Security Rules, Crate Rules, and Rule Improvements In Rust

Hi Rust Developers and Rustaceans,

We’re happy to announce a significant change to our Rust analyzer that includes a new analysis engine, security rules, and crate specific rules to make your development process even smoother.

The new analyzer includes:

  • 11 security rules focused rules around common risks
  • 18 crate focused rules to prevent common mistakes when using regex, serde, tokio, and more
  • 122 curated rules from Clippy to help enforce standards across your entire team

One of Rust’s strengths is that the native toolchain is very good, including Clippy for linting and static analysis. We feel that our new analyzer can sit beside these tools to help augment your development process.

You can run the toolchain you know locally while Sonar provides additional analysis, SCA, and reporting to help your organization run smoothly. And for those with specific requirements you can import code coverage reports in LCOV or Cobertura format or Clippy JSON reports to treat Sonar as the governance layer on top of your existing pipeline.

The analyzer is available now on SQC, and with the 2026.5 release of SonarQube Server. We look forward to hearing your feedback, and let us know if there are crates that we should look at adding rules for!

5 Likes