SonarQube

Home

Download
Start Free Trial

LTS Is More Secure

delivering secure code isn’t enough; you also need to deliver code securely

Delivering perfect code doesn’t mean much if it comes from a compromised pipeline. Securing your DevOps infrastructure is nearly as important as the code itself.

LTS 8.9

securing your instance

We don’t care only about the security of your code, we also care about the security of your SonarQube environment. From SonarQube 8.9 LTS, operating SonarQube is more secure than ever, with simple but effective new safeguards.

Download Now -->
LTS 8.9

Forcing administrators

to change the default SonarQube admin credentials – to make adherence to best practices routine.

Authenticated access

as the default – to help you keep private code private.

Limited plugin access

to core functionality and restricted library loading – to prevent 3rd-party plugins from tampering with your installation.

Additional controls

in the plugin Marketplace (as a gentle reminder that you use community plugins at your own risk) - to stay mindful about the risks you accept.

Cure53

a pen-tested, secure part of your pipeline

A routine part of delivery is periodic penetration testing. In addition to hardening SonarQube itself, we’ve also hardened our own build pipeline so you can be sure we’re delivering SonarQube to you securely. You can read more about what our penetration test, Cure53, had to say about SonarQube 8.9 LTS.

Read More -->

In Cure53’s expert opinion, this project confirmed a very solid security premise at SonarSource… [SonarQube] is currently well protected against a broad number of web application attack vectors.


One can argue that the outcome highlights the development team’s commitment to maintaining security features with due diligence and adherence to best practices. Despite extensive deep-dives and exemplary coverage toward a plethora of application features by the Cure53 testers, no serious issues were detected.

Penetration Testing @ Cure53

Background image of bits of code connecting to each other

get started SonarQube 8.9 LTS

Download Now -->
  • Follow SonarSource on Twitter
  • Follow SonarSource on Linkedin

© 2008-2023, SonarSource S.A, Switzerland. All content is copyright protected. SONAR, SONARSOURCE, SONARLINT, SONARQUBE and SONARCLOUD are trademarks of SonarSource SA. All other trademarks and copyrights are the property of their respective owners. All rights are expressly reserved.