18 años ayudando a las empresas
a elegir el mejor software

Sobre SonarQube

Integra fácilmente SonarQube en tu flujo de CI/CD (integración y entrega continuas, por sus siglas en inglés) para romper la compilación cuando no se cumplen tus estándares de calidad y para implementar solo código limpio.

Descubre más sobre SonarQube

Puntos a favor:

The only thing is that the UI integration could be improved.

Puntos en contra:

Integration with visual studio code and binding with project is tad difficult.

Valoraciones de SonarQube

Evaluación media

Facilidad de uso
4,3
Atención al cliente
4,0
Funcionalidades
4,4
Relación calidad-precio
4,4

Probabilidad de recomendación

8,7/ 10

SonarQube tiene una valoración global de 4,5 estrellas sobre 5 según las 64 opiniones de usuarios de Capterra.

¿Has utilizado SonarQube?

Comparte tu experiencia con otros compradores de software.

Filtrar opiniones (64)

Jimmy R
Oficial de seguridad de la informacion en Colombia
Ocio, viajes y turismo, 201-500 empleados
Ha utilizado el software durante: Más de un año
Fuente de la opinión

Mejoras para Sonarqube

4,0 hace 2 meses

Comentarios: Buena herramienta para equipo red de una empresa y de manera gratis puedes crear plantillas de correo para todas las areas o parte de ellas

Puntos a favor:

Envió de campañas de phising a usuarios de la empresa para reforzar ciberseguridad de las empresas

Puntos en contra:

la configuración inicial es complicada y la gestión de seguridad envió de correos, hay pocos ejemplos practicos o estan fuera de actualizacion

Pedro
Pedro
consultant en España
Usuario de Linkedin verificado
Software informático, 5.001-10.000 empleados
Ha utilizado el software durante: Más de un año
Fuente de la opinión

Manten código de calidad gracias a SonarQube

4,0 hace 2 años

Puntos a favor:

Me gusta mucho la integración con el servicio de devops de azure, gracias a ello puedo integrar las tareas de revisión de código de SonartiQube en la integración continua. Los reportes que genera son de gran utilidad para detectar malas prácticas o brechas de seguridad en el código.

Puntos en contra:

Me gustaría que el panel de administración de la herramienta fuera más configurable, para poder hacer que el análisis de código sea más efectivo.

Raul Antonio
Raul Antonio
Graduate en EE. UU.
Usuario de Linkedin verificado
Música, 2-10 empleados
Ha utilizado el software durante: Prueba gratis
Fuente de la opinión

Essential tool to guarantee quality and safety

4,0 hace 2 años

Comentarios: As a developer, it has been an invaluable tool in improving the quality and security of my code. It has helped me proactively identify and address issues, allowing me to run cleaner, less bug-prone software.

Puntos a favor:

I love its ability to provide a clear and concise view of code quality.

Puntos en contra:

At first, I found it a bit overwhelming to understand all the available features and settings. Although the documentation and support help, I think there could be a better guide for new users.

Yusmeidy
Java Developer en Chile
Telecomunicaciones, 1.001-5.000 empleados
Ha utilizado el software durante: Más de dos años
Fuente de la opinión

Well defined by consistency and high operability

4,0 hace 10 meses

Comentarios: Brings quality and professionalism in the final results. It is an impressive tool.

Puntos a favor:

One of the outstanding values about SonarQube is the speed of analysis. It makes it easy to collaborate with other features to generate clean codes. I and my team had an easy time during deployment. It was quite easy to relate with our needs. Combining all this benefits leads to a consistent and reliable coding behavior.

Puntos en contra:

Installation of the tool was troublesome. We were forced to buy a new device with higher processing speed to avoid the numerous rebooting. Later, deployment and use was smooth.

Michal
Software Engineer en Canadá
Contabilidad, 501-1.000 empleados
Ha utilizado el software durante: Más de un año
Fuente de la opinión

Perfect for detecting unit test coverage

4,0 hace 3 semanas Nuevo

Puntos a favor:

SonarQube is good at enforcing minimum code coverage on PRs

Puntos en contra:

It is really difficult to run it locally, however once set up on github it runs well, and provides valuable insights on code coverage.

Zach
CEO OWner en EE. UU.
Seguridad informática y de redes, 11-50 empleados
Ha utilizado el software durante: Más de un año
Fuente de la opinión
Fuente: SoftwareAdvice

Never use SonarQube

1,0 el mes pasado Nuevo

Comentarios: This service is a complete scam. Let's start with how it ended. I canceled my account, only to find out that it did not actually cancel. So I contacted support. It took them 2 months to resolve my request and they continued billing my card when the account was 100% not in use and I had no access to it. Now they refuse to refund my money. This is after they increased the cost of my plan by 3x without my approval (which is what prompted me to want to leave). In order to try to reduce my cost, our engineering team attempted to discsonnect some unused repos... nope, not possible. NEVER use this service. You absolutely cannot trust them. It's unbelievable that their system cannot be canceled and yet somehow it's my fault and I continue to get billed while their support team takes weeks to respond.

Puntos a favor:

There is nothing about this company that I would ever recommend.

Puntos en contra:

Of all the terrible things about this service and company, it's their customer support that takes the cake!

Kreasan
Jnr HR Business Partner en Sudáfrica
Construcción, 10.000+ empleados
Ha utilizado el software durante: Más de dos años
Fuente de la opinión

SonarQube delivers high code quality standards for every project

5,0 hace 10 meses

Comentarios: Vibrant customer service and interactive product demo. Their work is great and commendable.

Puntos a favor:

For a while, I used the SonarQube product demo which is great and interactive giving the best experience. The dashboard is easy to use since it is designed with a lot of clarity and motivation. While in use, SonarQube can detect and help remove secrets in code but at the same time offering security against any breaches. Dealing with security vulnerabilities in codes is now made possible. Lastly, there are clear security reports in PDF form which helps us to evaluate the risks on our systems.

Puntos en contra:

It meets our quality and security expectations. No setbacks.

Usuario verificado
Usuario de Linkedin verificado
Tecnología y servicios de la información, 201-500 empleados
Ha utilizado el software durante: 6-12 meses
Fuente de la opinión

Elevate your code quality to the next level

4,0 hace 12 meses

Comentarios: The development process has been a bit slower than usual after SonarQube integration, but the quality and readability of the code is much better.

Puntos a favor:

The main feature of SonarQube is that it detects code complexities within the code so that the developer can optimize it. It also detects accessibility and security issues; code smells and suggests changes.

Puntos en contra:

It is a bit difficult to integrate with existing services and the quality checks may also conflict with other integrations.

Usuario verificado
Usuario de Linkedin verificado
Banca, 10.000+ empleados
Ha utilizado el software durante: Más de dos años
Fuente de la opinión

Code Quality Assurance

4,0 hace 12 meses

Comentarios: Overall, impressed by this tool that supports multiple languages, monitoring code quality, bugs and vulnerability detection. Also, integrates well with Jenkins, GitHub, etc.

Puntos a favor:

- It supports almost all commonly used languages like JAVA, Python, Javascript, etc. - Integrates well with CI/CD pipeline established in tools like Jenkins and GitHub. - Detects code duplication, bugs and vulnerabilities in code.

Puntos en contra:

- May be complex to understand the reports for new users. - May block delivery/deployment if hard gates are enabled by DevOps team which may delay project delivery.

Allyson
Senior Staff Engineer en Alemania
Software informático, 51-200 empleados
Ha utilizado el software durante: 6-12 meses
Fuente de la opinión

Navigating Code Clarity with SonarQube

5,0 hace 10 meses

Puntos a favor:

I love SonarQube's real-time code analysis, providing instant feedback. Recently, while working on a project, it flagged potential code smells, helping me enhance code quality preemptively.

Puntos en contra:

It is sometimes overwhelming amount of information and alerts, which can make it challenging to prioritize and address issues effectively.

Anselmo
IT Strategy en Portugal
Servicios financieros, 501-1.000 empleados
Ha utilizado el software durante: Más de dos años
Fuente de la opinión

SonarQube cornerstone of our continuous development lifecycle

5,0 hace 11 meses

Puntos a favor:

Easy to use interface Rules flexibility Broad set of rules to activate

Puntos en contra:

No roadmap for dynamic analysis Reports API not so flexible Fixed price approach

Usuario verificado
Usuario de Linkedin verificado
Tecnología y servicios de la información, 1.001-5.000 empleados
Ha utilizado el software durante: 1-5 meses
Fuente de la opinión

SonarQube reivew

5,0 hace 11 meses

Puntos a favor:

SonarQube provides important metrics such as code smells, bugs, vulnerabilities, and code coverage. Easy integration with CI/CD tools.

Puntos en contra:

SonarQube may produce false positives, as with any static analysis tool.

Usuario verificado
Usuario de Linkedin verificado
Internet, Trabajador autónomo
Ha utilizado el software durante: Más de un año
Fuente de la opinión

Un super outil pour améliorer la qualité de code et la maintenir

5,0 el año pasado

Comentarios: J'ai utilisé SonarQube sur des repositories contenant des applications Angular, .NET et des scripts SQL. A chaque fois les recommandations étaient pertinentes et ont pu améliorer la qualité du code.

Puntos a favor:

SonarQube est complet. Il permet l'analyse de nombreux langages de développement sur plusieurs projets. Il propose de base plusieurs jeux de règles de qualité à appliquer et permet d'en ajouter d'autre. Pour chaque règle un exemple est fourni et des explications assez claire. Certaines règles concernent la qualité du code, mais pas que. Certaines touchent à la sécurité et d'autres aux performances. L'intégration dans un process de build via des tâches ou des jobs est assez facile.

Puntos en contra:

Le plus gros inconvénient de SonarQube est son coût qui peut s'avérer, selon les projets, un peu élevé. L'outil est néanmoins très facile à utiliser et à mettre en place.

Antonio
Software Engineering en Italia
Seguros, 51-200 empleados
Ha utilizado el software durante: 6-12 meses
Fuente de la opinión

Code quality matters

4,0 el año pasado

Comentarios: Very positive as it allows you to improve the writing of your code.

Puntos a favor:

Report both security and code quality vulnerabilities, indicating the reason for the flaw and the possible resolution. It allows you to set thresholds so as not to compromise too much the quality of the code and the coverage of the tests.

Puntos en contra:

It is necessary to configure it to avoid false positives in terms of code quality that can block the release of the code.

Franck
Franck
Software engineer en Camerún
Usuario de Linkedin verificado
Software informático, 11-50 empleados
Ha utilizado el software durante: Más de un año
Fuente de la opinión

Avis positif

5,0 hace 2 años

Puntos a favor:

Le fait que l'on puis enregistrer nos propre metriques pour les tests de qualités

Puntos en contra:

La documentation n'est pas forcément la plus aisée

Ie
DevOps Engineer en Estonia
Software informático, 1.001-5.000 empleados
Ha utilizado el software durante: Más de un año
Fuente de la opinión

Popular tool for code smell search in the organisation's repositories

5,0 hace 2 años

Puntos a favor:

Easy-to-administer tool, with good functionality to monitor security part of your code (using SAST methodology), with ability to integrate with Jenkins, GitHub and other tools. You are able to fail the build if the code doesn't meet percentage score.

Puntos en contra:

When new repository is added - there should be pop-up suggestion to create SonarQube project for it, coming from SonarQube. At the moment the user/administrator must watch out for new repositories in the organisation, without a note from the system itself that there is a new repository which you might want to add for scanning.

Susan
Software Engineer en Australia
Aerolíneas/aviación, 201-500 empleados
Ha utilizado el software durante: 6-12 meses
Fuente de la opinión

Great product!

5,0 hace 2 años

Puntos a favor:

This product has actually improved productivity within my team by making sure there’s no duplicate code and by making code easily understandable.

Puntos en contra:

Code maintenance is actually a difficult part.

Carlos
QAE en Portugal
Software informático, 1.001-5.000 empleados
Ha utilizado el software durante: Más de un año
Fuente de la opinión

SonarQube Review

4,0 hace 2 años

Comentarios: Overall experience about Sonarqube - Effective tool for improving code quality but demands expertise for setup and maintenance.

Puntos a favor:

Comprehensive code quality analysis. Really good to detect bugs, vulnerabilities and code smells. And integration with popular CI/CD pipelines is really impressive.

Puntos en contra:

Setup and configuration can be complex for begineers. And limited support for some programming languages is what could be improved.

Flor
Flor
Software Developer en Perú
Usuario de Linkedin verificado
Software informático, 11-50 empleados
Ha utilizado el software durante: Más de un año
Fuente de la opinión

A free tool for source code analysis

5,0 hace 2 años

Comentarios: It helped me to be able to do my job in improving the code, giving me possible solutions and saving me time.

Puntos a favor:

What I find most useful in this software is the code analysis, which gives detailed reports of the errors found and then suggests possible solutions. This saves time in software development.In addition, their large community helps solve problems that arise along the way.

Puntos en contra:

Sometimes the reports can give false positives, which requires that the personnel in charge of handling the software carefully review the results to avoid false positives.

Usuario verificado
Usuario de Linkedin verificado
Software informático, Trabajador autónomo
Ha utilizado el software durante: Prueba gratis
Fuente de la opinión

Free open source

4,0 hace 2 años

Puntos a favor:

- integrate CI/CD- customizable Quality Profiles- easy to use

Puntos en contra:

- performance Impact- limited programming language- open-source, some advanced features are only available in the commercial version

Carlos
IT Manager en España
Banca, 51-200 empleados
Ha utilizado el software durante: Más de dos años
Fuente de la opinión

Sonarqube essential code quality analysis tool

4,0 hace 2 años

Comentarios: In short, it is an indispensable tool and should be mandatory in all software development companies.

Puntos a favor:

The ability to analyze the quality of the code in each deployment or integration, together with the possibility of modifying the rules to allow deployment or not (quantity or criticality of errors or defects), as well as vulnerability analysis allows for better software, always keeping in mind of the developers the quality and security of the code.

Puntos en contra:

Like everything, the time it takes to leave it well configured and integrated with the rest of the systems, as well as the maintenance and updating of the standards, rules and vulnerabilities depending on the programming language and the news that are published at the level of security.

Pawan
Pawan
Tech Lead en India
Usuario de Linkedin verificado
Tecnología y servicios de la información, 201-500 empleados
Ha utilizado el software durante: 1-5 meses
Fuente de la opinión

Review for Sonar Qube

5,0 hace 2 años

Puntos a favor:

This is very good and user friendly application.

Puntos en contra:

As such i didn't found any con for this application.

Usuario verificado
Usuario de Linkedin verificado
Educación superior, 1.001-5.000 empleados
Ha utilizado el software durante: 6-12 meses
Fuente de la opinión

SonarQube is Great for Developers!

5,0 hace 2 años

Comentarios: We could identify many code related issues that are presented in our code and improve the quality of the application that we are developing. As a overall, SonarQube tool is able to add a value to our applications.

Puntos a favor:

It is simple for developers to recognize their code smells, unused lines of code, errors, problems with the third-party libraries they are using, etc. information and the precise location of the issue. It also offers answers to those problems. As a result, figuring out the problems and fixing them is simple. This will be a terrific tool for developers. Except that, we can introduce our own rules for checking the code quality. It could identify the code issues that are vulnerable to cyber attacks such as XSS, SQL Injection, etc.

Puntos en contra:

It was difficult to use the SonarQube on-premise application. Once we pushed a new code section, the server needed to restart in order for the application to work.

Marcin
Senior Technical Engineer/Senior DevOps Engineer en Polonia
Tecnología y servicios de la información, 10.000+ empleados
Ha utilizado el software durante: 6-12 meses
Fuente de la opinión

Staple in the CI/CD pipelined quality gate solutions

4,0 hace 2 años

Comentarios: It allows our dev teams to keep consistent level of code quality and known issues proof in code and used target platforms so as to provide to end users/customers highest quality products delivered in CI/CD methodology.

Puntos a favor:

Easily add source code analysis for potential bugs and pitfalls to warrant against developers' errors or just not efficient coding by novices, projects dependencies on vulnerable platforms and potential long-term support issues due to how your code is structured. Simple deployment of binaries needed for scans for major target build environments OSes, plus easy to use APIs, all for the benefit of easy integration into CI/CD pipelines.

Puntos en contra:

Caps and limits on key server instance component required when obtaining config for project and preset rules, when sending analysis results or getting quality gate results may make the pipelines seem to fail without easier discerning real reasons.

Chandramouli
DevSecOps Lead en India
Hospital y atención sanitaria, 501-1.000 empleados
Ha utilizado el software durante: 6-12 meses
Fuente de la opinión

Great tool to drive Coding Quality standards

3,0 hace 4 años

Comentarios: PR analysis and Integration with Bitbucket are most in avoiding the new issues.
The tool needs a lot of improvements
1. Number of rules should be increased.
2. Few rules should have custom exclusions. Ex: Naming conventions => Organisation-specific words will be there which should be in Capital.
3. Generating a lot of false positives
4. Executive reports should generate based on scheduled triggers. We have 20 projects which are assigned to a Portfolio. if you are going to generate a report and send an email for the first portfolio calculation then the rest of the 19 projects info for that day will be missed. Higher management will think that the generated report is the latest but it is not.
5. PR analysis reports should be generated Quickly

Puntos a favor:

PR analysis and Integration with Bitbucket are most helpful.

Puntos en contra:

1. Number of rules should be increased. 2. Few rules should have custom exclusions. Ex: Naming conventions => Organisation-specific words will be there which should be in Capital. 3. Generating a lot of false positives 4. Executive reports should generate based on scheduled triggers. We have 20 projects which are assigned to a Portfolio. if you are going to generate a report and send an email for the first portfolio calculation then the rest of the 19 projects info for that day will be missed. Higher management will think that the generated report is the latest but it is not. 5. PR analysis reports should be generated Quickly

Respuesta de SonarSource

hace 4 años

Thank you for your review, Chandramouli. We appreciate your feedback, and invite you to join the SonarSource Community Forum. SonarSource Community Forum: https://community.sonarsource.com/ Posting to the Forum will allow there to be transparency to the community, and allow our product managers & users to understand any issues you are facing. To better assist you, please indicate what language(s), and how long the PR analysis is actually taking; as well as, examples of the false positives. Thanks!