October 2026 Summaries
4 posts from Sonar
Filter
Month:
Year:
Post Summaries
Back to Blog
No summary generated yet.
Oct 09, 2026
2,984 words in the original blog post.
Sonar Vortex is an add-on for SonarQube Server Enterprise and Data Center that provides coding agents with project-specific rules, architecture constraints, semantic code navigation, and dependency health information before they make changes, then validates their edits using context previously generated by the CI analysis pipeline. Designed for self-hosted, air-gapped, and VPC-restricted deployments, it keeps code within an organization’s infrastructure while supporting agents such as Claude Code, OpenAI Codex, GitHub Copilot CLI, Cursor, and Google Antigravity through CLI, plugin, or local MCP integrations. By supplying targeted context and symbol relationships rather than requiring agents to repeatedly search and read entire files, the product claims to reduce token use by as much as 36%. Its verification process reuses stored dependencies, artifacts, type data, and build configuration to return checks on modified files within seconds using the same inputs as a full pipeline scan. Deployment requires a separate tool-call-based subscription, LicenseSpring activation, infrastructure configuration by administrators, and individual developer setup using an instance URL, token, and project key.
Oct 06, 2026
1,070 words in the original blog post.
Sonar front-end developer Quentin Chevrin describes how AI coding agents have greatly accelerated software generation while shifting the main constraint to reviewing and verifying larger volumes of pull requests. After moving from GitHub Copilot suggestions to a terminal-based workflow using Claude Code, Sonar CLI, and development plugins, he now relies on a three-layer process in which SonarQube checks code quality and security, Gitar assesses broader correctness and product fit, and human reviewers provide final approval. Chevrin argues that automated deterministic analysis and reasoning-based review address different risks, while agents should never approve or commit their own output. AI remains less effective for design review, can incur substantial context and token costs, and may create comprehension debt when developers delegate specification and planning work they need to understand themselves. He manages these risks by giving agents constrained tasks, using short sessions, scaling autonomy to a change’s potential impact, and actively steering work, while noting that AI has expanded his ability to contribute across backend, infrastructure, CI, and cloud systems.
Oct 02, 2026
1,301 words in the original blog post.
SonarQube Remediation Agent, available for Enterprise and Data Center editions of SonarQube Server, automates the generation, verification, and submission of pull requests that address technical debt and selected security issues in C#, Java, JavaScript/TypeScript, and Python. Operating within self-hosted, VPC-restricted, or air-gapped infrastructure, it lets organizations retain control over code residency while choosing approved AI endpoints including AWS Bedrock, Azure AI Foundry, Anthropic, OpenAI, or custom gateways. Users can manually assign issues or schedule recurring remediation jobs, while the agent groups similar fixes by rule and file type, applies them in a sandbox, and reruns Sonar analysis to reject changes that fail to resolve issues or introduce new ones. Developers retain approval control through standard pull-request workflows in GitHub, GitLab, and Azure DevOps, although existing CI and reviewers must still validate tests because the agent does not run test suites.
Oct 01, 2026
799 words in the original blog post.