SonarSource Launches SonarQube 9.9 LTS
February 07, 2023

SonarSource launched SonarQube 9.9 Long-Term Support (LTS).

The new release empowers organizations to achieve the Clean Code state quickly, securely, and at scale. With accelerated pull request analysis, support for building and deploying secure cloud-native applications, sophisticated enterprise-grade capabilities, and many innovations related to the detection engine and contextual education, SonarQube 9.9 LTS supercharges organizations to deliver new business value and keep their software a long-term asset.

Sonar’s latest 9.9 LTS release introduces key capabilities to enable enterprises to build better software in a sustained manner.

“Our mission is to equip organizations with the solution and methodology to achieve a state of Clean Code, making all code fit for development and production. When companies embrace Clean Code practices, they can derive more from their software, minimize risks, and ensure that their software continues to stay valuable,” said Olivier Gaudin, Founder and CEO of SonarSource. “SonarQube 9.9 LTS was designed to not only provide immediate value to our users for their current development but to steadily drive organizations toward a state of Clean Code in a way that’s predictable, reliable, and sustainable.”

Key release innovations:

- Pull Request Analyzed in Minutes: SonarQube 9.9 LTS provides a significant speed boost for Pull Request (PR) analysis. PRs are now analyzed more than twice as fast, while still providing the same high-precision results. With the implementation of incremental analysis and server-side caching, analysis is more efficient. As developers write and commit code, Pull Request analysis is an important step in merging new code changes to the main branch. Faster analysis means a more efficient software development lifecycle, as developers spend less time waiting and more time delivering business critical features.

- Secure Cloud Native Applications: As applications move to the cloud, organizations must ensure the security of not only the source code, but also their configuration files and deployments. SonarQube 9.9 LTS delivers in-depth analysis capabilities to detect ‘secrets’ in code, bad practices, and vulnerabilities so that developers can build and deploy secure cloud native applications. The release adds support for major cloud providers – AWS, Google Cloud, Microsoft Azure, and their underlying technologies – serverless and SAM frameworks, AWS Cloud Development Kit, Infrastructure-as-Code tools (Terraform and Cloudformation), and containerization tools with Kubernetes and Docker. With these additions, organizations can be sure that their cloud native apps are as secure as their traditional on-prem apps.

- Enterprise-grade features for Coding at Scale: SonarQube 9.9 LTS introduces stronger access management, administration, governance, and reporting capabilities, enabling organizations to better manage the security and administration of their SonarQube instance and their portfolio of code assets. Chief among these new features are advanced security and compliance reporting, project and portfolio reporting, secure token handling, SCIM integration for user management, and more. Customers using the Data Center Edition can now deploy SonarQube clusters with Kubernetes. Together, these reporting, authentication and operational improvements make it easier to use, secure, and manage SonarQube instances than ever before.

Continued innovation in the detection engine allows for improved precision, speed, accuracy, and coverage of all issue types. Users can find and fix more issues in their code. And this LTS release brings in rich educational content to make taint analysis rules easy to understand and contextual to the users’ code and framework – continuing the advancement of the company’s education initiative.

Sonar is a strong proponent of deploying compliant quality gates that will progressively drive organizations to reach a state of Clean Code. This LTS release adds enhancements to the quality gate user experience to help everyone implement and practice Clean as You Code. Quality gates that are not compliant with this methodology can be easily identified and updated.

SonarQube 9.9 LTS is now available for everyone.

Share this

Industry News

May 01, 2024

Amazon Web Services (AWS) announced the general availability of Amazon Q, a generative artificial intelligence (AI)-powered assistant for accelerating software development and leveraging companies’ internal data.

May 01, 2024

Red Hat announced the general availability of Red Hat Enterprise Linux 9.4, the latest version of the enterprise Linux platform.

May 01, 2024

ActiveState unveiled Get Current, Stay Current (GCSC) – a continuous code refactoring service that deals with breaking changes so enterprises can stay current with the pace of open source.

May 01, 2024

Lineaje released Open-Source Manager (OSM), a solution to bring transparency to open-source software components in applications and proactively manage and mitigate associated risks.

May 01, 2024

Synopsys announced the availability of Polaris Assist, an AI-powered application security assistant on the Synopsys Polaris Software Integrity Platform®.

April 30, 2024

Backslash Security announced the findings of its GPT-4 developer simulation exercise, designed and conducted by the Backslash Research Team, to identify security issues associated with LLM-generated code. The Backslash platform offers several core capabilities that address growing security concerns around AI-generated code, including open source code reachability analysis and phantom package visibility capabilities.

April 30, 2024

Azul announced that Azul Intelligence Cloud, Azul’s cloud analytics solution -- which provides actionable intelligence from production Java runtime data to dramatically boost developer productivity -- now supports Oracle JDK and any OpenJDK-based JVM (Java Virtual Machine) from any vendor or distribution.

April 30, 2024

F5 announced new security offerings: F5 Distributed Cloud Services Web Application Scanning, BIG-IP Next Web Application Firewall (WAF), and NGINX App Protect for open source deployments.

April 29, 2024

Code Intelligence announced a new feature to CI Sense, a scalable fuzzing platform for continuous testing.

April 29, 2024

WSO2 is adding new capabilities for WSO2 API Manager, WSO2 API Platform for Kubernetes (WSO2 APK), and WSO2 Micro Integrator.

April 29, 2024

OpenText™ announced a solution to long-standing open source intake challenges, OpenText Debricked Open Source Select.

April 29, 2024

ThreatX has extended its Runtime API and Application Protection (RAAP) offering to provide always-active API security from development to runtime, spanning vulnerability detection at Dev phase to protection at SecOps phase of the software lifecycle.

April 29, 2024

Canonical announced the release of Ubuntu 24.04 LTS, codenamed “Noble Numbat.”

April 25, 2024

JFrog announced a new machine learning (ML) lifecycle integration between JFrog Artifactory and MLflow, an open source software platform originally developed by Databricks.

April 25, 2024

Copado announced the general availability of Test Copilot, the AI-powered test creation assistant.