web analytics

SonarQube Server 10.8 Release Announcement – Source: securityboulevard.com

Rate this post

Source: securityboulevard.com – Author: Robert Curlee

In the 10.8 release of SonarQube Server, you’ll find these new and exciting capabilities:

  • Use your own quality gate for AI Code Assurance
  • Early Access to AI CodeFix is extended to Developer Edition
  • Standard Experience and Multi-Quality Rule Mode
  • Dart/Flutter moves from early access to a fully supported language
  • Introducing architecture rules for Java
  • Support for Ansible IaC
  • Advanced secrets detection
  • Includes many more language updates

Read on to find out more.

Powerful AI Enhancements

Our newly released AI Code Assurance helps you take back ownership of your projects that include AI-generated code. With a new Sonar-recommended AI Code Assurance quality gate, both new code and overall code are checked to make sure your whole codebase meets our strict standards. Want to use your own quality gate for AI Code Assurance? You can! Simply mark your custom quality gate as “Qualified for AI Code Assurance”, and teams will know which company-trusted quality gate to use for AI Code Assurance. Everyone wants to try out our AI CodeFix suggestions, so we’re extending Early Access to Developer Edition. Now, all developers using SonarQube Server can get AI CodeFix suggestions. Lastly, you can accept AI CodeFix suggestions right in place in your code in connected mode with all the IDEs we support: IntelliJ, VS Code, Eclipse, and now Visual Studio.

Chose Between Operating Modes

There are now two different operating modes for SonarQube Server: Standard Experience and Multi Quality Rule (MQR) Mode. The Standard Experience preserves the familiar rule and issue qualities (Bug, Vulnerability, and Code Smell) and custom severities Sonar has historically offered. MQR Mode shows the new Clean Code Taxonomy model, where rules and issues can have multiple qualities, including a severity setting per quality. In MQR Mode, we’ve also added the ability to set custom severity levels just like in the Standard Experience, so you can override the default with a severity level that suits your business needs. Moreover, you can decide which model works best for your business and switch at any time without disruption. If you’re not sure which one is right for you, don’t worry. We’ll default to the one that best matches the behavior of the SonarQube version you’re upgrading from.

Language Updates: Architecture, Ansible IaC, and More

This release introduces our first architecture rules to help developers find circular class dependencies in Java code. These kinds of architectural issues can be hard to find on your own. This is just the beginning, too. Be on the lookout as we continue adding more rules to SonarQube Server to help developers uncover and correct complex architecture issues in your code. Ansible is one of the leading infrastructure-as-code (IaC) tools for automating application provisioning, configuration, updating, and deployment. Now, SonarQube Server helps developers improve the quality and security of your Ansible IaC. Dart is the fastest-growing multiplatform developer language and is increasingly popular for building mobile apps, especially mobile games. With a total of 115 rules for Dart, we move Dart/Flutter from Early Access to a fully supported language in this release. Lastly, SonarQube Server receives a further boost in secrets detection now with a whopping 119 rules covering 166 secrets patterns and 113 cloud services. Our goal is to deliver industry-leading secrets detection as we scan your code repository and enable you to start left in your IDE when SonarQube Server and SonarQube for IDE are connected.

The SonarQube Server 10.8 release announcement and our 10.8 release notes provide more details about the release.

Are you still using an older version of SonarQube Server?

If you’re on a version older than 9.9, upgrade to SonarQube Server 9.9 LTA before upgrading to 10.8. Check out this helpful checklist for a smoother upgrade. Watch the on-demand LTA upgrade webinar, which explains a step-by-step approach and highlights common pitfalls encountered during the upgrade.

*** This is a Security Bloggers Network syndicated blog from Blog RSS feed authored by Robert Curlee. Read the original post at: https://www.sonarsource.com/blog/sonarqube-server-10-8-release-announcement/

Original Post URL: https://securityboulevard.com/2024/12/sonarqube-server-10-8-release-announcement/

Category & Tags: Security Bloggers Network – Security Bloggers Network

Views: 2

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post