← DevOps tools
Security Scanning

SonarQube

A code quality platform that performs static application security testing and analyzes source code for bugs, vulnerabilities, code smells, and maintainability issues.

Why it exists.

It gives teams an automated quality and security gate before code reaches production.

Where it shines.

CI pipelines that need repeatable SAST, code-quality analysis, and pull-request reporting.

Where not to use it.

Do not treat a SAST score as a substitute for tests, review, threat modeling, or runtime security testing.

What it is made of.

  • Scanner
  • Rules
  • Quality profiles
  • Quality gates
  • Dashboard

How it works.

  1. A scanner analyzes the repository
  2. Rules classify findings
  3. The quality gate evaluates the result
  4. The pipeline reports or blocks the change
Questions and answers.Open the interview practice set for SonarQube.
Search