Introducing SonarQube Advanced Security

Build a Comprehensive Security Shield—from Source Code to Dependencies

Advanced Security is SonarQube’s enterprise-grade security extension, powered by semantic SAST technology. It enables deep detection of high-risk vulnerabilities such as SQL injection, XSS, and command injection. With full coverage across custom code, AI-generated code, and open-source components, it empowers organizations to implement smarter, more accurate security measures early in the development lifecycle.

SonarQube core security

SAST

Detect code vulnerabilities, early in development

Taint analysis

Cross-file data flow analysis to prevent injection attacks

IaC scanning

Secure cloud infrastructure configurations

Secrets detection

Prevent exposure of credentials, tokens, and keys

ADD-ON

Advanced Security

Requires SonarQube Server 2025 Release 3 Enterprise or higher

Integrated Advanced SAST and SCA

Deeper Vulnerability Detection and Open Source Risk Management
Comprehensive Protection for Your Code Security

Advanced SAST

Extends taint analysis to dependencies to uncover complex vulnerabilities:

SCA

Comprehensive open source risk & compliance management :

Advanced SAST

Deeper taint analysis

Dependency-aware taint analysis to find hidden security flaws

SCA

CVE detection

Fix known vulnerabilities (CVEs)

SCA

License management

SCA

Software Bill of Materials (SBOM)

Advanced SAST benefits

Find deeply hidden security issues

99% of software applications use and interact with the code in third-party libraries (dependencies). Today, most SAST tools only analyze application code and not library code which are mostly a black box for these tools.

Advanced SAST from Sonar extends code analysis and scanning to cover the unknown parts of the code that are in the open-source dependencies. Scanning dependencies (libraries) allows Sonar SAST to extend the dataflow analysis and find deeply hidden security issues in code that other tools cannot find.

Advanced SAST is available today for Java, C#, and JavaScript/TypeScript in SonarQube Server and SonarQube Cloud. It supports thousands of the topmost and commonly used open-source libraries, including their subsequent (transitive) dependencies. It scales automatically and will be expanded to cover more languages and libraries in the future. Machine Learning (ML) is used for optimization.

Accelerate secure development

SAST can be performed earlier in the software development lifecycle (SDLC) before code is deployed into and released into production. Utilizing SAST in the development phase allows security vulnerabilities and bugs to be identified and remediated more quickly before they can be exploited by attackers.

SAST analysis of Pull Requests helps empower developers by shifting security left and presenting security vulnerabilities as early as possible in the process - when the code is fresh in mind and the fix is still easy.

SAST is available by default with SonarQube Server and SonarQube Cloud and runs as part of a normal code analysis and integrates seamlessly with the DevSecOps pipeline.

Reduce risk of security breaches

By implementing secure coding practices, organizations can enhance the quality of their codebase and prevent malicious attackers from exploiting vulnerabilities to steal sensitive information.

Sonar analyzers identify issues—such as bugs, vulnerabilities, and security hotspots—during code scans to uncover potential security risks. When Sonar detects an exploitable weakness in the code that requires remediation, it reports it as a vulnerability. Security-sensitive code sections that need developer review and assessment are categorized as “security hotspots.”

Sonar’s security rules also detect hardcoded credentials, such as passwords and keys. The cloud secrets detection feature extends these rules to identify unintentionally hardcoded passwords, credentials, tokens, cloud access keys, API keys, and account/secret information embedded in code. It supports major cloud providers, including AWS, GCP, Microsoft Azure, IBM, and Alibaba Cloud.

Automate code scanning

Sonar SAST can scan large amounts of code quickly – saving time and money in the software development life cycle process. Automating code scanning with SAST helps improve the overall security posture of an application and reduces the reliance on manual code reviews, allowing developers to focus on remediation efforts while maintaining an efficient and secure development lifecycle. Developers can identify and address code quality and security issues early in the development lifecycle; promoting continuous improvement by providing actionable insights, security reports, and metrics that help teams track and enhance the overall code of their applications.

Code security and compliance

Sonar provides comprehensive application security tracking and governance for the most complex projects with SAST. It allows security auditors to track code security compliance and evaluate the risks on their software assets at an enterprise level with detailed reports. Security reports, executive aggregation, and PDF reports provide the oversight larger organizations need to evaluate risks on their software assets. Using Sonar SAST can quickly give security champions the big picture of their application's security posture.

In SonarQube Server Enterprise Edition and Data Center Edition and in SonarQube Cloud Enterprise Plan, dedicated reports track the application’s code security against standards such as OWASP Top 10, OWASP ASVS, CWE Top 25 (2021, 2020, and 2019), STIG, CASA, as well as PCI DSS. The SonarSource report helps security professionals translate security problems into language developers understand.

Comprehensive detection engine and coverage

Sonar provides code quality and security analysis for 30+ languages (and frameworks), with more than 6,000 out-of-the-box Clean Code rules – and is continuously updating the scope of languages covered. Sonar detects bugs and security flaws at the code level – source code, support code (including config code, infrastructure code, scripting, and test code), and third-party code, such as external dependencies and libraries – often exceeding a true positive rate (TPR) of 90%.

Security coverage includes cross-site scripting, SQL injection, path injection, to secrets, IaC misconfigurations, phishing, and a variety of others.

SCA benefits

Unblock developers with actionable solutions

Empowering developers to work efficiently, Sonar provides actionable solutions that help prioritize and address the most critical issues first. With clear remediation guidance and a structured list of detected problems, teams can resolve issues effectively and stay focused on continuous building and innovation.

Deep open source insights

Long-term contractual partnerships with open source project maintainers provide strong economic incentives for secure development and rapid vulnerability response, helping enterprises build a more proactive security posture. These collaborations also offer unique insights into license compliance and vulnerability data.

Eliminate tool sprawl and developer toil

As an integrated code quality solution, SonarQube seamlessly analyzes all code within existing development workflows—from IDE to CI/CD—without requiring additional configuration. It significantly reduces management overhead, supports the implementation of a shift-left testing strategy, and boosts both development efficiency and code quality.

Unmatched accuracy and speed

Achieve fast analysis with an exceptionally low false positive rate, enabling your team to focus on real threats and code quality issues. By minimizing distracting noise, Sonar helps streamline issue resolution and accelerate quality improvements.

Comprehensive license compliance

Navigate the complexities of open source licensing with accurate and reliable data, helping you confidently mitigate legal and business risks and ensure compliant operations across your organization.

SonarQube security reports

Comprehensive reporting for all security issues in all code

Actionable insights

Detailed code security findings with severity, trends, and remediation guidance

Rich dashboards Visualize

quality and security trends, and KPIs in unified dashboards

Compliance reports

Generate security reports for OWASP Top 10, CWE, PCI DSS, STIG, and more

Scheduled reports

Automate report delivery on daily, weekly, or monthly schedules

Integrated code quality and code security

SonarQube is an integrated code quality and security analysis platform that provides actionable intelligence to help build better software, faster.

Elevate code quality standards

Deliver robust, reliable, and maintainable code with fast, accurate analysis across all code

Core security: foundation for secure code

Includes SAST, taint analysis, secrets detection, IaC scanning for first-party and AI-generated code

Advanced Security add-on

Advanced Security extends to open source code with advanced SAST and Software Composition Analysis (SCA)

DragonSoft Provides Localized SonarQube Support Empower Your Team to Build a Safer, More Reliable Code Quality Framework

As an officially authorized Sonar partner, DragonSoft is committed to helping enterprises successfully implement SonarQube and its Advanced Security features to strengthen code security and ensure high-quality standards.

We offer end-to-end services—from deployment to training—and can tailor security governance solutions based on your development workflows, enabling your team to quickly identify and remediate critical vulnerabilities.

Whether you're introducing a code review tool for the first time or looking to integrate advanced code security into your existing systems, DragonSoft provides expert technical consulting, implementation, compliance guidance, and ongoing support. We ensure you stay at the forefront of DevSecOps while leveraging the latest security capabilities of SonarQube.

Contact DragonSoft today — start your journey toward enterprise-grade secure development.