SonarQube Previous Solutions

Chetan Jayatheertha - PeerSpot reviewer
Lead DevOps Consultant at itcinfotech

We previously used a different solution but moved to SonarQube because it better suits our use cases. 

View full review »
SG
Lead Engineer at a healthcare company with 10,001+ employees

Way back in the past, we used other static analysis tools like PC-lint or Gimpel Lint. I still have plans to resurrect some of that, but I'm of the mindset that the more opinions you get about your code, the better off you are. You get to look from different angles with different tools. In terms of the automated tool, SonarQube was the first one we had for getting into the DevOps generation of stuff.

View full review »
Jaile Sebes - PeerSpot reviewer
Senior Software Architect at a tech vendor with 10,001+ employees

In comparing Coverity and SonarQube, Coverity stands out for its superior vendor support and enterprise-level analysis capabilities, particularly in security and leak detection across procedures. SonarQube excels in dashboard usability and cost-effectiveness but lacks certain advanced features like inter-procedural analysis and some leak detections available in Coverity.

View full review »
Buyer's Guide
SonarQube
March 2024
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,578 professionals have used our research since 2012.
MarkRyall - PeerSpot reviewer
Strategist Individual Contributor at Peraton

Previously, we used Fortify. The company that I worked for owned Fortify. We then sold Fortify to another company. We could look at other products to do the job.

View full review »
Gert Kersten - PeerSpot reviewer
Software Developer at BKWI
AS
Information Technology Security at a consultancy with 10,001+ employees

I used the Micro Focus Fortify, but the performance integration in the pipeline is faster in SonarQube. But in Fortify, the support is better as it is a commercial product, and we paid for it, so we can complain and get feedback in case of any issue. We complain if anything needs to be fixed, and they accept and fix it, but SonarQube does not have such a platform.


View full review »
BS
IT Developer at PT Oto Multiartha

We chose SonarQube due to its free community edition. After a while, when we will need more features, we will probably purchase the solution next year. 

View full review »
Angelo Quaglia - PeerSpot reviewer
Independent Professional at Studio Dott. Ing. Angelo Quaglia
Daniel Antonio Jimenez Quintana - PeerSpot reviewer
IT Systems Architect at Banco Ripley

We try to primarily use open-source solutions. The organization tries not to spend money for the moment. Many clients do not want to pay for solutions during this time, especially in the case of products that are expensive.

View full review »
reviewer1812603 - PeerSpot reviewer
Works

We did use another solution, however, we found issues such as:

  • Ineffective time management
  • Lack of instant communication
  • Not receiving timely feedback
  • Not receiving clear instructions or expectations
  • Share time management apps and resources for students
  • Utilize educational technology (“EdTech”)
  • There's also a need to increase peer review
View full review »
Denis Walrave - PeerSpot reviewer
Project Leader / Technical Expert at La francaise des jeux

We did not use another similar solution prior to this one.

View full review »
AE
Test Expert at Saudi Telecom Company

We only use SonarQube with SonarScanner.

View full review »
Yash Brahmani - PeerSpot reviewer
Devops Engineer at BNP Paribas

We used Fortify, it is also another tool for static code analysis. The security team used to use that, but not in our team because ours was a newly assembled team for the work. 

View full review »
KG
Cyber Security Architect (USDA) at a government with 10,001+ employees

No, not that I am aware of.

View full review »
VD
Lead Security Architect at a comms service provider with 1,001-5,000 employees

I have previously used Checkmarx, Blackbelt and WhiteSource.

View full review »
RR
Manager at kellton

We also use Checkmarx and Snyk. One of the main differences between them and SonarQube is that they have dynamic testing and analysis, rather than static analysis. 

View full review »
DG
Head of Software Delivery at a tech services company with 51-200 employees

I have used Checkmarx and also tried a demo of Veracode. 

Checkmarx was far too heavy-handed and only handled security concerns for a VERY large price tag. 

Veracode is very good, however, the price vs a free solution was a deciding factor in many cases. 

View full review »
SG
Lead Engineer at a healthcare company with 10,001+ employees

We didn't have a previous solution other than paper systems that we never got in the habit of going back to referring to. We didn't switch, we started fresh.

View full review »
HK
Country Manager Senegal at a financial services firm with 10,001+ employees

We use this solution in parallel with Checkmarx because both of them are good for different things. SonarQube is good for code quality, whereas Checkmarx is more for security.

View full review »
AS
Program Manager at a computer software company with 1,001-5,000 employees

I have used some tools previously, such as Eclipse and Checkmarx. I used some tools directly linked with Eclipse, but SonarQube is much better. It has a better ability to link with Eclipse as well as the standalone features for a code review I have found the SonarQube most efficient.

View full review »
Wang Dayong - PeerSpot reviewer
Senior Software Engineering Manager at Hill

We were previously using Coverity. We used it for three years or so.

View full review »
Anshuman Kishore - PeerSpot reviewer
Director Product Development at Mycom Osi

I have also used Veracode and when comparing the two, I find that Veracode is better at finding security-related issues during the static code analysis. At the same time, during my PoC with Veracode, they did not claim to be able to provide everything that SonarQube does. 

View full review »
PC
Engineer at a pharma/biotech company with 201-500 employees

We have used open-source origins of the tools.

PCI is an open-source solution that we used before, and we used Snyk as well.

View full review »
it_user713202 - PeerSpot reviewer
Vice President at a financial services firm with 1,001-5,000 employees

We were using some other products, but not on an enterprise level. There were several locally developed applications, but when we tried to consolidate all of these into an enterprise-level solution, we opted for this.

View full review »
EG
Backend Architect at Sngular

I have used Codestyle and a few other tools. SonarQube is similar to other tools.

View full review »
DH
Technical Architect at Dwr Cymru Welsh Water

I did not use another solution prior to this one.

View full review »
VS
Product Security Architect at a tech services company with 51-200 employees

I have worked with Snyk. Snyk is more developer friendly. I have also worked with Coverity. SonarQube has features that are similar to Snyk and Coverity. So, SonarQube is better because it is an open-source tool.

View full review »
Calinescu Tudor - PeerSpot reviewer
Security Project Leader at ATOSS AG

I have used Veracode.

View full review »
it_user100635 - PeerSpot reviewer
Technical Authority Digital at a insurance company with 1,001-5,000 employees

Yes. We had been using Coverity. However, whilst an excellent product with perhaps more capability, we found that it was more difficult to integrate into the development lifecycle and take up was relative modest. The sophistication of the solution was not well suited to our requirements in the sense that we are not producing commercial software but creating applications for internal use, and therefore the depth of analysis available was not really needed especially given the much higher learning curve. Also, licensing and platform costs were also high. We found SonarQube to be sufficiently powerful at a much more affordable price point.

More recently we have added two products with a specific focus on detecting security vulnerabilities. SQ does offer basic OWASP top 10 support within the language rule sets, but it's fair to say that this is probably not sufficient to keep your security folks happy. We definitely wanted to add support for scanning 3rd party libraries which probably make up 80%+ of our released app.

View full review »
TS
Security consultant at a computer software company with 1,001-5,000 employees

I have previously created a report comparing SonarQube with other products such as Micro Focus Fortify. SonarQube is way ahead than Micro Focus Fortify because SonarQube has a cloud solution. Micro Focus Fortify does not support cloud-based hosting.

View full review »
JI
Automation Tool Specialist at a comms service provider with 1,001-5,000 employees

We were not using another solution prior to this one. As we've evolved, this is one of the tools that we decided to go with.

View full review »
it_user727500 - PeerSpot reviewer
Senior Java Developer at a financial services firm

Yes, I have used individual components which SonarQube uses, such as FindBugs, but having the static analysis run and reported back within a continuous integration server. This gives you back some of the results, but SonarQube is a single, complete solution for static analysis and has added improvements like a great UI and visualisations.

View full review »
AJ
DevOps Lead at a marketing services firm with 1,001-5,000 employees

We are also onboarding Checkmarx. We use both solutions.

We are not replacing anything. Maybe we will use both in conjunction. Checkmarx provides DAST, whereas this product does not. 

View full review »
it_user718230 - PeerSpot reviewer
Devops Engineer at a healthcare company with 10,001+ employees

Previously, we used to use regular code review (static analysis, coverage tools) without much into single dashboard. SonarQube helped to put everything together into place supporting almost all languages, or quality profiles.

View full review »
RV
Development Team Lead at a financial services firm with 1,001-5,000 employees

I have minor experience with Q One. The main difference is in the licensing structure, with regards to lines of code. We have noticed that Q One has a bit more details, but support for various languages is lacking. 

View full review »
HT
Information Technology Technical Architect at a insurance company with 51-200 employees

We have not used any other solution, but we did some comparisons and decided to go with SonarQube because it was open-source.

View full review »
it_user697050 - PeerSpot reviewer
SW Automation Team Leader at a tech services company with 201-500 employees

We did not use a different solution in the past.

View full review »
it_user327384 - PeerSpot reviewer
Assistant Director Implementation Services at a financial services firm with 5,001-10,000 employees

No previous solution was used.

View full review »
EG
Senior System Analyst at a tech services company with 1,001-5,000 employees
CV
CTO at a computer software company with 11-50 employees

I have used a wide variety of tools.SonarQube covers a wide variety of issues and it is well well designed robust framework.

View full review »
it_user700128 - PeerSpot reviewer
Director at a consultancy with 10,001+ employees

Yes, we used PMD, FindBugs and FxCop. Switched for the reporting and dashboard capabilities.

View full review »
it_user697056 - PeerSpot reviewer
Senior Software Developer at a tech vendor

Previous to this solution, we used static code analysis using built-in IDE tools and plugins. SonarQube just centralizes the same thing and adds some extra layers to systemize and create a somewhat better pipelining for the quality analysis process.

IDE-related tools and plugins are still in use today, as first-in-line hints and helpers. SonarQube manages the quality threshold and it is part of the larger overall process.

View full review »
it_user333735 - PeerSpot reviewer
QA Engineer at a tech services company with 51-200 employees

I used a few specific tools for the PHP language, that tools were really powerful (Codesniffer, PHPCPD, PHP Mess Detector among others) and provide a good information about the quality of our code. Nowadays, I am mixing that tools with SonarQube, but in shortly, I am thinking of using just SonarQube. The reason is that SonarQube is including more and more PHP rules in every PHP plugin version.

View full review »
PJ
Staff DevOps Specialist at a computer software company with 201-500 employees

I don't think that we used anything else previously. SonarQube was the first one.

View full review »
NB
Security Engineer at a computer software company with 201-500 employees

Previously I worked with Fortify and Veracode and I have found those tools provided much better because they are from a commercial solution.

View full review »
KV
Senior Technical Architect at a tech services company with 501-1,000 employees

I have used Veracode previously.

View full review »
LZ
Application Security Analyst at a agriculture with 501-1,000 employees

We did not use another solution, prior to this one.

View full review »
it_user347526 - PeerSpot reviewer
Software Engineer, Agile/Lean Evangelist, Scrum Master at a tech services company with 51-200 employees

My development team adopted SonarQube in January 2015 for code quality improvement, and had not used any code quality checking tool before.

View full review »
AS
Senior/Lead Software Engineer at a government with 51-200 employees

We did not previously use a different solution. It was always manual code reviewing via the most experienced team members who would offer guidance on adjustments.

View full review »
HJ
IT Infrastructure Head / Facilities Manager - ITIL V3 Certified ,Vmware Vsphere5 at a financial services firm with 51-200 employees

We service client needs so we consider all solutions we are aware of and weigh the pros and cons for deployment with a specific client.

View full review »
PR
Scala Contractor at a tech services company with 10,001+ employees

It was years ago. They probably evaluated other solutions. 

We're evaluating the use of different solutions at the moment, but I've just withdrawn from that task.

View full review »
LD
Software Engineer at a tech services company with 11-50 employees

I have used Snyk and it is more catered to a different audience than SolarQube.SolarQube is more for software developers.

View full review »
KN
Security at a tech services company with 51-200 employees

I have not used any other similar solutions in the past. SonarQube is the first of its kind in my experience.

View full review »
it_user697038 - PeerSpot reviewer
DevOps at a tech company with 10,001+ employees

We did not use a different tool before this one.

View full review »
RB
Security Information Manager at a tech services company with 10,001+ employees

We've also used Fortify.

View full review »
HM
Founder at a tech services company with 11-50 employees

This was our first one.

View full review »
it_user344817 - PeerSpot reviewer
Service Line Leader at a tech services company with 10,001+ employees

Nothing was implemented before this software, only PMD, a light control tool.

View full review »
it_user333624 - PeerSpot reviewer
Software Developer at a tech services company with 501-1,000 employees
  • Squale
  • Panopticode
  • CodePro AnalytiX
View full review »
it_user732738 - PeerSpot reviewer
Technical Architect and Software Engineer at a tech services company

We used the same tests, but with every developer running them individually. Now management can also get a picture of the quality assurance.

View full review »
Buyer's Guide
SonarQube
March 2024
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,578 professionals have used our research since 2012.