The context tax is real 💸 Coding agents working in large codebases end up re-reading the same files over and over, and every one of those reads gets billed again on every later turn. Sonar Vortex fixes this with SemSitter™, our semantic navigation engine, which gives agents a graph of the codebase instead of a filesystem to search blind. Agents run faster, cost less to operate, and miss fewer bugs, because they're working from a real map of your codebase instead of guessing their way through it. Read how it works: https://bit.ly/4gKhXPo
Sonar
Software Development
Vernier, Geneva 42,970 followers
Trusted by 7M devs, Sonar is committed to enabling developers and organizations to build better code for better software
About us
Sonar is the trust and verification layer for AI code, and the industry standard for automated code review for 17+ years. Sonar delivers deterministic, repeatable, and actionable code verification at scale by integrating code quality and code security into a single platform. The company analyzes more than 750 billion lines of code daily to ensure software is secure, reliable, and maintainable. Sonar is rooted in the open source community and is trusted by 7M+ developers globally, including teams at Snowflake, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company. To learn more about Sonar, please visit: www.sonar.com
- Website
-
https://sonarsource.com/
External link for Sonar
- Industry
- Software Development
- Company size
- 501-1,000 employees
- Headquarters
- Vernier, Geneva
- Type
- Privately Held
- Founded
- 2008
- Specialties
- software quality, open source, code quality management, ALM, Continuous Inspection, and Code Analysis
Products
SonarQube
Static Code Analysis Tools
The SonarQube platform delivers automated code quality and security analysis for modern development teams. Designed to seamlessly integrate with your CI/CD pipelines and DevOps tooling, it continuously reviews your source code to uncover bugs, security vulnerabilities, security hotspots, code smells, and architecture issues before code is merged or released. With broad support for 40+ programming languages and frameworks, SonarQube empowers developers and organizations to uphold high standards of code health across web, mobile, embedded, and cloud-native apps. It’s trusted by more than 7 million developers, underscoring its industry leadership as a critical solution for secure, maintainable, and high-quality software development.
Employees at Sonar
Locations
Updates
-
We're excited to team up with Westcon-Comstor 🤝 Thank you for your partnership!
We’ve partnered with Sonar, a global leader in AI code verification and governance. 💻 Through the agreement, partners across EMEA and APAC can help their customers build more secure, reliable software while tapping into new opportunities in the fast-growing DevSecOps market. 📈 Learn more 👇 https://okt.to/SwkCV2 #PartnerSuccess
-
-
Starting September 11, the EU Cyber Resilience Act gives you 24 hours to report actively exploited vulnerabilities. Join our webinar on September 2 for a practical action plan for codebase readiness. We'll cover: 1️⃣ Embedding independent, multilayered verification to support secure-by-design development 2️⃣ Gaining control over third-party dependency risk 3️⃣ Making remediation continuous instead of reactive Register here: https://lnkd.in/gqw5dGDv
-
-
Sonar reposted this
One command can take out a monorepo. Gautam has a story about that from his Uber days. Backups saved it, and the lesson stuck. The connection to AI agents: a person can mess that up once. An agent you're instructing in plain English can mess it up at scale. When you talk to an agent in natural language, it may or may not do what you meant. At Gitar by Sonar they run every input and output through what they call the judge, which checks for prompt injection and anything else that looks off before it runs. Build the guardrails on day one. Not after something breaks.
-
200+ zero days surfaced in internal tests, with average precision of 80–90%. That's the power of the SonarQube Hunter Agent 🚀 In our latest blog post, we go deeper on how our new AI security agent catches the flaws SAST was never built to see, and what makes its findings reliable enough to act on. Read the full breakdown: https://lnkd.in/gXPNyRCZ
-
Sonar reposted this
SonarQube Hunter Agent is generally available! Yes, the SonarQube that your dev teams love now hunts, verifies, and fixes some of the nastiest security vulnerabilities often hidden in logic flaws behind your code - broken access control, flawed business logics, missing MFA, non-expiring sessions... Agentic security meets state-of-the-art algorithmic security analyses (SAST, SCA, secrets detection, IaC scan), multi layered, token efficient, from an independent party that your engineering and compliance leaders trust. Hunter Agent works the way a human security researcher would, by tracing how code, data, and identity move through a system, then investigating and confirming each candidate issue before it ever reaches a developer. Verified security findings land directly inside the SonarQube workflow that dev teams are already familiar with. This means that security and dev teams triage, assign, remediate, and track without learning a new tool or switching context. To learn more: https://lnkd.in/eJRJUqNZ
-
Sonar reposted this
When code is produced and shipped at a higher volume and speed than ever before, and time to exploit flaws shrinks to minutes, every vulnerable code line matters. That’s why I am very excited to share that we launched SonarQube Hunter Agent today! It leverages agentic analysis to uncover entire classes of critical logic-based vulnerabilities that traditional code analysis misses. This perfectly complements SonarQube’s SAST, SCA, IaC and Secrets Scanning to reduce risks from all OWASP Top 10 categories early in the agent centric development cycle. Very proud of the cutting edge tech that our team built here. Read our press release for details: https://lnkd.in/eSY5fB_v
-
The SonarQube Hunter Agent is here 🏹 It closes a blind spot pattern-based scanning was never built to see, vulnerabilities where the code runs as written but permits something it shouldn't. Think broken access control, business-logic flaws, and authentication or session-management issues — the kind of thing that used to require a manual security review or a pentest to catch. Hunter Agent reasons through your codebase the way a human security researcher would, confirming every finding before it reaches you and landing verified issues right inside the SonarQube workflow you already use. No new tool to learn, and no PRs blocked in the process. Now generally available on SonarQube Cloud. Read the full announcement: https://lnkd.in/gDki9ynB
-
Multilayered verification ➡️ 44% fewer AI-derived production outages. At the AI Engineer World's Fair, Sonar CEO Tariq Shaukat explains what we're hearing from customers – marked improvements in reliability, security, and maintainability that come with verifying AI code.