GitHub Advanced Security vs SonarQube comparison

Cancel
You must select at least 2 products to compare!
GitHub Logo
2,353 views|2,043 comparisons
100% willing to recommend
Sonar Logo
54,985 views|43,627 comparisons
80% willing to recommend
Comparison Buyer's Guide
Executive Summary
Updated on Mar 6, 2024

We compared SonarQube and GitHub Advanced Security based on our user's reviews in several parameters.

SonarQube offers a comprehensive solution with versatile language support, seamless integration with DevOps pipelines, and configurable features, making it a cost-effective choice with exceptional customer service. GitHub Advanced Security focuses on effective security measures, robust vulnerability detection, and user-friendly features, providing a valuable investment with flexible pricing and customizable options. Both platforms have room for improvement in areas such as analysis speed, user interface refinement, and integration capabilities.

Features: SonarQube's valuable features emphasize comprehensive code quality parameters, multiple language support, and integration with DevOps pipelines. GitHub Advanced Security focuses on software composition analysis, code scanning, and vulnerability alerts, with robust security measures and seamless workflow integration.

Pricing and ROI: The setup cost for SonarQube is considered straightforward and easy, with users appreciating the simplicity of the process. On the other hand, GitHub Advanced Security also has a straightforward and hassle-free setup cost. Both products offer flexible and customizable licensing options to cater to different user requirements., SonarQube has been praised for its ability to improve code quality, identify issues, and enhance project efficiency. Users benefit from its vulnerability detection and code compliance tools. On the other hand, GitHub Advanced Security offers enhanced security features, comprehensive vulnerability scanning, and automated security alerts, resulting in significant ROI and eliminating the need for third-party security tools.

Room for Improvement: In terms of areas for improvement, SonarQube could benefit from enhancing analysis speed, refining the user interface, providing clearer setup instructions, improving the documentation, addressing occasional performance issues, and enhancing integration options. On the other hand, users have suggested better integration with third-party tools, more customization options, improved usability and intuitiveness of the user interface, and increased speed and responsiveness for GitHub Advanced Security.

Deployment and customer support: Users report varying durations for implementing a new tech solution with SonarQube. Some took 3 months for deployment and a week for setup, while others took a week for both. For GitHub Advanced Security, some users took 3 months for deployment and a week for setup, while others took a week for both., SonarQube's customer service has been praised for its prompt and knowledgeable assistance. Users highlight the team's willingness to address any issues. GitHub Advanced Security's customer service is highly commendable, with users appreciating the level of assistance and guidance they receive. The team is described as responsive, knowledgeable, and efficient in resolving issues.

The summary above is based on 39 interviews we conducted recently with SonarQube and GitHub Advanced Security users. To access the review's full transcripts, download our report.

To learn more, read our detailed GitHub Advanced Security vs. SonarQube Report (Updated: March 2024).
768,886 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"It ensures user passwords or sensitive information are not accidentally exposed in code or reports.""It is a stable solution...It is a scalable solution as it can handle new applications along with the analysis part.""GitHub provides advanced security, which is why the customers choose this tool; it allows them to rely solely on GitHub as one platform for everything they need.""The most valuable is the developer experience and the extensibility of the overall ecosystem.""Dependency scanning is a valuable feature.""The product's most valuable features are security scan, dependency scan, and cost-effectiveness."

More GitHub Advanced Security Pros →

"I like that it covers most programming languages for source code review.""SonarQube has a lot of value, it reviews the basic coding standards and security vulnerabilities of code that help to reduce issues.""It helps our developers work more efficiently as we can identify things in a code prior to it being pushed to where it needs to go.""SonarQube is one of the more popular solutions because it supports 29 languages.""It has very good scalability and stability.""We can create a Quality Gate in order to fail Jenkins jobs where the code coverage is lower than the set percentage.""The customizable dashboard and ability to include results and coverage from unit test and other static analysis code tools.""It provides you with many features, as it does with the premium model, but there are still extra features that can be purchased if needed."

More SonarQube Pros →

Cons
"The customizations are a little bit difficult.""The deployment part of the product is an area of concern that needs to be made easier from an improvement perspective.""A more refined approach, categorizing and emphasizing specific vulnerabilities, would be beneficial.""There could be DST features included in the product.""There could be a centralized dashboard to view reports of all the projects on one platform.""The report limitations are the main issue."

More GitHub Advanced Security Cons →

"If the product could assist us with fixing issues by giving us more pointers then it would help to resolve more of the warnings without such a commitment in terms of time.""I think the code security can be improved.""Monitoring is a feature that can be improved in the next version.""If I configure a project in SonarQube, it generates a token. When we're compiling our code with SonarQube, we have to provide the token for security reasons. If IP-based connectivity is established with the solution, the project should automatically be populated without providing any additional token. It will be easy to provide just the IP address. It currently supports this functionality, but it makes a different branch in the project dashboard. From the configuration and dashboard point of view, it should have some transformations. There can be dashboard integration so that we can configure the dashboard for different purposes.""Lacks sufficient visibility and documentation.""It requires advanced heuristics to recognize more complex constructs that could be disregarded as issues.""For improvement, this solution could be offered on Docker and the cloud and the support for this solution could be improved. Customizing rules could also be made simpler.""Our developers have complained about the Quality Gates and the number of false positives that this product reports."

More SonarQube Cons →

Pricing and Cost Advice
  • "The current licensing model, which relies on active commitments, poses challenges, particularly in predicting and managing growth."
  • "The solution is expensive."
  • More GitHub Advanced Security Pricing and Cost Advice →

  • "This is open source."
  • "We did not purchase a license (required for C++ support), but this option was considered."
  • "Get the paid version which allows the customized dashboard and provides technical support."
  • "People can try the free licenses and later can seek buying plugins/support, etc. once they started liking it."
  • "This product is open source and very convenient."
  • "The licence is standard open source licensing"
  • "The price point on SonarQube is good."
  • "Some of the plugins that were previously free are not free now."
  • More SonarQube Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
    768,886 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:It is a stable solution...It is a scalable solution as it can handle new applications along with the analysis part.
    Top Answer:The deployment part of the product is an area of concern that needs to be made easier from an improvement perspective. In my company, the actual implementation phase takes time, though the tool is… more »
    Top Answer:I use the solution in my company to develop web applications and mobile apps. In my company, we use GitHub Advanced Security to check the vulnerabilities in the codes.
    Top Answer:I am not very familiar with SonarQube and their solutions, so I can not answer But if you are asking me about which tools that are the best for for Static Code Analysis, I suggest you have  a look… more »
    Top Answer:SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use… more »
    Top Answer:We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing… more »
    Ranking
    Views
    2,353
    Comparisons
    2,043
    Reviews
    6
    Average Words per Review
    433
    Rating
    9.0
    Views
    54,985
    Comparisons
    43,627
    Reviews
    19
    Average Words per Review
    391
    Rating
    8.0
    Comparisons
    Also Known As
    Sonar
    Learn More
    Interactive Demo
    GitHub
    Demo Not Available
    Overview

    GitHub makes extra security features available to customers under an Advanced Security license. These features are also enabled for public repositories on GitHub.com.

    SonarQube is a self-managed open-source platform that helps developers create code devoid of quality and vulnerability issues. By integrating seamlessly with the top DevOps platforms in the Continuous Integration (CI) pipeline, SonarQube continuously inspects projects across multiple programming languages, providing immediate status feedback while coding. SonarQube’s quality gates become part of your release pipeline, displaying pass/fail results for new code based on quality profiles you customize to your company standards. Following Sonar’s Clean as You Code methodology guarantees that only software of the highest quality makes it to production.

    At its core, SonarQube includes a static code analyzer that identifies bugs, security vulnerabilities, hidden secrets, and code smells. The platform guides you through issue resolution, fostering a culture of continuous improvement. SonarQube’s comprehensive reporting is a valuable tool for dev teams to monitor their codebase's overall health and quality across multiple projects in their portfolio. With SonarQube, you can achieve a state of Clean Code, leading to secure, reliable, and maintainable software.

    Sonar is the only solution combining the power of industry-leading software quality analysis with static application security testing (SAST) and real-time coding guidance in the IDE (with SonarLint) to meet the DevOps and DevSecOps demand of putting agility, automation, and security in the hands of developers. Further accelerate DevOps continuous integration by helping developers find and fix issues in code before the software testing stage, reducing the churn of finding, fixing, rebuilding, and retesting your app.

    With over 5,000 Clean Code rules, SonarQube analyzes 30+ of the most popular programming languages, including dozens of frameworks, the top DevOps platforms (GitLab, GitHub, Azure DevOps, and Bitbucket, and more), and the leading infrastructure as code (IaC) platforms.

    SonarQube is the most trusted static code analyzer used by over 7 million developers and 400,000 organizations globally to clean over half a trillion lines of code.

    Sample Customers
    Information Not Available
    Top Industries
    VISITORS READING REVIEWS
    Computer Software Company14%
    Financial Services Firm12%
    Manufacturing Company8%
    Insurance Company6%
    REVIEWERS
    Computer Software Company30%
    Financial Services Firm21%
    Comms Service Provider7%
    Manufacturing Company7%
    VISITORS READING REVIEWS
    Financial Services Firm17%
    Computer Software Company15%
    Manufacturing Company11%
    Government6%
    Company Size
    VISITORS READING REVIEWS
    Small Business23%
    Midsize Enterprise14%
    Large Enterprise63%
    REVIEWERS
    Small Business25%
    Midsize Enterprise16%
    Large Enterprise59%
    VISITORS READING REVIEWS
    Small Business17%
    Midsize Enterprise13%
    Large Enterprise70%
    Buyer's Guide
    GitHub Advanced Security vs. SonarQube
    March 2024
    Find out what your peers are saying about GitHub Advanced Security vs. SonarQube and other solutions. Updated: March 2024.
    768,886 professionals have used our research since 2012.

    GitHub Advanced Security is ranked 15th in Application Security Tools with 6 reviews while SonarQube is ranked 1st in Application Security Tools with 108 reviews. GitHub Advanced Security is rated 9.0, while SonarQube is rated 8.0. The top reviewer of GitHub Advanced Security writes "A tool that provides ease of integration with the set of existing codes in an infrastructure". On the other hand, the top reviewer of SonarQube writes "Easy to integrate and has a plug-in that supports both C and C++ languages". GitHub Advanced Security is most compared with Snyk, Veracode, Fortify on Demand, Checkmarx One and GitLab, whereas SonarQube is most compared with Checkmarx One, SonarCloud, Coverity, Veracode and Fortify on Demand. See our GitHub Advanced Security vs. SonarQube report.

    See our list of best Application Security Tools vendors.

    We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.