In most organizations, AI agents are writing more and more of their code every day transitioning to agentic software factories. Code creation is abundant. Code confidence is not.
SonarQube is designed to fill that gap, to help you ensure that every line of code agents write is secure, reliable, maintainable, compliant, and built to scale with your organization. We help guide your coding agents with context, verify the quality of the code they produce, and solve the issues that they generate along the way.
SonarQube Server customers have watched SonarQube Cloud customers get Sonar’s full agentic capabilities, Sonar Vortex, SonarQube Remediation Agent, and SonarQube Hunter Agent and maybe felt a little envious. Moving to SonarQube Cloud might not have been an acceptable option.
Well, your time is now. With the 2026.5 LTA, all three are now available for purchase with SonarQube Server Enterprise and Data Center editions, running entirely inside the infrastructure of your choice, along with a host of other new capabilities, from enterprise LLM governance and reachability-driven dependency analysis to architecture management and customizable executive dashboards. Every SonarQube customer, Cloud or Server, now gets the same platform for shipping agent-written code with confidence.
Sonar Vortex is now deployable in your infrastructure of choice, even in VPC-restricted environments. With Vortex, your agents produce safer, more reliable and more maintainable code faster, for fewer tokens. It injects the right project context and constraints before the first line of code is written, helping your agent explore and understand the code faster, more completely, and more efficiently, reducing token consumption by up to 36%. Vortex gives coding agents your project's security standards, architecture rules, coding standards, and approved libraries before they even generate code. It then verifies every proposed code change with Sonar’s trusted algorithmic analysis in real time, inside the agent's own loop. AI agent output gets corrected before it is committed and a developer ever reviews it. PRs are then cleaner, easier to review, and ready to merge.
SonarQube Remediation Agent is also now deployable in your infrastructure of choice. Technical debt backlogs grow faster than teams can clear them as AI-assisted software development increases code output. The SonarQube Remediation Agent addresses this by reviewing your backlog of tech debt and proposing fixes for issues within your selected categories (reliability bugs, maintainability issues, security vulnerabilities, hardcoded secrets, vulnerable dependencies), all without pulling developers off roadmap work. Each generated fix is applied in a sandbox and re-analyzed by Sonar's own algorithmic analysis before it ever reaches a pull request. This closed-loop verification runs on Sonar's own Foundation Agent (its LLM backbone), supports bring-your-own-LLM options including GPT-5.5 and Claude Opus 4.6, covers Java, JavaScript, TypeScript, Python and C#, and integrates with GitHub, GitLab, and Azure DevOps.
SonarQube Hunter Agent is the third new agentic capability you can self deploy and you can use it with your own Anthropic key. Static analysis and human code review both stop at code that looks syntactically correct, which means broken access control, business logic abuse, and authentication gaps routinely reach production undetected. The SonarQube Hunter Agent closes that gap by reasoning about a codebase's intent, tracing data and identity flows across files to catch issues like IDOR, privilege escalation, and session fixation, then validating each proposed fix before it's surfaced so teams get high-precision findings instead of a false-positive queue to triage. It works through curated, multi-step security playbooks, the same logic a human security researcher would apply, across the full codebase. It delivers confirmed findings directly into the existing SonarQube issue list, including severity, explanation, and location, so code verification scales alongside AI-accelerated development without adding headcount.
But there’s more…
None of this works without governable AI connectivity. New since the 2026.1 LTA release, agentic capabilities in SonarQube are model agnostic and can be configured with AWS Bedrock, Azure AI Foundry, self-hosted proxy gateways (Ollama, LiteLLM, vLLM) using your own API key or model ID, or bring-your-own-key providers. 2026.5 adds Azure API Management support so Azure OpenAI customers authenticate without static keys. Underlying all of it is the embedded SonarQube MCP Server endpoint, also introduced since the 2026.1 LTA, which lets Cursor, Claude Code, GitHub Copilot and other agentic coding tools reach your project issues and quality gates with zero configuration, governed by a token-based kill-switch.
Verification also deepened beyond AI connectivity. A new quality gate purpose-built for agent-generated code enforces stricter security, reliability, and supply-chain standards while staying permissive on coding style to reduce noise when using agentic development. Architecture management automatically catches architectural drift and surfaces it in the issue list developers already use. Direct reachability analysis tells Java and C# teams which dependency vulnerabilities their code actually calls, cutting through backlog noise. New taint analysis brings command-injection and path-traversal detection to C and C++. Cross-translation-unit awareness makes C/C++ symbolic execution consistent across file boundaries, reducing false positives and finding issues that were previously undetectable.
Native support for MuleSoft DataWeave and R closes language coverage gaps for integration-heavy and data-heavy enterprises. Detected secrets are now masked and redacted by default to reduce potential exposure by SonarQube. Language coverage now spans Java 25, Python web frameworks (FastAPI, Flask and Django), Jenkins Groovy, PowerShell, Gosu, Ruby and Apex, verifying application code and automation scripts alike.
Rust analysis goes beyond Clippy extending Rust governance to codebases without replacing the developer workflow teams already rely on. While leveraging Clippy rules, SonarQube layers on centralized quality profiles, quality-gate enforcement, adds maintainability metrics (Cognitive Complexity and Cyclomatic Complexity), correlates code coverage from LCOV or Cobertura, detects duplication in Rust sources, covers the most popular Rust crates, and brings Rust under the same organization-wide governance standard alongside C/C++, Java, JavaScript and other languages in multi-language projects, all of which Clippy on its own can’t do.
Compliance failures carry real cost, in audit findings, delayed releases, and regulatory exposure. SonarQube 2026.5 helps you close that gap with expanded, automated support for the standards safety-critical and accessible software must meet. For safety-critical projects, 2026.5 raises MISRA C automated coverage to 38.4% for MISRA C:2012, delivered on the same terms as the existing MISRA C++:2023 compliance support. A new MISRA C/C++ Compliance Report generates audit-ready, tamper-evident attestation artifacts automatically. A new WCAG Accessibility and CRA Compliance Reports proves conformance to regulations at the project, application, and portfolio level. C accounts for a large share of functional-safety development, and teams that have needed separate tools for MISRA C and MISRA C++ can now start consolidating onto a single platform.
The results compound where teams feel them. Incremental taint analysis cut pull request scans on large Java and C# projects by up to 90%, some dropping from 20 minutes to under a minute, with no coverage traded away. Security hotspots migrate into a single unified vulnerability model that preserves full history. Customizable portfolio and project dashboards arrive with a new overview landing page that brings organization-wide reporting to organize SonarQube’s findings in the way your organization needs them. A project coverage dashboard shows administrators which DevOps platforms are connected, which repositories are imported, and which projects have not been analyzed yet, so unanalyzed projects are visible before they sit outside your quality and security process. And a quality gate adherence dashboard replaces anecdote with evidence, flagging risky releases that shipped despite a failing gate.
Better models alone do not make AI-generated code trustworthy. Verification does: deterministic, multilayered, transparent, and applied consistently, never left to an agent checking its own work.
Ready to verify at the speed your agents ship? Request a trial of SonarQube Server and bring agentic verification inside the perimeter you already control.
Want to see it in action? Join our session on October 14th for SonarQube Server 2026.5: The LTA release built to verify what your agents write to discover how this LTA delivers full verification and automated governance directly to your enterprise agentic development pipelines.

