Announcement

SonarQube Server 2026.5 LTA:agentic AI, verified inside your perimeter

Your teams are shipping at agentic speed. The new SonarQube Server 2026.5 LTA is coming soon to verify every line of code before it ships, on infrastructure you manage yourself.

Why update?

smily

Build code confidence

lightning

Be ready for for the AC/DC

ai

Sonar’s agentic stack where you operate

What's in store for your engineering teams

Scale agentic AI without ceding code control

Self-managed infrastructure exists for a reason: local data residency, compliance, and control over what leaves your perimeter. Sending source code to an external service to verify AI-generated code undermines that control. Sonar's full agentic stack, Sonar Vortex, the SonarQube Remediation Agent, and the SonarQube Hunter Agent, will soon be available for purchase with SonarQube Server Enterprise and Data Center editions and runs entirely inside the infrastructure of your choice, including air-gapped and VPC-restricted environments. Your code never crosses the perimeter, and your agentic AI governance no longer depends on a cloud migration.

Cut AI coding costs at the source

Every file an AI agent has to explore to understand your codebase costs tokens, and every misaligned suggestion costs a retry. Sonar Vortex feeds AI coding agents context and constraints. Your project's security standards, architecture, and library policies are followed before agents generate a single line of code. Sonar Vortex then verifies each code change against Sonar's algorithmic analysis inside the agent's own loop. AI agents produce cleaner output on the first attempt instead of iterating against your standards after the fact, cutting token consumption by up to 36% while improving output quality where it originates without sacrificing speed.

Prevent architectural drift at agentic speed across your portfolio

AI agents solve the task in front of them without seeing the architecture around it, and that blindness compounds as agentic output scales across teams. Organization-wide architecture management automatically visualizes relationships across every project, applies reusable patterns organization-wide, and surfaces standalone directives for straightforward remediation. It is available in open beta at no additional cost with Enterprise and Data Center editions, giving every team the same structural guardrails instead of leaving architecture to institutional memory. It's early, so tell us what you find. Your feedback shapes where it goes next.

Make compliance a byproduct of development, not a separate project

Audit season should not require weeks of manual evidence gathering. New audit-ready compliance reports, including a MISRA C/C++ Compliance Report and a WCAG Accessibility Compliance Report, generate tamper-evident attestation artifacts automatically from analysis your teams already run. Expanded MISRA C coverage brings safety-critical C and C++ codebases together onto a single platform for both standards, so your compliance evidence accumulates continuously instead of arriving as a last-minute deliverable.

Frequently asked questions

Do I need to change my infrastructure to use the new agentic capabilities?

What license do I need to access the agentic stack?

Is organization-wide architecture management included in my current edition?

Will upgrading disrupt my existing pipelines or quality gates?

Where can I see the full list of changes since the 2026.1 LTA?

Verify at the speed your AI agents ship

The SonarQube Server 2026.5 LTA release is coming soon to bring agentic AI verification fully inside the perimeter you already control. When it ships, there's a whole lot more it includes too! So keep an eye out for it.