can add a single long-lived branch to the portfolio.

{% hint style="info" %}
Before you can view the Enterprise-level reports, your organization must be added to an enterprise. For more information, see [Managing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise).
{% endhint %}

## Retrieving a portfolio <a href="#retrieving-portfolio" id="retrieving-portfolio"></a>

<div align="left"><figure><img src="/files/fO12S6yvKELjrYvdRq7w" alt="Retrieving a portfolio"><figcaption></figcaption></figure></div>

1. Click **My Portfolios** in the top navigation bar and select your enterprise, if you belong to more than one. Alternatively, you can retrieve your enterprise and select **Portfolios** from the left side menu.
2. The **Portfolios** home page lists all the portfolios that belong to this organization. Use the search box to narrow down the results.
3. Here, you can review the portfolio’s overall code ratings, including the number of projects with the worst rating, see the number of Lines of Code analyzed, and see the number of projects included in the portfolio.
4. Click on the portfolio name to view more details.

See [Managing portfolios](/sonarqube-cloud/managing-portfolios) for more information about how to create, edit, and delete portfolios.

## Portfolio metrics <a href="#portfolio-metrics" id="portfolio-metrics"></a>

The reliability, security vulnerabilities, security review, maintainability, and releasability ratings are calculated as the average of the ratings for all projects included in the portfolio.

SonarQube Cloud converts each project’s letter rating to a number, calculates an average number for the projects in the portfolio, and converts that average to a letter rating. Averages ending with .5 are rounded up, resulting in the "lower" of the two possible ratings, so an average of 2.5 would be rounded up to 3 and result in a "C" rating).

This gives a *problem density* measure for your portfolio’s five axes: reliability, security vulnerabilities, security review, maintainability, and releasability.

Rating conversion: E->5, D->4, C->3, B->2, A->1

A risk level is associated with each metric, except for the Releasability:

* **High**: if at least one project in the portfolio is rated E or D.
* **Medium**: if at least one project in the portfolio is rated C or B.
* **Low**: If all projects in the portfolio are rated A.

Each metric is calculated by SonarQube Cloud for New and Overall Code.

<details>

<summary>Releasability</summary>

* The releasability rating is based on the proportion of projects in the portfolio that have passed their quality gate. The rating is as follows:\
  **A**: > 80%\
  **B**: > 60% and <= 80%\
  **C**: > 40% and <= 60%\
  **D**: > 20% and <= 40%\
  **E**: <= 20%
* At the project level: The state of the quality gate associated with the project can be passed or failed.

</details>

<details>

<summary>Security</summary>

* The average security rating of all projects in the portfolio.
* At the project level: The security rating is related to issues that mark potential weaknesses to hackers. The rating is as follows:\
  **A**: 0 vulnerability\
  **B**: at least one minor vulnerability\
  **C**: at least one major vulnerability\
  **D**: at least one critical vulnerability\
  **E**: at least one blocker vulnerability

</details>

<details>

<summary>Reliability</summary>

* The average reliability rating of all projects in the portfolio.
* At the project level: The reliability rating is related to issues that mark code where you will get behavior other than what was expected. The rating is as follows:\
  **A**: 0 bugs\
  **B**: at least one minor bug\
  **C**: at least one major bug\
  **D**: at least one critical bug\
  **E**: at least one blocker bug

</details>

<details>

<summary>Maintainability</summary>

* The average maintainability rating of all projects in the portfolio.
* At the project level: The maintainability rating is related to issues that mark code that will be more difficult to update competently than it should. The maintainability rating is based on the technical debt ratio value (the ratio between the cost to develop the software and the cost to fix it). The default rating is as follows (this rating definition can be changed):\
  **A**: <= 0.05\
  **B**: > 0.05 and <= 0.1\
  **C**: > 0.1 and <= 0.20\
  **D**: > 0.2 and <= 0.5\
  **E**: > 0.5

</details>

<details>

<summary>Security review</summary>

* The average security review rating of all projects in the portfolio.
* At the project level: The security review rating is based on the percentage of reviewed security hotspots. Note that security hotspots are considered reviewed if they are marked as **Fixed** or **Safe**. The rating is as follows:\
  **A**: >= 80%\
  **B**: >= 70% and <80%\
  **C**: >= 50% and <70%\
  **D**: >= 30% and <50%\
  **E**: < 30%

</details>

<details>

<summary>Dependency risk</summary>

* The average dependency risk rating of all projects in the portfolio. Requires [Advanced Security](/sonarqube-cloud/advanced-security).
* At the project level: The dependency risk rating calculates the severity of dependency risks on the project (prohibited license, vulnerability, and malicious packages). The rating is as follows:\
  **A**: 0 risks, or only 'info' level risks\
  **B**: at least one low risk\
  **C**: at least one medium risk\
  **D**: at least one high risk\
  **E**: at least one blocker risk

</details>

## Overview page <a href="#overview-page" id="overview-page"></a>

Once you retrieve a portfolio, you will land on an Overview page, which displays a summary of information from the project branches included in the portfolio for Releasability, Security, Reliability, Maintainability, and Security Review. The ratings are calculated on new and overall code and include project distribution for a rating as well as a risk level.

Click **Download Portfolio Reports** view a list of downloadable reports for your portfolio. See [Viewing portfolio PDF reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-portfolio-pdf-reports) for more information.

<div align="left"><figure><img src="/files/cWhIwqbHMbikY0WtvfsR" alt="Overview page with quality gates ratio and ratings"><figcaption></figcaption></figure></div>

## Portfolio Breakdown page <a href="#portfolio-breakdown-page" id="portfolio-breakdown-page"></a>

The Portfolio Breakdown page lists projects included in the portfolio for which you have the **Browse** permission. They are ordered alphabetically, and you can switch between **New code** and **Overall code** views.

<div align="left"><figure><img src="/files/iLM5GdrdxD8ZsVCSQfns" alt="The Portfolio Breakdown page reveals even more detail about each project in the portfolio."><figcaption></figcaption></figure></div>

## Measures page <a href="#measures-page" id="measures-page"></a>

The Measures page provides an in-depth breakdown of metrics across your portfolio projects, helping you gain broader visibility. It includes:

* **Software quality rating breakdown**: View ratings breakdown across multiple projects at once.
* **Code coverage visibility**: Easily see code coverage at the portfolio level without manually aggregating project data.
* **Duplication insights**: View duplications by project in your portfolio to maintain high-quality, maintainable software. Note that his feature does not cover cross-project duplications.
* **Lines of Code (LOC) tracking**: Quickly understand LOC usage breakdown by language and by project.

<figure><img src="/files/FXZclwRT8mBlBApy5J3v" alt="Portfolio measures page"><figcaption></figcaption></figure>

See [Understanding measures and metrics](/sonarqube-cloud/managing-your-projects/metric-definitions) for more information about code metrics used in the Sonar solution.

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Managing portfolios](/sonarqube-cloud/managing-portfolios)
* [Administering portfolios](/sonarqube-cloud/getting-started-with-enterprise/administering-portfolios)
* [Viewing portfolio security reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/portfolio-security-reports)
* [Managing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise)
* [Viewing portfolio PDF reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-portfolio-pdf-reports)
* [Understanding measures and metrics](/sonarqube-cloud/managing-your-projects/metric-definitions)


# Viewing portfolio security reports

Your SonarQube Cloud porfolio's security reports page provides an aggregated view of security ratings across projects in the portfolio.

This feature is only available in the [Enterprise plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features).

{% hint style="info" %}
Before you can view the Enterprise-level reports, your organization must be added to an enterprise. For more information, see [Managing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise).
{% endhint %}

## Overview <a href="#overview" id="overview"></a>

Portfolio security reports provide an aggregated view of your organization’s security across multiple projects. They are aimed at enterprise security teams, compliance and audit teams, and IT administrators who manage multiple projects and require an in-depth view of their enterprise security status.

## Security standards

Security reports help you understand where you may have issues related to the following security standards:

* [OWASP Top 10](https://owasp.org/Top10/) (versions 2025, 2021, 2017)

<details>

<summary>OWASP Top 10 security standards covered by Sonar for version 2025</summary>

<table><thead><tr><th width="207.765625">Category</th><th width="87.17962646484375">Python</th><th width="92.93603515625">JS/TS</th><th width="78.802490234375">Java</th><th width="78.2628173828125">C#</th><th width="81.49072265625">C/C++</th><th width="80.1341552734375">PHP</th><th width="86.203125">Kotlin</th><th>Go</th></tr></thead><tbody><tr><td>A01:Broken Access Control</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A02: Security Misconfiguration</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A03: Software Supply Chain Failures</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td></td><td></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A04: Cryptographic Failures</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A05: Injection</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A06: Insecure design</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A07: Authentication Failures</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A08: Software and Data Integrity Failures</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>A09: Logging and Alerting Failures</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td></td></tr><tr><td>A10: Mishandling of Exceptional Conditions</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr></tbody></table>

</details>

* [OWASP Mobile Top 10 2024](https://owasp.org/www-project-mobile-top-10/)

<details>

<summary>OWASP Mobile Top 10 security standards covered by Sonar for version 2024</summary>

<table><thead><tr><th width="206.4246826171875">Standard</th><th>Java</th><th>Kotlin</th><th>Dart</th><th>Swift</th></tr></thead><tbody><tr><td>M1: Improper Credential Usage</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>M2: Inadequate Supply Chain Security</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>M3: Insecure Authentication/Authorization</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>M4: Insufficient Input/Output Validation</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>M5: Insecure Communication</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>M6: Inadequate Privacy Controls</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>M7: Insufficient Binary Protections</td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td></td><td></td></tr><tr><td>M8: Security Misconfiguration</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>M9: Insecure Data Storage</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td></td></tr><tr><td>M10: Insufficient Cryptography</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr></tbody></table>

</details>

* [CWE Top 25](https://cwe.mitre.org/top25/archive/2024/2024_cwe_top25.html) (versions 2024, 2023, 2022, and 2021)

<details>

<summary>CWE Top 25 security standards covered by Sonar for version 2024</summary>

<table><thead><tr><th width="210.5675048828125">Category</th><th width="83.29473876953125">Python</th><th width="83.7493896484375">JS/TS</th><th width="86.885009765625">Java</th><th width="71.547607421875">C#</th><th width="82.7052001953125">C/C++</th><th width="78.1668701171875">PHP</th><th>Kotlin</th></tr></thead><tbody><tr><td>CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-787 Out-of-bounds Write</td><td><br></td><td><br></td><td><br></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-89 Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-352 Cross-Site Request Forgery (CSRF)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td></tr><tr><td>CWE-22 Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-125 Out-of-bounds Read</td><td><br></td><td><br></td><td><br></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-78 Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-416 Use After Free</td><td><br></td><td><br></td><td><br></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-862 Missing Authorization</td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr><tr><td>CWE-434 Unrestricted Upload of File with Dangerous Type</td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr><tr><td>CWE-94 Improper Control of Generation of Code (‘Code Injection’)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-20 Improper Input Validation</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-77 Improper Neutralization of Special Elements used in a Command (‘Command Injection’)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td></tr><tr><td>CWE-287 Improper Authentication</td><td><br></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-269 Improper Privilege Management</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr><tr><td>CWE-502 Deserialization of Untrusted Data</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-200 Exposure of Sensitive Information to an Unauthorized Actor</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-863 Incorrect Authorization</td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr><tr><td>CWE-918 Server-Side Request Forgery (SSRF)</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</td><td><br></td><td><br></td><td><br></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-476 NULL Pointer Dereference</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-798 Use of Hard-coded Credentials</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-190 Integer Overflow or Wraparound</td><td><br></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-400 Uncontrolled Resource Consumption</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><br></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>CWE-306 Missing Authentication for Critical Function</td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr></tbody></table>

</details>

* [EU Cyber Resilience Act](https://docs.sonarsource.com/cyber-resilience-act)

<details>

<summary>EU Cyber Resilience Act security standards covered by Sonar security features</summary>

<table><thead><tr><th width="420">Requirement</th><th width="140">Security</th><th width="140">Dependency Risks</th></tr></thead><tbody><tr><td>Part I - Cybersecurity requirements relating to the properties of products with digital elements</td><td><img src="/files/Y3YH4JBMORdkKV7Ta6jn" alt="Partial coverage"> (partial)</td><td><img src="/files/Y3YH4JBMORdkKV7Ta6jn" alt="Partial coverage"></td></tr><tr><td>1.1 Risk-Based Security Standards for Digital Products</td><td></td><td></td></tr><tr><td>1.2 Security Obligations Derived from Risk Assessments</td><td><img src="/files/Y3YH4JBMORdkKV7Ta6jn" alt="Partial coverage"></td><td><img src="/files/Y3YH4JBMORdkKV7Ta6jn" alt="Partial coverage"></td></tr><tr><td>1.2.a be made available on the market without known exploitable vulnerabilities</td><td></td><td></td></tr><tr><td>1.2.b be made available on the market with a secure by default configuration, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, including the possibility to reset the product to its original state</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>1.2.c ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic security updates that are installed within an appropriate timeframe enabled as a default setting, with a clear and easy-to-use opt-out mechanism, through the notification of available updates to users, and the option to temporarily postpone them</td><td></td><td></td></tr><tr><td>1.2.d ensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorised access</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>1.2.e protect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by state of the art mechanisms, and by using other technical means</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>1.2.f protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>1.2.g process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended purpose of the product with digital elements (data minimisation)</td><td></td><td></td></tr><tr><td>1.2.h protect the availability of essential and basic functions, also after an incident, including through resilience and mitigation measures against denial-of-service attacks</td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td><td><img src="/files/UcrUyuCZIncsW4F5GS3S" alt="Checkmark icon"></td></tr><tr><td>1.2.i minimise the negative impact by the products themselves or connected devices on the availability of services provided by other devices or networks</td><td></td><td></td></tr><tr><td>1.2.j be designed, developed and produced to limit attack surfaces, including external interfaces</td><td></td><td></td></tr><tr><td>1.2.k be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques</td><td></td><td></td></tr><tr><td>1.2.l provide security related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user</td><td></td><td></td></tr><tr><td>1.2.m provide the possibility for users to securely and easily remove on a permanent basis all data and settings and, where such data can be transferred to other products or systems, ensure that this is done in a secure manner</td><td></td><td></td></tr><tr><td>Part II - Vulnerability handling requirements</td><td></td><td></td></tr><tr><td>2.1 identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products</td><td></td><td></td></tr><tr><td>2.2 in relation to the risks posed to products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates</td><td></td><td></td></tr><tr><td>2.3 apply effective and regular tests and reviews of the security of the product with digital elements</td><td></td><td></td></tr><tr><td>2.4 once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch</td><td></td><td></td></tr><tr><td>2.5 put in place and enforce a policy on coordinated vulnerability disclosure</td><td></td><td></td></tr><tr><td>2.6 take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third-party components contained in that product, including by providing a contact address for the reporting of the vulnerabilities discovered in the product with digital elements</td><td></td><td></td></tr><tr><td>2.7 provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner and, where applicable for security updates, in an automatic manner</td><td></td><td></td></tr><tr><td>2.8 ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between a manufacturer and a business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken</td><td></td><td></td></tr></tbody></table>

</details>

* [CASA](https://appdefensealliance.dev/casa)
* [OWASP ASVS](https://owasp.org/www-project-application-security-verification-standard/) (version 4.0 level 1, 2, 3)
* [PCI DSS](https://www.pcisecuritystandards.org/) (versions 4.0 and 3.2.1)
* [STIG ASD](https://www.cyber.mil/stigs/) (version 6 and 5)

{% hint style="info" %}
To ensure reliable security reports, the relevant security rules must be activated in your portfolio’s project quality profiles. For instance, if no rule corresponding to a given OWASP category is activated in your quality profile, you won’t get Security issues or Security Hotspots linked to that specific category in the OWASP report. See [Viewing project security reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/project-security-reports#checking-security-rules) for more information.
{% endhint %}

### Dependency Risks in security reports

Dependency Risks are the security and compliance problems SonarQube detects in your projects' open source and third-party dependencies through [Software Composition Analysis (SCA)](/sonarqube-cloud/advanced-security/analyzing-projects-for-dependencies-sca). They include known vulnerabilities such as CVEs, malicious packages, and dependencies that use a prohibited license.

Dependency Risks ratings are included in SonarQube security reports in both the SonarQube Cloud UI and exported PDFs. To view Dependency Risks, you need access to SonarQube Advanced Security. See the [Subscribing to the Advanced Security product](/sonarqube-cloud/administering-sonarcloud/managing-subscription/signing-up-for-plan#advanced-security) article for signup instructions.

## Retrieving portfolio security reports <a href="#retrieving-security-report" id="retrieving-security-report"></a>

1. Retrieve your portfolio. See [Viewing portfolios](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-portfolios) for more information.
2. Go to **Security Reports** to open the report.

The portfolio report displays:

1. The security standards used to filter the results.
2. Your **Security reports overview** is at the top of the page which includes your **Portfolio overall Security rating**, **Portfolio overall Security Review rating**, and **Portfolio overall Dependency Security Risks rating** ([Advanced Security](/sonarqube-cloud/advanced-security/introduction) license is required) for the selected standard.
3. Review the total number of **Security** issues, **Security Hotspots**, and **Dependency Risks** ([Advanced Security](/sonarqube-cloud/advanced-security/introduction) license is required) that need to be addressed for your selected security standard. The report results are generated based on relevant active security rules for projects in your portfolio.
4. A list of categories that contain Security issues, Security Hotspots, and Dependency Risks fitting each category are sorted by rating. Select a **Category** row from the table to open a category specific report. Note that a single Security issue, Security Hotspot or Dependency Risk may show up in more than one category.

<figure><img src="/files/RmyvZoPEeOdig73KEKzQ" alt="Breakdown of the portfolio security reports page"><figcaption></figcaption></figure>

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Introduction](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/introduction) to Viewing the enterprise reports
* [Viewing portfolios](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-portfolios)
* [Administering portfolios](/sonarqube-cloud/getting-started-with-enterprise/administering-portfolios)
* [Viewing portfolio PDF reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-portfolio-pdf-reports)
* [Cyber Resilience Act capability mapping](https://docs.sonarsource.com/cyber-resilience-act)


# Viewing portfolio PDF reports

The Portfolio PDF report provides a snapshot of your portfolio’s code quality.

This feature is only available in the [Enterprise plan](https://www.sonarsource.com/plans-and-pricing/#sonarqube-cloud-features).

The code quality in the portfolio PDF report is presented through a number of lenses such as security, reliability, maintainability, security review, and releasability. Additionally, it includes information about code coverage and duplication for new and overall code.

{% hint style="info" %}
Before you can view the Enterprise-level reports, your organization must be added to an enterprise. For more information, see [Managing your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise).
{% endhint %}

## Downloading a portfolio report

1. Retrieve a portfolio. See [Viewing portfolios](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-portfolios#retrieving-portfolio) for more details.
2. Click on **Download Portfolio Report (pdf)** located in the top right of the Overview page.

## Contents of the portfolio report PDF file

<figure><img src="/files/tKBW8HKkIFdp4F7b6jYN" alt="Portfolio overview page"><figcaption></figcaption></figure>

### Portfolio overview page

* **Portfolio information** includes the name of the portfolio, number of projects that make up the portfolio, links to Portfolio Breakdown, number of Lines of Code (LOC), and a link to Language Breakdown
* **Portfolio metrics** overview shows software quality matrices for new and overall code, and releasability rating.

### Portfolio health factors

The ratings for new and overall code in the portfolio health factors include security, reliability, maintainability, security review, coverage, and duplication. See the Portfolio metrics article for more information about how these ratings are calculated.

### Definitions

The last page of the portfolio PDF report is the definitions page. It includes information about the ratings, rating conversion, and related definitions.

## Related pages

* [Managing portfolios](/sonarqube-cloud/managing-portfolios)
* [Viewing portfolios](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/viewing-portfolios)
* [Viewing portfolio security reports](/sonarqube-cloud/getting-started-with-enterprise/viewing-enterprise-reports/portfolio-security-reports)


# Viewing usage information

Enterprise’s billing and usage information in SonarQube Cloud.

To view your enterprise’s usage information, see [Managing the lines of code within your enterprise](/sonarqube-cloud/administering-sonarcloud/managing-enterprise/managing-the-lines-of-code-within-your-enterprise#loc-consumption).

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Setting up your enterprise](/sonarqube-cloud/getting-started-with-enterprise/setting-up-your-enterprise)\
  This page explains the different steps necessary to create and configure an enterprise.
* [Setting up SSO](/sonarqube-cloud/getting-started-with-enterprise/setting-up-sso)
* [Onboarding a new organization](/sonarqube-cloud/getting-started-with-enterprise/onboarding-new-org)


# Analyzing source code

This section explains how to set up and run analysis of your source code with SonarQube Cloud: automatic analysis, CI-based pipelines, scanners, branch and pull request analysis, and more.

{% content-ref url="/pages/lo5QD9gZLH1YgFKSlyFA" %}
[Concepts](/sonarqube-cloud/analyzing-source-code/concepts)
{% endcontent-ref %}

{% content-ref url="/pages/k5rg22X5DV2gFwKoDRUZ" %}
[Automatic analysis](/sonarqube-cloud/analyzing-source-code/automatic-analysis)
{% endcontent-ref %}

{% content-ref url="/pages/XfWk9W7EecVA4uREC9El" %}
[CI-based analysis](/sonarqube-cloud/analyzing-source-code/ci-based-analysis)
{% endcontent-ref %}

{% content-ref url="/pages/d0TTgmUlegTXHfr4CnR9" %}
[Scanners](/sonarqube-cloud/analyzing-source-code/scanners)
{% endcontent-ref %}

{% content-ref url="/pages/MYa1Tj6sYPOEQv8khBri" %}
[Languages](/sonarqube-cloud/analyzing-source-code/languages)
{% endcontent-ref %}

{% content-ref url="/pages/vQ9rUyZlHtOzJTaYhNjm" %}
[Branch analysis](/sonarqube-cloud/analyzing-source-code/branch-analysis)
{% endcontent-ref %}

{% content-ref url="/pages/qP33DRspwynA3txdjLA5" %}
[Pull request analysis](/sonarqube-cloud/analyzing-source-code/pull-request-analysis)
{% endcontent-ref %}

{% content-ref url="/pages/7WsYAu4qmv9zFGNEnUtY" %}
[Analysis parameters](/sonarqube-cloud/analyzing-source-code/analysis-parameters)
{% endcontent-ref %}

{% content-ref url="/pages/mcuZaMs41TqD2dpPStR1" %}
[Test coverage](/sonarqube-cloud/analyzing-source-code/test-coverage)
{% endcontent-ref %}

{% content-ref url="/pages/KaPo6pLbxLt92f3EWEpo" %}
[Importing external issues](/sonarqube-cloud/analyzing-source-code/importing-external-issues)
{% endcontent-ref %}

{% content-ref url="/pages/BISP9bUsAIZU6QCJKA9Q" %}
[.NET environments](/sonarqube-cloud/analyzing-source-code/dotnet-environments)
{% endcontent-ref %}

{% content-ref url="/pages/5CIHVP84AaP7PS3n5fsp" %}
[Monorepo support](/sonarqube-cloud/analyzing-source-code/monorepo-support)
{% endcontent-ref %}

{% content-ref url="/pages/RmlqT7fMbqPmZdMh9ORd" %}
[Incremental analysis mechanisms](/sonarqube-cloud/analyzing-source-code/incremental-analysis-mechanisms)
{% endcontent-ref %}

{% content-ref url="/pages/kXWS0j1HNw9oOEVzMy16" %}
[SonarQube for IDE](/sonarqube-cloud/analyzing-source-code/connected-mode)
{% endcontent-ref %}


# Concepts

This page presents essential analysis concepts you will encounter while analyzing your code with SonarQube Cloud.

## Automatic vs CI-based analysis <a href="#automatic-versus-ci-based-analysis" id="automatic-versus-ci-based-analysis"></a>

When setting up a new project, the first choice you will have to make is between automatic analysis and CI-based analysis.

* With automatic analysis, SonarQube Cloud analyzes your code simply by reading it from your repository, without the need to configure a CI-based analysis.
* With the CI-based method, the analysis takes place in your build environment. It's done by a separate tool, called a scanner, that is run in your build environment. The results of the analysis are then sent to the SonarQube Cloud server, processed and displayed in the SonarQube Cloud web interface.

If your project is eligible and you don’t require any of the unsupported features, automatic analysis is the recommended method to use.

See the [Automatic analysis](/sonarqube-cloud/analyzing-source-code/automatic-analysis) and [Overview of integrated CIs](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/overview-of-integrated-cis) pages for more information.

## Keeping the focus on new code <a href="#keeping-the-focus-on-new-code" id="keeping-the-focus-on-new-code"></a>

SonarQube Cloud is designed with two principles in mind:

1. Prevent issues from being introduced in the first place.
2. When issues are introduced, catch them as early as possible.

To achieve this, SonarQube Cloud integrates into your daily development workflow at multiple points, so that analysis results surface every time you make changes and not as a separate, periodic task.

SonarQube Cloud provides three layers of defense:

1. In your IDE: Catch issues before you push using SonarQube for IDE.
2. On your pull request: Catch issues before they reach the main branch.
3. On your main branch: Catch anything that slipped through.

The goal is to make code quality part of normal, feature-driven development work.

## Catching issues with SonarQube for IDE <a href="#catching-issues-in-the-ide-with-sonarlint" id="catching-issues-in-the-ide-with-sonarlint"></a>

SonarQube for IDE is your first line of defense against code quality and security issues. It can catch issues in your code right in your IDE, before you even push changes to your repository, using the SonarQube for IDE extension.

SonarQube for IDE is available for:

* [JetBrains IDEs](https://www.sonarsource.com/products/sonarqube/ide/features/jetbrains/), including IntelliJ IDEA, CLion, and others
* [Visual Studio](https://www.sonarsource.com/products/sonarqube/ide/features/visual-studio/)
* [VS Code](https://www.sonarsource.com/products/sonarqube/ide/features/vs-code/), including Cursor, Devin Desktop, and more.
* [Eclipse](https://www.sonarsource.com/products/sonarqube/ide/features/eclipse/)

The automated code review in SonarQube for IDE works like a spell checker, highlighting issues in your code as you type. When an issue is identified, SonarQube for IDE provides you with clear remediation guidance so you can fix it right away. In many cases, it also provides a *quick fix* that can automatically fix the issue for you.

You can also connect SonarQube for IDE to your SonarQube Cloud project. This allows SonarQube for IDE to leverage your team’s quality profiles, synchronize other analysis settings and alert you to analysis results that appear at later stages in the dev cycle.

For more information, see [SonarQube for IDE](/sonarqube-cloud/analyzing-source-code/connected-mode).

## Pull request analysis <a href="#pull-request-analysis" id="pull-request-analysis"></a>

A pull request code review and analysis is your second line of defense against code quality and security issues after SonarQube for IDE. Issues that SonarQube for IDE cannot detect are detected by pull request analysis before they are merged into the main branch.

When you open a pull request (or, in GitLab, a merge request) SonarQube Cloud will automatically analyze all (and only) the changes introduced by that pull request. The result is reported both in the pull request view of the SonarQube Cloud interface and in your DevOps platform (GitHub, Bitbucket Cloud, Azure DevOps, or GitLab), as a pull request decoration. On every subsequent push to the pull request branch, the analysis is run again.

Each pull request analysis result displays [Quality gates](/sonarqube-cloud/standards/quality-gates). The quality gate applies only to the actual code that was changed in the pull request. It can be set to prevent the merging of the pull request branch into its target branch if the analysis results don't meet your requirements.

For more information, see the [Pull request analysis](/sonarqube-cloud/analyzing-source-code/pull-request-analysis) page.

## Main branch analysis <a href="#main-branch-analysis" id="main-branch-analysis"></a>

A main branch code review and analysis is your third line of defense against code quality and security issues, after SonarQube for IDE and pull request analysis. Issues that neither SonarQube for IDE nor pull request analysis can detect are detected by main branch analysis.

Every time you make a change to the main branch of your project SonarQube Cloud will automatically analyze all the code in the current state of the main branch.

The main branch results display [Quality gates](/sonarqube-cloud/standards/quality-gates). The quality gate applies to all the code in the main branch. For more information, see [Main branch analysis](/sonarqube-cloud/analyzing-source-code/branch-analysis/main-branch-analysis).

## Scanners <a href="#advanced-setup-languages" id="advanced-setup-languages"></a>

A scanner is the tool that runs the actual code analysis. It inspects your source code, applies the rules from your quality profile, and sends the results to SonarQube Cloud.

SonarQube Cloud provides dedicated scanners for common build systems and languages — including .NET, Maven, Gradle, NPM, and Python — as well as a general-purpose SonarScanner CLI for everything else. See the [Scanners](/sonarqube-cloud/analyzing-source-code/scanners) pages for more information.

## Languages <a href="#advanced-setup-languages" id="advanced-setup-languages"></a>

SonarQube Cloud supports a wide range of languages. See the full list on the [Supported languages](/sonarqube-cloud/discovering-sonarcloud/overview) page. To find the supported versions and language-specific configuration information, search the page list on the [Languages](/sonarqube-cloud/analyzing-source-code/languages) page.

## Analysis parameters <a href="#analysis-parameters" id="analysis-parameters"></a>

Analysis parameters allow you to control many details of how an analysis is performed.

See the [Analysis parameters](/sonarqube-cloud/analyzing-source-code/analysis-parameters) page for more information.

## Incremental analysis

SonarQube Cloud uses incremental analysis mechanisms to keep analysis times fast by only re-analysing code that has changed since the last scan.

See the [Incremental analysis mechanisms](/sonarqube-cloud/analyzing-source-code/incremental-analysis-mechanisms) page for more information.

## Enriching your analysis

The above sections describe the core features of SonarQube Cloud and how they can improve the quality and security of your code by identifying issues early in the development cycle. The following features allow you to enrich your code review and analysis results with additional insights.

{% hint style="warning" %}
Test coverage, external analyzers, and branch analysis are only available in projects that use CI-based analysis. They are unavailable in projects that use automatic analysis.
{% endhint %}

### Test coverage

Checking the test coverage of your code with coverage reporting tools is an essential part of the development process.

SonarQube Cloud lets you set up the automatic importing of test coverage reports produced by your language-specific tools and integrate the results into the SonarQube Cloud analysis results.

By setting up this integration you bring an important additional metric into the mix of your SonarQube Cloud results allowing coverage to be taken into account when calculating quality gates.

To set up test coverage import you need to first set up the test coverage reporting tool for your project. This depends largely on the language that you are using. Once this tool is set up to run on every build, you can configure SonarQube Cloud to import that report and integrate it into the analysis.

For details, see [Overview](/sonarqube-cloud/analyzing-source-code/test-coverage/overview) and [Generic test data](/sonarqube-cloud/analyzing-source-code/test-coverage/generic-test-data).

### Importing external issues

In addition to importing coverage reports, SonarQube Cloud can also import reports from external analysis tools such as linters. Importing these reports allows SonarQube Cloud to integrate them into the analysis results, providing you with more insight into the state of your code.

To set up import from external analyzers you need to first set up the external reporting tool for your project. This depends largely on the language and other build tools that you are using. Once this is set up to run on every build, you can configure SonarQube Cloud to import the external analysis report and integrate it into the analysis.

For more information, see [Importing external issues](/sonarqube-cloud/analyzing-source-code/importing-external-issues).

### Branch analysis <a href="#branch-analysis" id="branch-analysis"></a>

So far we have seen that SonarQube Cloud performs code review and analysis on the main branch of your project and individual pull requests.

But, SonarQube Cloud can also provide analysis of other branches in your repository that are neither the main (that is, default) branch nor pull request branches. This feature can be used if:

* Your project has long-living branches other than the main branch that you want to analyze. For example, a development branch or maintenance branches for older versions.
* Your project use short-lived branches (for example, "feature" branches) to introduce changes to your main branch but you don't use them with a pull request mechanism in a supported CI.

If your project has either of these characteristics, configuring branch analysis will let you have the full benefit of SonarQube Cloud analysis. For details, see the [Branch analysis](/sonarqube-cloud/analyzing-source-code/branch-analysis/branch-analysis) and [Branch analysis setup](/sonarqube-cloud/analyzing-source-code/branch-analysis/branch-analysis-setup) pages.

For more information running automatic analysis on your projects, see [Automatic analysis](/sonarqube-cloud/analyzing-source-code/automatic-analysis) and [Automatic analysis](/sonarqube-cloud/analyzing-source-code/automatic-analysis#deactivating-automatic-analysis) pages.

For information on setting up a CI-based analysis, see the [Overview of integrated CIs](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/overview-of-integrated-cis) pages.

## Working with AI agents

SonarQube Cloud includes features designed to integrate with AI coding agents. These features are part of the Agent Centric Development Cycle (AC/DC), which guides AI agents to generate better code, verify the result, and solve issues.&#x20;

See the [Agent Centric Development Cycle](/agent-centric-development-cycle) section for more information.

## Related online learning

* <i class="fa-desktop">:desktop:</i> [SonarQube analysis: From local scans to CI/CD automation](https://www.sonarsource.com/learn/course/core-concepts/f16bd24c-2a61-490d-9040-0e90039d14c0/sonarqube-analysis-from-local-scans-to-cicd-automation)


# Automatic analysis

SonarQube Cloud can automatically analyze your code simply by reading it from your repository, without the need to configure a CI-based analysis.

Automatic analysis is available for GitHub and Azure DevOps repositories.

When you first import a project that supports automatic analysis, SonarQube Cloud Cloud analyzes the default branch (usually the main branch). For GitHub repositories, the five most recently active pull requests are also analyzed. After this, automatic analysis runs whenever you push to the default branch or a pull request branch.

## Considerations <a href="#considerations" id="considerations"></a>

Currently, automatic analysis has the following limitations:

* [Branch analysis](/sonarqube-cloud/analyzing-source-code/branch-analysis/branch-analysis) (analysis of non-pull request branches other than *main* branch) is not supported.
* Automatic analysis does not support monorepos (the *monorepo* strategy). See the [Monorepo support](/sonarqube-cloud/analyzing-source-code/monorepo-support) page for more details.
* Code coverage information is not supported.
* Import of external rule engine reports is not supported.
* Automatic analysis logs are not available.

If you experience prolonged analysis times or need to review the analysis logs, consider onboarding your project using a CI-based analysis. See the [Overview of integrated CIs](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/overview-of-integrated-cis) page for more information.

{% hint style="warning" %}
**Analyzing Gradle files**

If you are analyzing Gradle files, your Gradle build file must be located in the root of your repository in order to be detected by the scanner because SonarScanner checks for the presence of a \`pom.xml\`, \`build.gradle\`, or \`build.gradle.kts\` file.

If your Gradle build file is located in sub-directory, you have to use CI-based analysis instead. For more information, see [Analyzing multi-project builds](/sonarqube-cloud/analyzing-source-code/importing-external-issues/external-analyzer-reports).
{% endhint %}

## Supported languages <a href="#supported-languages" id="supported-languages"></a>

Automatic analysis is available for all of SonarQube Cloud's [supported languages](/sonarqube-cloud/discovering-sonarcloud/overview) except for Objective-C, Dart, and Rust. For Java, there are some known limitations. See the dedicated sections below for the details.

For ABAP, Apex, COBOL, JCL, PL/I, RPG, automatic analysis is available in the [Enterprise plan](https://www.sonarsource.com/plans-and-pricing/).

## Turning on automatic analysis <a href="#activating-automatic-analysis" id="activating-automatic-analysis"></a>

**Prerequisite**

For Azure DevOps repositories, automatic analysis requires specific token permissions. For details, see [Importing Azure DevOps organization](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-azure-devops-organization#generating-your-azure-pat).

**For new projects**

* After importing a project from [GitHub](/sonarqube-cloud/administering-sonarcloud/managing-organization/creating-organization/importing-github-organization) or [Azure DevOps](/sonarqube-cloud/getting-started/azure-devops), SonarQube Cloud will automatically check whether your project is eligible for automatic analysis. This should take a few seconds.
  * SonarQube Cloud will deem a project *eligible* for automatic analysis only if *at least 20%* of the lines of code in the project are in a *supported language*.
  * For a Java project to be eligible, the amount of Java code cannot exceed 10MB.
* If your project is eligible, SonarQube Cloud will automatically trigger the first analysis. On this first analysis, the system will analyze the default branch of the project and the five most recently active pull requests. All you have to do is wait for the analysis to finish.
* If your project is not compatible, SonarQube Cloud will suggest other analysis methods such as using a CI tool.
* You can force automatic analysis on an initially non-eligible project by going to your project's **Administration** > **Analysis Method** page and switching on automatic analysis. However, doing this is not recommended as it will typically not provide useful information.

**For existing projects**

* Go to your project’s **Administration** > **Analysis Method** page and turn on **Automatic Analysis**.
* The **Analysis Method** page will display a compatibility check, so you are aware of our recommendations for your specific project.

## Presence of a properties file <a href="#presence-of-a-properties-file" id="presence-of-a-properties-file"></a>

If you import a project that already contains a `sonar-project.properties` file, SonarQube Cloud will ignore the parameters in your `sonar-project.properties` file. To analyze your code with the settings defined in this file, you can turn off automatic analysis and configure a CI/CD analysis. See [#deactivating-automatic-analysis](#deactivating-automatic-analysis "mention") for instructions.

## Analysis method indicator <a href="#analysis-method-indicator" id="analysis-method-indicator"></a>

If a project uses automatic analysis, then on the **Project information** page > **Last analysis method** the system displays *Analyzed by SonarQube Cloud.*

<div align="left"><figure><img src="/files/XdLxZdJMhSUoYTi14WAr" alt="Last analysis method is displayed on the Project information page"><figcaption></figcaption></figure></div>

## Conflict with CI-based analysis <a href="#conflict-with-ci-based-analysis" id="conflict-with-ci-based-analysis"></a>

Automatic analysis is not intended to be used in conjunction with CI-based analysis.

If you enable automatic analysis, you must ensure that you do not have any CI-based analyses configured. If you do then these CI-based analyses will fail and *cause a failure in your build process*.

Similarly, if you wish to use a CI-based analysis on a project, you must ensure that automatic analysis is turned off for that project.

This is done to prevent duplicate analyses from being sent to SonarQube Cloud that would cause problems in your project activity reports.

## Turning off automatic analysis <a href="#deactivating-automatic-analysis" id="deactivating-automatic-analysis"></a>

Go to your project’s **Administration** > **Analysis Method** page and turn off **Automatic Analysis**.

From the same page, you can then follow one of our tutorials for configuring SonarQube Cloud analyses with another method.

{% hint style="info" %}
As an organization admin, you can turn off automatic analyses in your Enterprise plan organization. See the [Turning off automatic analysis](/sonarqube-cloud/administering-sonarcloud/managing-organization/setting-config-at-org-level/disabling-automatic-analysis) page for details.
{% endhint %}

## Additional analysis configuration <a href="#additional-analysis-configuration" id="additional-analysis-configuration"></a>

You can refine the configuration of your analyses by adding a `.sonarcloud.properties` file to your repository’s default branch. *Note that this is different from the `sonar-project.properties` file used for CI-based analysis*.

Below are the supported optional settings for the `.sonarcloud.properties` file. Wildcard patterns are not allowed. Read more on the [Analysis parameters](/sonarqube-cloud/analyzing-source-code/analysis-parameters) page.

```properties
# Path to sources
# sonar.sources=
# sonar.exclusions=
# sonar.inclusions=

# Path to tests
# sonar.tests=
# sonar.test.exclusions=
# sonar.test.inclusions=

# Source encoding
# sonar.sourceEncoding=

# Exclusions for copy-paste detection
# sonar.cpd.exclusions=

# Python version (for python projects only)
# sonar.python.version=

# C++ standard version (for C++ projects only)
# If not specified, it defaults to the latest supported standard
# sonar.cfamily.reportingCppStandardOverride=c++98|c++11|c++14|c++17|c++20
```

Not all properties work with all scanner versions. Be sure to review the [Analysis parameters](/sonarqube-cloud/analyzing-source-code/analysis-parameters#analysis-scope) and check which are available for your scanner and scanner version.

Some of these settings can also be configured from the SonarQube Cloud UI. In your project’s **Administration** > **General Settings** > **Analysis Scope** > **Files** section, you can define source and test file exclusions and inclusions. If you have different options set in the UI than are defined in your `.sonarcloud.properties` file, SonarQube Cloud will only take into account the value from the `.sonarcloud.properties` file.

{% hint style="info" %}

* This feature works for any project, public or private.
* It can be activated at no extra cost.
* If you were previously using the *Automatic Analysis Beta*, removing the `.sonarcloud.properties` file will no longer turn off automatic analysis. It will only disable the additional configuration settings you might have defined in it. You will still have to turn off automatic analysis from the SonarQube Cloud UI, in the **Administration** > **Analysis Method** page.
  {% endhint %}

## Automatic analysis for Java, Kotlin, and Scala <a href="#automatic-analysis-for-java-projects" id="automatic-analysis-for-java-projects"></a>

Automatic analysis provides the quickest way to get your Java, Kotlin, and Scala projects up and running on SonarQube Cloud and see code analysis results fast.

To be eligible for automatic analysis, your Java project must:

* Use either Maven or Gradle
* Have less than 10MB in total amount of code

Automatic analysis for Java has the following limitations:

* XSS (Cross-Site Scripting) issues can’t be detected: to get the full power of Sonar analyzers, it’s required to switch to CI-based analysis.
* For Gradle-based projects, there are less security issues detected: to get the full power of Sonar analyzers, it’s required to switch to CI-based analysis.
* Rules that belong to [this list](https://github.com/SonarSource/sonar-java/blob/3c8b11346c6cc84e3bc936a2b1a5487dd1c0ee1e/check-list/src/main/java/org/sonar/java/CheckListGenerator.java#L177C64-L177C100) are not supported because the results that they currently produce are not accurate enough (see the line with `JAVA_CHECKS_NOT_WORKING_FOR_AUTOSCAN`)
* Not all properties are supported (see below).

{% hint style="warning" %}
Java automatic analysis does not support the following properties:

* sonar.sources
* sonar.tests
* sonar.inclusions
* sonar.test.inclusions

This is because we assume that your files will follow the standard directory layout that is expected by Maven and Gradle (`**/src/main/**/*` and `**/src/test/**/*`) for Java projects.
{% endhint %}

With these limitations in mind, the next step in your Java project onboarding is to set up CI-based analysis to get the most out of SonarQube Cloud analysis. See the [Overview of integrated CIs](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/overview-of-integrated-cis) page for more information.

## Automatic analysis for .NET projects <a href="#automatic-analysis-for-net-projects" id="automatic-analysis-for-net-projects"></a>

SonarQube Cloud automatic analysis now also supports .NET projects. .NET Framework, .NET Core, .NET 5 and .NET 6 projects can be analyzed but are subject to some limitations:

* Projects must contain at least 20% code in a supported language. The amount of .NET code for automatic analysis is calculated by adding the sum of \*.cs and \*.vb files together.
* Projects must contain at least one XML file - \*.csproj or \*.vbproj. A combination of both file types is acceptable.
* If your .NET solution is large enough that the analysis exceeds the container's memory budget, automatic analysis will fail (typically appearing as a stalled PR check).

With these limitations in mind, the next step in your .NET project onboarding is to set up CI-based analysis to get the most out of SonarQube Cloud analysis. See the [Overview of integrated CIs](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/overview-of-integrated-cis) page for more information.

## Automatic analysis for C and C++ projects <a href="#automatic-analysis-for-c-and-c-projects" id="automatic-analysis-for-c-and-c-projects"></a>

There are no additional requirements for [C and C++ projects](https://www.sonarsource.com/products/sonarqube/cloud/features/auto-analysis-for-c-and-cpp/), apart from the standard [#considerations](#considerations "mention") for automatic analysis.

* C & C++ automatic analysis does not have any toolchain or project structural requirements.
* C & C++ can be analyzed in combination with all other supported languages (including Java and .NET.)

SonarQube Cloud automatic analysis for C and C++ is already available and ready to analyze. The quality of analysis is very similar to a CI-based analysis and, for most users, it is the only analysis you really need.

For other users, there are a few cases where a CI-based analysis remains a better option.

* If your project is so big that the analysis cannot be completed before the analysis times out, automatic analysis will fail.
* If you require faster analysis. You should run the analysis using self-hosted resources with an increased hardware capacity. It would also allow you to keep full control of the analysis cache if needed.
* If your project uses generated code that you want to analyze. For example, this can happen in some custom build systems.
* If you need control over the configuration of your code. For example, with automatic analysis, you cannot analyze a specific build variant. Automatic analysis uses a configuration that maximizes the amount of code analyzed and the OS and architecture used for this can differ from your own configuration.
* If your project is experiencing missing issues. In rare cases, automatic analysis can lead to such limitations.

See [Overview of integrated CIs](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/overview-of-integrated-cis) page for more information.

## Related online courses

* <i class="fa-desktop">:desktop:</i> [SonarQube analysis: From local scans to CI/CD automation](https://www.sonarsource.com/learn/course/core-concepts/f16bd24c-2a61-490d-9040-0e90039d14c0/sonarqube-analysis-from-local-scans-to-cicd-automation)


# CI-based analysis

These pages explain how to integrate SonarQube Cloud into your CI/CD pipeline. Instructions include how to connect your SonarScanner and configure analysis parameters for different CI tools.

{% content-ref url="/pages/BSEenblYqmKqOZAHKvXz" %}
[Overview of integrated CIs](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/overview-of-integrated-cis)
{% endcontent-ref %}

{% content-ref url="/pages/0LyEhzhG1DXdlnLEdgUf" %}
[Github Actions](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/github-actions-for-sonarcloud)
{% endcontent-ref %}

{% content-ref url="/pages/aBk3hjM6OYVru1czkmeD" %}
[Bitbucket Pipelines](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/bitbucket-pipelines-for-sonarcloud)
{% endcontent-ref %}

{% content-ref url="/pages/PgpEMMiAba445LtwCp6F" %}
[Azure pipelines](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/azure-pipelines)
{% endcontent-ref %}

{% content-ref url="/pages/5ZRvDQdAw3gTMRbrAxMM" %}
[GitLab CI](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/gitlab-ci)
{% endcontent-ref %}

{% content-ref url="/pages/TuF0S3rUK705HSTm8vlM" %}
[Jenkins](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/jenkins)
{% endcontent-ref %}

{% content-ref url="/pages/hEw61m6HZOf96uCsRAXE" %}
[Amazon CodeCatalyst](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/amazon-codecatalyst)
{% endcontent-ref %}

{% content-ref url="/pages/ILfxIy39Ud09ThUEGyMk" %}
[CircleCI](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/circleci)
{% endcontent-ref %}

{% content-ref url="/pages/Hg7zvBFu7XlQuIbm5EXv" %}
[Codemagic](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/codemagic)
{% endcontent-ref %}

{% content-ref url="/pages/77DFFXFmXG7ElWhCjg5U" %}
[Other CIs](/sonarqube-cloud/analyzing-source-code/ci-based-analysis/other-cis)
{% endcontent-ref %}




---

[Next Page](/llms-full.txt/1)

