SonarSource/sonar-java is a Backend project on GitHub, written primarily in Java. It has 1.2k stars. :coffee: SonarSource Static Analyzer for Java Code Quality and Security
Snapshot summary built from the project's own GitHub metadata — there's no written TopGit review yet. The page will update automatically when a full review is published.
WHY NO REVIEW YET
TopGit writes full reviews for the most-starred, most-requested repositories. This page is a snapshot until then — see the READ ME tab for the original README in full.
This Sonar project is a code analyzer for Java projects to help developers deliver integrated code quality and security. Information about the analysis of Java features is available here.
Metrics (cognitive complexity, number of lines, etc.)
Import of test coverage reports
Custom rules
Useful links
Project homepage
Issue tracking
Available rules
Sonar Community Forum
Demo project analysis
Plugin Wiki
Have questions or feedback?
To provide feedback (request a feature, report a bug, etc.) use the Sonar Community Forum. Please do not forget to specify the language (Java!), plugin version and SonarQube Server version.
If you have a question on how to use plugin (and the docs don't help you), we also encourage you to use the community forum.
Contributing
Topic in Sonar Community Forum
To request a new feature, please create a new thread in Sonar Community Forum. Even if you plan to implement it yourself and submit it back to the community, please start a new thread first to be sure that we can use it.
Pull Request (PR)
To submit a contribution, create a pull request for this repository. Please make sure that you follow our code style and all tests are passing (all checks must be green).
Custom Rules
If you have an idea for a rule but you are not sure that everyone needs it you can implement a custom rule available only for you. Note that in order to help you, we highly recommend to first follow the Custom Rules 101 tutorial before diving directly into implementing rules from scratch.
Work with us
Would you like to work on this project full-time? We are hiring! Check out https://www.sonarsource.com/hiring
Testing
To run tests locally follow these instructions.
Java versions
You need Java 26 to compile and run the Unit Tests of the project and Java 21 run most Integration Tests (ITs).
Ruling test on Guava project require Java 17.
Note that Java 21 can be used to build and test all modules except under java-checks-test-sources (as they require Java 26).
If you are adding or moving rule test samples, see java-checks-test-sources/README.md
for guidance on when samples belong in the dedicated test-source modules instead of java-checks/src/test/files.
Build the Project and Run Unit Tests
To build the plugin and run its unit tests, execute this command from the project's root directory:
mvn clean install
Note that
Running unit tests within the IDE might incur in some issues because of the way the project is built with Maven.
If you see something like this:
java.lang.SecurityException: class ... signer information does not match signer information of other classes in the same package
try removing the Maven nature of the 'jdt' module.
Integration Tests
To run integration tests, you will need to create a properties file like the one shown below, and set the URL pointing to its location in an environment variable named ORCHESTRATOR_CONFIG_URL.
# version of SonarQube Server
sonar.runtimeVersion=LATEST_RELEASE
orchestrator.updateCenterUrl=http://update.sonarsource.org/update-center-dev.properties
# The location of the Maven local repository is not automatically guessed. It can also be set with the env variable MAVEN_LOCAL_REPOSITORY.
maven.localRepository=/home/myName/.m2/repository
With for instance the ORCHESTRATOR_CONFIG_URL variable being set as:
Before running the ITs, be sure your MAVEN_HOME environment variable is set.
Sanity Test
The "Sanity Test" is a test that runs all checks against all the test source files without taking into account the result of the analysis. It verifies that rules are not crashing on any file in our test sources. By default, this test is excluded from the build. To launch it:
mvn clean install -P sanity
Plugin Test
The "Plugin Test" is an integration test suite that verifies plugin features such as metric calculation, coverage, etc. To launch it, build the plugin first (mvn clean install), then run:
cd its/plugin
mvn clean install -Pit-plugin -DcommunityEditionTestsOnly=true
Note for internal contributors: in order to also execute the tests that depend on the SonarQube Server Enterprise Edition, use:
mvn clean install -Pit-plugin
Ruling Test
The "Ruling Test" is an integration test suite that launches the analysis of a large code base, saves the issues created by the plugin in report files, and then compares those results to the set of expected issues (stored as JSON files).
To run the test, first make sure the submodules are checked out:
git submodule update --init --recursive
Then, ensure that the JAVA_HOME environment variable is set for the ruling tests execution and that it points to your local JDK 21 installation.
Failing to do so will produce inconsistencies with the expected results.
From the its/ruling folder, launch the ruling tests:
This test gives you the opportunity to examine the issues created by each rule and make sure they're what you expect. Any implemented rule is highly likely to raise issues on the multiple projects we use as ruling code base.
For a newly implemented rule, it means that a first build will most probably fail, caused by differences between expected results (without any values for the new rule) and the new results. You can inspect these new issues by searching for files named after your rule (squid-SXXXX.json) in the following folder:
For existing rules which are modified, you may expect some differences between "actual" (from new analysis) and expected results. Review carefully the changes that are shown and update the expected resources accordingly.
All the json files contain a list of lines, indexed by file, explaining where the issues raised by a specific rule are located. If/When everything looks good to you, you can copy the file with the actual issues located at:
You can debug ITs by adding -Dmaven.binary=mvnDebug as an option when running the tests. This will cause the analyzer JVM to wait for a debugger to be attached before continuing.
Updating licenses:
When dependencies change, update the committed license files using the updateLicenses profile:
mvn clean package -PupdateLicenses
This regenerates licenses in sonar-java-plugin/src/main/resources/licenses/ based on current project dependencies.
License
Copyright 2012-2026 SonarSource.
SonarQube analyzers released after November 29, 2024, including patch fixes for prior versions, are published under the Sonar Source-Available License Version 1 (SSALv1).
See individual files for details that specify the license applicable to each file.
Files subject to the SSALv1 will be noted in their headers.
How active is development on SonarSource/sonar-java?
The most recent commit recorded on SonarSource/sonar-java was 17 days ago, based on the GitHub push timestamp. The repository has 724 forks — one of the better signals of community interest.
Is SonarSource/sonar-java open source?
TopGit's metadata for SonarSource/sonar-java does not record a license. Most public repositories on GitHub ARE open source, but the exact terms vary — verify by opening the LICENSE file directly.
What topics is SonarSource/sonar-java associated with?
The project maintains a homepage at https://docs.sonarqube.org/latest/analysis/languages/java/. The README tab on this page also usually contains screenshots and a quickstart.
Where do I read more about SonarSource/sonar-java?
This TopGit page is a snapshot — the READ ME tab shows the project's own README content (links stripped, images preserved). The GitHub repository at github.com/SonarSource/sonar-java is the definitive source.
Read full README in the tab above.
Curious whether sonar-java is right for you?
Let ChatGPT, Claude, or Perplexity look into it — click below and see what AI actually says about sonar-java.