SO

SonarQube

Continuous code quality and security inspection

Developer Tools & Git ★ 10.9k stars Medium setup LGPL-3.0

SonarQube is a platform for continuous inspection of code quality and security, detecting bugs, vulnerabilities, and code smells. It targets development teams enforcing code standards. It is deployed via Docker with a database.

Key features

  • Detects bugs and vulnerabilities
  • Supports many languages
  • Quality gates for CI
  • Pull request decoration

Pros & cons

Strengths

  • Strong static analysis
  • Broad language coverage
  • CI-friendly quality gates

Trade-offs

  • Heavy memory requirements
  • Best features in paid editions

SonarQube replaces

Compare SonarQube

31 head-to-head comparisons.

Similar developer tools & git apps