Sonarの最新ブログ記事

注目の投稿

The future is AC/DC: the Agent Centric Development Cycle

おなじみのプロセスやワークフローを特徴とする継続的インテグレーション(CI)の時代は、急速に終わりを迎えつつあります。従来のCIは、開発者が小規模で頻繁な反復的なコミットを行うことを前提としていました。今日、「継続的」という側面そのものが変化しつつあります。

記事を読む
Image
Category
Category
The java.time bugs that don’t throw exceptions
Blog

The java.time bugs that don’t throw exceptions

Learn how SonarQube detects java.time bugs that compile cleanly but cause wrong timezone math, flaky tests, and bad comparisons.

Read article >

How SonarQube traces a SQL injection your AI coding agent produced
Blog

How SonarQube traces a SQL injection your AI coding agent produced

Learn how SonarQube traces SQL injection across Spring Boot files using taint analysis to expose unsafe database queries from user input.

Read article >

Get new blog posts delivered directly to your inbox!

Stay up-to-date with the latest Sonar content. Subscribe now to receive the latest blog articles.

Jellyfin remote code execution: Inconsistent validation leads to argument injection
Blog

Jellyfin remote code execution: Inconsistent validation leads to argument injection

Explore a Jellyfin remote code execution flaw where inconsistent validation enables FFmpeg argument injection and unauthenticated code execution.

Read article >

Now available: SonarQube Agent App in GitHub
Blog

Now available: SonarQube Agent App in GitHub

Learn how the SonarQube Agent App brings code quality and security checks directly into GitHub agent workflows for faster feedback.

Read article >

Now available: SonarQube plugin for GitHub Copilot CLI
Blog

Now available: SonarQube plugin for GitHub Copilot CLI

Connect GitHub Copilot CLI to SonarQube for quality gates dependency risk checks coverage insights and agent driven analysis.

Read article >