Sonar's latest blog posts

Featured Post

State of Code Developer Survey report: The current reality of AI coding

Sonar analyzes over 750 billion lines of code every day. This gives us a unique, high-level view of the state of code quality and security across the globe.

Read article
https://assets-eu-01.kc-usercontent.com:443/ef593040-b591-0198-9506-ed88b30bc023/7ab133c1-b3f7-4652-82a1-3376b953d6bd/soc_survey_report_featured_blog_article_2x.webp
Image for Stop secrets before the commit: Join the beta for SonarQube's new secrets CLI
Blog post

Stop secrets before the commit: Join the beta for SonarQube's new secrets CLI

This blog post explains why secrets detection is critical and how Sonar’s integrated approach reduces noise. It also explains how the new SonarQube Secrets CLI helps teams catch secrets locally.

Read article >

Image for The AI trust gap: Why code verification matters
Blog post

The AI trust gap: Why code verification matters

In this second chapter of our State of Code Developer Survey report, we dig deeper into the developer psyche to answer a critical question: Do developers actually trust the code that AI systems are generating?

Read article >

Get new blog posts delivered directly to your inbox!

Stay up-to-date with the latest Sonar content. Subscribe now to receive the latest blog articles.

I do not wish to receive promotional emails about upcoming SonarQube updates, new releases, news and events.

By clicking “Sign up”, you consent to receive email communications from SonarSource containing blog updates, product news, and other relevant content. We will store and process your personal data for this purpose as described in our Privacy Policy. You can withdraw your consent at any time by clicking the unsubscribe link in our emails or by contacting us in accordance with the Privacy Policy.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Image for Modernizing finance: Insights from a platform engineering leader
Blog post

Modernizing finance: Insights from a platform engineering leader

We recently sat down with a Platform Engineering leader at a major financial services institution to discuss the realities of modern software development in their highly regulated, distributed environment.

Read article >

Image for State of Code Developer Survey report: The current reality of AI coding
Blog post

State of Code Developer Survey report: The current reality of AI coding

What we found challenges the common narrative. While AI adoption is massive, it hasn’t led to a simple, linear boost in productivity. Instead, it has shifted the bottleneck from writing code to verifying it.

Read article >

Image for Vibe, then verify: SonarQube 2025 year in review
Blog post

Vibe, then verify: SonarQube 2025 year in review

As we look back at the year we just closed, one thing is clear: 2025 was the year of acceleration. Development teams moved faster than ever.

Read article >

Image for Seven indicators your codebase is unmanageable
Blog post

Seven indicators your codebase is unmanageable

This article outlines seven indicators of an unmanageable codebase and details how continuous, automated code review using SonarQube provides the mandatory data metrics for diagnosis, quantitative prioritization, and remediation, transforming the management of code quality issues from a severe burden into a strategic investment.

Read article >

Image for Introducing architecture in SonarQube
Blog post

Introducing architecture in SonarQube

Today, we are announcing a transformative step forward to help teams manage their software at a higher level, with the addition of architecture capabilities in SonarQube.

Read article >

Image for New data on code quality: GPT-5.2 high, Opus 4.5, Gemini 3, and more
Blog post

New data on code quality: GPT-5.2 high, Opus 4.5, Gemini 3, and more

Today, we are making all evaluations available in a new Sonar LLM leaderboard and sharing our latest findings on GPT-5.2 High, GPT-5.1 High, Gemini 3.0 Pro, Opus 4.5 Thinking, and Claude Sonnet 4.5.

Read article >

Image for SonarQube Server 2025.6 is here: Vibe, then verify faster than ever
Blog post

SonarQube Server 2025.6 is here: Vibe, then verify faster than ever

This release delivers deeper integrations, dramatically faster analysis, and unmatched support for the latest, most popular languages, helping your team embrace the “vibe, then verify” philosophy.

Read article >

Image for The intelligent approach to achieve MISRA C++:2023 compliant source code
Blog post

The intelligent approach to achieve MISRA C++:2023 compliant source code

SonarQube provides an intelligent, high-precision, and integrated solution for development teams to achieve full, friction-free compliance with the MISRA C++:2023 coding standard for C++17 safety-critical applications.

Read article >

Image for Zombie Workflows: A GitHub Actions horror story
Blog post

Zombie Workflows: A GitHub Actions horror story

Our research team recently discovered an exploitable pattern in GitHub Actions that lets attackers exploit seemingly fixed vulnerabilities.

Read article >