SonarQube Benefits

Wang Dayong - PeerSpot reviewer
Senior Software Engineering Manager at Hill

When we deliver a code, the solution scans the code and reports whether the code has bugs or any other vulnerability issues. Thus the solution helps us identify issues and improve the quality of our code before delivering it to the customer.

View full review »
Devid William - PeerSpot reviewer
Application Security Architect at Banco Votorantim

We see the security issues in our solutions with the help of the product. It helps us improve the solutions.

View full review »
Jayashree Acharyya - PeerSpot reviewer
Director at PepsiCo

The developers have responsibility for unit testing, but it is very important that we check what they have been doing. SonarQube allows us to see the result directly in the pipeline.

View full review »
Buyer's Guide
SonarQube
March 2024
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,740 professionals have used our research since 2012.
BS
IT Developer at PT Oto Multiartha

The solution has helped us to find flaws in the Syntax and comply with requirements. 

View full review »
Angelo Quaglia - PeerSpot reviewer
Independent Professional at Studio Dott. Ing. Angelo Quaglia

Our developers are learning how to improve their code.

View full review »
DA
Sr DevOps Engineer at incatech

We can see what's being flagged by whatever requirements in the environment that we're going to. SonarCube has these rules that you set up. You can set the rules and adjust them. It allows us to either be at 80% or whatever the case may be. If you set up these conditions that can tighten down the developer's coding.

View full review »
reviewer1812603 - PeerSpot reviewer
Works

It improved our website's look and feel. 

We consider it a handy tool that helps to resolve our issues immediately. 

It is a good tool for evaluating technical debt and introducing junior developers to codification standards and good practices. There is an amazing code quality application that defines coding standards. 

The tool is pretty much useful for a technical lead to reduce his efforts in reviewing the codes. The tool has integration with several languages. 

View full review »
Denis Walrave - PeerSpot reviewer
Project Leader / Technical Expert at La francaise des jeux

Using SonarQube benefits us because we are able to avoid the inclusion of malware in our applications. We can repair vulnerabilities and exploits from outside of the organization.

View full review »
AE
Test Expert at Saudi Telecom Company

It prevents some vulnerabilities in the production environment.

View full review »
KG
Cyber Security Architect (USDA) at a government with 10,001+ employees

It definitely helped our organization in hardening the software, the application itself. This is a part of our process now.

View full review »
VD
Lead Security Architect at a comms service provider with 1,001-5,000 employees

This solution has helped with the integration and building of our CICD pipeline. Without any scans or assessments, the pipeline and build are not complete. One of the good features of SonarQube is the many languages it supports including Java, dotNET, Typescript and HTML CSS. It also allows us to set custom quality gates and rules.

View full review »
DG
Head of Software Delivery at a tech services company with 51-200 employees

It has helped many of the organizations that I have worked at to improve overall security, quality, and test confidence within the codebases. It also provides this in a speed efficient way. Engineers now feel much more proud of their solution as they gain confidence from these scans and their results. 

Engineers have also learned from the results and have improved themselves as engineers. This will help them with their careers. 

We are also able to get reports on our suite and generate a quality rating for ourselves utilizing this data and more. 

View full review »
SG
Lead Engineer at a healthcare company with 10,001+ employees

We have the software metrics that SonarQube gives us, which is something we did not have before. This helps us work towards aiming coding standards to empower us to move in the direction of better code quality. SonarQube provides targets and metrics for that.

View full review »
AS
Program Manager at a computer software company with 1,001-5,000 employees

Code quality improvement, Secure coding pracitices 

View full review »
it_user713202 - PeerSpot reviewer
Vice President at a financial services firm with 1,001-5,000 employees

This solution figures out and tells you when there are code quality issues.

View full review »
JI
Automation Tool Specialist at a comms service provider with 1,001-5,000 employees
  • Higher code quality. 
  • Faster to market.
  • Less errors.
View full review »
DH
Technical Architect at Dwr Cymru Welsh Water

This has improved our process because it allows us to pick up on a lot of the smaller best practices that might otherwise be missed, in addition to ensuring code quality is not compromised between builds.

View full review »
PD
Manager at a wireless company with 11-50 employees

SonarQube has not yet had an impact on our organization. In the past, however, I've used it to control the security vulnerabilities and establish standards for API control.

View full review »
it_user100635 - PeerSpot reviewer
Technical Authority Digital at a insurance company with 1,001-5,000 employees

It would be utterly impossible to contemplate Continuous Delivery without including a major focus on ensuring affordable software quality. SonarQube plays a key role in this endeavour and provides Senior Management oversight across multiple project teams and business deliveries. Fits in very well with existing Continuous Integration build pipeline workflows. As we move towards Continuous Delivery ensuring a ‘no surprises’ release management.

Our software quality assessment at an affordable cost (licensing, time and effort). Previous attempts have failed to win the support of the development community (typically overly complex and intrusive and/or not sufficiently timely) without which the initiative will be doomed to failure.

View full review »
JI
Automation Tool Specialist at a comms service provider with 1,001-5,000 employees

This solution is part of our pipeline. We use GitLab for source control and Jenkins to build management. Jenkins kicks off our SonarQube scans, we use Checkmarx for static code analysis, UrbanCode Deploy, and UrbanCode Release.

Using SonarQube has helped us to identify areas of technical debt to work on, resulting in better code, fewer vulnerabilities, and fewer bugs.

View full review »
it_user727500 - PeerSpot reviewer
Senior Java Developer at a financial services firm

This product has helped us improve the quality of code within the business and ensure all new developers keep to a similar code convention per project. This can basically be tracked back to saving the company money, because improved quality of the code means less technical debt which means it's easier to extend or add functionality to the code base. The quicker the development team can roll out changes, the less developer hours needed to implement the changes, which the company needs to convert into profits.

View full review »
it_user718230 - PeerSpot reviewer
Devops Engineer at a healthcare company with 10,001+ employees

SonarQube ensures that we release a good quality of code to our customers. We have incorporated test driven development within the organization. It is also very helpful to bring a DevOps culture within the organisation.

View full review »
HT
Information Technology Technical Architect at a insurance company with 51-200 employees

Sonarqube has improved our best practice of pair programming that aligned with the CI pipeline.

View full review »
it_user697050 - PeerSpot reviewer
SW Automation Team Leader at a tech services company with 201-500 employees

SonarQube and SonarLint were adapted as part of the CI development process, i.e., the developers who committed to high severity issues in the repository were immediately notified via mail/Jenkins.

An actual RuntimeException bug was discovered and immediately fixed by using SonarQube with CI.

View full review »
it_user327384 - PeerSpot reviewer
Assistant Director Implementation Services at a financial services firm with 5,001-10,000 employees

It was brought in to help with best practices in writing test cases, and each test should pass given all numbers are highlighted on SonarQube.

Executing sonar analysis on a big chunk of code - with an Oracle database does take up a lot of time.

View full review »
EG
Senior System Analyst at a tech services company with 1,001-5,000 employees

SonarQube simplified some of the processes and made others more complex.

View full review »
it_user700128 - PeerSpot reviewer
Director at a consultancy with 10,001+ employees

It has improved code quality and helped shift quality left. It also paved the way for implementing Continuous Integration/Continuous Delivery.

View full review »
SM
Manager at Dassault Systèmes

This has improved our organization because it has helped to find security vulnerabilities.

View full review »
it_user697056 - PeerSpot reviewer
Senior Software Developer at a tech vendor

Better live process: More automated quality control in the lifecycle of development/testing/deployment/production. This includes the prevention of potential bugs due to ineffective code, as well as keeping a more unified style of solutions. This is thanks to standard solutions offered by the issue tips. It raises code maintainability as well as flexibility, to some extent.

View full review »
it_user333735 - PeerSpot reviewer
QA Engineer at a tech services company with 51-200 employees

This product helps us to determine the maturity and quality of the coding of our software customers, preventing future crashes in the software. We get users used to developing clean code makes SonarQube a valuable tool. Also, we use it for our internal software development helping us to create a good quality software.

View full review »
PJ
Staff DevOps Specialist at a computer software company with 201-500 employees

In some instances, the project stakeholders were able to implement quality gate control for code coverage, security alerts, and things like that. It greatly improved the quality of the product. If our test code coverage is 80% and a person commits a change that brings the code coverage to below 80%, that code cannot be merged. We've been able to improve the quality of the products that we produce by using SonarQube. We are using it as a gate.

It is a great tool in a situation where you have a dynamic team, and you sometimes hire staff or subcontractors from other companies. It provided us with the ability to implement quality gates in our project. We could look at the data and see which developers were producing quality code and which developers were not too worried about the quality. It helped us out with our junior devs. I know of a few cases where having this system helped our junior devs in taking their skills one level up because we had set up a hard quality gate.

View full review »
LZ
Application Security Analyst at a agriculture with 501-1,000 employees

We use this program as a compliment to our security scans, in addition to Checkmarx.

View full review »
it_user347526 - PeerSpot reviewer
Software Engineer, Agile/Lean Evangelist, Scrum Master at a tech services company with 51-200 employees

My team uses just two features - dashboards and CI-build-breaker - for checking code quality and the stability of our code base. For those purpose, SonarQube has done its work greatly. We have seen a decrease of about 25% of issues from since we first started using it a few months ago, and my team code bases are getting better.

View full review »
RB
Senior Solutions Architec at OSENTERPRISE SAC

The solution has helped us mitigate problems in applications before they were a bigger issue.

View full review »
HJ
IT Infrastructure Head / Facilities Manager - ITIL V3 Certified ,Vmware Vsphere5 at a financial services firm with 51-200 employees

It has improved our options for offering products to our clients that can better meet their needs, lower costs, and improves code quality and basic security. 

View full review »
PR
Scala Contractor at a tech services company with 10,001+ employees

We have literally thousands of rules and they are of medium effectiveness. The problem is that most people bypass the rules or turn them off. But even that is information to us. The fact that they have to turn the rules off is as much value to us as the rules themselves.

View full review »
JS
DevSecOps Lead at a tech services company with 11-50 employees

The developers are rejecting the idea that this product is useful.

View full review »
it_user347733 - PeerSpot reviewer
DevOps Engineer at Trantor Software Private Limited

It had changed the whole attitude of the developers of our team as they can see their code exceptions at compile time. With this, we have delivered a quality product to our stakeholders.

View full review »
KN
Security at a tech services company with 51-200 employees

SonarQube lets us find security issues during development and testing so that we can release more secure and higher quality applications.

View full review »
it_user697038 - PeerSpot reviewer
DevOps at a tech company with 10,001+ employees

Quality Gate helps us to merge code that was not covered with tests.

View full review »
it_user344817 - PeerSpot reviewer
Service Line Leader at a tech services company with 10,001+ employees

It's enabled us to improve software quality and help us to disseminate best practices.

View full review »
it_user347595 - PeerSpot reviewer
Java Developer at a tech consulting company with 51-200 employees

For the record, what I do with SonarQube is develop a language plugin for a language not previously covered by SonarQube. As such, my experience of running SonarQube is limited to that necessary to have the plugin tested, nothing more.

View full review »
it_user336438 - PeerSpot reviewer
Web Developer/DevOps Engineer with 501-1,000 employees

It allows for better collaboration of our team members on security findings.

View full review »
it_user333624 - PeerSpot reviewer
Software Developer at a tech services company with 501-1,000 employees

I have fallen in love with SonarQube when I could've easily built custom rules checks. However, doing that manually checking takes tons of time.

View full review »
it_user732738 - PeerSpot reviewer
Technical Architect and Software Engineer at a tech services company

Individual developers are more concerned about the quality of their work when they see their results in the big picture.

View full review »
Buyer's Guide
SonarQube
March 2024
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,740 professionals have used our research since 2012.