Sonarcloud / Sonarqube vulnerability database

Hi,

Our security team asks what vulnerability database does sonarcloud / sonarqube uses.
Do I have some guidance where to find the information? We use javascript, c#, java, python…

Example list:
CWE
https://wiki.sei.cmu.edu/

Thank you

Hello @void! You can check all the rules we check at https://rules.sonarsource.com/.

Regards,

Alexandre.

1 Like

Thank you!