SonarQube Community Edition for Ubuntu 18.04 with support by Kurian
Kurian | 10.1.0-20230830Linux/Unix, Ubuntu 18.04 - 64-bit Amazon Machine Image (AMI)
Reviews from AWS Marketplace
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
Awesome tool for Analyse code along with security vulnerabilities in application
What do you like best about the product?
Analyzing every commit point from the author to see the quality of code being pushed is a great feature. Integrating it with pipelines like the ci/cd pipeline is also a great feature I felt.
What do you dislike about the product?
There should be more examples provided and explains in detail how ci/cd pipeline integration for different environments like Maven, Gradle or any build environment is much needed. Since the community support is not so great so it becomes a tedious task if while setting up one problem comes in the process
What problems is the product solving and how is that benefiting you?
Helps in code scanning for a better quality of code an author can write along with that provides details of CVE's caused by severity-wise vulnerabilities like Critial, Major or Minor.
- Leave a Comment |
- Mark review as helpful
Best Opensource program for code test
What do you like best about the product?
It is similar to Jenkins but a much more powerful automation action tool for DevOps engineers. I used it for batch production release and the sonar cube never disappointed me. It is GUI based tool that came with a lot of features like code test and bug finder etc.
What do you dislike about the product?
We need expert knowledge to integrate it with Jenkins and Terraform. Installation and Configuration are hard and once you did the wrong configuration led to the failure of function. and a little bit lower than Jenkins in batch production releases.
What problems is the product solving and how is that benefiting you?
I am using it useful in Bug finding in my code. the environment is easy to manage. We use it for code Deployment directly from GitHub pull. SonarQube maintains its code quality which I can trust.
I is good for developers
What do you like best about the product?
For learning ubuntu it is very heplfull and for oraganization
What do you dislike about the product?
need to improve some more feature for learning easy like tutorial
What problems is the product solving and how is that benefiting you?
I do not have any free version when i get this i can learn ubuntu
Code Quality automated testing in Devops pipeline
What do you like best about the product?
Its easier to use and its free. It also provides useful test coverage reports.
What do you dislike about the product?
Limited support for containerization environments
What problems is the product solving and how is that benefiting you?
Code Quality testing in Jenkins pipelines
Recommendations to others considering the product:
Sonarqube is one of the best code scanning tools in the market. For anybody starting things with code quality testing, sonar qube is the first option to be considered.
I have used sonarqube in different applications and found it easy to use.
What do you like best about the product?
Dashboard and UI of the new version is user friendly.
What do you dislike about the product?
We can increase more rules in the default installation so that users don't have to add rules manually.
What problems is the product solving and how is that benefiting you?
I am using sonarqube for multiple different purpose.
1. Finding syntax issues.
2. A daring with the latest syntax.
3. Finding errors, vulnerability, code smells
1. Finding syntax issues.
2. A daring with the latest syntax.
3. Finding errors, vulnerability, code smells
Recommendations to others considering the product:
Sonarqube is a great tool to find code smells, and vulnerabilities in your application repo.
Very likely
What do you like best about the product?
Features provided by Sonar, code quality
What do you dislike about the product?
, code coverage, quality gates, major, minor, blocker issues
What problems is the product solving and how is that benefiting you?
Best to avoid problems
My experience with SonarQube was very good. Because it has all that features that i was looking.
What do you like best about the product?
SonarQube is a very easy-to-use tool and it has multiple tech stacks that provide a good view of static code in terms of vulnerabilities, hotspots, code smell etc. And even there are some additional plugins for CI/CD integration.
What do you dislike about the product?
The installation process should be smooth. And even reporting should be much fair.
What problems is the product solving and how is that benefiting you?
Detecting Bugs & Vulnerabilities
Code analysis and Quality check
Security Hotspot
Code analysis and Quality check
Security Hotspot
Good support of you face any issues with sonar
What do you like best about the product?
Ready to use,no need to install,only need to configure
What do you dislike about the product?
Not much to say,lack of customisation like change database
What problems is the product solving and how is that benefiting you?
Main benifit sonarqube is having support
Overall experience is good and I love the community edition
What do you like best about the product?
This feature is totally awesome and highly appreciate the support
What do you dislike about the product?
There is nothing which I don't dislike regarding Sonarqube
What problems is the product solving and how is that benefiting you?
Static code analysis and code quality check
Great tool for code Quality & analysis ...also security & vulnearbility test
What do you like best about the product?
The assignment of the issues for the concerned author whoever committed that change and also analysis of each & every pull request. The cherry on the top is the simplified setup with an integrated pipeline.
What do you dislike about the product?
Sonarqube has fewer examples for setting up a pipeline in a more refined way ...should have elaborated examples to set up the pipeline from scratch for each like maven, Gradle , PHP...etc. We only see the steps to enter.
What problems is the product solving and how is that benefiting you?
The code smells, Bugs, security vulnerability based on severity (Major, Minor, Critical) and also the code quality improves with each setup parameter of quality gates with multiple profile.
Recommendations to others considering the product:
Best industry tool for maintaining a high standard of code quality with security considerations.
showing 1 - 10