Hello Community!
This week has been a big one for us at Sonar. In case you live under a rock: SonarQube Server 2026.5 LTA is here!
This new LTA is packed with new features, most notably a set of agentic features which were already live on SonarQube Cloud for a while, and now are within reach of on-prem users too. I won’t dive too deep into the features, go read the linked announcement and go update your instance!
So now, like every week, we’d like to take a moment to recognize you, the users, who help improve the ecosystem for everyone by sparking valuable discussions and providing feedback to drive continuous improvement in our products.
SonarQube for IDE ![]()
-
Running SonarQube for IntelliJ inside a dev container failed with a “No files nor directories matching” error for @mhn, who shared detailed logs and even tried setting
sonar.java.binariesby hand. Sorry for the wait. SonarQube for IDE doesn’t support dev containers at the moment, and we’ll make sure that’s documented. Thanks for digging in! -
Right after the 6.0.0 release of SonarQube for VS Code, @SoN9ne spotted that custom SonarQube MCP Server configurations, such as an mTLS setup, were being overwritten every time the IDE opened. You’re right, that was an oversight on our side, and a new fix release already shipped the same day. Thanks for the quick feedback and for closing the loop!
SonarQube Cloud ![]()
-
A required SonarQube Cloud status check never reached GitHub on one project, leaving every PR stuck on “Expected, waiting for status to be reported.” Thanks @caquino for the thorough write-up! We merged a fix, so please analyze your project again and let us know how it goes.
-
After the Forge migration, the SonarQube Cloud Bitbucket widget got stuck on “Not analyzed on SonarQube Cloud yet” on pull requests, as @Rodrigo_de_Moraes_Al, @Irineu_Ruiz, @frvingstdk, @quang.kieu and @Umut_Ozkan all reported. Your details made it quick to pin down. The fix is deployed, so reload the pull request page if you still see the old message. Thanks for sticking with us!
-
Lines of code for PostgreSQL files went missing during PR analysis, while branch analysis showed them fine. @chml0204 provided a clear reproduction, and we’re rolling out a fix on SonarQube Cloud soon. Nice catch!
SonarQube Server / Community Build ![]()
- The new architecture analysis missed connections in Python code that uses the
import x.y as zsyntax. @Micha_Nelis, thanks for the sharp eye! You’re right, and that’s now resolved.
Scanners ![]()
sonarqube-scan-actionfailed to fetch the GPG public key when the only way out is through an HTTPS proxy. @Torbjorn-Svensson went above and beyond by reporting the problem upstream to the GnuPG maintainers and opening a PR with a workaround. It has been merged and released in v8.3.0, and we owe it all to you!
Rules & Languages ![]()
-
java:S5542doesn’t flag weak cipher transformations passed toCipher.getInstancewhen they come from an array iterated in a loop, as @Belle pointed out with a minimized example. Sorry for the long wait, and thanks for the clear reproducer! Here goes SONARJAVA-6861! -
Your custom naming pattern for
csharpsquid:S6669was ignored, and @ooredm noticed the default regex still showing up in the messages. Thanks for the report! It’s fixed and ready to roll out with upcoming releases. -
java:S3400doesn’t flag a method that returnsCollections.singletonList("fixed").get(0), even though it always returns the same constant. @MarkLee131 also wondered whether a clearer rule description might be the better fix. Fair point, we’ve added it to our backlog. -
The same user, @MarkLee131, also reported that
java:S1488goes silent when the declaration and the assignment of a returned local variable are split in two statements. Thanks for the detailed examples, duly noted! -
csharpsquid:S2325incorrectly raised on MAUI events, as @s.arnas.ext let us know. The fix will roll out with upcoming releases. Thanks for flagging it! -
typescript:S4144raises an issue on functions with identical bodies even when the duplication is a single call expression spanning several lines. @unblocker put together a thorough report showing this contradicts the rule description. You’re right, so we’ll update the documentation and look into counting statements instead of lines. We’re tracking the improvements in JS-2595. -
javascript:S3827flags the VuedefineModel()macro as an undeclared variable, just as @Paulo_Pontes reported. You’re right,defineModel()deserves the same treatment asdefineProps()anddefineEmits(). We’re tracking the fix in JS-2585. -
A huge thank-you to @marktiwnzhao, who deserves a special call-out this week for an outstanding run of minimal, ready-to-run Java reports. Each one came with a self-contained reproducer, which made triage and ticketing fast on our side:
-
java:S2200misses a comparison ofComparator.compare()against a specific value like1. You’re right, the rule currently only coversComparable. Here goes SONARJAVA-7081! -
java:S2695overlooks a zeroResultSetindex derived from a loop. We’re tracking the fix in SONARJAVA-7103. -
java:S2695also skips zero indices passed toPreparedStatement.setAsciiStream()andResultSet.updateInt(). SONARJAVA-7110 was created as a result. -
java:S3039rejectssubstring(string.length()), which is perfectly valid and returns an empty string. See SONARJAVA-7111. -
java:S3046treats reentrant acquisition of the same monitor as multiple locks. We’re on it: SONARJAVA-7112.
-
-
javascript:S9114raises on non-React functions with PascalCase names, such as old-style functions used as classes. @lukpsaxo even dug into the rule’s implementation to explain why. Thanks for the detective work! We’ll improve how React components are detected, and we’re tracking it in JS-2586. -
csharpsquid:S8949asks for aCancellationTokento be passed toWithAnalyzers, even though the only overload accepting one is obsolete. @Corniel, you’re right. We’ll exclude obsolete overloads and point the issue at the exact method. Insightful note about Visual Studio hiding that overload too! -
@Corniel also spotted that
csharpsquid:S1144flags a private indexer setter that is in fact used. We reproduced it and created an internal ticket to fix it. Thanks for another clear snippet! -
eslint-plugin-sonarjscould lint its own rules witheslint-plugin-eslint-plugin, as @rakleed suggested. That would catch deprecated APIs and broken fixers before users ever hit them. Great suggestion, and JS-2587 is how we’ll make it happen!
Thanks again to everyone mentioned here - and to anyone we may have missed - for your ongoing contributions in making this community stronger and helping us improve Sonar products.
If you’d like to give a shout-out to someone, whether a community member or a SonarSourcer who helped you, please do so below. And if there’s someone you think we should acknowledge next week, let us know!