Sonar's latest blog posts

Featured Post

The Coding Personalities of Leading LLMs

Make smarter AI adoption decisions with Sonar's latest report in The State of Code series. Explore the habits, blind spots, and archetypes of the top five LLMs to uncover the critical risks each brings to your codebase.

Read More
https://assets-eu-01.kc-usercontent.com:443/55017e37-262d-017b-afd6-daa9468cbc30/7f6e6498-f9d3-4c75-8cb2-16917f0d95c2/LLMs-coding-personalities_featured-blog%402x.webp
Image for SonarQube Server 2025 Release 4: Faster analysis, stronger security, better coverage
Blog post

SonarQube Server 2025 Release 4: Faster analysis, stronger security, better coverage

Our new 2025.4 release empowers developers with significant advancements to enhance code quality, security, and efficiency across multiple languages for your projects and while using open-source code.

Read article >

Image for Cyber Resilience Act: Geschwindigkeit und Sicherheit mit KI-Codierung steuern
Blogbeitrag

Cyber Resilience Act: Geschwindigkeit und Sicherheit mit KI-Codierung steuern

Die moderne Softwareentwicklung steht im Spannungsfeld zweier mächtiger Kräfte. Einerseits beschleunigen generative Codierungstools auf Basis künstlicher Intelligenz (KI) die Entwicklungsgeschwindigkeit auf Kosten strenger Sicherheitsüberprüfungen.

Artikel lesen >

Get new blogs delivered directly to your inbox!

Stay up-to-date with the latest Sonar content. Subscribe now to receive the latest blog articles.

I do not wish to receive promotional emails about upcoming SonarQube updates, new releases, news and events.

By submitting this form, you agree to the storing and processing of your personal data as described in the Privacy Policy and Cookie Policy. You can withdraw your consent by unsubscribing at any time.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Image for Java 23: Embrace the new era of code comments
Blog post

Java 23: Embrace the new era of code comments

We’ve covered Java 22, and are now getting into Java 23, which introduces several new language features. We’ll focus on enhancing documentation, and how to leverage the new features with simple examples.

Read article >

Image for What's the top bug in your language? Find out in The State of Code: Languages report
Blog post

What's the top bug in your language? Find out in The State of Code: Languages report

The State of Code report analyzes 7.9B lines of code, revealing top security risks like log injection and XSS and how to fix them.

Read article >

Image for How Sonar Helps Achieve a Strong SOC 2 Type II Report
Blog post

How Sonar Helps Achieve a Strong SOC 2 Type II Report

An SOC 2 Type II report is a critical attestation for service organizations, demonstrating their commitment to securely managing customer data over time. Learn how SonarQube can streamline your SOC 2 compliance journey!

Read article >

Image for Protecting your AI code: How SonarQube defends against the "Rules File Backdoor"
Blog post

Protecting your AI code: How SonarQube defends against the "Rules File Backdoor"

This case highlights an issue where configuration files were manipulated through hidden Unicode characters, which is a vector now commonly referred to as the "Rules File Backdoor".

Read article >

Image for Java 22: Leverage unnamed variables and patterns
Blog post

Java 22: Leverage unnamed variables and patterns

Java 22 introduces several new language features but there’s one particularly important. This article shows you how to leverage the Unnamed variables and patterns with simple examples.

Read article >

Image for Wie SonarQube die DORA-Konformität für Finanzinstitute ermöglicht
Blogbeitrag

Wie SonarQube die DORA-Konformität für Finanzinstitute ermöglicht

Die Finanzdienstleistungsbranche befindet sich an einem kritischen Punkt. Da der Digital Operational Resilience Act (DORA) nun in der gesamten Europäischen Union in vollem Umfang in Kraft ist, müssen Finanzinstitute robuste Cybersicherheit und operative Belastbarkeit nachweisen.

Artikel lesen >

Image for Tame technical debt with insights from The State of Code: Maintainability report
Blog post

Tame technical debt with insights from The State of Code: Maintainability report

Tame technical debt with insights from The State of Code: Maintainability report

Read article >

Image for Securing Kotlin Apps With SonarQube: Real-World Examples
Blog post

Securing Kotlin Apps With SonarQube: Real-World Examples

Explore how real-world vulnerabilities look in the Kotlin code of Android apps and see how SonarQube helps detect them.

Read article >

Image for The biggest security risks unveiled in The State of Code: Security report
Blog post

The biggest security risks unveiled in The State of Code: Security report

The State of Code report analyzes 7.9B lines of code, revealing top security risks like log injection and XSS and how to fix them.

Read article >

  • Follow SonarSource on Twitter
  • Follow SonarSource on Linkedin
language switcher
Deutsch (German)
  • Rechtliche Dokumentation
  • Vertrauenszentrum

© 2008-2024 SonarSource SA. All rights reserved. SONAR, SONARSOURCE, SONARQUBE, and CLEAN AS YOU CODE are trademarks of SonarSource SA.