For the complete documentation index, see llms.txt. This page is also available as Markdown.

Security contact

As an administrator of your organization you can set up a dedicated contact for urgent, security-related communications.

Overview

As an organization administrator, you can manage the security contact for your SonarQube Cloud organization. This email address is designated for organization-level security alerts, such as official security advisories or notifications regarding data breaches and infrastructure incidents.

This contact is strictly for platform integrity communications and does not receive code analysis scan results. See Subscribing to email notifications for more information about how to set up notifications for analysis-related and background task events.

Permissions

You need the Administer Organization permission to set up the security contact for an organization. To change the permissions, select your organization from the Account menu and go to Administration > Permissions to apply the permission to users or groups.

Setting up the security contact email address

To set up the security contact email address:

  1. Select your organization from the Accounts menu.

  2. Go to Administration > Organization settings > Security contact.

  3. Click on Add email and enter the email address for your security contact.

  4. Click Save.

Sonar recommends that you use a distribution list or group alias, for example securityteam@yourcompany.com, for the security contact email.

Once you have saved the security contact email address, you can Edit it, or delete it. Additionally, the entry shows the email address of the user who set up the security contact and the date when it was updated.

Last updated

Was this helpful?