For over a decade, SonarQube has been a trusted name in the developer community, renowned for its industry-leading code quality analysis. But did you know that SonarQube has also been simultaneously investing in providing developers and security professionals with robust security analysis? From Static Application Security Testing (SAST) and taint analysis to Infrastructure as Code (IaC) scanning and secrets detection, SonarQube has added a broad portfolio of code security capabilities to help teams secure their first-party and AI-generated code.
Today, we’re excited to announce SonarQube Advanced Security, a major enhancement to SonarQube’s existing code quality and code security capabilities. SonarQube Advanced Security will include Software Composition Analysis (SCA) and advanced Static Application Security Testing (SAST) and will be available to all SonarQube customers. This new offering not only builds on SonarQube’s existing core security capability but also extends its reach to include analysis of first-party, third-party open source, and AI-generated code. With SonarQube Advanced Security, Sonar now provides one integrated code quality and code security analysis solution for all your code, based on the same developer-first philosophy we’ve always had.
Modern software development moves fast, often driven by generating code with AI and building on top of third-party open source libraries. Unfortunately, this speed can leave security as an afterthought. Vulnerabilities are often discovered too late—right before release or even after deployment—leading to costly rework, production delays, and increased risks.
Traditional security tools exacerbate the problem by overwhelming teams with false positives, missing hidden risks in third-party open source code, and making compliance a tedious process. To address these challenges, development teams need a proactive, developer-first approach to security—one that integrates seamlessly into their workflows and ensures that all parts of their software’s code are secure.
SonarQube integrates into the developer workflow, from IDE to CI/CD, delivering integrated code quality and code security. It already provides robust core security features, including:
These capabilities focus on protecting first-party and AI-generated code, helping teams identify vulnerabilities early in the development process.
SonarQube Advanced Security extends this protection to third-party open source code, providing comprehensive security coverage for modern codebases.
Key features of Advanced Security include:
Software Composition Analysis (SCA)
Advanced SAST
With Advanced Security, SonarQube addresses these challenges head-on, offering a unified solution for:
SonarQube Advanced Security is the first step in integrating Sonar’s recent acquisition of Tidelift and its unique, proactive approach to improving third-party code quality and code security by working directly with open source maintainers. This allows to get verified insights about false positives, exploitability, and available workarounds for dependency risks.
Created by developers for developers, SonarQube helps teams supercharge their work with:
SonarQube ensures your entire codebase is secure, reliable, and maintainable—helping you build better, safer applications faster.
The General Availability (GA) of SonarQube Advanced Security is planned for the end of May 2025. It will be available as a new purchasable license for SonarQube Server Enterprise Edition 2025 Release 3 and shortly after that for SonarQube Cloud Enterprise.
Learn more about our security solution.
*** This is a Security Bloggers Network syndicated blog from Blog RSS feed authored by Johannes Dahse. Read the original post at: https://www.sonarsource.com/blog/announcing-sonarqube-advanced-security/