Tokenomics of quality: switch sonar list issues to --format toon for measured token savings
See how sonar list issues with TOON reduces token usage while preserving data and comprehension for AI coding agents and automated workflows.
SonarSource Blog
Live Last read · last published · next check
See how sonar list issues with TOON reduces token usage while preserving data and comprehension for AI coding agents and automated workflows.
Set up a minimal SonarQube Agentic Analysis hook in Claude Code with five lines of Bash and understand how exit codes control feedback.
Learn how Claude Code hooks enforce deterministic AI guardrails and how Sonar Vortex verifies AI generated code inside the development loop.

Learn how AI coding agents can expose secrets and how local detection helps keep credentials from reaching model providers and external logs.
Learn what Claude Opus 5 performance metrics reveal about code quality security findings review effort and the impact of generating far more code.
Sonar joins the Open Secure AI Alliance to help strengthen AI code security through open source collaboration with NVIDIA and other industry leaders.
Learn what changed in GPT 5.6 coding performance from correctness gains to new security and concurrency challenges in this detailed evaluation.

Learn how the Shai-Hulud npm worm spreads and see how SonarQube detects malicious packages before they reach production and steal credentials.
Introducing the new Sonar Migration Tool to automate moving from SonarQube Server to SonarQube Cloud. Now migrating is easier than ever.
Discover why Sonar signed the Open Weights and American AI Leadership letter and why openness and verification matter for trusted AI.
Choose the AI coding environment that fits your style and use SonarQube to keep code quality, security, and reliability consistent everywhere.
Learn how AI-assisted development helps US financial institutions deliver software faster while maintaining security, quality, and FFIEC-aligned controls.

Discover the SonarQube plugin for Antigravity and verify AI generated code with trusted quality security and coverage checks in every session.
As AI accelerates COBOL modernization, organizations face a new bottleneck. See why trusted verification is essential for every commit.

Learn how an AppleScript injection flaw in OpenInTerminal let crafted folder names execute arbitrary code and how safer APIs prevent similar attacks.
Discover SonarQube Server 2026.4 with architecture management, faster scans and stronger verification for agent generated code.
SonarQube Cloud now supports GitHub Enterprise Cloud with data residency (GHE.com). Bind your GHE.com org, bulk-import repos & verify code—no CI needed.
Scale secure AI-assisted development in regulated industries. Learn how SonarQube and the AC/DC framework automate code verification and compliance.
Close the security logic gap with SonarQube Hunter Agent. Automate your whitebox code audits to find broken access control & business logic flaws instantly.
Learn how SonarQube CLI helps AI coding agents verify code, detect secrets, scan dependencies, and resolve issues from the terminal.