SonarQube Server 2026.5 LTA:agentic AI, verified inside your perimeter
Your teams are shipping at agentic speed. The new SonarQube Server 2026.5 LTA is coming soon to verify every line of code before it ships, on infrastructure you manage yourself.
Why update?
Build code confidence
Your teams already build with Claude Code, Codex, Cursor, and GitHub Copilot. Getting agents to write code is easy. Trusting it is not. The same model that wrote the code can't catch what it got wrong.
Be ready for for the AC/DC
Since the 2026.1 LTA, SonarQube Server has become the independent verification layer for agentic development, and the backbone of Sonar's Agent Centric Development Cycle (AC/DC). It guides your agents with your standards, verifies every change against one consistent standard, and solves what it finds. Any tool. Any model. One standard.
Sonar’s agentic stack where you operate
The soon-to-be-released 2026.5 LTA completes it. Sonar's full agentic stack will be available on self-managed SonarQube Server in addition to SonarQube Cloud, so you adopt agentic coding at full speed and keep control of your code.
What's in store for your engineering teams
Scale agentic AI without ceding code control
Self-managed infrastructure exists for a reason: local data residency, compliance, and control over what leaves your perimeter. Sending source code to an external service to verify AI-generated code undermines that control. Sonar's full agentic stack, Sonar Vortex, the SonarQube Remediation Agent, and the SonarQube Hunter Agent, will soon be available for purchase with SonarQube Server Enterprise and Data Center editions and runs entirely inside the infrastructure of your choice, including air-gapped and VPC-restricted environments. Your code never crosses the perimeter, and your agentic AI governance no longer depends on a cloud migration.
Cut AI coding costs at the source
Every file an AI agent has to explore to understand your codebase costs tokens, and every misaligned suggestion costs a retry. Sonar Vortex feeds AI coding agents context and constraints. Your project's security standards, architecture, and library policies are followed before agents generate a single line of code. Sonar Vortex then verifies each code change against Sonar's algorithmic analysis inside the agent's own loop. AI agents produce cleaner output on the first attempt instead of iterating against your standards after the fact, cutting token consumption by up to 36% while improving output quality where it originates without sacrificing speed.
Prevent architectural drift at agentic speed across your portfolio
AI agents solve the task in front of them without seeing the architecture around it, and that blindness compounds as agentic output scales across teams. Organization-wide architecture management automatically visualizes relationships across every project, applies reusable patterns organization-wide, and surfaces standalone directives for straightforward remediation. It is available in open beta at no additional cost with Enterprise and Data Center editions, giving every team the same structural guardrails instead of leaving architecture to institutional memory. It's early, so tell us what you find. Your feedback shapes where it goes next.
Make compliance a byproduct of development, not a separate project
Audit season should not require weeks of manual evidence gathering. New audit-ready compliance reports, including a MISRA C/C++ Compliance Report and a WCAG Accessibility Compliance Report, generate tamper-evident attestation artifacts automatically from analysis your teams already run. Expanded MISRA C coverage brings safety-critical C and C++ codebases together onto a single platform for both standards, so your compliance evidence accumulates continuously instead of arriving as a last-minute deliverable.
Do I need to change my infrastructure to use the new agentic capabilities?
No. Sonar Vortex, the SonarQube Remediation Agent, and the SonarQube Hunter Agent all run inside the infrastructure you already operate, including air-gapped and VPC-restricted environments. Deployment does not require sending code to an external service.
What license do I need to access the agentic stack?
Sonar Vortex, the SonarQube Remediation Agent, and the SonarQube Hunter Agent are available for purchase with a SonarQube Server Enterprise or Data Center license.
Is organization-wide architecture management included in my current edition?
It is available in open beta at no additional cost for Enterprise and Data Center editions. Single-project architecture management has been available in SonarQube Server since version 2026.4.
Will upgrading disrupt my existing pipelines or quality gates?
No. The 2026.5 LTA builds on the same deterministic quality gates and CI/CD integrations your teams already rely on. New capabilities, including the compliance reports and architecture management, extend your existing workflow rather than replacing it.
Where can I see the full list of changes since the 2026.1 LTA?
The complete release notes cover every capability shipped between the 2026.1 and 2026.5 LTAs, including expanded language support, reachability analysis for software composition analysis, and native AI connectivity. All the details will be available on the day it is released.
Verify at the speed your AI agents ship
The SonarQube Server 2026.5 LTA release is coming soon to bring agentic AI verification fully inside the perimeter you already control. When it ships, there's a whole lot more it includes too! So keep an eye out for it.