RSS Amplifier

Blog

SonarSource Blog

SonarSource Blog

sonarsource.comSource feed ↗20 posts

Live Last read · last published · next check

Latest posts

Tokenomics of quality: switch sonar list issues to --format toon for measured token savings

See how sonar list issues with TOON reduces token usage while preserving data and comprehension for AI coding agents and automated workflows.

Bring your own hook: a 5-line PostToolUse template calling sonar analyze agentic

Set up a minimal SonarQube Agentic Analysis hook in Claude Code with five lines of Bash and understand how exit codes control feedback.

Claude Code hooks and how Sonar Vortex verifies AI code inside the loop

Learn how Claude Code hooks enforce deterministic AI guardrails and how Sonar Vortex verifies AI generated code inside the development loop.

Your secrets are leaking to AI coding agents (and how to stop it)

Learn how AI coding agents can expose secrets and how local detection helps keep credentials from reaching model providers and external logs.

Claude Opus 5: An evaluation review & metrics benchmarks

Learn what Claude Opus 5 performance metrics reveal about code quality security findings review effort and the impact of generating far more code.

Sonar joins the Open Secure AI Alliance to advance AI safety and security

Sonar joins the Open Secure AI Alliance to help strengthen AI code security through open source collaboration with NVIDIA and other industry leaders.

OpenAI GPT-5.6 Sol and Terra: An evaluation

Learn what changed in GPT 5.6 coding performance from correctness gains to new security and concurrency challenges in this detailed evaluation.

The return of Shai-Hulud: How SonarQube detects and contains the npm worm

Learn how the Shai-Hulud npm worm spreads and see how SonarQube detects malicious packages before they reach production and steal credentials.

Migrating to SonarQube Cloud just got a whole lot easier

Introducing the new Sonar Migration Tool to automate moving from SonarQube Server to SonarQube Cloud. Now migrating is easier than ever.

Why Sonar signed the Open Weights and American AI Leadership letter

Discover why Sonar signed the Open Weights and American AI Leadership letter and why openness and verification matter for trusted AI.

CLI vs. IDE: How to choose the best environment

Choose the AI coding environment that fits your style and use SonarQube to keep code quality, security, and reliability consistent everywhere.

Scaling AI-assisted development in US financial services without losing control

Learn how AI-assisted development helps US financial institutions deliver software faster while maintaining security, quality, and FFIEC-aligned controls.

Now available: SonarQube plugin for Antigravity

Discover the SonarQube plugin for Antigravity and verify AI generated code with trusted quality security and coverage checks in every session.

COBOL is back, and AI is writing it. Who's verifying the code?

As AI accelerates COBOL modernization, organizations face a new bottleneck. See why trusted verification is essential for every commit.

Escape from AppleScript: Even folder names can be user input

Learn how an AppleScript injection flaw in OpenInTerminal let crafted folder names execute arbitrary code and how safer APIs prevent similar attacks.

Introducing SonarQube Server 2026.4

Discover SonarQube Server 2026.4 with architecture management, faster scans and stronger verification for agent generated code.

SonarQube Cloud now supports GitHub Enterprise Cloud with data residency (GHE.com)

SonarQube Cloud now supports GitHub Enterprise Cloud with data residency (GHE.com). Bind your GHE.com org, bulk-import repos & verify code—no CI needed.

AI Assistant Development in Regulated Industries

Scale secure AI-assisted development in regulated industries. Learn how SonarQube and the AC/DC framework automate code verification and compliance.

Introducing SonarQube Hunter Agent(beta): Catch logic flaws, as you code.

Close the security logic gap with SonarQube Hunter Agent. Automate your whitebox code audits to find broken access control & business logic flaws instantly.

SonarQube CLI brings multilayered verification to agentic development

Learn how SonarQube CLI helps AI coding agents verify code, detect secrets, scan dependencies, and resolve issues from the terminal.