Titelbild von SonarSonar
Sonar

Sonar

Softwareentwicklung

Vernier, Geneva 42.029 Follower:innen

Trusted by 7M devs, Sonar is committed to enabling developers and organizations to build better code for better software

Info

Sonar is the trust and verification layer for AI code, and the industry standard for automated code review for 17+ years. Sonar delivers deterministic, repeatable, and actionable code verification at scale by integrating code quality and code security into a single platform. The company analyzes more than 750 billion lines of code daily to ensure software is secure, reliable, and maintainable. Sonar is rooted in the open source community and is trusted by 7M+ developers globally, including teams at Snowflake, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company. To learn more about Sonar, please visit: www.sonar.com

Website
https://sonarsource.com/
Branche
Softwareentwicklung
Größe
501–1.000 Beschäftigte
Hauptsitz
Vernier, Geneva
Art
Privatunternehmen
Gegründet
2008
Spezialgebiete
software quality, open source, code quality management, ALM, Continuous Inspection und Code Analysis

Produkte

Orte

Beschäftigte von Sonar

Updates

  • Sonar hat dies direkt geteilt

    "AI is going to make the boat bigger. It's going to create the need for more developers, not less." I sat down with Anirban Chatterjee, Product Marketing Lead at Sonar, at our AI Engineer booth to talk about verifying AI-generated code, and where developers fit as agents write more of it. His take is that as AI makes software development more accessible, more people start building. We'll write less source code line by line, but ship far more software, and the need for developers goes way up, not down. Thanks Anirban, this was a great conversation. Full episode in the comments!

  • Sonar hat dies direkt geteilt

    Most teams try to control AI token spend with usage caps and dashboards. They miss that the largest factor is the codebase the agent is working in. I got into the why with ComputerWeekly.com's Adrian Bridgwater. Agents go back to files when they're unsure. They re-read to resolve ambiguity and to work out how one change affects the rest of the code. Debt-laden code creates more of that uncertainty, and you pay for it again on every interaction. Cleaner code gives an agent fewer reasons to backtrack, because responsibilities are clearer and dependencies are easier to follow. Our research backs this up. Higher-quality codebases used roughly 7% fewer input tokens and around 8% fewer output tokens. Agents also re-read files they'd already edited about 34% less often. Treat technical debt as an operating cost, start with the code your agents touch most, and build verification into the loop. Full article: https://lnkd.in/eDUxRcUz

  • Unternehmensseite für Sonar anzeigen

    42.029 Follower:innen

    Data sovereignty and managed cloud verification don't have to be a tradeoff anymore. SonarQube Cloud now supports GitHub Enterprise Cloud with data residency. If your org runs on a GHE.com subdomain, you can bind it to SonarQube Cloud, keep your code inside your residency boundary, and still get the same zero trust verification across every repo and every agent. No infrastructure to stand up yourself. Great news for financial services, healthcare, automotive, and defense teams working under strict data sovereignty requirements. Take a look: https://lnkd.in/gBbVTvsJ

  • Unternehmensseite für Sonar anzeigen

    42.029 Follower:innen

    Scaling AI-assisted coding across a global engineering org is one thing. Keeping quality consistent while you do it is another. DEPT®, a global technology and marketing company, was running decentralized SonarQube instances across teams. Flexible, but it meant fragmented reporting and inconsistent standards — and as AI-generated code volume grew, so did the risk of unreliable code slipping into production. Their fix: centralize on SonarQube Cloud as a single verification layer across every team and project. That gave every developer immediate, consistent feedback in their workflow, and let DEPT® fully embrace a "vibe, then verify" culture — use AI to move fast, then verify every line, human-written or AI-generated, against one standard before it ships. The results: issues surface 60% faster, troubleshooting time is down at least 30%, and code quality and maintainability are both measurably stronger. See how they did it: https://lnkd.in/gzV3i6uU

  • Unternehmensseite für Sonar anzeigen

    42.029 Follower:innen

    Advanced Security, beyond the enterprise 💪 SonarQube Advanced Security is now available on the SonarQube Cloud Team plan. It adds dependency risk analysis, software composition analysis (SCA), and malware detection, and it works inside your existing developer workflow — the same code quality gates and IDE you already use, no separate security tool required. Teams can identify vulnerable public packages, track license visibility, and enforce secure code standards before merging. Learn more about what's included: https://lnkd.in/gjxSY3UG

  • Sonar hat dies direkt geteilt

    I had the privilege of delivering a keynote earlier this month at the AI Engineer World’s Fair in San Francisco. In this talk, I highlight the challenge every industry is facing with AI slop - even coding - and outline Sonar’s proven approach to Agent Centric Development that a) reduces token consumption (over 30% lower), b) lowers risks (92% reduction in agentic loop issues) and c) delivers better outcomes (eg 44% fewer outages due to AI coding). Check out the talk and let me know what you think. https://lnkd.in/ekCfYAv5 And, if you haven’t already, check out the new products we announced at this keynote: Sonar Vortex - agentic loop context and verification Gitar - superhuman core review and agentic verification #SonarQube Remediation Agent - verified fixes for security, quality, maintainability issues, run in the background P.S. yes, for the first time in my career, my keynote followed a keynote by another Thariq (different spelling, same name), in this case from Anthropic. Tariq’s are everywhere in AI!

  • Unternehmensseite für Sonar anzeigen

    42.029 Follower:innen

    🏆 SonarQube is a 2026 CODiE Awards winner! We're thrilled to be recognized as "Best DevOps Tool" in Developer & AI Technology. SonarQube stood out for its role as the trust and verification layer for the Agent Centric Development Cycle (AC/DC), catching issues like technical debt, security vulnerabilities, and architectural inconsistencies. Thank you CODiE for the recognition 🎉

    • Kein Alt-Text für dieses Bild vorhanden
  • Sonar hat dies direkt geteilt

    The AI Engineer World's Fair was fantastic! Here are my key takeaways. Shawn Wang (swyx) set the tone with his opening, "Loopcraft: The Art of Stacking Loops" tracing AI engineering's arc from chat → tools → goals → and now automations, cron jobs, and loops. That single word felt like it kept coming up for days. Romain Huet & Alexander Embiricos (OpenAI) built on this in their Codex keynote: an agent does more when you connect it to the why behind the work, not just the task - and then connect it to what comes after (review + deploy). Context on both ends is how an agent goes from starting work to actually landing it. Peter Steinberger (OpenClaw/OpenAI) drove it home. He no longer watches agents code - he sets requirements and lets them plan, execute, and validate. His line I keep coming back to: the future isn't 20 terminal tabs, it's better loops. The hard part now is deciding what to pay attention to. But not everyone's sold. Geoff Huntley (of "ralph loop" fame) argued it's basically inevitable, comparing it to the early Kubernetes years: painful and messy, then suddenly a revolution. His honest prediction is next year we'll get a wave of "our factories failed / our loops failed" talks, because we haven't cracked this yet. Dex Horthy (HumanLayer) said he'd run the experiment of pulling humans out of the coding loop entirely, watched closely, and the results weren't good. His point wasn't "loops are bad" - it's that too many people are sprinting in with too little thought, and the loudest early adopters are the ones who'll get burned. 🧠 Understanding and verification are the new bottleneck. Geoffrey Litt (Notion) had a great talk on "Understanding is the new bottleneck." we don't understand code just to verify it (agents are getting good at verifying their own work) - we understand to participate. A project is never one loop; it's hundreds, and the mental model in your head is what lets you come up with the next idea. Lose that, and you've quietly limited your ability to steer. Tariq Shaukat (Sonar CEO) came at the same problem from the other end: "In the Land of AI Agents, the Verifiers Are King." When generating code becomes near-infinite and near-free, the scarce, valuable thing is whatever can verify it - tests, static analysis, quality gates. And Laurie Voss gave a talk literally titled "The Death of the Code Review" - the provocation being that line-by-line human review just doesn't survive contact with agent-scale output, and needs reinventing rather than scaling. 📖 And Fable is back! One of my favorites: Thariq Shihipar (Anthropic) gave the world's first "Field Guide to Fable" celebrating the model's relaunch after a genuinely wild few weeks. A fantastic session and great to see it back in builders' hands. Huge thanks to swyx and the entire team. Loved seeing friends on stage this yea. If you build with AI and you can make it next year: go. #ai #programming #softwareengineering

    • Kein Alt-Text für dieses Bild vorhanden
  • Unternehmensseite für Sonar anzeigen

    42.029 Follower:innen

    Meet your new security reviewer 🔍👋 The SonarQube Hunter Agent is now in Beta. AI coding assistants help teams ship code faster than ever, but they also introduce logic-level vulnerabilities that traditional SAST tools can't catch. The SonarQube Hunter Agent closes that gap. It targets three vulnerability classes that are hardest to catch automatically but most common in AI-generated code: broken access control, business logic flaws, and authentication and session issues. Built on Sonar's Foundation Agent harness for consistent, reliable results, it's a timely solution as teams accelerate development with AI. Open to SonarQube Cloud customers on the Enterprise plan. Read the full breakdown: https://lnkd.in/g3eFDFqF

Ähnliche Seiten