What’s new
Discover the latest features released in SonarQube Cloud
September 04, 2026
Four new languages: MuleSoft DataWeave, Gosu, Groovy, and PowerShell
SonarQube Cloud now supports four new programming languages: MuleSoft DataWeave, Gosu, Groovy, and PowerShell. Each verified with the same deterministic analysis applied across the other 40+ languages in SonarQube, catching bugs, security vulnerabilities, and maintainability issues before they reach production.
What's changing
- MuleSoft DataWeave: Analysis reads your MuleSoft DataWeave configuration files and flows, so integration issues surface before a flawed flow takes down the systems it connects.
- Gosu: Coverage extends to insurance and enterprise systems, including Guidewire, closing a longstanding gap in policy, billing, and claims logic.
- Groovy: Analysis covers, web development, rapid prototyping, and metaprograming, and even the recently popular Jenkins pipeline definitions, Gradle build scripts, so a broken script does not stall your pipeline.
- PowerShell: Detection targets the failures that cause real incidents: unsafe type handling, hardcoded credentials, injection risks, and unsafe command execution.
How it works
No extra plugins. No manual programming language configuration. Your next scan detects files in all four languages and analyzes them alongside your existing code, with results in the same dashboards and pull request checks you already use. All four are supported in GitHub, GitLab, BitBucket, and Azure DevOps.
The code verification standard does not change based on who, or what, wrote the code. AI-generated and AI-generated code meet the same deterministic bar, so you catch issues before they compound.
Get started: Connect a repository and run your first analysis, or rerun an analysis on an existing repository connected to SonarQube Cloud to start verifying these new languages.
Read more details in the blog post.
August 31, 2026
Bitbucket Cloud: switch to the new SonarQube Cloud app before 30 November 2026
Atlassian is retiring the Connect platform that the current SonarQube Cloud app for Bitbucket Cloud is built on. We have released a replacement app built on Atlassian's Forge platform, live now on the Atlassian Marketplace with full feature parity.
If your SonarQube Cloud organization is bound to Bitbucket Cloud, an organization admin needs to switch to the new app before 30 November 2026. This is an Atlassian platform change, not a change to SonarQube Cloud - it affects every third-party app still built on Connect.
What you need to do
- A full step by step guide can be found in the docs. It should take an estimated 5 minutes.
- Top level overview:
- Install the new SonarQube Cloud app for Bitbucket Cloud from the Atlassian Marketplace.
- In your Bitbucket workspace, go to Forge Apps → SonarQube Cloud.
- Select the SonarQube Cloud organization to reconnect, and confirm.
- Once the new app is working, remove the old app from Apps and features → Installed apps → Connect apps.
For additional information and to ask questions, please see this Community post.
August 12, 2026
Opt-in strict enterprise governance and SSO enforcement in SonarQube Cloud Enterprise
SonarQube Cloud Enterprise now gives administrators opt-in controls to lock down organization creation and enforce strict SSO identity paths for verified corporate domains. This builds on the Domain Verification and the Breakglass Mechanism controls already available.
What's new:
- Centralized organization governance: Block any user authenticating via your Enterprise SSO - or matching a verified corporate domain - from creating SonarQube Cloud organizations outside your Enterprise.
- Strict SSO identity enforcement: Once activated, block logins and Personal Access Token (PAT) usage via parallel DevOps accounts (e.g., independent GitHub or GitLab authentication) for users on your verified domains, routing all access through your SSO Identity Provider.
- Opt-in per verified domain: Turn these policies on only when you're ready, domain by domain.
Where to find it:
Go to Administration > Authentication / SSO in your organization settings, complete the Domain Verification step if you haven't already, then toggle on the new governance and SSO enforcement controls.
For more details, see the documentation and the Community post.
July 14, 2026
Announcing SonarQube Cloud support for GitHub Enterprise Cloud with data residency (GHE.com)
SonarQube Cloud Enterprise plan now supports GitHub Enterprise Cloud with data residency (GHE.com). Organizations in regulated industries, such as financial services, automotive, healthcare, and defense, that run GitHub on a dedicated subdomain like yourcompany.ghe.com can now connect to SonarQube Cloud and start analyzing their code with no analysis infrastructure to manage.
- Bind your GHE.com organization to SonarQube Cloud: Create a GitHub App on your GHE.com instance (permissions are auto-configured), set up a SonarQube Cloud organization pointing at your subdomain, and start importing repositories.
- Bulk-import existing repositories in one click: Onboard your entire GitHub footprint instantly, no manual project-by-project setup required.
- Auto-import new repositories: New repositories created in your GHE.com organization are automatically provisioned in SonarQube Cloud and scanned as they're created.
- Automatic analysis and pull request decoration: SonarQube Cloud handles initial analysis automatically and surfaces quality and security results directly on your pull requests, with no CI/CD configuration required.
Note: this applies to GHE.com (GitHub's managed, cloud-based data-residency offering).
For more information, and to get started, check the documentation, and the Community post.
June 04, 2026
Domain verification and streamlined SSO flows in SonarQube Cloud Enterprise
SonarQube Cloud Enterprise now lets organization administrators verify ownership of their corporate email domain directly within the SSO setup wizard — no support contact required.
Verification immediately removes login friction for your team: once your domain is verified, SonarQube Cloud trusts the identity authenticated by your Identity Provider and skips redundant OTP prompts for users on that domain. It also establishes the foundation for upcoming corporate security policy enforcement across all users under your domain.
What's new:
- Domain verification in the SSO wizard: A dedicated domain verification step is now built into the SSO configuration flow, giving you a clear, self-serve path to register and prove ownership of your corporate domain.
- OTP prompts skipped for verified domains: Users no longer encounter extra one-time password steps during post-login actions. SonarQube Cloud implicitly trusts identities authenticated by your IdP for verified domains.
- Fully self-serve: Domain-level trust settings are managed directly from your admin console — no need to contact support.
- Foundation for future policy enforcement: Completing domain verification today prepares your organization for upcoming controls that will govern identity and access policies across all users under your corporate domain.
Where to find it: Go to Administration > Authentication / SSO in your organization settings, and follow the Domain Verification step in the setup wizard.
For more details, see the documentation and the Community post.
May 05, 2026
Bulk import for GitLab projects is available
You can now bulk import projects from a GitLab group into SonarQube Cloud, letting you import multiple GitLab projects in a single step and giving your teams code quality and security coverage across multiple projects at once.
- Import at scale – bulk-import all existing projects within a GitLab group (including subgroups) instead of setting up each project individually.
- See a clear summary of imported projects and anything that needs attention before you finalize.
If you manage many GitLab groups, you can run bulk import per group to quickly cover your entire GitLab footprint.
We invite you to discover more here.
Get quick and insightful SonarQube Cloud updates delivered directly to your inbox
SonarQube Cloud product news shares the most important product updates and the latest helpful content, allowing you to get the most out of your SonarQube Cloud plan.