Ross ROSS = Recommend OSS · open-source software intelligence for agents

SonarQube

Continuous Inspection observed · 2026-08-28

github.com/SonarSource/sonarqube · homepage · Java · LGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

98/100

  • Activity 99
  • Release rhythm 96
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 28
  • age_days: 5719
  • days_rel: 28
  • days_push: 7
  • n_releases_24m: 24

Full methodology

Adoption not part of the score

10928 stars · 2223 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

SonarQube is a continuous code inspection platform that performs static analysis to track code quality, security vulnerabilities, and technical debt across codebases. It integrates with CI/CD pipelines and Git platforms to enforce Quality Gates and review issues on pull requests.

Use cases

  • run static analysis on my codebase to find bugs and vulnerabilities
  • enforce quality gates in my CI/CD pipeline before merging pull requests
  • track technical debt and code quality metrics over time
  • detect security hotspots and OWASP vulnerabilities in my code
  • decorate pull requests with code quality results on GitHub or GitLab
  • verify AI-generated code quality automatically
  • self-host a code quality server for my organization

When to choose

  • you need continuous, multi-language static analysis integrated into your CI/CD workflow
  • you want quality gates that fail builds when new code introduces issues
  • you need a self-hosted or SaaS platform with dashboards, portfolios, and enterprise governance
  • you want pull request decoration and security scanning across GitHub, GitLab, Bitbucket, or Azure DevOps

When to avoid

  • you only need a lightweight linter or formatter inside your editor without a server
  • you want a fully community-driven project that accepts outside feature contributions
  • you need advanced languages, security reports, or SSO that require paid editions

Facets

application · maturity stable

static-site-generator security code-review ci-cd developer-tools monitoring developer-tools security testing self-hosted cloud jvm static-analysis code-quality quality-gates sonarqube technical-debt pull-request-analysis clean-code devops docker web-server

10 sources

Member repositories

RepositoryRoleHealth v2
SonarSource/sonarqubemain98
SonarSource/sonar-javaplugin100

For agents

markdown · JSON · MCP: product_card(name="SonarSource/sonarqube")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem