Skip to main content

Sonar Cloud

TopicsSecurity, Quality
LanguagesJava, Javascript, C#

SonarCloud is a service operated by SonarSource, the company that develops and promotes open-source code quality products SonarQube and SonarLint; SonarSource provides SonarCloud for open source projects, free of charge.

Below are some of the most important features used by Foundation projects:

  1. Integration with CI environments
  2. Measures test coverage
  3. Scans code for security vulnerabilities
  4. Scans code for bad practices (duplicated logic, debts and code smells)
  5. Scans code for bugs

Request access

Sign into and register your Github project.

Build configuration

There are different ways to enable Sonar in your project, follow the Getting Started guide to know more.

You can configure a SonarCloud badge by adding the following syntax at the top of your

[![Quality Gate Status](<group-id>%3A<artifact-id>&metric=alert_status)](;group-id&gt;%3A&lt;artifact-id>)

From the Account > Security menu of SonarCloud dashboard, you'll be able to generate the token that needs to be passed as SONAR_TOKEN environment variable.