Cve management and checking code
Management risks Review collected by and hosted on G2.com.
Slow to trigger runs and need manual intervention Review collected by and hosted on G2.com.
Generated from real user reviews
Cve management and checking code
Management risks Review collected by and hosted on G2.com.
Slow to trigger runs and need manual intervention Review collected by and hosted on G2.com.
I like SonarQube because it quickly flags code quality and security issues, making it easier for me to keep the codebase clean, reliable, and maintainable over time. Review collected by and hosted on G2.com.
I don’t like that SonarQube can sometimes feel complicated to configure, and it can also generate too many warnings that still need manual review to sort through. Review collected by and hosted on G2.com.

I like SonarQube's integration with third-party tools, which makes it really convenient to use alongside other tools we have internally. It's also light to host, which is a big plus for us. The initial setup was fairly easy, with just a couple of properties to adjust, and those improved over time. Review collected by and hosted on G2.com.
I don't like the upgrades and Java versions decommissioning, which usually impact a lot of users using SonarQube. Review collected by and hosted on G2.com.

SonarQube makes it easy to maintain high code quality by automatically detecting bugs, vulnerabilities, and code smells. I like how it integrates with CI/CD pipelines and provides clear, actionable insights for developers. The detailed dashboards and quality gates help enforce coding standards across teams. Review collected by and hosted on G2.com.
The initial setup and configuration can be a bit complex, especially for new users. It also requires tuning to avoid too many false positives. For very large projects, performance can sometimes feel slower, and the UI could be more modern and intuitive. Review collected by and hosted on G2.com.
The ability to detect errors, combined with Quality Gates, is vital to our stability; it filters out defective code before it reaches production and helps mitigate serious operational risks. Review collected by and hosted on G2.com.
It consumes too much RAM, and it sometimes flags false positives on code patterns that are actually correct, which makes it quite tedious to use. Review collected by and hosted on G2.com.
I really like how SonarQube separates new code from older code. It helps me prioritize the newest findings first, especially since older findings aren’t always as critical in some cases. Review collected by and hosted on G2.com.
I wish there were more ways to group users and teams, and then automatically send them reports that include vulnerability details. I wish you can tweak false positives at a more granular level allowing you more options to exclude some findings but not the whole category. Review collected by and hosted on G2.com.
Integration within our existing CI/CD tooling, with AI capabilities available. Review collected by and hosted on G2.com.
Using the web interface, I prefer to manage everything through our existing workflow tools, so this works well for me because I don’t need to use it very often. Review collected by and hosted on G2.com.

SonarCloud is very easy to set up, and integrates nicely into your development platform.
It supports a large number of languages, rules, and can be configured to fit your needs.
Teams use it on a daily basis without needing to think of it.
It is also very intuitive and robust, so you will hardly need technical support; if you need to, the community website is the way to go for quick answers. Review collected by and hosted on G2.com.
The 2024 changes in pricing and product organization led to some hard discussions on pricing internally. The pricing is fair, but the price hike was hard to swallow by the management. Review collected by and hosted on G2.com.

I like how easy it is to spot issues before they hit production. SonarQube gives clear feedback and keeps our codebase clean and secure. Review collected by and hosted on G2.com.
The community edition is pretty difficult to upgrade. All the available documentation is vague. Review collected by and hosted on G2.com.

I love that it is really easy to use, it can be integrated with GitHub, and it can review a wide array of code languages Review collected by and hosted on G2.com.
It can be overwhelming when you get your first review Review collected by and hosted on G2.com.