Sonar's latest blog posts
Announcing SonarSweep: Improving training data quality for coding LLMs
Recent research from Anthropic has shown that even a small amount of malicious or poor quality training data can have a massively negative impact on a model’s performance, exposing users to significant security and quality issues.


Java24: Go deeper on parsing Java class files and broader with Stream gatherers
Version 24 version introduces several new language features which collectively simplify code, and provide powerful tools for bytecode manipulation and advanced stream processing.
Read article >

Sonar's Take: Software Development Under America's AI Action Plan
The White House's "America's AI Action Plan" aims to accelerate innovation, but for software development, speed must not compromise security. Nathan Jones, VP of Public Sector at Sonar, explores the recently published plan, risks of AI-generated code, and explains how static analysis tools help ensure AI adoption is both fast and secure.
Read article >
Get new blog posts delivered directly to your inbox!
Stay up-to-date with the latest Sonar content. Subscribe now to receive the latest blog articles.

AI CodeFix is now generally available
AI CodeFix seamlessly integrates AI-driven code fix suggestions into your development workflow with no additional cost for eligible SonarQube subscriptions.
Read article >

SonarQube Server 2025.4 LTA : Faster analysis, stronger security, better coverage
Our new 2025.4 LTA release empowers developers with significant advancements to enhance code quality, security, and efficiency across multiple languages for your projects and while using open-source code.
Read article >

Loi sur la cyber-résilience : naviguer entre vitesse et sécurité grâce au codage par IA
Le développement logiciel moderne est pris entre deux forces puissantes. D'un côté, les outils de codage basés sur l'intelligence artificielle (IA) générative accélèrent le développement au détriment d'un contrôle de sécurité rigoureux.
Lire l'article >

Java 23: Embrace the new era of code comments
We’ve covered Java 22, and are now getting into Java 23, which introduces several new language features. We’ll focus on enhancing documentation, and how to leverage the new features with simple examples.
Read article >

What's the top bug in your language? Find out in The State of Code: Languages report
The State of Code report analyzes 7.9B lines of code, revealing top security risks like log injection and XSS and how to fix them.
Read article >

How Sonar Helps Achieve a Strong SOC 2 Type II Report
An SOC 2 Type II report is a critical attestation for service organizations, demonstrating their commitment to securely managing customer data over time. Learn how SonarQube can streamline your SOC 2 compliance journey!
Read article >

Protecting your AI code: How SonarQube defends against the "Rules File Backdoor"
This case highlights an issue where configuration files were manipulated through hidden Unicode characters, which is a vector now commonly referred to as the "Rules File Backdoor".
Read article >

Java 22: Leverage unnamed variables and patterns
Java 22 introduces several new language features but there’s one particularly important. This article shows you how to leverage the Unnamed variables and patterns with simple examples.
Read article >

Comment SonarQube permet la conformité DORA pour les institutions financières
Le secteur des services financiers se trouve à un tournant décisif. Avec l'entrée en vigueur de la loi sur la résilience opérationnelle numérique (DORA) dans toute l'Union européenne, les institutions financières doivent démontrer de solides capacités en matière de cybersécurité et de résilience opérationnelle.
Lire l'article >