Hi everyone,
We’ve decided to phase out the concept of Security Hotspots. By July 1st, 2026
, all hotspots will be rewritten as issues impacting the software quality security. This means all security findings will finally be in one place and not split between the Issues and the Hotspots tab.
Why we are doing this:
- Confusion:
- Most of you did not catch the difference between a “hotspot” and an “issue” and we had to explain it many times which is a sign that something was wrong.
- Hotspots were not made compatible with the Clean Code taxonomy and the MQR mode adding to the confusion.
- Visibility: Many users miss the hotspots tab. This makes them think we find fewer security problems than others while the findings were in the hotspots tab.
- Value: Because they are in a separate tab, users think these findings are less important.
- Market Standard: No one else in the industry uses “hotspots”. The concept never became popular outside of Sonar.
We know this works:
We have already started this process with good results:
- We migrated PHP hotspots to security issues
- We migrated secret rules (S2068 and S6418) for almost all languages. We have received no negative feedback so far. The feedback we received was good one and we fix the mistake.
What I should do:
If you have any concerns or questions about this migration, please let us know here or via private message.
We will do our best to ensure there is no negative impact on you, such as making sure that existing hotspots are not reopened as new security issues.
The only anticipated side effect is a positive one: some projects may now fail their quality gates. This is because what was previously classified as a “hotspot” to review is now a “security issue” to fix which may cause a quality gate to fail. Overall, this is beneficial as it will make your projects more secure.
Timeline:
The full rewrite will happen during Q2 2026. Our goal is to finish everything by July 1st.
This change will make the product simpler and ensure you better see the full value of our security findings in one view.
Alex