SonarQube Server has sharpened code verification release over release for organizations scaling agentic development and transitioning to agentic code factories. This article gathers together the major capabilities added since the 2026.1 LTA for your reference.
Self-managed agentic code verification 🆕 in 2026.5
SonarQube customers running self-managed infrastructure do so for a reason: data residency, compliance, and control. Since the 2026.1 LTA, Sonar's agentic capabilities have expanded steadily. With 2026.5, you get all of SonarQube’s full agentic capabilities self-deployed and under your control. Code never crosses the perimeter, AI governance never depends on a cloud migration, and confidence in code where you manage it remains high.
🆕 in 2026.5: Sonar Vortex makes your agent produce better code, faster, for fewer tokens. Vortex guides your agent to write code aligned with your standards, and prevents it from introducing new issues. You get PRs that are more secure, more reliable and more maintainable, easier to review, and ready to merge with confidence. Its semantic Code Navigation engine helps your agent explore code efficiently, reducing token consumption. Vortex feeds your agent your project's coding rules, architecture, and dependency policies before it writes a line of code, making it produce code that follows your conventions by default. It then verifies every code change inside the agent's own reasoning loop, including taint analysis for injection-class defects. Findings return in seconds, so the agent corrects its own work before a developer ever reviews it. Vortex can equip any agent through the SonarQube CLI or through the SonarQube MCP server. It is a consumption-based add-on metered by tool calls, giving engineering leaders a direct lever on AI spend by reducing token consumption by up to 30% while raising code quality at the source. It is available to purchase for SonarQube Server, deployable in air-gapped and VPC-restricted environments.
🆕 in 2026.5: SonarQube Remediation Agent can be purchased to bring automated, verified code repair to self-managed environments. A containerized Agent Core Engine runs inside your own Kubernetes or Docker containerized infrastructure, connects to your chosen cloud LLM endpoint using your own key, requires no public internet exposure and integrates into your GitHub, GitLab, or Azure DevOps platform. Every fix is analyzed and proven correct by SonarQube before it reaches a software developer.
🆕 in 2026.5: Hunter Agent, is now available for purchase with Server using your own Anthropic key. It runs as an on-demand background agent, uncovering the broken access control, business logic, and authentication flaws that pattern-based scanners are not built to catch, and it surfaces confirmed findings directly as SonarQube issues rather than in a separate tool or portal.
Sonar Vortex, SonarQube Remediation Agent, and SonarQube Hunter Agent are available for purchase with a SonarQube Server Enterprise or Data Center license.
A verification standard built for agentic code
AI coding agents introduce a risk profile generic quality gates were never designed to catch. The "Sonar way for Agentic AI" quality gate, introduced since the 2026.1 LTA, replaces the previous AI-code gate with a standard calibrated for agent-generated output: stricter on security, reliability, and new dependency risk, more permissive on the minor maintainability issues agents already handle well. It adds supply-chain risk conditions targeting the exact failure mode of agentic development: agents autonomously pulling in typosquatted, hallucinated, or vulnerable packages. In-product banners, badges, and tooltips promote the Agentic AI quality profiles for JavaScript/TypeScript, Python, and Java at the moment teams decide which standard to apply.
The result is a default posture for AI-generated code instead of a hand-tuned one. Developers stay unblocked from style nitpicks that do not matter. Leaders adopt agentic development without a corresponding spike in incidents.
Native AI connectivity and enterprise governance
AI assistants are only as good as the context they access. Since the 2026.1 LTA, the embedded SonarQube MCP Server integration ships a Model Context Protocol-compliant endpoint directly in the platform, delivered via streamable HTTP/SSE. Point Cursor, Claude Code, or GitHub Copilot at your SonarQube URL and it gets on-demand access to project issues and quality gates, with no self-hosted container to stand up or maintain. Security managers keep centralized control through a global kill-switch built on existing SonarQube user tokens, so there is no new authentication system to secure. Agentic capabilities are only as trustworthy as the LLM behind them.
🆕 NEW: Enterprise AI connectivity and governance gives administrators a central configuration surface to register their own LLM providers (AWS Bedrock, Azure Foundry, proxy and gateway configurations, or bring-your-own-key) and make them available across the SonarQube Remediation Agent, SonarQube AI CodeFix, and the Hunter Agent. The system enforces model compatibility per capability and flags mismatches automatically.
For organizations standardized on Azure, 🆕 NEW: APIM support for Azure OpenAI connectivity replaces static API-key authentication with Azure API Management, unblocking SonarQube AI CodeFix and other capabilities for security policies that prohibit long-lived keys.
Since the 2026.1 LTA, on-premises, model-agnostic SonarQube AI CodeFix has also delivered AI-generated fix suggestions inside your secure perimeter, so teams fix issues faster without sending code to public LLMS.
Architecture management on SonarQube Server
Architecture management is available in SonarQube Server since version 2026.4, at no additional cost in every commercial edition, closing the gap with SonarQube Cloud. It runs automatically with every scan for Java, C#, JavaScript, TypeScript, and Python, and delivers four capabilities: visualize your project’s current architecture, define an intended architecture that specifies which components may depend on one another, detect deviations and architectural flaws, and remediate issues through existing workflows integrated with quality profiles and quality gates. Architecture issues appear in the same issue list developers already use. There is no separate tool to learn, and no reliance on institutional memory or manual effort to catch, track, and remediate tangled dependencies, oversized components, or split responsibilities.
Software composition analysis and dependency risk
🆕 NEW: Reachability for SCA in Advanced Security determines whether your first-party code actually calls a vulnerable function in a dependency, not just whether the library is present. Initial support covers Java, Python, and C#, letting teams prioritize the most relevant risks in their applications, turning an unmanageable dependency backlog into a prioritized, defensible workload.
🆕 NEW: Dedicated alerts for new critical findings. Security alerts allow security teams to be notified of, find, and act on critical security findings. SonarQube immediately informs the relevant teams when known exploited vulnerabilities and malicious software is detected, across any branch of any project.
🆕 NEW: on-prem dependency analysis with cloud-sourced vulnerability intelligence. Analysis stays local, while the enriching vulnerability data is pulled from Sonar's continuously updated advisory database, closing the freshness gap on-prem deployments typically face.
The releases since the 2026.1 LTA built toward this. Unified dependency risk in security reports wove software composition analysis data directly into application and portfolio reports, in both the UI and exported PDFs, giving leaders one executive-ready view of first-party and third-party risk. Dependency Risks gained bulk actions for triage at scale: sending multiple risks to Jira, reassigning them, or changing status or severity at once. Plus, CycloneDX 1.6 VEX export compiles vulnerability status and engineering justifications into a compliance-ready document that accompanies your SBOMs as regulations like the Cyber Resilience Act raise the bar.
Deeper static analysis and programming language coverage
Verification has to reach every language your teams and agents write. Across releases since the 2026.1 LTA, coverage deepened substantially:
- 🆕 NEW: A dedicated taint analysis engine for C and C++ detects OS command injection (CWE-78), path injection (CWE-22), logging injection (CWE-117), and dynamic code execution injection (CWE-95), closing a gap that forced C/C++ teams to maintain a separate specialist SAST tool. Cross-translation-unit awareness (CTU) makes the C/C++ symbolic-execution engine understand function behavior across file boundaries instead of approximating it, eliminating false positives and false negatives that depended on where a function happened to be defined.
- 🆕 NEW: Native MuleSoft DataWeave support. MuleSoft Dataweave transforms your critical customer, financial, and billing data as it moves between platforms in your organization such as SAP ERP, Salesforce CRP, and your data warehouse. An issue with your Dataweave code risks entire business processes and workflows grinding to a halt. SonarQube now scans both DataWeave files and embedded Dataweave in XML files to find and prevent reliability and security issues before they ever hit production.
- 🆕 NEW: Native R language support. R is where your clinicians, actuaries, and market researchers do their statistics. It drives business and regulatory decisions, and today very little of it is scanned for security or reliability issues. SonarQube brings code quality rules, central
- 🆕 NEW: Rust analysis beyond Clippy adds a centralized governance layer that goes beyond the Rust linter. SonarQube integrates a curated set of Clippy rules alongside coverage for the most popular Rust crates as first-party rules, managed through quality profiles and quality gates instead of per-repository configuration. It correlates code coverage from LCOV or Cobertura, and detects duplication in Rust sources. SonarQube can import an existing Clippy JSON report as an additional aggregation and governance layer on top of it’s own scans. Rust comes under the same governed, gate-enforced pipeline as the rest of the estate,
- Python: Since the 2026.1 LTA, more than 70 issue types for collections, object-oriented patterns, and data structures catch memory bloat, variable leaks, and inheritance bugs before they trigger out-of-memory kills in containerized production. Advanced SAST for Python for the top 1K libraries and expanded issue types for FastAPI, Flask, and Django catch incorrect middleware ordering, accidental public network bindings, and sensitive data leaks in query parameters.
- Java: Full Java 25 LTS support, added since the 2026.1 LTA, delivers deep semantic analysis for Scoped Values, Flexible Constructor Bodies, and Module Imports, targeting the concurrency traps and uninitialized field bugs AI assistants introduce from stale preview APIs. Catch a notoriously hard-to-reproduce class of bug issue types for date and time.
- Automation and CI/CD: Since the 2026.1 LTA, 17 new issue types for Groovy in Jenkins pipelines, tested to a false-positive rate under five percent, prevent CI/CD outages from avoidable script defects. Native PowerShell support brings syntax highlighting, code metrics, and 20+ new issue types for Windows automation and GitHub Actions workflows. First-class Groovy coverage extends the same rigor to deployment scripts.
- More language coverage: In addition to MuleSoft DataWeave and R, support for Groovy and PowerShell were also added since the 2026.1 LTA, 40 new Ruby issue types we added alongside a 54% faster Ruby scanner, plus Gosu opens SonarQube to Guidewire-based insurance applications, and enhanced Apex analysis brings Salesforce development onto the same platform, both at a false-positive rate below five percent.
Compliance for safety-critical and a11y applications
🆕 NEW: Expanded MISRA C automated MISRA C:2012 coverage has been updated to over 38.4%, delivered on the same terms as MISRA C++:2023 compliance, available in Enterprise Edition and above. C accounts for up to 80% of functional-safety development in many organizations, and teams that must comply with both MISRA C and MISRA C++ need a tool to cover both. With this release, SonarQube Server moves towards a viable single platform for both standards.
🆕 NEW: The MISRA C/C++ Compliance Report generates audit-ready, tamper-evident reports aligned to the MISRA Compliance framework, turning existing analysis into a downloadable attestation artifact for auditors and regulators.
🆕 NEW: The WCAG Accessibility Compliance Report shows where code contravenes WCAG 2.1 AA and WCAG 2.2 AA standards at the project, application, and portfolio level, helping organizations demonstrate conformance to accessibility regulations across the UK, US, and EU.
Plus a new EU CRA compliance report added since the last 2026.1 LTA gives regulated organizations the attestation they need to pass strict audits.
Faster analysis where it helps most
Since the 2026.1 LTA, two performance improvements have targeted the codebases where analysis time was a genuine bottleneck. A 30% improvement in pull request analysis performance applies across the board as the taint analyzer becomes compatible with Sonar's advanced analysis design. More significantly, incremental analysis in the Taint Engine now covers both Java and C#: some large Java projects dropped from roughly 20 minutes to under a minute, a reduction of up to 90%, with no configuration changes and no reduction in security coverage.
Security workflow consolidation
Sonar is unifying two triage models into one coherent security signal. Since the 2026.1 LTA, Security Hotspots have begun their deprecation into standard Security Issues, with deprecation notices on the Hotspots and Measures pages, deprecated APIs and Plugin API elements, and a documented removal timeline, giving teams building against /api/hotspots advance notice.
🆕 NEW: Security model simplification delivers the transition through a deliberately non-disruptive path. An admin-triggered, idempotent migration API converts hotspot findings into vulnerabilities, preserving history, assignees, comments, and timestamps, and tagging each migrated issue "former-hotspot" for traceability. Organizations can pilot it on a single project before rolling out instance-wide.
🆕 NEW: Secrets masking and redaction closes a related exposure gap. Detected secrets are now masked and redacted by default. When SonarQube finds a hardcoded credential, it no longer exposes their plain-text value on screen or in analysis results, minimizing the blast radius of a leak instead of amplifying it.
Structured issue resolution, added since the 2026.1 LTA, replaced the blind, all-or-nothing NOSONAR comment with sonar-resolve, which requires a specific issue reference and resolution status directly in the code and syncs with the SonarQube UI. Compliance teams get full auditability (critical for meeting security standards and safety standards like MISRA C++:2023) without slowing developers down.
Enterprise administration and governance visibility
Governance has to be provable, not assumed. The quality gate adherence dashboard, introduced since the 2026.1 LTA, shows how often main branch releases pass versus fail the gate over a selectable window and flags "risky releases" promoted despite a failing gate, turning a values statement into a metric leadership can act on.
🆕 NEW: Customizable portfolio dashboards bring Server to parity with SonarQube Cloud, a capability not available in the 2026.1 LTA. A new Dashboards section provides a dedicated overview page for both portfolios and individual projects, with a built-in Portfolio and Project Health view, plus custom dashboards built from a widget library (metric counts, rating badges, pie and donut charts, trend lines, and top-five lists), with drill-down from portfolio to project and new measures including issue density, issues closed, and mean time to resolve issues and dependency risks.
🆕 NEW: The project coverage dashboard gives administrators a unified view of DevOps platform bindings, repository import status, and scan coverage on the instance. It shows which repositories are not yet imported or analyzed, with next steps from the same page.
Administration is quieter since the 2026.1 LTA. Optimized GitLab authentication and provisioning delivers faster JIT logins, cleaner logs, native mapping for GitLab's "Planner" role, and an "Allow all groups" option that bypasses the 4,000-character allowlist limit, all while preserving a secure default. Standard alerts for performance issues put configurable thresholds directly in the UI for the 96% of customers running without third-party monitoring. GitHub App Manifest setup cut integration setup from roughly 12 minutes to under two through a guided one-click flow. And automatic license refresh polls the license server every 12 hours, so new capabilities and expanded tier limits activate the moment a contract updates.
Developer experience
The tool cannot get in the way of the team using it. Since the 2026.1 LTA, a modernized workspace replaced the horizontal top menu with a vertical sidebar and context switcher, so developers, leads, and security professionals move between enterprises, portfolios, and projects without losing their place. SonarQube Server now also supports a new dark theme, with light, dark, and system-following modes, matching SonarQube Cloud and the dark-themed IDEs most developers already use.
