CIOPages
DirectoryCybersecurityApplication SecuritySonarQube

SonarQube

Open Source

About SonarQube

SonarQube provides automated code review, static code analysis, and static application security testing. It includes quality metrics tracking, security analysis, and AI-powered code remediation.

Key Capabilities

  • Automated static code analysis and code review
  • Real-time security vulnerability detection
  • AI code quality validation and verification
  • Secrets detection and software composition analysis
  • Seamless CI/CD and IDE integration

Integrations

GitHubBitbucketAzure DevOps

Related Buyer Guides

Independent evaluation frameworks for this category.

API Security Platforms
The API is now the primary attack surface, and a WAF pointed at it isn't API security. Evaluate Salt, Akamai (Noname), Imperva, F5, Traceable, Wallarm, Cequence, and Data Theorem on whether they actually discover your shadow APIs and catch BOLA and business-logic abuse at runtime — not just sign endpoints off as “protected.”
Attack Surface Management (ASM / CTEM)
Evaluate Wiz, CrowdStrike Falcon Surface, Microsoft Defender EASM, Cortex Xpanse, Censys, CyCognito, Tenable, and runZero across EASM, CAASM, and platform-embedded camps — judged on discovery accuracy and how cleanly the surface feeds prioritization, not how many assets it claims to find.
Cloud Access Security Broker (CASB)
Evaluate Netskope, Microsoft Defender for Cloud Apps, Zscaler, and Palo Alto for SaaS security, shadow IT discovery, and data protection.

This profile was compiled by CIOPages from public sources with AI assistance, and may be incomplete or out of date. It is informational only and not an endorsement. Represent this vendor? Claim this listing or .

Quick Facts

www.sonarqube.org
CategoryCybersecurity
SubcategoryApplication Security
PricingSubscription
DeploymentSaaS, On-Premises
Target SizeEnterprise