WHAT'S NEW
The latest SonarQube Server news and updates
Discover the features in each SonarQube Server release
September 29, 2026
SonarQube Server 2026.5 LTA: Ship AI code inside your perimeter with confidence
- Sonar Vortex makes your agent produce better code, faster, for fewer tokens. Vortex guides your agent to write code aligned with your standards, and prevents it from introducing new issues. You get PRs that are more secure, more reliable and more maintainable, easier to review, and ready to merge with confidence. Its semantic Code Navigation engine helps your agent explore code efficiently, reducing token consumption.
- SonarQube Remediation Agent can be purchased to bring automated, verified code repair to self-managed environments. A containerized Agent Core Engine runs inside your own Kubernetes or Docker containerized infrastructure, connects to your chosen cloud LLM endpoint using your own key, requires no public internet exposure and integrates into your GitHub, GitLab, or Azure DevOps platform. Every fix is analyzed and proven correct by SonarQube before it reaches a software developer.
- Hunter Agent, is now available for purchase with Server using your own Anthropic key. It runs as an on-demand background agent, uncovering the broken access control, business logic, and authentication flaws that pattern-based scanners are not built to catch, and it surfaces confirmed findings directly as SonarQube issues rather than in a separate tool or portal.
Sonar Vortex, SonarQube Remediation Agent, and SonarQube Hunter Agent are available for purchase with a SonarQube Server Enterprise or Data Center license.
July 22, 2026
SonarQube Server 2026.4: Verification built for the agentic era
- Architecture management, now in SonarQube Server. Define intended architecture, visualize the current state, and catch architectural deviations automatically, at no added cost.
- A new quality gate and rules built for agentic code. "Sonar way for Agentic AI" tightens security, reliability, and dependency checks while easing off minor style feedback, so agent-driven pipelines aren't slowed by low-impact noise. A new dedicated family of agentic-security rules extends AI security detection, catching the threat classes that emerge specifically when agents write the code.
- Faster, simpler workflows. A unified security issue and hotspot workflow, a guided one-click GitHub App setup that cuts integration time from around 12 minutes to under two, and research-backed performance baselines remove friction across the development lifecycle.
May 20, 2026
In SonarQube Server 2026.3 you'll find our embedded MCP Server, deepened language and pipeline analysis, and streamlined administration and compliance.
- Next-Generation AI Connectivity with an embedded MCP Server
- Advanced Programming Language & Automation Support with new Python, PowerShell and Groovy for Jenkins rules
- Enterprise Administration, Resilience & Compliance with GitLab auth and autoprovisioning, alerts for performance issues, and VEX doc support
March 25, 2026
SonarQube Server 2026.2: New user experience, deepened language intelligence, and unified security reporting.
- Redesigned workspace for frictionless, low-cognitive-load navigation
- Model-agnostic AI CodeFix for secure, automated remediation
- Deepened AI-bug detection and expanded analysis for Java 25, Python, Groovy, and Apex
- Unified enterprise security reporting combining proprietary and supply chain risks
January 29, 2026
Purpose built for the AI-native developer workflow, the latest 2026.1 LTA helps teams reach their full potential
- Ready for the AI and agentic SDLC: Integrated with AI-native IDEs like Cursor, Claude Code, Windsurf and delivers deep code insights to agents to verify AI code instantly in your software development workflow.
- Significantly enhanced code security: Protect your software supply chain and detect complex dependency vulnerabilities early with Advanced Security.
- Dependable code quality: Find bugs faster with updated analysis engines that increase accuracy and speed for Java, Python, JavaScript, and TypeScript.
- Expanded compliance standards: Meet strict industry mandates automatically with full MISRA C++:2023 coverage and new reports for common code security standards.
- Broader language coverage: Maintain consistent code health across your entire tech stack with new support for new languages and the latest major language versions.
- Deeper DevOps integrations: Streamline communication by bringing code health insights directly into tools like JFrog, Slack, and Jira.
- Optimized platform operations: Smoother version updates and leverage modern ways to operate the server.
December 11, 2025
2025.6 includes deeper integrations, dramatically faster analysis, and unmatched support for the latest, most popular languages
Deeper workflow integration and faster feedback
- Accelerated developer flow with new Jira Cloud and Slack integrations
- Quick feedback with up to 40% faster analysis for JavaScript/TypeScript
- 58 new quick fixes in the IDE for JavaScript/TypeScript
Expanded language coverage
- Swift (5.9 to 6.2) with SAST and secrets detection, plus Python 3.14
- Write efficient PyTorch, Apex and Ruby code including Ruby on Rails
- New code quality for Go and Shell/Bash
Inherent security and compliance
- New compliance: MISRA C++:2023, OWASP Top 10 2025, STIG V6R3
- Enhanced supply chain security: Import CycloneDX and SPDX SBOMs
- Improved Advanced SAST: optimized top libraries in C#, Java, Python
Get SonarQube updates delivered directly to your inbox
By signing up, you will receive product and marketing information about upcoming SonarQube updates, new releases, news, and events.