Self-hosted editions for automated code review
Priced per instance, per year, based on your lines of code.
Developer
Essential capabilities for small teams
Includes:
- Recommended for 100K+ lines of code
- 34 languages & frameworks
- Autodetect AI-generated code
- AI Code Assurance
- Advanced bug detection
- Secrets detection
Enterprise
Deeper insights and enterprise performance
Developer Edition, plus:
- Recommended for 1M+ lines of code
- 40 total languages & frameworks
- Commercial support available
- 24/7 white glove support available
- AI CodeFix
- MISRA C++:2023 compliance
- Detailed project health insights
Data Center
Performance, high availability & scalability
Enterprise Edition, plus:
- Recommended for 20M+ lines of code
- Autoscaling based on demand
- High performance for distributed teams
Feature comparison
Compare SonarQube Server plans
| Capability | Developer | Data Center | |
|---|---|---|---|
| Recommended lines of code | 100K or above | 1M or above | 20M or above |
| DevOps platform integrationSupports one integration each for the following DevOps platforms• GitHub • GitLab • Bitbucket • Azure DevOps | |||
| IDE synchronization with SonarQube for IDESupports the following IDEs• VS Code • Visual Studio • IntelliJ • Eclipse • Cursor • Windsurf | |||
| Detect issues in AI generated code | |||
| Combine third-party tool results with SARIF reports | |||
| AutoConfig for C and C++ projects | |||
| Autoprovision users and groups from GitHub and GitLab | |||
| Automatically sync permissions with GitHub and GitLab | |||
| Integrate with unlimited numbers of DevOps platformsSupports the following• GitHub Actions • GitLab CI/CD • Bitbucket Pipelines • Azure Pipelines • Jenkins • Codemagic | — | ||
| Consolidate projects into a central instance | — | ||
| Pull request decoration and guided setup for monorepos | — | ||
| Configure testing and staging environments with additional licenses | — | ||
| Automatically provision users and groups through SCIM with Okta and Azure AD | — | ||
| Set rule priority to uphold your coding standards | — | ||
| Component redundancy | — | — | |
| Data resiliency | — | — | |
| Horizontal scalability | — | — | |
| High performance under extreme load | — | — | |
| Autoscale in a Kubernetes cluster | — | — | |
| Languages and frameworksDeveloper EditionJava · C# · JavaScript · TypeScript · Kotlin · CloudFormation · Terraform · Docker · Kubernetes/Helm · Ruby · Go · Scala · Flex · Python · PHP · Rust · HTML · Shell · CSS · XML · VB.NET · Azure Resource Manager/Bicep · Ansible · C · C++ · Dart/Flutter · Obj-C · Swift · ABAP · T-SQL · PL/SQL · JSON · YAML · GitHub ActionsEnterprise & Data Center EditionsAll Developer Edition languages plus APEX · COBOL · JCL · PL/I · RPG · VB6 | 34 | 40 | 40 |
| Detect security, reliability, and maintainability issues | |||
| Detect issues in AI generated code | |||
| Auto-trigger code reviews and block substandard code in CI/CD pipelinesSupports the following• GitHub Actions • GitLab CI/CD • Bitbucket Pipelines • Azure Pipelines • Jenkins • Codemagic | |||
| Automatically analyze feature and maintenance branches and pull requests | |||
| Display quality gate pass/fail status in DevOps pull request commentsVisible in• GitHub pull request • GitLab merge request • Bitbucket pull request • Azure DevOps pull request | |||
| Analyze with parallel processing to improve performance for large teams | — | ||
| Quality profiles | |||
| Quality gates | |||
| Discover issues in code that cause bugs | |||
| Track and resolve technical debt | |||
| Find advanced dataflow bugs | |||
| Show percentage of test case coverage for improved code quality | |||
| MISRA C++:2023 compliance | — | ||
| Discover issues in code that cause hotspots and security vulnerabilities | |||
| Industry leading secrets detectionDetects 400+ secrets patterns with 340+ rules, including coverage of 248 public, private, commercial, and enterprise cloud services. | |||
| Taint analysis with cross-function and cross-file trackingSupported languages• Java • C# • JavaScript • TypeScript • Python • PHP • Kotlin • Go • VB.NET | |||
| Display security vulnerabilities in GitHub and GitLab | |||
| Custom configure the security engine for more powerful taint analysis | — | ||
| Create custom rules to detect private secret patterns | — | ||
| SCA and Advanced SAST with Advanced Security | — | *Additional subscription | *Additional subscription |
| Monitor code quality metrics and history of activity | |||
| Collect multiple projects together as an application for a single view | |||
| Create custom rules to detect private secret patterns | — | ||
| Aggregate projects and applications into a portfolio | — | ||
| Project, application, and executive portfolio reports | — | ||
| Security reports for common security standardsSupported standards• PCI DSS • OWASP Top 10 • OWASP ASVS • OWASP Mobile Top 10 • CWE Top 25 • STIG • CASA • OWASP Top 10 for LLM Application • OWASP MASVS | — | ||
| Regulatory reports and audit logs | — | ||
| AI CodeFix | — | ||
| AI Code AssuranceEnsures AI generated code is fully understood and verified before reaching production. | |||
| MCP Server | |||
| Standard commercial support availableFor detailed pricing, contact sales. | |||
| 24/7 premium commercial support availableFor detailed pricing, contact sales. | — | ||
How are the plans licensed?
Developer Edition, Enterprise Edition, and Data Center Edition are priced per instance per year and based on your lines of code (LOC). An instance is an installation of SonarQube Server. You pay per instance for a maximum number of LOC to be analyzed.
Get in touch with sales for pricing specific to your needs.
Is support included in my SonarQube Server plan?
Standard commercial support is included in your Enterprise Edition or Data Center Edition plan starting at 30M lines of code and above. For other plans, standard commercial support is available for an additional cost. See the benefits of commercial support, including details on how to purchase. You are also always welcome to ask questions in our vibrant and active Sonar Community.
How are my Lines of Code (LOC) calculated?
LOC is calculated by summing up the LOC of each project analyzed in your SonarQube Server instance. Blank lines, comments, and lines of test code are never included in the count. The LOC of a project is counted as the lines in the largest branch of the project. If you have set up branch analysis for your project, the LOC used for a project are the ones found during the most recent analysis of the project with the largest branch or pull request. More details can be found on the Lines of Code page in our docs.
What happens if my instance gets close to or reaches the limit of LOCs?
If you are getting close to the threshold, you will be notified to either upgrade your plan or reduce the number of LOCs in your projects. If you reach your limit, you will receive an error message and the SonarQube Server instance will reject any new analysis whose total lines of code exceed the limit defined by your license. However, SonarQube Server will retain basic functionality such as saving configuration changes and allowing project browsing.
Which programming languages does SonarQube Server analyze?
SonarQube Server Developer Edition covers the following languages and frameworks: Java, C#, C, C++, Objective-C, Dart/Flutter, Python, JavaScript, TypeScript, Kotlin, CloudFormation, Terraform, Azure Resource Manager, Docker, Kubernetes/Helm Charts, Ruby, Go, Scala, Flex, PHP, HTML, CSS, XML, VB.NET, Swift, ABAP, T-SQL, and PL/SQL.
Enterprise Edition and Data Center Edition additionally cover the following languages: Apex, COBOL, JCL, PL/I, RPG, and VB6.
How do I get an evaluation license and do I need to pay now?
You can request an evaluation license by clicking on any of the trial buttons above for the edition you are interested in. Once you submit your request, our sales representative will contact you to activate the trial and discuss options once your trial is complete. No payment is required to request or activate a free trial license.
Why upgrade from the Community Build to SonarQube Server Enterprise Edition?
SonarQube Community Build is a powerful, free, and open-source tool. However, upgrading to Enterprise Edition unlocks exclusive support, more powerful security, efficiency, and scalability, along with advanced features that will take your code quality to the next level. Read more about the benefits of upgrading.
What if my question hasn't been answered?
You can contact our team.