Code security

Filter by Category...
Security that works for you: Exploring the new enhancements in SonarQube
Blog

Security that works for you: Exploring the new enhancements in SonarQube

Our latest enhancements in SonarQube establish a non-negotiable code verification layer designed to bridge this trust gap, unifying the analysis of first-party, AI-generated, and third-party code.

Read article >

The intelligence paradox: Why Claude Opus 4.6 requires verification
Blog

The intelligence paradox: Why Claude Opus 4.6 requires verification

Read on for an exhaustive comparison of the technical architectures of Claude Opus 4.5 and 4.6, an evaluation of their performance across industry-standard benchmarks, and an outline of Sonar’s focus on embracing agentic development.

Read article >

Managing the tricky relationship between AI and code security
Blog

Managing the tricky relationship between AI and code security

The sixth installment in our series, where we examine a critical tension in modern development: the tricky relationship between AI and code security.

Read article >

How SonarQube minimizes false positives in code analysis below 5%
Blog

How SonarQube minimizes false positives in code analysis below 5%

Read on to learn how SonarQube’s static code analysis engine works under the hood and the specific strategies that help it deliver accurate results.

Read article >

Using dashboards in SonarQube Cloud
Blog

Using dashboards in SonarQube Cloud

Visualizing key code quality and security metrics for your SonarQube Cloud projects just became easier with the general availability of customizable project dashboards.

Read article >

Stop malicious packages in your CI/CD pipeline with SonarQube
Blog

Stop malicious packages in your CI/CD pipeline with SonarQube

“Malware”, short for “malicious software” has been around for decades, starting with the first computer viruses of the 1990s. Early malware was mostly experimentation and pranks.

Read article >