Any vulnerability testing reports for SonarQube instance?

Hi Guys,

Anyone know if how I can find vulnerability testing report for SonarQube itself? For proving that SonarQube have been tested and secure to use. Just want to reference it.

I plan to use deploy it as Docker in version 9.9.4-community.

Hey there.

Here you go!

You can read more in our Trust Center, which points to our Whistic profile with related documents.

1 Like

Appreciated Colin! :pray:

Those documents look like an Attestation letter. Is it possible for us to see actual Pen Test report provided by Cure53?

Thank you,
Nuttachai C.

All the docs we have available are in our Trust Center .