New projects now private-by-default on plans that support private projects

Hello everyone,

To enable you to more easily protect your code and align with a secure-by-default approach, we are changing the default visibility for new projects to private for all plans that allow for the analysis of private code.

This update ensures that all projects created (for example, via automation like CI/CD scanners or the API) are private unless you make a deliberate choice to share them publicly.

What’s new?

  • New private-by-default setting: If your SonarQube Cloud plan allows for the analysis of private code, any newly created project will now default to ‘private’ visibility. This applies whether you create the project through the UI, a CI/CD scanner, or the API. For plans that only support public projects, the default remains ‘public’.

  • Explicit opt-in for public visibility: If you want a new project to be public, you now need to explicitly set its visibility to ‘public’ during creation (e.g., by passing the correct parameter in your scanner analysis). This ensures public projects are always an intentional choice.

How to check your project’s visibility

You can always check and change a project’s visibility by navigating to your project page and going to Administration > Permissions.

Let us know your thoughts on this change in the comments below!

-Simone

P.S.: Want to chat about your security and project management needs? Feel free to book a call with me (a Product Manager) to share more about your use cases: Calendar Booking Link

3 Likes