SonarQube Cloud Team Plan
Automated code checks have improved quality gates and prevent weak code from reaching production
What is our primary use case?
When developers write code and prefer testing it manually, we use SonarQube rather than conducting manual testing. In SonarQube, we check for duplicacy, code smells, bugs, environment variables, and passwords, which helps significantly.
We have integrated SonarQube through the Jenkins plugin and created a project in SonarQube, connecting that SonarQube project to our pipeline, GitHub, and Jenkins pipeline with the SonarQube token.
This integration has helped substantially, and by using SonarQube, we have saved considerable time. It excels at detecting bugs and security vulnerabilities. The Quality Gate feature is valuable because it prevents low-quality code from reaching production, and the integration with Jenkins provides clear visibility into code quality metrics across all projects. Overall, SonarQube is a reliable and mature code quality platform.
Regarding features, I have integrated SonarQube with Jenkins, but we can also integrate it with GitHub, GitLab, and Azure DevOps.
When we started using SonarQube, we conducted testing manually beforehand, and it significantly improved our software quality by identifying bugs that manual testing could not catch. With SonarQube, we can easily identify vulnerabilities, code smells, and the development cycle runs smoothly after its implementation. Since integrating it into our CI/CD pipeline, developers fix issues before deployment. Before SonarQube, developers wrote the code, pushed it to GitHub, and triggered the pipeline for deployment. SonarQube prevents this direct deployment to production, ensuring fixes are applied before deploying to production servers. The Quality Gate feature also helps enforce coding standards across teams, such as when excessive comments or repetitive blocks are present in code, utilizing the code duplicacy feature.
How has it helped my organization?
We have integrated SonarQube through the Jenkins plugin and created a project in SonarQube, connecting that SonarQube project to our pipeline, GitHub, and Jenkins pipeline with the SonarQube token.
This integration has helped substantially, and by using SonarQube, we have saved considerable time. It excels at detecting bugs and security vulnerabilities. The Quality Gate feature is valuable because it prevents low-quality code from reaching production, and the integration with Jenkins provides clear visibility into code quality metrics across all projects. Overall, SonarQube is a reliable and mature code quality platform.
When we started using SonarQube, we conducted testing manually beforehand, and it significantly improved our software quality by identifying bugs that manual testing could not catch. With SonarQube, we can easily identify vulnerabilities, code smells, and the development cycle runs smoothly after its implementation. Since integrating it into our CI/CD pipeline, developers fix issues before deployment. Before SonarQube, developers wrote the code, pushed it to GitHub, and triggered the pipeline for deployment. SonarQube prevents this direct deployment to production, ensuring fixes are applied before deploying to production servers. The Quality Gate feature also helps enforce coding standards across teams, such as when excessive comments or repetitive blocks are present in code, utilizing the code duplicacy feature.
A specific outcome I can share is that after integrating SonarQube into our CI/CD pipeline, we reduced production bugs by 30 to 40 percent and improved code coverage from 65 to 85 percent by enforcing the Quality Gate, along with a 25 percent reduction in technical debt over the last six to seven months post-implementation. Additionally, manual code review time has been cut by 40 percent because common code quality issues are detected automatically. Before, a manager or senior developer manually checked code after a developer pushed it to GitHub, but sometimes things were missed, while SonarQube easily catches those issues, improving compliance with secure coding standards across teams and allowing for faster release cycles due to code quality checks becoming part of the automated pipeline.
In my daily work, SonarQube is important, assisting in maintaining consistency, code quality, and early identification of issues in the DevSecOps workflow. While there is room for improvement in areas involving false positives and advanced security capabilities, overall, it is a reliable solution that promotes better coding practices and more stable software releases.
What is most valuable?
The best features I can mention include analyzing static code, which is excellent, and while integrating with Jenkins, it becomes stronger in CI/CD integration. The dashboards are easy to read; even a non-technical person can check for issues. If we set any threshold limit in the Quality Gate and it fails, the pipeline fails, showing reports of that code. SonarQube supports many programming languages, and the Quality Gates improve deployment confidence.
I find myself relying most on detecting bugs, vulnerabilities, and code smells and the support of many programming languages, which helps reduce technical debts, so this aspect has helped me considerably.
SonarQube provides strong security and governance capabilities by enforcing secure coding standards and consistent code quality across all teams. It identifies security vulnerabilities and allows organizations to define policies requiring no critical vulnerabilities and minimum code coverage. Role-Based Access Control enables administrators to manage project permissions, ensuring that if a developer makes a mistake in code, only their team can check the issue, which is very helpful. SonarQube emphasizes SAST, focusing on static application security testing, although it is not a complete application security platform, with key strengths in Role-Based Access Control, security hotspots for manual review, and centralized governance dashboards.
Working with SonarQube, it consistently analyzes source code and provides actionable insights into bugs. The results are generally accurate and help developers identify issues early in the development cycle, improving the consistency of our code. The Quality Gate feature reliably enforces predefined coding standards.
What needs improvement?
SonarQube could improve by reducing false positives in its static code analysis; while its detection capabilities are strong, some findings require manual verification, increasing developers' workload. More accurate analysis would enhance productivity, and SonarQube would benefit from enhanced AI-powered recommendations for fixing issues. For instance, in our pipeline, if it fails during SonarQube stage, we could check the dashboard for identified issues involving code smells, bugs, or duplicacy. An AI feature should be integrated into SonarQube to resolve issues quickly; optimizing scanning performance for very large repositories and providing faster analysis times would enhance the developer experience, especially in large code bases with frequent commits.
For anyone planning to implement SonarQube, I advise starting by defining coding standards first and integrating Quality Gates into the pipeline. You can customize quality profiles to match project requirements; rather than relying entirely on default rules, you can adjust settings for stronger detection and enforcement. Organizations with advanced security, branch analysis, and governance features might consider commercial editions based on their needs.
For how long have I used the solution?
I have been using SonarQube for the last one and a half years, as we have our CI/CD pipelines, so we have integrated SonarQube in pipelines.
What do I think about the stability of the solution?
SonarQube is stable since we use it consistently; it performs reliably with minimal downtime, analyzing our code within our pipeline as a part of it. Once properly configured, it runs smoothly, integrating well with tools like Jenkins. Regular updates and appropriate database maintenance ensure long-term stability, and we have experienced very few stability issues after the initial setup.
What do I think about the scalability of the solution?
I find SonarQube to be highly scalable, supporting both small development teams and large enterprise environments. As the number of projects, repositories, and developers grows, it continues to perform well when deployed with the right infrastructure. We have initiated SonarQube for multiple projects and every pipeline, creating a new project for each microservice. With adequate CPU, memory, and database resources, it efficiently handles increasing code analysis workloads.
How are customer service and support?
We have not connected with customer support yet, but customer support is responsive and knowledgeable, especially for commercial editions. Being a startup focused on budget, we rely on the Community Edition, and technical issues are handled professionally; detailed documentation is available. For Community Edition users, active community forums serve as valuable resources for troubleshooting and best practices.
Which solution did I use previously and why did I switch?
Previously we were not using any solution, as I mentioned earlier, our testing was completely manual.
How was the initial setup?
Regarding pricing, we have not explored much since we are using the Community Edition. The initial setup cost is relatively low because the software can be deployed on existing infrastructure. We prefer the Community Edition over purchasing a license due to budget considerations as a startup.
What about the implementation team?
We are using the Community Edition of SonarQube.
What was our ROI?
I cannot quantify the savings in monetary terms, but we have saved considerable time and freed up resources because testers who were manually testing are now working on different projects. The time they spent finding bugs, SonarQube identifies quickly, allowing us to utilize the testers on other tasks.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing, we have not explored much since we are using the Community Edition. The initial setup cost is relatively low because the software can be deployed on existing infrastructure. We prefer the Community Edition over purchasing a license due to budget considerations as a startup.
Which other solutions did I evaluate?
As a junior DevOps engineer, I have not had the chance to explore other options; my senior decided on SonarQube, and I set it up with him, so I have not evaluated other options. I believe SonarQube provides extensive facilities compared to others.
What other advice do I have?
For anyone planning to implement SonarQube, I advise starting by defining coding standards first and integrating Quality Gates into the pipeline. You can customize quality profiles to match project requirements; rather than relying entirely on default rules, you can adjust settings for stronger detection and enforcement. Organizations with advanced security, branch analysis, and governance features might consider commercial editions based on their needs. My overall rating for SonarQube is eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Shift-left analysis has improved code quality but security rules still need more depth
What is our primary use case?
I am not heavily involved in the deployment side of SonarQube, such as infrastructure management, as there is a separate team who takes care of deployment, updates, and maintenance. I work primarily on abstract functions, where I use SonarQube to perform static and code analysis, followed by remediation. I do not work from the deployment, upgrade, or update perspective.
What is most valuable?
The strong side of SonarQube is that it has both CLI-based channels and is user-friendly for testers, allowing them to scan code locally. Those are advantages, and SonarQube has secret scanning included in their scan. Now they have the capability of software composition analysis, which is a win-win situation and a great advantage because under one umbrella, you can get multiple scanning capabilities.
The integration of SonarQube into DevOps pipelines impacts my development workflow positively by adopting a shift-left approach. Integrating into the pipeline allows recommendations at every pull request or even at the IDE level while writing the code itself, so issues can be identified and action can be taken at an early stage.
What needs improvement?
SonarQube does not have robust or strong rules because I have seen some other products able to identify specific vulnerabilities in the code base that SonarQube is unable to identify.
Command injection analysis is needed to make SonarQube a better product. For technologies such as C and C++, SonarQube does not have static analysis tools or custom rules available, but other open source tools do, and they are able to identify vulnerabilities. It is comparatively easy to add custom rules compared to SonarQube.
For how long have I used the solution?
I have been working with SonarQube for more than four or five years, using the SonarQube product, including SaaS, scanners, secrets, and advanced software composition analysis.
How are customer service and support?
The technical support for SonarQube is quite helpful and supportive, at least with my recent experience. I would rate support an eight out of ten.
What other advice do I have?
I feel that the licensing cost for SonarQube is on the higher side.
I would rate SonarQube around seven point five as a product because there are some areas where open-source tools are able to identify high and critical vulnerabilities in the code base that SonarQube is unable to do. There is a question of why to pay so much if open-source is available that helps to improve and secure the quality of the code base.
I am not involved in deployment, but from what I know, one person takes care of deployment, and maybe one more person from the infosec IT team is involved, so one to two people are involved in the deployment, maintenance, upgrade, or anything related.
From what I know, it does not take much time. I think it takes only a couple of hours, not a full day. My overall rating for this product is seven point five out of ten.
Code reviews have become more effective as integration with Jira and IDE plugins streamlines fixes
What is our primary use case?
We still use SonarQube, Nexus Lifecycle or Sonatype Lifecycle, and Fortify. We are still using the same tools. There should be about four or five tools in total.
What is most valuable?
The integration with Atlassian Jira is very useful and it works very well. The plugins to connect to the instance from your IDE such as IntelliJ work very well.
It's very effective for that.
What needs improvement?
The support is managed by another department, so I don't deal with that. However, there could be an improvement in providing additional training resources. SonarQube is very good at explaining everything, but we have another tool called Fortify where our division of IT managed to put a link to a Code Warrior site where our developers can learn about a specific type of issue, understand it fully, and learn. This I'm not seeing in our instance of SonarQube.
It's actually training for the developers. If there is a specific issue, such as cross-site request forgery, SonarQube is very clear in explaining what the issue is and how to fix it. However, there is another website called Code Warrior that really takes you through the entire journey, so you can truly understand what the issue is along with some actual coding examples. It's very effective. In the Fortify dashboard, we can actually click on a link that will open Code Warrior in the correct context. I think it would be a nice improvement for SonarQube as well.
For how long have I used the solution?
We have been using this for years.
Has helped our team catch code bugs and improve developer skills through actionable suggestions
What is our primary use case?
My main use case for SonarQube Cloud (formerly SonarCloud) is for code checking and the quality of code.
A specific example of how I use SonarQube Cloud (formerly SonarCloud) for code checking and quality is that we have enabled quality gates for the pipeline.
What is most valuable?
The best features SonarQube Cloud (formerly SonarCloud) offers are that it is quite good and offers a perfunct feature.
The perfunct feature in SonarQube Cloud (formerly SonarCloud) shows the bugs in the codes and suggests the fixes.
SonarQube Cloud (formerly SonarCloud) has had a positive impact on my organization by giving the best impact for code checking and code structuring, making the code more usable and better.
It has made my code better because the team can improve their skills. It suggests fixes where needed, enabling the team to code better and maintain high code quality.
What needs improvement?
SonarQube Cloud (formerly SonarCloud) performs well currently and I cannot identify any needed improvements at this time.
For how long have I used the solution?
I have been using SonarQube Cloud (formerly SonarCloud) for three years.
What do I think about the stability of the solution?
In my experience, SonarQube Cloud (formerly SonarCloud) is stable and I did not face any major issues.
What do I think about the scalability of the solution?
SonarQube Cloud (formerly SonarCloud) has handled my organization's needs as we've grown.
How are customer service and support?
The customer support for SonarQube Cloud (formerly SonarCloud) has been better. Some of my teammates have interacted with support by raising tickets, and their issues were successfully resolved.
What other advice do I have?
My advice to others is to use SonarQube Cloud (formerly SonarCloud).
I rate SonarQube Cloud (formerly SonarCloud) nine out of ten.
We maintain high code standards with effective static code analysis and integration
What is our primary use case?
The primary use cases of SonarQube Server (formerly SonarQube) in my system include static code analysis, code review, unit test coverage, and similar functionalities.
I use its multi-dimensional analysis for code quality inspection because the product comes with its own features and capabilities, which are sufficient for us at this point in time.
What is most valuable?
The most valuable features in SonarQube Server (formerly SonarQube) are static code analysis, code review, and unit test coverage, with heavy usage of all three.
I have used SonarQube Server (formerly SonarQube)'s centralized management and visualization of code quality metrics. This feature helps me in understanding and improving code quality trends over time because we are able to set a standard.
The ability to tailor metrics tracking with SonarQube Server (formerly SonarQube) has been beneficial to my team and stakeholders as we are able to get portfolio reports and project-wise reports, though there are areas for improvement.
What needs improvement?
SonarQube Server (formerly SonarQube) could be improved on the reporting front. Instead of grouping, I would prefer to scan the code as part of development and then generate a report on a daily basis among different units or projects, which is currently complicated. We need to change it to more of a portfolio report, where configuring or setting up things on the portfolio requires tagging at the ADO level.
For how long have I used the solution?
I have been working with SonarQube Server (formerly SonarQube) for six or seven years. Our organization is structured with an enterprise security team which handles all primary security and other matters. From the application standpoint, we wanted to explore something within our unit. That is where we were exploring this solution, and for peer review we have been using a couple of tools during this time.
What was my experience with deployment of the solution?
Since it is a web application, it doesn't take much time to deploy.
How are customer service and support?
I haven't had much interaction with technical support because I rarely needed it. I reached out to them once or twice in the last five years, and the support was satisfactory.
Which solution did I use previously and why did I switch?
I cannot provide many details on which other solutions I evaluated before choosing SonarQube Server (formerly SonarQube).
How was the initial setup?
The deployment process was easy.
What was our ROI?
It is challenging to determine the return on investment because it requires substantial effort in tracking. I am satisfied overall because it's more about maintaining standards and being able to prevent issues before they occur. I am unable to extract specific data to calculate value gained because there are many moving elements, and some of the costs saved by developers are difficult to quantify.
What other advice do I have?
I am still exploring new solutions while using the current one.
I have been generally satisfied with this tool, rating it 9 out of 10. With the emergence of AI, I am exploring that aspect as well.
I assess the impact of SonarQube Server (formerly SonarQube)'s integration with DevOps pipelines on my development workflow as quite good. The only area that could be improved is SonarLint for IDE integration.
Regarding additional features for the next release, I would suggest improvements in the AI area.
Offers significant benefits in code quality but user interface improvements needed
What is our primary use case?
Once integrated with the pipeline for the organization, we would be able to fetch vulnerabilities and code smells. We can have quality gates installed in the pipeline so that the pipeline should only be moved and processed further if the quality gates are passed.
This product is used with the deployment cycles. We have multiple CI/CD pipelines.
When we push our code to the repo, while in continuous integration, it will run a few tests. Based on the vulnerability data set it has, it has multiple tests. We can also have multiple unit tests along with this for code coverage. It has multiple offerings, not only the quality check and the vulnerability check. It also has code coverage, indicating how much code is covered by all the unit tests, integration tests, and those sorts of things. It has a complete database by itself and depending on that, it needs to be regularly updated so that we can track the vulnerabilities in the code. If it is not connected to the data source, for example, it has 10 versions, so if we are using a very old version, it would not be able to track the vulnerabilities which have the latest release.
We can track the vulnerabilities if our code is updated. If we are using the cloud version, then it is automatically upgraded because it is a paid version. We can track the vulnerabilities, where the vulnerability is, and at which code line we need to improve our code. We can have all the tracks only after we push our code to the repo.
What is most valuable?
SonarQube Cloud (formerly SonarCloud) has two offerings: cloud and server. We can use either of these. One is a paid version, and another one is a free version.
I have used the SonarQube Cloud (formerly SonarCloud)'s code analysis feature.
What needs improvement?
Sometimes, there are tracking issues. It has its own graphical GUI where we can track everything.
Since most of our projects are open source, there are multiple features which can be improved. For example, while creating a PR, the automatic runs from SonarQube Cloud (formerly SonarCloud) should also be run, but this is a feature which was in the previous version, but not with this version. You need to spend some money to buy that feature.
SonarQube Cloud (formerly SonarCloud) is one of the first of its kind which supports all these functionalities. I do not have any perception of documentation or support because once it is integrated with the pipeline, most of the task is done. The people who are developers need automatic bug creation and everything is done. This feature can be improved where, once it tracks the criticals and highs, it should create automatic tickets and assign them to the user who has pushed the code.
For how long have I used the solution?
I have used the SonarQube Cloud (formerly SonarCloud)'s code analysis feature.
What was my experience with deployment of the solution?
We have used it in AWS, but not from the marketplace.
Which other solutions did I evaluate?
We use other products because SonarQube Cloud (formerly SonarCloud) only offers SAST. It doesn't cover DAST, SCA, or those sorts of testing. Also, performance-based testing is not covered.
What other advice do I have?
SonarQube Cloud (formerly SonarCloud) doesn't offer notifications, but we have some features in the pipeline which send notifications to the team leads or the assigned users to review the code.
SonarQube Cloud (formerly SonarCloud) is one of the first of its kind which supports all these functionalities. I do not have any perception of documentation or support because once it is integrated with the pipeline, most of the task is done. The people who are developers need automatic bug creation and everything is done. This feature can be improved where, once it tracks the criticals and highs, it should create automatic tickets and assign them to the user who has pushed the code.
On a scale of one to ten, I would give SonarQube Cloud (formerly SonarCloud) a rating of six.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Consistent improvements in code quality and security with effective integration and reliable technical support
What is our primary use case?
My main use cases for SonarQube Server (formerly SonarQube) are mostly focused on static code analysis. We use it at the development level to improve the quality of the code and to analyze the technical debt of the current systems.
What is most valuable?
The features of SonarQube Server (formerly SonarQube) that I find most useful are the suggestions received from reviewing the code. When they review the code, they provide suggestions on how to fix it, and we find those very useful from a development perspective.
We use SonarQube Server's (formerly SonarQube) centralized management and visualization of code quality metrics on the dashboard because that's the executive dashboard that we send to the executives to show where we are in terms of quality, security, and where the company can improve. We use that for organizational improvement purposes.
The ability to tailor metrics tracking in SonarQube Server (formerly SonarQube) has been beneficial to my team. There are team-specific dashboards which are related to specific repositories they utilize, and we have that aggregative dashboard that shows the whole organization's performance. We can drill down per specific repository, which makes it easier for the team to improve specific things.
What needs improvement?
I think SonarQube Server (formerly SonarQube) should improve by integrating a new feature that includes AI. As soon as I see that they've got a new feature that integrates AI that is not as generative as other GenAI platforms that actually generate the code and help developers develop faster, I believe that capability is lacking. Currently, it should also be able to analyze the code and generate and fix the code for specific developers or features that the developers are tracking.
For how long have I used the solution?
I have been working with SonarQube Server (formerly SonarQube) for more than five years.
What do I think about the stability of the solution?
SonarQube Server (formerly SonarQube) is very stable. I have never experienced any crashes at all.
What do I think about the scalability of the solution?
I find SonarQube Server (formerly SonarQube) very scalable because we're able to create a new repository and integrate all the tools on that project and it just works.
How are customer service and support?
The technical support for SonarQube Server (formerly SonarQube) is great. It was only once when we wanted to extract some reports, and they showed us where we can actually get those granular level reporting extracted for Excel, which was a quick guide. I would give it a nine. The reason for giving a nine is that the developers could have informed us about other features that are outside of what we see.
Which solution did I use previously and why did I switch?
We previously decided to use AppScan before SonarQube Server (formerly SonarQube). AppScan had many features that were not available that SonarQube Server (formerly SonarQube) was offering. The code suggestion was one of those features we were looking for, so we opted for SonarQube Server (formerly SonarQube) after AppScan.
How was the initial setup?
The initial setup experience with SonarQube Server (formerly SonarQube) is quite straightforward. The adaptation in the current organization when we introduced SonarQube Server (formerly SonarQube) was a bit difficult for the developers, but with my experience from a developer perspective, it helped drive the adoption. I would rate it probably nine. We implemented it ourselves with a DevOps team that was handling it in our space, and there was no difficulty at all.
What was our ROI?
During these years of usage, I see that the return on investment with SonarQube Server (formerly SonarQube) is mostly implicit because there are costs. We see productivity increasing based on the fact that the code review is mostly automated, allowing the developer to fix the code themselves before assigning it to someone else to review, thus receiving that ROI.
What's my experience with pricing, setup cost, and licensing?
The price of SonarQube Server (formerly SonarQube) is reasonable for my company, but it's actually per organizational infrastructure. We pay about 1.2 million rand in terms of South African rands per year. They always offer around a two-year contract, but we always take a one-year contract because it's expensive.
There are no additional costs apart from the license cost. That's the whole cost of enterprise SonarQube Server (formerly SonarQube).
What other advice do I have?
We definitely use SonarQube Server (formerly SonarQube) for vulnerabilities and the security aspect of it. It's very effective because we've managed to address issues such as code that was exposing passwords, so we had to restructure the code to mask security passwords.
The integration of SonarQube Server (formerly SonarQube) with DevOps pipelines on my development workflow is very good. We use both GitHub and Azure DevOps, and it integrates well with both repositories that we utilize. In my previous company, we were using GitLab, and it integrated with GitLab without any issues at all.
The main benefits from using SonarQube Server (formerly SonarQube) are improvements in handling security and vulnerabilities. In our space, there have been huge improvements. Some teams had almost 1,000 plus issues with security, but now we're sitting at around 50. That has helped us quite a bit, and also the automated code review process speeds up the process of reviewing code.
The flexibility of deploying SonarQube Server (formerly SonarQube) both in cloud and on-prem has adapted to our organization's infrastructure needs. We've never used the cloud version of it. We use on-premises because of the reporting facilities that SonarCloud didn't have.
I rate SonarQube Server (formerly SonarQube) a nine out of ten. I recommend it as it can integrate with any repository tool, making it quite easy to integrate with your code. If you want to reduce your technical debt, you should look no further than SonarQube Server (formerly SonarQube).
Gains control over rule customization and achieves reliable vulnerability assessment
What is our primary use case?
My usual use cases for SonarQube Server (formerly SonarQube) are for static code analysis to detect any build vulnerabilities, and we use it only for this reason.
What is most valuable?
The most valuable features of SonarQube Server (formerly SonarQube) for us include having control of the rules, enabling and disabling them. This feature was very helpful. However, I see a problem because the vulnerability assessment is continuous; if I fix some vulnerabilities today, they reappear in the next scan, and there will be completely different issues that need to be fixed. So, there should be a way for me to control when SonarQube can scan or when it should not scan.
What needs improvement?
I see a problem with SonarQube Server (formerly SonarQube) because the vulnerability assessment is continuous; if I fix some vulnerabilities today, they reappear in the next scan, and there will be completely different issues that need to be fixed. So, there should be a way for me to control when SonarQube can scan or when it should not scan.
For how long have I used the solution?
I have been working with SonarQube Server (formerly SonarQube) in my current organization for about 2 to 3 years, and in my previous organization, overall, it has been more than 10 years.
What do I think about the stability of the solution?
I think SonarQube Server (formerly SonarQube) is stable, and we did not face any problems unless there was a power outage or if the LAN cable was plugged out. Apart from that, I do not see issues with the SonarQube instance coming down, so it is reliable. I would give it a mark of 10 out of 10.
What do I think about the scalability of the solution?
I would rate the scalability of SonarQube Server (formerly SonarQube) as a 10 because we can configure the server to scan multiple projects based on the number of lines, and it is not an issue for us to integrate many projects into SonarQube.
How are customer service and support?
I would rate the technical support for SonarQube Server (formerly SonarQube) as a 10 because we have not faced any specific issues that required us to contact tech support, which is a very rare case. It was a long time back since we connected with tech support, but I do not remember the specific reason.
Which solution did I use previously and why did I switch?
Before using SonarQube Server (formerly SonarQube), I was using Coverity.
I decided to switch from Coverity to SonarQube Server (formerly SonarQube) about a year back. We are making use of both because, in the medical devices space, SonarQube recently got FDA approval, which means it is now capable, and the FDA accepts the report from SonarQube. Previously, the FDA had restrictions on SonarQube and accepted reports only from Coverity, which was a certified tool. Since SonarQube obtained this certification, we are slowly switching from Coverity to SonarQube.
How was the initial setup?
I would rate my experience with the initial setup of SonarQube Server (formerly SonarQube) as an 8 or 9, considering 10 as easy. It is all documented, and we get enough support even from the online community, making it easy to configure SonarQube once we receive the license.
What about the implementation team?
Two people were involved in the deployment process of SonarQube Server (formerly SonarQube).
Now, I need one person for the maintenance of SonarQube Server (formerly SonarQube).
What was our ROI?
I have seen a return on the investment from SonarQube Server (formerly SonarQube) because the value it adds relates to static code analysis and vulnerability assessments needed for our FDA approval process. It is a must for us to generate these reports.
What's my experience with pricing, setup cost, and licensing?
I would rate the pricing for SonarQube Server (formerly SonarQube) as an 8, where 1 is very cheap and 10 is very expensive, because Coverity is very expensive, and while SonarQube is not cheap, it is still less expensive than Coverity. Since there are not many players in this space with FDA regulation approvals, I find the pricing justifiable.
Which other solutions did I evaluate?
I decided to go with SonarQube Server (formerly SonarQube) because it is a good solution.
What other advice do I have?
The deployment process took me about 2 or 3 hours to deploy SonarQube Server (formerly SonarQube), although I do not remember exactly since it was done about 2 years back.
Currently, about 10 of my developers are using SonarQube Server (formerly SonarQube) in my company.
I do not have plans to increase the usage of SonarQube Server (formerly SonarQube) in the future as there will not be any requirement to increase.
I am a senior software engineer and supervisor at Mozark Medical.
My corporate email address is karthik.k.a.r.t.h.i.k.h.a.r.p.a.n.h.a.l.l.i@mozarkmedical.com.
Overall, I would rate SonarQube Server (formerly SonarQube) as a 9 out of 10.