Sonar's latest blog posts

Featured Post

The future is AC/DC: the Agent Centric Development Cycle

The era of Continuous Integration, with its familiar processes and workflows, is rapidly coming to an end. Traditional CI relies on developers making small, frequent, iterative commits. Today, the “continuous” part is changing.

Read article
Image
Category
Category
Scripting Outside the Box: API Client Security Risks (2/2)
Blog

Scripting Outside the Box: API Client Security Risks (2/2)

Continuing on API client security, we cover more sandbox bypasses, this time in Bruno and Hoppscotch, as well as JavaScript sandboxing best practices.

Read article >

Scripting Outside the Box: API Client Security Risks (1/2)
Blog

Scripting Outside the Box: API Client Security Risks (1/2)

Discover hidden risks in API testing tools like Postman and Insomnia. We dive into scripting vulnerabilities and explore JavaScript sandbox security pitfalls.

Read article >

Get new blog posts delivered directly to your inbox!

Stay up-to-date with the latest Sonar content. Subscribe now to receive the latest blog articles.

7 Guidelines for Federal Agencies Adopting AI for Software Development
Blog

7 Guidelines for Federal Agencies Adopting AI for Software Development

With the release of two new Artificial Intelligence (AI) policies, The White House has provided clear direction for federal agencies regarding how to embrace AI to improve efficiency, effectiveness, and overall service delivery.

Read article >

Seven Habits of Highly Effective AI Coding
Blog

Seven Habits of Highly Effective AI Coding

Massive codebases can hugely benefit from developers using AI coding tools, but they must be harnessed in a responsible way. Sonar CEO, Tariq Shaukat, shares what coding "habits" organizations should adopt.

Read article >

Data in Danger: Detecting Cross-Site Scripting in Grafana
Blog

Data in Danger: Detecting Cross-Site Scripting in Grafana

Learn how SonarQube detected a Cross-Site Scripting (XSS) vulnerability in Grafana, a popular open-source data observability platform.

Read article >

Unsubscribe