# SonarQube

Continuous Inspection

Repository: https://github.com/SonarSource/sonarqube
Canonical: https://ross.abutalabs.com/products/sonarqube
Homepage: http://www.sonarqube.org
Language: Java
License: LGPL-3.0
License Family: copyleft
Topics: sonarqube, code-quality, static-analysis
Last push: 2026-08-26T20:48:29+00:00
Link (homepage): http://www.sonarqube.org
Link (site_page): https://www.sonarsource.com/integrations/github
Link (site_page): https://www.sonarsource.com/integrations/bitbucket
Link (site_page): https://www.sonarsource.com/integrations/azure
Link (site_page): https://www.sonarsource.com/integrations/gitlab

## Health v2 (maintenance only)
Score: 98/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 96, longevity 100
- inputs: {"age_days": 5719, "days_push": 7, "days_rel": 28, "gap_med": 28, "n_releases_24m": 24}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 10928, forks 2223 (observed 2026-08-28T04:10:44.718517+00:00)

## What it is
SonarQube is a continuous code inspection platform that performs static analysis to track code quality, security vulnerabilities, and technical debt across codebases. It integrates with CI/CD pipelines and Git platforms to enforce Quality Gates and review issues on pull requests.

## Use cases
- run static analysis on my codebase to find bugs and vulnerabilities
- enforce quality gates in my CI/CD pipeline before merging pull requests
- track technical debt and code quality metrics over time
- detect security hotspots and OWASP vulnerabilities in my code
- decorate pull requests with code quality results on GitHub or GitLab
- verify AI-generated code quality automatically
- self-host a code quality server for my organization

## When to choose
- you need continuous, multi-language static analysis integrated into your CI/CD workflow
- you want quality gates that fail builds when new code introduces issues
- you need a self-hosted or SaaS platform with dashboards, portfolios, and enterprise governance
- you want pull request decoration and security scanning across GitHub, GitLab, Bitbucket, or Azure DevOps

## When to avoid
- you only need a lightweight linter or formatter inside your editor without a server
- you want a fully community-driven project that accepts outside feature contributions
- you need advanced languages, security reports, or SSO that require paid editions

## Facets
- artifact type: application
- maturity: stable
- function: static-site-generator, security, code-review, ci-cd, developer-tools, monitoring
- domain: developer-tools, security, testing
- platform: self-hosted, cloud, jvm
- tags: static-analysis, code-quality, quality-gates, sonarqube, technical-debt, pull-request-analysis, clean-code, devops, docker, web-server

## Member repositories
- SonarSource/sonarqube (main) score 98
- SonarSource/sonar-java (plugin) score 100

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:44.718517+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:17:20.046776+00:00, confidence not recorded.
  - readme: https://github.com/SonarSource/sonarqube (fetched 2026-08-28T04:10:44.718517+00:00, sha 6f31e9825002)
  - homepage: http://www.sonarqube.org (fetched 2026-08-29T08:16:25.179370+00:00, sha 4cc350d371f0)
  - site_page: https://www.sonarsource.com/company/about (fetched 2026-08-29T08:16:25.199796+00:00, sha 8c18d35c8428)
  - site_page: https://docs.sonarsource.com/ (fetched 2026-08-29T08:16:25.201600+00:00, sha a2d0882f2520)
  - site_page: https://www.sonarsource.com/integrations/github (fetched 2026-08-29T08:16:25.189667+00:00, sha 3e3309df9603)
  - site_page: https://www.sonarsource.com/integrations/bitbucket (fetched 2026-08-29T08:16:25.191910+00:00, sha 6f2d83d365e3)
  - site_page: https://www.sonarsource.com/integrations/azure (fetched 2026-08-29T08:16:25.193818+00:00, sha 76632ffb3997)
  - site_page: https://www.sonarsource.com/integrations/gitlab (fetched 2026-08-29T08:16:25.195765+00:00, sha 3b51e6d90981)
  - site_page: https://www.sonarsource.com/integrations/overview (fetched 2026-08-29T08:16:25.198150+00:00, sha 461c039cc927)
  - site_page: https://www.sonarsource.com/plans-and-pricing (fetched 2026-08-29T08:16:25.203932+00:00, sha 718dcbe47ebe)
- Data as of 2026-08-30T08:39:29.467469+00:00.
