新機能

今すぐ試す
ログイン

What’s new

Discover the latest features released in SonarQube Cloud

  • 営業担当へのお問い合わせ
  • 14日間無料トライアル
  • 価格を見る

July 16, 2025

SonarQube Cloud now detects over 400 secret patterns

We're excited to announce a significant update to SonarQube Cloud's secret detection. To deliver even stronger security coverage for your projects, we've introduced 89 new rules (active by default). This significantly boosts secret detection capabilities.

Your projects now benefit from over 400 distinct secret patterns, powered by a total of 346 rules.

Dive deeper into the details in our Community post.


secure blue-large

July 09, 2025

Detecting injection vulnerabilities in Go projects

SonarQube Cloud now supports taint analysis for Go, enabling you to detect injection vulnerabilities in your Go projects. 

Find supported injection rules here, with a complete list of Go security rules here.

Learn more in this Community post.


secure blue-large

July 08, 2025

Enhanced Single Sign On (SSO)

Enterprise plan users can now benefit from a streamlined setup flow for their SSO. 


Includes:

  • A step-by-step configuration assistant
  • Automatic configuration option with Metadata
  • Connection validation step to eliminate misconfigurations


Learn more in this Community post, and SonarQube Cloud documentation.


innovation red-large

June 27, 2025

Project Security report downloadable PDFs now available for Enterprise users.

Enterprise plan users can now directly generate and download Project Security report PDFs for their projects:

  • Generate a detailed PDF security report for any project, capturing its overall security status.
  • Customize the report by selecting the specific security standards you want to include, such as Sonar, OWASP Top 10 2021, CWE, and more.
  • Surface actionable insights including:
    • An overview page that highlights 'Accepted' security issues and 'To Review' security hotspots.
    • A detailed breakdown of security issues by severity for each standard.
    • A summary of issues to address and hotspots to review, categorized by standard.

Learn more in this Community post and SonarQube Cloud documentation.


innovation red-large

June 10, 2025

SonarQube Cloud now analyzes “dotfiles” for secrets.

Secret detection capabilities have been enhanced. The updated analysis engine now scans dotfiles and files within dot paths for leaked secrets.


These files and paths, such as .env, .credentials, .npmrc, and .github/workflows, are frequently used to store sensitive information like API keys, passwords, and other credentials. The improved analysis can, for example, detect credentials in .env files, and GitHub tokens in .gitconfig files. This helps developers keep their code secure and prevent the exposure of sensitive information.


It is recommended to run a fresh analysis on projects to benefit from this enhanced level of protection.


Additional details can be found in the Community post.


innovation red-large

June 05, 2025

Announcing Sonar Dataflow Bug Detection (DBD) engine 2.0 - Enhanced bug detection for Java and Python code.

Sonar Dataflow Bug Detection (DBD) engine 2.0 has been released, providing more precise bug detection. This update notably improves bug detection for Java and Python code, both human and AI-generated, resulting in more relevant findings.


Initial results, documented in a blog post, show a significant increase in true positives and a decrease in false positives.


Additional details can be found in the Community post.


SonarQube Cloud のアップデートを直接メールでお届けします

サインアップすると、今後の SonarCloud のアップデート、新リリース、ニュース、イベントに関する製品およびマーケティング情報を受け取ることができます。

Select your preferred languages
I do not wish to receive promotional emails about upcoming SonarQube updates, new releases, news and events.

このフォームを送信することにより、 プライバシー ポリシー および Cookieポリシーに記載された個人データの保存と処理に同意したことになります。登録解除することでいつでも同意を取り消すことができます。このサイトは reCAPTCHA と Google の プライバシー ポリシー によって保護されており、 利用規約が 適用されます。

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

  • Follow SonarSource on Twitter
  • Follow SonarSource on Linkedin
language switcher
日本語 (Japanese)
  • 法的文書
  • トラスト センター

© 2008-2024 SonarSource SA.無断複写·転載を禁じます。SONAR、SONARSOURCE、SONARLINT、SONARQUBE、およびCLEAN AS YOU CODEは、SonarSource SAの商標です。