SonarCloud Documentation
What is SonarCloud?
SonarCloud is a Software-as-a-Service (SaaS) code analysis tool designed to detect coding issues in 30+ languages, frameworks, and IaC platforms. By integrating directly with your CI pipeline or one of the supported DevOps platforms, your code is checked against an extensive set of rules that cover many attributes of code, such as maintainability, reliability, and security issues, on each merge/pull request.
SonarCloud extends your DevOps experience by performing automated code checks within minutes. Here’s how to get started using SonarCloud:
Please have a look at the Discovering SonarCloud section to learn more about What SonarCloud can do. For on-premise code repositories, see SonarQube.
The approach to Clean Code
Clean Code is the standard for all code that results in secure, reliable, and maintainable software therefore, writing clean code is essential to maintaining a healthy codebase. This applies to all code: source code, test code, infrastructure as code, glue code, scripts, and more.
Sonar's Clean as You Code approach is a software development practice based on the principle that new code (code that you added or modified recently) needs to comply with quality standards. The Sonar solution implements Clean as You Code by warning you whenever issues are detected in your new code, helping you maintain high standards and focus on code quality by incrementally improving the entire code base.
SonarCloud comes with a built-in quality profile designed for each supported language, called the Sonar Way profile. The Sonar way activates a set of rules that should be applicable to most projects and is a starting point to help you implement clean code practices in your organization.
The Sonar Solution
Sonar products are designed to help you achieve a state of Clean Code. By linking SonarLint with SonarCloud or SonarQube, checks are performed at every stage of the development process; we call this the Sonar solution. This means your project settings, new code definitions, and quality profiles are applied locally to an analysis in the IDE. The Sonar solution is designed to help you achieve a state of Clean Code. Your project settings, new code definitions, and the quality profiles managed in SonarCloud are applied locally to an analysis in the IDE.
- SonarLint helps catch issues early because it provides immediate feedback in the IDE. As engineers write code, they can find and fix issues even before they commit.
- Then, SonarQube and SonarCloud will analyze each pull request before it’s merged, providing another layer of protection against code issues.
- Finally, SonarQube and SonarCloud analyze the code on each build as part of your CI/CD workflow and together with the quality profile, prevent code with issues from being released to production.
The Sonar solution helps you incorporate the Clean as You Code methodology by helping engineers pay attention to new code. Focusing on writing new, clean code during development ensures that all code released for production will be incrementally improved over time.
Connected Mode
Connected Mode joins SonarCloud with SonarLint to deliver the full Sonar solution. While in Connected Mode, SonarCloud sends notifications to SonarLint when a quality gate changes or a new issue is assigned to the user. Smart notifications can be enabled or disabled from the SonarLint UI while creating or editing the connection settings. In addition, SonarLint helps the engineer focus on writing clean code by using the new code definition defined on the server.
Connected Mode joins SonarLint with SonarQube and SonarCloud to deliver the full Sonar solution. SonarCloud and SonarLint analyses help ensure that only clean code is included in your project. Be sure to check out all of the Connected Mode benefits.
Getting started
Now that you've heard about how SonarCloud can help you write clean code, you are ready to try out SonarCloud for yourself. After signing up for SonarCloud using the login from your DevOps platform account, you can import your organizations and repositories to set up a First analysis.
The Overview of integrated CIs section explains how to connect your scanner to your CI pipeline and provides instructions for analyzing your project’s branches and pull requests.
Here is a page with everything you need to Discover SonarCloud.
Learn more
Check out the entire suite of Sonar products: SonarQube, SonarCloud, and SonarLint.
Then, have a look at how to fix issues detected by SonarLint for IntelliJ, Visual Studio, VS Code, and Eclipse when combined with SonarQube and SonarCloud, and browse a full list of Sonar Rules and Rule Descriptions available for static code analysis.
More getting started resources
- Getting started with SonarCloud
- Advanced setup and Automatic analysis
- How to administer quality profiles
- How to manage portfolios
And if you need help, visit our online community to search for answers and reach out with questions!
Was this page helpful?