Why Sonar

The independent code verification layer

Sonar provides the automated code review and deterministic verification layer to ensure AI-generated code meets the highest standards of reliability and security.

始めましょうContact sales

世界中の開発チームから信頼されています

すでにSonarQubeを活用して優れたコードを提供している数千の組織に加わりましょう

0M+
開発者はSonarを使用する
0 +
コミュニティのメンバー
0+
プログラミング言語、フレームワーク、およびIaC技術
0%
稼働時間SLA

最適なSonarQubeデプロイメントを選択してください

SonarQube Cloud

現代のDevOpsのためのSaaSソリューション

SonarQube Cloudは35以上の言語のコードを分析し、問題を検出するとともにAIを活用した修正案を提供します。DevOpsツールと統合され、マージのたびに保守性、信頼性、セキュリティに関するルールを適用します。

  • 数分で稼働開始
  • メンテナンスとインフラ管理不要
  • 自動更新と新機能の展開
  • 99.9%稼働率のSLAとグローバル可用性
  • SOC 2 Type II認証取得済みセキュリティ
始めましょう詳細はこちら

SonarQube Server

オンプレミスで最大限の制御を実現

SonarQube Serverは、35以上の言語に対応したオンプレミス型コード分析を提供し、AIを活用した提案機能で問題を検出します。CI/CDツールと統合され、マージのたびに保守性、信頼性、セキュリティを確保します。

  • 完全なデータ居住性とプライバシー制御
  • カスタム設定とエンタープライズ統合
  • エアギャップ環境でのデプロイメントオプション
  • 専任サポートとプロフェッショナルサービス

Core capabilities

Comprehensive code quality, security, and governance features designed for modern engineering teams.

Automated code reviews

Systematically review all code for bugs, security vulnerabilities, and stylistic errors without human intervention. 

  • Real-time and continuous feedback 
  • Code assurance for verifying AI-generated code 
  • Pull request (PR) decoration and branch analysis
  • AI-native IDES, MCP Server, CI/CD, and DevOps integration 

Learn more >

Code quality analysis

Comprehensive code quality assessment to maintain high-quality, reliable, maintainable codebases.

  • Comprehensive and deep systematic  code analysis
  • Consistent, deterministic, and idempotent
  • Breadth, depth, and accurate analysis for 40+ languages 
  • Finds bugs, code smells, and technical debt

Learn more >

Code security analysis

All-in-one comprehensive and accurate code scanning to identify vulnerabilities and security risks. 

  • SAST, taint analysis, secrets detection, IaC scanning
  • Mobile Application Security Testing (MAST)
  • Software Composition Analysis (SCA) (needs in Advanced Security)
  • Security reports, dashboards, and posture rating

Learn more >

Architecture management

Automatically visualizes and enforces your system design, ensuring that human and AI-generated code adhere to a modular, maintainable framework. 

  • Architecture discovery 
  • Architecture visualization 
  • Define intended architecture
  • Automated architectural reviews
  • In-workflow issues management

Learn more >

Remediation

LLM-powered, context-aware fix suggestions for issues detected by SonarQube. One-click remediation directly in your IDE or PR workflow.

  • Instant AI-generated context-aware fixes
  • IDE integration with AI CodeFix
  • Bring your OpenAI model in SonarQube Server
  • Remediation Agent (beta) with automatic verification of fixes

Learn more >

Secrets detection

Identify and prevent exposure of sensitive credentials, API keys, and secrets. Real-time detection of secrets in IDEs, commits, and pull requests. 

  • Hardcoded password detection
  • API  and private key detection
  • OAuth token detection
  • Cloud provider secret detection (AWS, Azure, GCP)

シークレット検出の詳細 >

Software composition analysis (SCA)

SCA automatically identifies third-party open source components to manage security vulnerabilities, license compliance, and supply chain risks

  • Vulnerability (CVE) detection, license policy, and SBOM 
  • Severity scores: CVSS (Common Vulnerability Scoring System) 
  • Data from EPSS and KEV 
  • Malicious package detection
  • Open source maintainer network insights for supply chain security

SCA を探る >

IaC scanning

Infrastructure as Code (IaC) security analysis for detecting risks, and misconfigurations in infrastructure templates.

  • Multi-cloud IaC support
  • Security misconfiguration detection
  • Terraform, AWS CloudFormation, Azure Resource Manager
  • Kubernetes, Docker, and Helm, and Ansible

Learn more >

Mobile application security (MAST)

Find and fix bugs, vulnerabilities, and quality issues in your Android and iOS apps before they hit the app store. 

  • Native iOS: Swift and Objective-C.
  • Native Android: Kotlin and Java.
  • Cross-Platform: Dart/Flutter and JavaScript/TypeScript 
  • OWASP Mobile Top 10 reports
  • IDE support for early detection of issues

Learn more >

SAST and Taint analysis

Advanced data-flow analysis that tracks untrusted input through your codebase to identify injection vulnerabilities. 

  • Cross-file data-flow tracking
  • Lexical analysis
  • Syntax and control flow analysis
  • Injection vulnerability detection
  • Sanitization validation

Learn more >

Open source license management

License compliance tracking for open-source dependencies. Identify license conflicts, ensure policy compliance, and manage legal risks.

  • Automated enforcement in PRs 
  • License detection & categorization
  • Policy violation alerts
  • Compliance reporting
  • Software Bill of Materials (SBOM)

SCA を探る >

CI/CD integration

Scanners and plugins for all major CI/CD and DevOps platforms for automated quality checks. Features include:

  • Jenkins 
  • GitHub Actions 
  • GitLab CI 
  • Azure DevOps 

Learn more >

Project & portfolio management

High-level visibility and aggregated data across all projects, allowing leaders to monitor risk, track compliance, and ensure coding standards. Features include:

  • Multi-project dashboard
  • Portfolio view
  • Project tagging & categorization
  • Monorepo support
  • Historical trend analysis, custom metrics and KPIs, reporting

Learn more >

Governance & compliance

Provides centralized oversight and reporting necessary to enforce regulatory standards and corporate security policies across your organization. Features include:

  • Quality gate, quality profile definition & enforcement
  • Regulatory Compliance Reporting (PCI-DSS, OWASP, MISRA, etc.)
  • Audit trail, activity logs, and dashboards
  • Role-Based Access Control (RBAC)
  • License compliance tracking

Learn more >

Reporting & analytics

Provides actionable insights and automated reports to monitor trends, evaluate risk, and drive data-backed decisions across the organization. Features include:

  • Executive summary reports
  • Dashboards
  • Detailed Issue Reports
  • Trend analysis & charts
  • Scheduled reports

Learn more >

Enterprise-ready platform

All capabilities run on both SonarQube Server (self-hosted) and SonarQube Cloud (SaaS) with enterprise features including RBAC, LDAP/SAML integration, audit logs, and portfolio management for organization-wide governance.

The complete platform for every need

Cloud-Native Code Analysis

SonarQube Cloud

Fully managed SaaS solution with seamless DevOps integration. Zero infrastructure overhead with automatic updates and instant setup for GitHub, GitLab, and Azure DevOps.

  • Zero maintenance
  • Free for open source
  • Auto PR decoration
  • Usage-based pricing
Learn more
Centralized Code Quality Hub

SonarQube Server

Self-hosted, comprehensive code quality and security platform. Complete control over your data with deep analysis, Quality Gates, and enterprise governance.

  • Self-managed deployment
  • Quality Gate enforcement
  • 360° code health view
  • Portfolio management
Learn more
Start left with real-time analysis

SonarQube for IDE

Real-time code quality and security analysis directly in your IDE. Catch bugs, vulnerabilities, and code smells as you write—before they reach version control.

  • 6,000+ analysis rules
  • Connected mode sync
  • Instant feedback in IDE
  • AI-powered fix suggestions
Learn more
Comprehensive security layer

SonarQube Advanced Security

Enterprise-grade security with SAST, SCA, taint analysis, and secrets detection. Protect both first-party code and third-party dependencies with human-curated intelligence.

  • Software Composition Analysis
  • SBOM generation
  • Advanced taint analysis
  • License management
Learn more
Image shows filtering of dependency risks in SonarQube
AI agent integration

SonarQube MCP Server

Programmatic access to Sonar's analysis engine for AI agents and automated workflows. Integrate code quality checks into custom AI pipelines and development tools.

  • Programmatic API
  • Custom automation
  • AI agent workflows
  • Multi-tool pipelines
Learn more
The standard for code quality and security

AI Code Assurance: Vibe, then verify

Harness the speed of AI coding assistants while ensuring every line meets your quality and security standards. Trust, but verify.

40+ languages & frameworks

Apply consistent code quality and security standards across your entire technology stack from legacy mainframes to modern cloud-native applications.

Java
Language Icon
Python
python logo
JavaScript
java script logo
TypeScript
type script logo
C#
Language Icon
C++
c plus logo
C
c logo
PHP
php logo
Go
Language Icon
Rust
Language Icon
Kotlin
kotlin logo
Terraform
terraform logo
CloudFormation
cloud formation logo
Kubernetes
kubernetes logo
Helm
Language Icon
Docker
Language Icon
Dart
Language Icon
XML
Language Icon
Ruby
Language Icon
VB.NET
Language Icon
Scala
Language Icon
Swift
Language Icon
ABAP
Language Icon
Apex
Language Icon
COBOL
Language Icon
JCL
jcl logo
CSS
Language Icon
Flex
Language Icon
HTML 5
HTML 5
Objective-C
Language Icon
Azure Resource Manager
Language Icon
PL/I
PL/I
PL/SQL
PL/SQL
RPG
Language Icon
T-SQL
T-SQL
VB6
Language Icon
Language Icon
Language Icon

Supported IDEs: Cursor, Windsurf, Kiro, VS Code, IntelliJ IDEA, Eclipse, Visual Studio, PyCharm, WebStorm, Android Studio, Xcode, Rider, CLion, PhpStorm, and more.

CI/CD Integrations: Jenkins, GitHub Actions, GitLab CI, Azure DevOps, Bitbucket Pipelines, CircleCI, Travis CI, Bamboo, TeamCity.

Get Started with Sonar

Choose the edition that fits your needs. From free Community Edition to enterprise-grade solutions.

Image for rating

4.6 / 5

  • Follow SonarSource on Twitter
  • Follow SonarSource on Linkedin
language switcher
日本語 (Japanese)
  • 法的文書
  • トラスト センター

© 2025 SonarSource Sàrl.無断複写・転載を禁じます。