
Built on SonarQube’s powerful security foundation—including SAST, secrets detection, taint analysis, and IaC scanning—our solution extends deep, comprehensive protection to your dependencies. Gain greater visibility and control to manage complex codebases and software supply chains with confidence.
We provide end-to-end services for SonarQube Advanced Security, including consulting, licensing, implementation, training, and ongoing support.

Advanced Security is SonarQube’s enterprise-grade security extension, powered by semantic SAST technology. It enables deep detection of high-risk vulnerabilities such as SQL injection, XSS, and command injection. With full coverage across custom code, AI-generated code, and open-source components, it empowers organizations to implement smarter, more accurate security measures early in the development lifecycle.
Detect code vulnerabilities, early in development
Cross-file data flow analysis to prevent injection attacks
Secure cloud infrastructure configurations
Prevent exposure of credentials, tokens, and keys
ADD-ON
Advanced Security
Requires SonarQube Server 2025 Release 3 Enterprise or higher
Extends taint analysis to dependencies to uncover complex vulnerabilities:
Comprehensive open source risk & compliance management :
Advanced SAST
Dependency-aware taint analysis to find hidden security flaws
SCA
Fix known vulnerabilities (CVEs)
SCA
SCA
99% of software applications use and interact with the code in third-party libraries (dependencies). Today, most SAST tools only analyze application code and not library code which are mostly a black box for these tools.
Advanced SAST from Sonar extends code analysis and scanning to cover the unknown parts of the code that are in the open-source dependencies. Scanning dependencies (libraries) allows Sonar SAST to extend the dataflow analysis and find deeply hidden security issues in code that other tools cannot find.
Advanced SAST is available today for Java, C#, and JavaScript/TypeScript in SonarQube Server and SonarQube Cloud. It supports thousands of the topmost and commonly used open-source libraries, including their subsequent (transitive) dependencies. It scales automatically and will be expanded to cover more languages and libraries in the future. Machine Learning (ML) is used for optimization.
SAST can be performed earlier in the software development lifecycle (SDLC) before code is deployed into and released into production. Utilizing SAST in the development phase allows security vulnerabilities and bugs to be identified and remediated more quickly before they can be exploited by attackers.
SAST analysis of Pull Requests helps empower developers by shifting security left and presenting security vulnerabilities as early as possible in the process - when the code is fresh in mind and the fix is still easy.
SAST is available by default with SonarQube Server and SonarQube Cloud and runs as part of a normal code analysis and integrates seamlessly with the DevSecOps pipeline.
By implementing secure coding practices, organizations can enhance the quality of their codebase and prevent malicious attackers from exploiting vulnerabilities to steal sensitive information.
Sonar analyzers identify issues—such as bugs, vulnerabilities, and security hotspots—during code scans to uncover potential security risks. When Sonar detects an exploitable weakness in the code that requires remediation, it reports it as a vulnerability. Security-sensitive code sections that need developer review and assessment are categorized as “security hotspots.”
Sonar’s security rules also detect hardcoded credentials, such as passwords and keys. The cloud secrets detection feature extends these rules to identify unintentionally hardcoded passwords, credentials, tokens, cloud access keys, API keys, and account/secret information embedded in code. It supports major cloud providers, including AWS, GCP, Microsoft Azure, IBM, and Alibaba Cloud.
Sonar SAST can scan large amounts of code quickly – saving time and money in the software development life cycle process. Automating code scanning with SAST helps improve the overall security posture of an application and reduces the reliance on manual code reviews, allowing developers to focus on remediation efforts while maintaining an efficient and secure development lifecycle. Developers can identify and address code quality and security issues early in the development lifecycle; promoting continuous improvement by providing actionable insights, security reports, and metrics that help teams track and enhance the overall code of their applications.
Sonar provides comprehensive application security tracking and governance for the most complex projects with SAST. It allows security auditors to track code security compliance and evaluate the risks on their software assets at an enterprise level with detailed reports. Security reports, executive aggregation, and PDF reports provide the oversight larger organizations need to evaluate risks on their software assets. Using Sonar SAST can quickly give security champions the big picture of their application's security posture.
In SonarQube Server Enterprise Edition and Data Center Edition and in SonarQube Cloud Enterprise Plan, dedicated reports track the application’s code security against standards such as OWASP Top 10, OWASP ASVS, CWE Top 25 (2021, 2020, and 2019), STIG, CASA, as well as PCI DSS. The SonarSource report helps security professionals translate security problems into language developers understand.
Sonar provides code quality and security analysis for 30+ languages (and frameworks), with more than 6,000 out-of-the-box Clean Code rules – and is continuously updating the scope of languages covered. Sonar detects bugs and security flaws at the code level – source code, support code (including config code, infrastructure code, scripting, and test code), and third-party code, such as external dependencies and libraries – often exceeding a true positive rate (TPR) of 90%.
Security coverage includes cross-site scripting, SQL injection, path injection, to secrets, IaC misconfigurations, phishing, and a variety of others.
Empowering developers to work efficiently, Sonar provides actionable solutions that help prioritize and address the most critical issues first. With clear remediation guidance and a structured list of detected problems, teams can resolve issues effectively and stay focused on continuous building and innovation.
Long-term contractual partnerships with open source project maintainers provide strong economic incentives for secure development and rapid vulnerability response, helping enterprises build a more proactive security posture. These collaborations also offer unique insights into license compliance and vulnerability data.
As an integrated code quality solution, SonarQube seamlessly analyzes all code within existing development workflows—from IDE to CI/CD—without requiring additional configuration. It significantly reduces management overhead, supports the implementation of a shift-left testing strategy, and boosts both development efficiency and code quality.
Achieve fast analysis with an exceptionally low false positive rate, enabling your team to focus on real threats and code quality issues. By minimizing distracting noise, Sonar helps streamline issue resolution and accelerate quality improvements.
Navigate the complexities of open source licensing with accurate and reliable data, helping you confidently mitigate legal and business risks and ensure compliant operations across your organization.
Comprehensive reporting for all security issues in all code
Detailed code security findings with severity, trends, and remediation guidance
quality and security trends, and KPIs in unified dashboards
Generate security reports for OWASP Top 10, CWE, PCI DSS, STIG, and more
Automate report delivery on daily, weekly, or monthly schedules
SonarQube is an integrated code quality and security analysis platform that provides actionable intelligence to help build better software, faster.
Deliver robust, reliable, and maintainable code with fast, accurate analysis across all code
Includes SAST, taint analysis, secrets detection, IaC scanning for first-party and AI-generated code
Advanced Security extends to open source code with advanced SAST and Software Composition Analysis (SCA)
As an officially authorized Sonar partner, DragonSoft is committed to helping enterprises successfully implement SonarQube and its Advanced Security features to strengthen code security and ensure high-quality standards.
We offer end-to-end services—from deployment to training—and can tailor security governance solutions based on your development workflows, enabling your team to quickly identify and remediate critical vulnerabilities.
Whether you're introducing a code review tool for the first time or looking to integrate advanced code security into your existing systems, DragonSoft provides expert technical consulting, implementation, compliance guidance, and ongoing support. We ensure you stay at the forefront of DevSecOps while leveraging the latest security capabilities of SonarQube.
Contact DragonSoft today — start your journey toward enterprise-grade secure development.