TrustRadius: an HG Insights company

SonarQube Server

Score9.5 out of 10

94 Reviews and Ratings

What is SonarQube Server?

SonarQube is a code quality and vulnerability solution for development teams that integrates with CI/CD pipelines to ensure the software you produce is secure, reliable, and maintainable.

Read more details.

Media

Screenshot of Application Status.
Screenshot of Portfolio Overview.
Screenshot of Taint Analysis.

1 / 3

Screenshot of Application Status.

Who Buys & Uses SonarQube Server

Code Quality is a Must!

Use Cases and Deployment Scope

We use SonarQube as part of the CICD pipeline running on Azure DevOps. Mostly .Net projects, and currently integrating with react native.

Pros

  • Ongoing code quality management
  • Increase developer skills.
  • Detect and report problems.
  • Scale with business needs
  • Optimize the quality
  • it is sustainable

Cons

  • The main “disadvantage” is code maintenance, being more expensive, it also takes more time, as well as producing “false positives”.

Most Important Features

  • Not conforming to code standards and conventions.
  • Duplicate code detection
  • Code file size.
  • Known security vulnerabilities.
  • Method size.
  • Cyclomatic complexity
  • Quality thresholds

Return on Investment

  • It gives the ability of the projects to evolve and be modified.
  • Keeping applications without bugs directly impacts the business. Giving continuity and maintaining productivity.

Alternatives Considered

Veracode

Other Software Used

Postman, Microsoft Visual Studio Code, Docker

SonarQube, you don't need to search more!

Use Cases and Deployment Scope

It's used as a quality gate for software development in the feature implementation, as well as a security barrier for bugs and good practices enforcer.

Pros

  • Easily setup quality gate for code analysis and tests.
  • Quick reports for vulnerabilities and good practices.
  • Easy setup of vulnerabilities level requirements.

Cons

  • Credentials manager, like managing users, groups and permissions is complex.
  • UI for code review can be improved, feels old but is useful nonetheless.
  • The ticket management system can also be improved.

Most Important Features

  • Code analisys.
  • Quality Gate.
  • Vulnerability check.

Return on Investment

  • It can save some money finding and alerting for severe vulnerabilities that can cost money if exploited.
  • Development team speed and communication with Security departments greatly improved.

Other Software Used

Microsoft To Do, Microsoft Visual Studio Code, Azure Machine Learning

Usability

SonarQube: Helper of Dev and organisation for better code quality and security practices.

Use Cases and Deployment Scope

As service based and product based organisation we are dealing with variety of products and projects so in order to maintain the Code Quality and also improve the coding structure by following the suggestions given by SonarQube Analysis and also checking the Code Coverage so we get to know that our code has fully passed through the Sonar Analysis. As a part of DevOps team we integrate SonarQube checks in CI(continuous integration part) so its an part of continuous code quality and we have also created custom Quality Gates in order to prevent the false or unimproved code from going into any environments.

Pros

  • Static Code Scanning
  • Code Coverage reports, User Friendly Dashboard
  • Integration with various tools in order to maintain code quality
  • Pre-built as well as Custom Quality Gates
  • Detect Bugs & Vulnerabilities, Review Security Hotspots, Track Code Smells
  • Also has many plugins to interact with

Cons

  • As in SonarQube community edition they should enable the after scanning report generation
  • other security reports like, vulnerability with preferred solution
  • Guide on scalability, backups, resiliency as well
  • small report type UI on other tools as well like Jenkins

Most Important Features

  • Integrations with CI/CD
  • Many plugins which we can integrate
  • Code coverage
  • Vulnerability, code smells, bugs
  • Custom as well prebuilt code quality gates
  • Support many current trends tech stacks languages
  • User management and project management
  • User friendly UI for seeing after scans report

Return on Investment

  • Helped the Developer in maintaining code quality and also better at coding structures
  • maintaining the security best practices before they are going to production
  • also resolved vulnerabilities and bugs on bases of best given suggestion

Other Software Used

Checkmarx, Amazon Elastic Kubernetes Service (EKS), Docker, GitLab, GitHub, Prometheus, Grafana Loki

Great Code Analysis Tool

Use Cases and Deployment Scope

It's always best to catch bugs and other code issues as soon as possible, especially when people from different teams and time zones touch the same code. While code reviews are obviously still necessary, SonarQube does filter the code seamlessly so that obvious issues are immediately detected and resolved. In some cases, there is customisation required for the general best practice rules and SonarQube accommodates this.

Pros

  • Static code analysis
  • Code best practices

Cons

  • Quality profile selection

Most Important Features

  • Static Code Analysis
  • Security Issue detection
  • Code Smells detection

Return on Investment

  • Positive Impact: Less bugs

SonarQube- A perfect QC for Reviewers

Use Cases and Deployment Scope

We are a product based Company where we are using SonarQube to keep an eye on the Code quality of our all the projects. It really reduced the workload of the reviewers and helped a lot to improved our code quality and efficiency of the project. It helped us a lot where we can define our own set of rules in all the languages. It has helped us to identify the static code which reduced our deployment efforts.

Pros

  • You can set your own rules for almost all the languages
  • Most of the rules are already defined you just need to use them
  • It helps us on Security aspects too.
  • you can place a gate on Code coverage too.

Cons

  • UI part of reporting needs more improvement.
  • Simple tooltips can be there for the users to understand better instead of reading documents.
  • For report extraction in Excel or Pdf you need Enterprise version

Most Important Features

  • Easy Integration with DevOps tools
  • Very less efforts required for the project setup.
  • Dynamic rules setup in multiple languages.

Return on Investment

  • It helped by giving the valid reason and Explanation why the code is not passed.
  • Removal of static code helped us in the easy deployment
  • developers were acknowledged with the latest security and issues running around.

Other Software Used

GitHub, Redis™*, Gradle Build Tool (Open Source)