Hi all,
Sonar is thrilled to announce the availability of SonarQube Server 2026.5, our newest Long-Term Active (LTA) version! This is a particularly exciting release, bringing Sonar’s new agentic capabilities to SonarQube Server for the first time.
The official announcement provides a summary of all new features introduced since the last 2026.1 LTA release.
This release brings a lot to unpack, from new agentic capabilities to expanded language and security coverage:
- Sonar’s full agentic capabilities - Sonar Vortex, SonarQube Remediation Agent, and SonarQube Hunter Agent - now available and deployable entirely inside your own self-managed infrastructure, including VPC-restricted environments
- Enterprise AI connectivity, letting administrators register their own LLM provider (AWS Bedrock, Azure AI Foundry, now with APIM support, or bring-your-own-key) and share it across the agentic products
- Reachability-driven SCA in Advanced Security for Java, Python, and C#, plus local SCA parsing: manifest files are parsed entirely on your infrastructure, and only package identifiers (never file contents or your project name) are sent to the cloud, which is used only for vulnerability and licensing lookups
- Security alerts for immediate notification of critical findings, and secrets masking and redaction by default
- Customizable dashboards for quality and security posture across projects and portfolios, plus a new project coverage dashboard for administrators
- Cross-project architecture management, in beta, extending architecture visibility and governance across your whole organization
- Deeper C/C++ analysis, with a new taint analysis engine and cross-file analysis that catches bugs spanning multiple files
- MuleSoft DataWeave and R language support, plus Rust analysis beyond Clippy
- MISRA C/C++ Compliance, WCAG Accessibility, and the EU Cyber Resilience Act (CRA) Compliance reports, alongside expanded MISRA C:2012 coverage
- Flexible, consumption-based billing for teams scaling usage beyond their contract
Since SonarQube Server 2026.1, key additions include a quality gate purpose-built for agent-generated code, native AI connectivity through the embedded SonarQube MCP Server, unified dependency risk reporting with CycloneDX 1.6 VEX export, up to 90% faster pull request analysis for large Java and C# projects, Groovy and Gosu support, and expanded language coverage across Java 25, Python web frameworks, PowerShell, Ruby, and Apex.
Technical requirements & server environment:
- The new agentic products (Sonar Vortex, SonarQube Remediation Agent, and SonarQube Hunter Agent) ship as additive, opt-in containers as part of the SonarQube platform and require a customer-provided shared storage layer (e.g., S3 or NFS) and a sandboxed container runtime. See the AI Agents deployment documentation for guidance.
- ZIP install of SonarQube Server is supported but deprecated. Support will be removed in a future release. We encourage you to move to Docker and/or Kubernetes going forward.
- Several significant changes are included in this release - Helm chart ingress-nginx removal, an Elasticsearch version update, a Kubernetes/OpenShift minimum version bump, PostgreSQL 15+ now required, Node.js 20 no longer supported for JS/TS scanners, and Security Hotspots deprecated in favor of Security Issues. Please review the update notes carefully before updating.
Upgrade path and documentation
- You must be on the 2026.1 LTA before updating to the 2026.5 LTA.
- You’ll find information about SonarQube Server 2026.5 LTA in the release notes and details in the full release notes).
- If you’re updating from the previous LTA (2026.1), you’ll find a consolidated version of the release notes in the LTA to LTA release notes. When upgrading across multiple versions, ensure you review the upgrade notes for all intervening versions. Importantly, if your current SonarQube version is older than 2026.1, you must first upgrade to 2026.1 before proceeding to 2026.5 LTA.
Please open new threads for any questions you have about this release or other features.
As usual, Docker images are also available on Docker Hub and Helm charts are available on ArtifactHub. Downloads are available at sonarsource.com.
Chris