Hello, I’m using Sonarqube community edition version 9.4.0.54424 without any additional plugins or tools. I need to perform static code analysis on NodeJS / Javascript codes. Is this version of sonarqube enough to capture OWASP Top 10 vulnerabilities? Should I install anything on top of the vanilla install? Also, will I get more vulnerability rules if I upgrade my license to Developer?
Hi @Colin thanks for the response. I am not able to identify any keyword related to the Developer edition with the link you provided. Is the difference simply the Injection tag? Is there a place I can view the complete set of rules offered by Developer but not Community?