SonarQube for IDE
Best practices for shifting left with SonarQube for IDE
This course outlines best practices for shifting left by using SonarQube for IDE, which allows you to analyze your code as it's being written.
Transcript
Hi! I'm Mahwish Riaz-Jamil, I'm a technical advisor at Sonar, and today I'll be speaking to you about shifting left through SonarQube for IDE. As a developer, you’re likely familiar with the concept of shift left. Shifting left means moving to an earlier stage in your software development lifecycle to find and fix issues in your code. SonarQube for IDE allows you to shift left by analyzing code directly in your IDE. This extension gives you real-time feedback on human-written or AI-generated code, so you can fix issues on the fly. This prevents issues from being released into production and therefore reduces costly rework for you down the line. SonarQube for IDE can function as a standalone extension, but we do recommend you use it in Connected Mode. This binds your IDE with your SonarQube Server or Cloud instance, and gives you access to advanced features such as synchronized quality profiles, advanced security and bug detection rules, custom secrets detection, and any automatic analyzer updates. When setting up Connected Mode, be sure to share the project binding in your project repository so it won’t need to be configured again later by other developers working on the same project. If you’re using SonarQube for local analysis and not in Connected Mode, we recommend you to customize the settings and rulesets to meet your code standards. Configure SonarQube for IDE to focus on new code. This allows you to control the number of issues you can see in your findings and reduces noise in your IDE. When new issues are flagged in the IDE, you should mark their status as Accepted or False positive, and add a reason as a comment. The next time you run an analysis, the issue status will be automatically updated in SonarQube. Leverage Sonar’s Quick Fix feature. This allows you to resolve issues with one click. Using this, Sonar automatically edits the code for you to comply with the rule. We also recommend you to use AI CodeFix to resolve issues in your IDE. This feature needs to be enabled by your SonarQube administrator. You can also review taint security issues in the IDE using the dedicated Taint Vulnerabilities view. This is usually more convenient for developers that are way more comfortable with code navigation in the IDE. If you’re unsure of how to fix an issue, view the full rule description in the IDE. If your organization has purchased SonarQube Advanced Security, you can also find and fix dependency risks directly in your IDE. See our related courses on SonarQube Advanced Security to learn more. Lastly, leverage Sonar MCP Server to find and fix issues in your IDE using natural language.