Does SonarCloud support SCA?

Does SonarCloud support SCA or 3rd party library vulnerability scan? I don’t seem to find it, if not. Do you know if there is a plan for that?

Hi,

Welcome to the community!

SonarCloud does not support SCA, and I’m not aware of any current plans.

That said, one option would be to

  • run SCA before your SonarCloud analysis
  • convert the report to the Generic Issues format
  • include the Generic Issues report in your SonarCloud analysis.

But the details of the first two steps are out of scope for us here.

 
HTH,
Ann

Hello from the future!

We recently announced SonarQube Advanced Security, which will include SCA capabilities. While it’s not available yet, we expect general availability for SonarQube Server in May 2025, and SonarQube Cloud Enterprise shortly after.

Please see this announcement for more details.

If you’re looking for beta-testers, we’re actually trying one of your competitors, and are not very statisfied…