Security Scanning
SonarQube
A code quality platform that performs static application security testing and analyzes source code for bugs, vulnerabilities, code smells, and maintainability issues.
Problem it solves
Why it exists.
It gives teams an automated quality and security gate before code reaches production.
Optimized for
Where it shines.
CI pipelines that need repeatable SAST, code-quality analysis, and pull-request reporting.
Use with care
Where not to use it.
Do not treat a SAST score as a substitute for tests, review, threat modeling, or runtime security testing.
Components
What it is made of.
- Scanner
- Rules
- Quality profiles
- Quality gates
- Dashboard
Process
How it works.
- A scanner analyzes the repository
- Rules classify findings
- The quality gate evaluates the result
- The pipeline reports or blocks the change