Sonar's latest blog posts

Featured Post

The Coding Personalities of Leading LLMs

Make smarter AI adoption decisions with Sonar's latest report in The State of Code series. Explore the habits, blind spots, and archetypes of the top five LLMs to uncover the critical risks each brings to your codebase.

Read More
https://assets-eu-01.kc-usercontent.com:443/55017e37-262d-017b-afd6-daa9468cbc30/7f6e6498-f9d3-4c75-8cb2-16917f0d95c2/LLMs-coding-personalities_featured-blog%402x.webp
Image for SonarQube Server 2025 Release 3 Announcement
Blog post

SonarQube Server 2025 Release 3 Announcement

SonarQube Server 2025 Release 3 unifies your tooling for code quality and code security with GA for Advanced Security (SCA & advanced SAST), Kotlin SAST support, more secrets detection, end of Early Access for AI CodeFix, expanded compliance (MISRA, CWE, OWASP Mobile), enhanced language coverage (Rust, Java, PySpark) and extended architectural protection.

Read article >

Image for Advances in SonarQube's Bug Detection
Blog post

Advances in SonarQube's Bug Detection

At Sonar we strive to provide the tools to help you to create the highest quality code possible. One of the biggest quality challenges is to find the bugs related to how your application is executed. SonarQube's advanced bug detection does just that.

Read article >

Get new blogs delivered directly to your inbox!

Stay up-to-date with the latest Sonar content. Subscribe now to receive the latest blog articles.

I do not wish to receive promotional emails about upcoming SonarQube updates, new releases, news and events.

By submitting this form, you agree to the storing and processing of your personal data as described in the Privacy Policy and Cookie Policy. You can withdraw your consent by unsubscribing at any time.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Image for Sonar Named Leader in G2 Spring Report
Blog post

Sonar Named Leader in G2 Spring Report

We are excited to share that the G2 Spring 2025 reports were recently released, and once again, Sonar has been named the LEADER in Static Code Analysis!

Read article >

Image for 9 Steps to a Successful SonarQube Cloud Team Plan Trial
Blog post

9 Steps to a Successful SonarQube Cloud Team Plan Trial

To maximize the benefits of your SonarQube Cloud Team Plan trial, it's essential to approach your free 14 days with a clear plan. Discover helpful tips to learn more about the product and get familiar with SonarQube Cloud Team Plan capabilities.

Read article >

Image for Scripting Outside the Box: API Client Security Risks (2/2)
Blog post

Scripting Outside the Box: API Client Security Risks (2/2)

Continuing on API client security, we cover more sandbox bypasses, this time in Bruno and Hoppscotch, as well as JavaScript sandboxing best practices.

Read article >

Image for 7 Guidelines for Federal Agencies Adopting AI for Software Development
Blog post

7 Guidelines for Federal Agencies Adopting AI for Software Development

With the release of two new Artificial Intelligence (AI) policies, The White House has provided clear direction for federal agencies regarding how to embrace AI to improve efficiency, effectiveness, and overall service delivery.

Read article >

Image for Scripting Outside the Box: API Client Security Risks (1/2)
Blog post

Scripting Outside the Box: API Client Security Risks (1/2)

Discover hidden risks in API testing tools like Postman and Insomnia. We dive into scripting vulnerabilities and explore JavaScript sandbox security pitfalls.

Read article >

Image for Seven Habits of Highly Effective AI Coding
Blog post

Seven Habits of Highly Effective AI Coding

Massive codebases can hugely benefit from developers using AI coding tools, but they must be harnessed in a responsible way. Sonar CEO, Tariq Shaukat, shares what coding "habits" organizations should adopt.

Read article >

Image for Data in Danger: Detecting Cross-Site Scripting in Grafana
Blog post

Data in Danger: Detecting Cross-Site Scripting in Grafana

Learn how SonarQube detected a Cross-Site Scripting (XSS) vulnerability in Grafana, a popular open-source data observability platform.

Read article >

Image for Introducing support for Rust in SonarQube
Blog post

Introducing support for Rust in SonarQube

The popularity of the Rust programming language is growing. Rustaceans have been asking for SonarQube to support Rust and now it's here!

Read article >

Image for MISRA C++:2023 Compliance for Auto Safety and Reliability
Blog post

MISRA C++:2023 Compliance for Auto Safety and Reliability

MISRA coding guidelines are a standard for automotive and other safety critical systems. SonarQube helps C++ developers deliver MISRA C++:2023 compliant apps with MISRA Compliance Early Access available in SonarQube Server Enterprise and Data Center.

Read article >