Sonar Community Roundup, Sept 26 - Oct 2

Hello Community!

This week has been a big one for us at Sonar. In case you live under a rock: SonarQube Server 2026.5 LTA is here! :tada: This new LTA is packed with new features, most notably a set of agentic features which were already live on SonarQube Cloud for a while, and now are within reach of on-prem users too. I won’t dive too deep into the features, go read the linked announcement and go update your instance!

So now, like every week, we’d like to take a moment to recognize you, the users, who help improve the ecosystem for everyone by sparking valuable discussions and providing feedback to drive continuous improvement in our products.

SonarQube for IDE :sonarlint:

  • Running SonarQube for IntelliJ inside a dev container failed with a “No files nor directories matching” error for @mhn, who shared detailed logs and even tried setting sonar.java.binaries by hand. Sorry for the wait. SonarQube for IDE doesn’t support dev containers at the moment, and we’ll make sure that’s documented. Thanks for digging in!

  • Right after the 6.0.0 release of SonarQube for VS Code, @SoN9ne spotted that custom SonarQube MCP Server configurations, such as an mTLS setup, were being overwritten every time the IDE opened. You’re right, that was an oversight on our side, and a new fix release already shipped the same day. Thanks for the quick feedback and for closing the loop!

SonarQube Cloud :sonarcloud:

SonarQube Server / Community Build :sonarqube-server:

  • The new architecture analysis missed connections in Python code that uses the import x.y as z syntax. @Micha_Nelis, thanks for the sharp eye! You’re right, and that’s now resolved.

Scanners :printer:

Rules & Languages :books:

  • java:S5542 doesn’t flag weak cipher transformations passed to Cipher.getInstance when they come from an array iterated in a loop, as @Belle pointed out with a minimized example. Sorry for the long wait, and thanks for the clear reproducer! Here goes SONARJAVA-6861!

  • Your custom naming pattern for csharpsquid:S6669 was ignored, and @ooredm noticed the default regex still showing up in the messages. Thanks for the report! It’s fixed and ready to roll out with upcoming releases.

  • java:S3400 doesn’t flag a method that returns Collections.singletonList("fixed").get(0), even though it always returns the same constant. @MarkLee131 also wondered whether a clearer rule description might be the better fix. Fair point, we’ve added it to our backlog.

  • The same user, @MarkLee131, also reported that java:S1488 goes silent when the declaration and the assignment of a returned local variable are split in two statements. Thanks for the detailed examples, duly noted!

  • csharpsquid:S2325 incorrectly raised on MAUI events, as @s.arnas.ext let us know. The fix will roll out with upcoming releases. Thanks for flagging it!

  • typescript:S4144 raises an issue on functions with identical bodies even when the duplication is a single call expression spanning several lines. @unblocker put together a thorough report showing this contradicts the rule description. You’re right, so we’ll update the documentation and look into counting statements instead of lines. We’re tracking the improvements in JS-2595.

  • javascript:S3827 flags the Vue defineModel() macro as an undeclared variable, just as @Paulo_Pontes reported. You’re right, defineModel() deserves the same treatment as defineProps() and defineEmits(). We’re tracking the fix in JS-2585.

  • A huge thank-you to @marktiwnzhao, who deserves a special call-out this week for an outstanding run of minimal, ready-to-run Java reports. Each one came with a self-contained reproducer, which made triage and ticketing fast on our side:

    • java:S2200 misses a comparison of Comparator.compare() against a specific value like 1. You’re right, the rule currently only covers Comparable. Here goes SONARJAVA-7081!

    • java:S2695 overlooks a zero ResultSet index derived from a loop. We’re tracking the fix in SONARJAVA-7103.

    • java:S2695 also skips zero indices passed to PreparedStatement.setAsciiStream() and ResultSet.updateInt(). SONARJAVA-7110 was created as a result.

    • java:S3039 rejects substring(string.length()), which is perfectly valid and returns an empty string. See SONARJAVA-7111.

    • java:S3046 treats reentrant acquisition of the same monitor as multiple locks. We’re on it: SONARJAVA-7112.

  • javascript:S9114 raises on non-React functions with PascalCase names, such as old-style functions used as classes. @lukpsaxo even dug into the rule’s implementation to explain why. Thanks for the detective work! We’ll improve how React components are detected, and we’re tracking it in JS-2586.

  • csharpsquid:S8949 asks for a CancellationToken to be passed to WithAnalyzers, even though the only overload accepting one is obsolete. @Corniel, you’re right. We’ll exclude obsolete overloads and point the issue at the exact method. Insightful note about Visual Studio hiding that overload too!

  • @Corniel also spotted that csharpsquid:S1144 flags a private indexer setter that is in fact used. We reproduced it and created an internal ticket to fix it. Thanks for another clear snippet!

  • eslint-plugin-sonarjs could lint its own rules with eslint-plugin-eslint-plugin, as @rakleed suggested. That would catch deprecated APIs and broken fixers before users ever hit them. Great suggestion, and JS-2587 is how we’ll make it happen!

Thanks again to everyone mentioned here - and to anyone we may have missed - for your ongoing contributions in making this community stronger and helping us improve Sonar products.

If you’d like to give a shout-out to someone, whether a community member or a SonarSourcer who helped you, please do so below. And if there’s someone you think we should acknowledge next week, let us know!

4 Likes