Based in Dubai required; relocation assistance available for the right candidate.
SonarSource provides tools to improve code quality and security across development teams. Its products include SonarLint (an IDE plugin that gives real-time feedback as code is written) and SonarQube (a self-managed code analysis platform) and SonarCloud (a cloud-based analysis service), which analyze code for bugs, vulnerabilities, and maintainability and present guidance and reports. The tools work by integrating into developers' workflows—from IDE feedback with SonarLint to repository-wide analysis with SonarQube or SonarCloud—delivering dashboards and trend reports. The company differentiates itself with an end-to-end, subscription-based suite that covers local IDE feedback through centralized governance, serving hundreds of thousands of organizations, with the goal of keeping code clean, secure, and reliable.
Company Size
501-1,000
Company Stage
Late Stage VC
Total Funding
$457.1M
Headquarters
Vernier, Switzerland
Founded
2008
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Flexible Work Hours
Hybrid Work Options
Professional Development Budget
Carahsoft and Sonar expand partnership to deliver AI code verification and governance across all North American markets. Agreement extends access to Sonar's solutions through Carahsoft's trusted channel ecosystem, enabling governed, enterprise-scale AI adoption. RESTON, Va., Sept. 09, 2026 (GLOBE NEWSWIRE) - Carahsoft Technology Corp., The Trusted Government IT Solutions Provider(R), today announced that it has expanded its partnership with Sonar, a global leader in AI code verification and governance, to make Sonar's validation platform, SonarQube, available beyond the U.S. Public Sector to all North American markets. Through Carahsoft's partner ecosystem, resellers and services partners, organizations will gain access to the independent, enterprise-scale AI adoption solution trusted by 7m+ developers. Through this expanded agreement, Carahsoft will give Sonar broader reach with organizations that prefer a channel-based purchasing model, enabling streamlined procurement and more deployment processes. The need for solutions like SonarQube heightens as enterprises embed agentic workflows throughout their organizations. According to Sonar's 2026 State of Code Developer Survey, 72% of developers who have tried AI coding tools use them every day, underscoring the need to balance speed with safety and avoid introducing new security, complexity and reliability risks. Together, Carahsoft and Sonar are bringing zero-trust, multilayered verification to more teams across North America. "Enterprises require verifiable, governed adoption of agentic development. Through our expanded partnership with Carahsoft, we will enable more organizations to do just that," said Bill Sullivan, Vice President, North America Channel Sales, at Sonar. "By making our solutions available through Carahsoft's partners, we're empowering teams to contain risk, deploy confidently and ship higher-quality, more secure code in their agentic workflows." The expanded Carahsoft agreement helps organizations across North America apply Sonar to practical AI-development use cases: independently verifying code generated by AI agents before merge; identifying security vulnerabilities, reliability issues and maintainability concerns before they reach production; and establishing consistent code quality and governance standards across teams adopting AI-assisted development. Organizations can also use Sonar's AI-native code review capabilities, expanded through its recent acquisition of Gitar, to review and validate agentic-written code with greater confidence. "We are pleased to expand our partnership with Sonar to bring its zero-trust, multilayered verification solutions to commercial markets across North America, helping reduce outages, improve security and lower costs and risks associated with AI and agentic coding," said Natalie Gregory, Vice President managing DevSecOps Solutions at Carahsoft. "Together, with our network of reseller and services partners, we are uniquely positioned to deliver Sonar's solutions through the channels our customers trust most, enabling IT teams to more efficiently adopt tools that improve code quality, strengthen security and accelerate innovation." Sonar's solutions are available now through Carahsoft's reseller and services partners. For more information, contact the Carahsoft Team at (703) 581-6680 or [email protected]; or register for Sonar's event, SonarQube World Tour in New York on October 15, 2026. Explore Sonar's solutions here. About Carahsoft Carahsoft Technology Corp. is The Trusted Government IT Solutions Provider, supporting Public Sector organizations across Federal, State and Local Government agencies and Education and Healthcare markets. As the Master Government Aggregator(R) for our vendor partners, we deliver solutions for DevSecOps, Cybersecurity, MultiCloud, Artificial Intelligence, Customer Experience and Engagement, Open Source and more. Working with resellers, systems integrators and consultants, our sales and marketing teams provide industry leading IT products, services and training through hundreds of contract vehicles. Visit us at www.carahsoft.com. About Sonar Sonar, a global leader in AI code verification and governance, helps reduce outages, improve security, and lower costs and risks associated with AI and agentic coding. As a zero-trust, multilayered verification platform, Sonar enables organizations to securely develop at the speed of AI, and with the addition of Gitar's AI-native code review, offers the most comprehensive way to verify code in the agentic era. A Leader in the Gartner(R) Magic Quadrant(TM) for Technical Debt Management Tools, Sonar is the foundation for high-performance software engineering - analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at Nvidia, ServiceNow, Booking.com, Goldman Sachs, AstraZeneca, and Ford Motor Company. Cautionary note: Forward-looking statements This press release may contain forward-looking statements about future expectations, plans, and prospects. These statements are based on current beliefs and assumptions and are subject to risks and uncertainties. The information in this press release is provided as of this date, and we undertake no obligation to update any statements. [1]Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner's business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.
Westcon-Comstor and Sonar sign multi-region deal to accelerate partners' AI adoption with trusted code verification. Sarah Weston 1 September, 2026 Westcon-Comstor, a global technology distributor specialising in cybersecurity, networking and hybrid cloud solutions, has announced a multi-region distribution agreement with Sonar, a global leader in AI code verification and governance. The partnership provides high-value growth opportunities for channel partners across Europe, the Middle East and Africa (EMEA) and Asia-Pacific (APAC) to help customers securely adopt AI into their software development workflows. The agreement makes Sonar's core platform, SonarQube, available to Westcon-Comstor partners, enabling them to extend their DevSecOps offerings with automated code verification that helps development and security teams identify and remediate security vulnerabilities, exposed secrets and other code issues before software reaches production. According to Sonar research, SonarQube users are 44% less likely to report AI-derived production outages. Additionally, by maintaining code quality with Sonar, users can reduce token usage by 7-8%, with further reductions possible when agents are guided with governed context. As AI agents become more deeply embedded in development workflows, organisations need to maintain the speed benefits of AI without introducing new security risks. Sonar's Agent Centric Development Cycle (AC/DC) methodology gives partners a clear framework for helping customers do so: guide AI agents with the right context and constraints, verify their output through fast, multi-layered feedback loops and resolve issues before they become a production risk. Through this Guide-Verify-Solve approach, partners can help customers build security and governance into AI-assisted development from the outset. Sonar provides automated code analysis that embeds verification directly into AI-driven workflows to reduce outages, improve security and lower costs and risks associated with AI and agentic coding. This gives security and development teams a shared, actionable view of code risk, while supporting faster remediation and stronger governance as software environments become more complex. The company's recent acquisition of Gitar expands its offering with AI code review, giving organisations the benefits of AI-native code review and comprehensive code verification for the highest level of assurance no matter the AI tool. With strong upsell and cross-sell potential, short sales cycles, fast time to revenue and attractive margins, Sonar enables partners to broaden customer relationships and create new recurring revenue streams. Partners will benefit from Westcon-Comstor's value-added distribution model, which supports market entry and growth through technical enablement, market intelligence and data-driven lead generation, alongside support for customer adoption, expansion and renewals. "Sonar is a recognised leader in its field, and this collaboration represents both a compelling commercial opportunity and a strategic technology play for the channel." "The rapid adoption of AI-assisted software development, combined with the shift-left movement, is creating new openings for partners as software quality, governance and security become board-level priorities. At the same time, many organisations are looking to consolidate fragmented development and security toolsets onto a single platform. "By combining Sonar's market-leading solutions with our enablement capabilities, technical expertise and international reach, we're empowering partners across EMEA and APAC to win new customers, expand existing relationships and drive sustainable revenue growth," said Adam Davison, Senior Director, Vendor Acquisition at Westcon-Comstor. "Organisations are embracing AI to accelerate software development, but speed only creates value if teams can trust what gets shipped," said Scott Musson, VP of Worldwide Channel at Sonar. "Westcon-Comstor's global reach, channel expertise and value-added approach make it an ideal distribution partner for expanding Sonar's platform to more customers. Together, we can help partners support organisations as they scale AI and agentic coding with stronger verification, clearer governance and greater confidence in every line of code."
Sonar has launched SonarQube Hunter Agent, an AI-powered security tool designed to detect logic-based vulnerabilities that traditional pattern-based scanning cannot identify. The agent finds broken access control, business-logic flaws, and authentication issues by analysing entire codebases and reasoning through how code, data, and identity flow through systems. Unlike conventional scanning tools that catch coding errors, Hunter Agent identifies vulnerabilities where code functions as written but permits unintended actions, such as unauthorised data access or bypassed checkout flows. These issues traditionally required manual security reviews or penetration testing. The agent operates on a scheduled basis without blocking pull requests or disrupting CI/CD pipelines. Verified findings appear directly in SonarQube's existing workflow, allowing teams to triage issues without switching tools. It complements rather than replaces Sonar's existing static application security testing capabilities.
Sonar launches Hunter Agent to find flaws code scanners can't see. Artificial intelligence code verification and governance company SonarSource Sàrl today released SonarQube Hunter Agent, an AI agent built to find security flaws that pattern-based scanning cannot see. The vulnerabilities it targets are the ones where the code does exactly what it was written to do. A user opens another customer's records. A checkout step gets skipped. A session stays alive long after it should have expired. Nothing in the source reads as broken, because at the level a scanner works, nothing is. Only someone who knows what the feature was meant to do can see the problem. So the work has gone to people. A security engineer reads the code by hand, and when the budget stretches, a penetration tester goes at the running application from outside. Both cost money, both take time and both are out of date as soon as new code ships. Sonar said the shrinking gap between release and exploitation has made that a bigger problem than it used to be, with AI-assisted development pushing code out faster than any audit cycle can follow and logic flaws going unnoticed for months at a time. Broken access control, business-logic flaws and weaknesses in authentication or session handling are the three things the agent looks for. Pattern matching finds none of them. Sonar has it work over a whole codebase, tracing where code, data and a user's identity travel through an application. Out of that comes a theory about where the implementation drifted from what the feature was meant to do, and the agent goes looking for proof. Every candidate issue is investigated and confirmed before a developer sees it. No second tool is involved. Confirmed findings show up in the SonarQube issue list, in the same queue a team is already working through, and get assigned and tracked there like anything else. The agent runs in the background on whatever schedule a team sets. Scans can also be started by hand. Pull requests are never blocked and continuous integration pipelines are not slowed. Johannes Dahse, Sonar's vice president of code security, said AI is changing "not only the speed of software development, but also the scale of the verification challenge." Putting reasoning-based findings into the SonarQube workflow gives security and development teams a practical way to extend verification as the pace of AI-driven development increases, he added. Sonar is positioning the agent as an addition to SonarQube's existing static application security testing rather than a replacement for it. SAST reads how code is written. Hunter Agent goes after what the code was supposed to do in the first place. An enterprise alpha ran earlier this year and beta access opened on July 9 to SonarQube Cloud Enterprise customers. Under the hood the agent runs playbooks, multistep sequences of security prompts that encode the company's own application security expertise. Findings arrive with the discovery path attached. Agents have been the throughline of Sonar's 2026. The company launched Sonar Vortex and the SonarQube Remediation Agent at the AI Engineer World's Fair in June, the latter a background agent that writes fixes for existing issues and opens pull requests. SonarQube Hunter Agent is generally available today on SonarQube Cloud. Support for SonarQube Server is planned, with no date given. Image: Sonar. A message from John Furrier, co-founder of SiliconANGLE: Support its mission to keep content open and free by engaging with theCUBE community. Join theCUBE's Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. * 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more * 11.4k+ theCUBE alumni - Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from its Marketplace portal page and links: https://siliconangle.com/aws-marketplace/. About SiliconANGLE Media. SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios - with flagship locations in Silicon Valley and the New York Stock Exchange - SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Its new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.
SonarQube integration in CI/CD pipeline - Quality Gate setup. Tl;dr. * Integrate SonarQube into your CI/CD pipeline to enforce code quality gates and improve overall code health * Use SonarQube's static code analysis capabilities to identify issues before they reach production * Configure Quality Gates to automatically fail builds when code quality thresholds are not met What you'll learn. In this tutorial, DevOps Duoo will cover the step-by-step process of integrating SonarQube into a CI/CD pipeline using GitHub Actions and Docker. DevOps Duoo will focus on setting up a Quality Gate to ensure that code quality standards are met before deploying to production. You will learn how to: * Configure SonarQube to analyze your codebase * Integrate SonarQube with GitHub Actions * Set up a Quality Gate to enforce code quality standards * Troubleshoot common issues and optimize performance Setting up sonarqube. To start, you need to set up a SonarQube instance. You can use the official SonarQube Docker image to run it in a container. Here's an example docker-compose.yml file to get you started: version: '3' services: sonarqube: image: sonarqube:9.9.0-community environment: - SONARQUBE_JDBC_URL=jdbc:postgresql://localhost:5432/sonarqube - SONARQUBE_JDBC_USERNAME=sonarqube - SONARQUBE_JDBC_PASSWORD=sonarqube ports: - "9000:9000" depends_on: - db volumes: - sonarqube-data:/opt/sonarqube/data - sonarqube-extensions:/opt/sonarqube/extensions db: image: postgres:14 environment: - POSTGRES_USER=sonarqube - POSTGRES_PASSWORD=sonarqube - POSTGRES_DB=sonarqube volumes: - sonarqube-db:/var/lib/postgresql/data volumes: sonarqube-data: sonarqube-extensions: sonarqube-db: This configuration sets up a SonarQube instance with a PostgreSQL database. You can adjust the environment variables and volume mounts as needed. To integrate SonarQube with GitHub Actions, you need to create a workflow file that analyzes your codebase and reports the results to SonarQube. Here's an example .github/workflows/sonarqube.yml file: name: SonarQube Analysis on: push: branches: - main jobs: sonarqube: runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v3 - name: Login to SonarQube uses: sonarqube/sonarqube-github-action@v1 with: sonarqube-url: ${{ secrets.SONARQUBE_URL}} sonarqube-token: ${{ secrets.SONARQUBE_TOKEN}} project-key: ${{ secrets.SONARQUBE_PROJECT_KEY}} - name: Analyze code run: | sonar-scanner -Dsonar.projectKey=${SONARQUBE_PROJECT_KEY} -Dsonar.projectName=${SONARQUBE_PROJECT_NAME} -Dsonar.sources=. -Dsonar.host.url=${SONARQUBE_URL} -Dsonar.login=${SONARQUBE_TOKEN} - name: Quality Gate uses: sonarqube/sonarqube-github-action@v1 with: sonarqube-url: ${{ secrets.SONARQUBE_URL}} sonarqube-token: ${{ secrets.SONARQUBE_TOKEN}} project-key: ${{ secrets.SONARQUBE_PROJECT_KEY}} quality-gate: true This workflow file checks out the code, logs in to SonarQube, analyzes the code, and checks the Quality Gate. You need to replace the SONARQUBE_URL, SONARQUBE_TOKEN, and SONARQUBE_PROJECT_KEY secrets with your actual SonarQube instance URL, token, and project key. Configuring Quality Gates. To configure Quality Gates, you need to set up a SonarQube project and define the quality criteria. Here's an example of how to create a Quality Gate: # Create a new SonarQube project curl -X POST \ http://localhost:9000/api/projects/create \ -H 'Content-Type: application/json' \ -d '{"name": "My Project", "key": "my-project"}' # Define the quality criteria curl -X POST \ http://localhost:9000/api/qualitygates/create \ -H 'Content-Type: application/json' \ -d '{ "name": "My Quality Gate", "conditions": [{"metric": "coverage", "operator": "LT", "value": "80"}]}' This example creates a new SonarQube project and defines a Quality Gate that fails if the code coverage is less than 80%. Common mistakes. When integrating SonarQube with GitHub Actions, common mistakes include: * Not replacing the SONARQUBE_URL, SONARQUBE_TOKEN, and SONARQUBE_PROJECT_KEY secrets with actual values * Not configuring the Quality Gate correctly * Not adjusting the sonar-scanner command to match the project structure To troubleshoot issues, you can check the SonarQube logs and the GitHub Actions workflow logs. You can also use the SonarQube API to verify the project configuration and Quality Gate settings. Performance considerations. When running SonarQube in a production environment, performance considerations include: * Ensuring sufficient memory and CPU resources for the SonarQube instance * Optimizing the database configuration for better performance * Using a load balancer to distribute traffic across multiple SonarQube instances Security implications. When integrating SonarQube with GitHub Actions, security implications include: * Ensuring that the SonarQube token is stored securely as a secret * Limiting access to the SonarQube instance to authorized personnel * Using SSL/TLS encryption to secure communication between the SonarQube instance and the GitHub Actions workflow Key takeaways. * Integrate SonarQube into your CI/CD pipeline to enforce code quality gates and improve overall code health * Use SonarQube's static code analysis capabilities to identify issues before they reach production * Configure Quality Gates to automatically fail builds when code quality thresholds are not met * Ensure sufficient memory and CPU resources for the SonarQube instance and optimize the database configuration for better performance * Store the SonarQube token securely as a secret and limit access to the SonarQube instance to authorized personnel By following these steps and best practices, you can effectively integrate SonarQube into your CI/CD pipeline and ensure high-quality code deployments. For more information on related topics, see and.