What’s new
Discover the latest features released in SonarQube Cloud
June 10, 2025
SonarQube Cloud now analyzes “dotfiles” for secrets.
Secret detection capabilities have been enhanced. The updated analysis engine now scans dotfiles and files within dot paths for leaked secrets.
These files and paths, such as .env, .credentials, .npmrc, and .github/workflows, are frequently used to store sensitive information like API keys, passwords, and other credentials. The improved analysis can, for example, detect credentials in .env files, and GitHub tokens in .gitconfig files. This helps developers keep their code secure and prevent the exposure of sensitive information.
It is recommended to run a fresh analysis on projects to benefit from this enhanced level of protection.
Additional details can be found in the Community post.
June 05, 2025
Announcing Sonar Dataflow Bug Detection (DBD) engine 2.0 - Enhanced bug detection for Java and Python code.
Sonar Dataflow Bug Detection (DBD) engine 2.0 has been released, providing more precise bug detection. This update notably improves bug detection for Java and Python code, both human and AI-generated, resulting in more relevant findings.
Initial results, documented in a blog post, show a significant increase in true positives and a decrease in false positives.
Additional details can be found in the Community post.
May 12, 2025
Expanded ruleset for PySpark code with Python
We have released an expanded ruleset for PySpark code. This update includes 5 new rules, bringing the total to 13, and is designed to help identify common issues, and encourage best practices.
Additional details can be found in the Community post.
April 22, 2025
SonarQube Cloud now supports Rust!
SonarQube Cloud has launched support for the Rust programming language.
This initial release emphasizes helping you write maintainable code.
Features include:
- 85 Clippy rules you can use in your Quality Profile
- Code coverage ingestion (LCOV and Cobertura format)
- Cognitive Complexity and Cyclomatic Complexity metrics
Rust analysis currently requires CI-based analysis, with cargo and Clippy needed on the analysis machine.
Additional details are available in the Community post.
April 16, 2025
New: Choose Your preferred LLM, plus broader coverage with AI CodeFix
SonarQube Cloud Team and Enterprise plan users can now experience enhanced flexibility and power in automated code remediation. We've expanded our AI CodeFix capabilities by introducing support for additional Large Language Models (LLMs), allowing you to select either Claude 3.5 Sonnet or Claude 3.7 Sonnet for generating code suggestions. This choice gives you greater control to tailor the AI assistance to your specific project needs and preferences.
Alongside the introduction of selectable LLMs, we have also increased the number of rules covered by AI CodeFix. This means SonarQube Cloud can now provide automated fix suggestions for an even wider array of code quality and code security issues, streamlining your workflow and helping you resolve problems more efficiently.
These enhancements are now available to all users on our Team and Enterprise plans.
Additional details are available here and in this Community post.
April 07, 2025
New: Portfolio security reports in the UI
SonarQube Cloud Enterprise now provides a centralized view of code security issues across multiple projects at the Portfolio level, saving you time and eliminating the need to check individual project reports.
It offers a comprehensive security snapshot, instant risk clarity to understand which portfolios are most at risk, as well as drill-down capabilities, accessible via a new Security Report tab in the Portfolios section.
This feature is available with the Enterprise plan. Additional details are available in the Community post.
SonarQube Cloud のアップデートを直接メールでお届けします
サインアップすると、今後の SonarCloud のアップデート、新リリース、ニュース、イベントに関する製品およびマーケティング情報を受け取ることができます。