SonarCloud Profile Banner
SonarCloud Profile
SonarCloud

@SonarCloud

Followers
2,831
Following
123
Media
73
Statuses
502

SonarCloud, crafted by @SonarSource , is the leading online service for Code Quality & Security. Free analysis for open-source projects covering 24 languages.

Geneva, Switzerland
Joined August 2017
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@SonarCloud
SonarCloud
4 years
#Developers , do you know how easy it is to start analyzing your @github repository with SonarCloud? Just log in with your GitHub account, select your projects, and wait for the analysis to end. #CodeQuality and #CodeQuality should always be that simple!
6
57
405
@SonarCloud
SonarCloud
4 years
Elevate #CodeQuality and #CodeSecurity in your @GitLab repositories. With SonarCloud, you detect Bugs and Vulnerabilities, and get clear remediation guidance to fix them. Your code instantly gets cleaner and safer!
6
37
345
@SonarCloud
SonarCloud
4 years
Mono-repository support for #GitHub and #AzureDevOps available now! This new feature allows you to define multiple #QualityGates per project and receive multiple results in your pull requests. #codequality #codesecurity
1
19
263
@SonarCloud
SonarCloud
4 years
Automate the detection of Bugs and Vulnerabilities in your #AzureDevOps repositories across all branches and pull requests. Get a chance to fix issues in your code before even merging and deploying. #codequality #codesecurity #codereview
5
48
216
@SonarCloud
SonarCloud
4 years
Merge clean, safe code in your @GitHub repositories with fast, accurate feedback in your #pullRequest . SonarCloud helps you assess your code health and fix issues early in your development workflow. #codequality #codesecurity
4
45
168
@SonarCloud
SonarCloud
4 years
Improve Code Quality and Security in your @GitHub repositories, one #pullRequest at a time. SonarCloud helps you identify, understand, and fix code issues in your PR. So you merge clean, safe code every time. #codequality #codesecurity #codereview
5
29
128
@SonarCloud
SonarCloud
4 years
Detect the issues in your #pullRequest with SonarCloud! And clean your @GitHub repositories from Bugs, Vulnerabilities, and Code Smells that don't belong to your code. Get started in seconds. It's free for open-source projects! #codequality #codesecurity
2
24
128
@SonarCloud
SonarCloud
4 years
Shift Code Quality and Security left to your #pullRequest ! SonarCloud detects the issues in your PR and development branches. You also get clear remediation guidance on fixing them. So your code instantly gets cleaner and safer. #codequality #codesecurity
5
22
112
@SonarCloud
SonarCloud
5 years
Here’s to you @GitHub community: a GitHub Action that makes it even simpler to catch bugs and vulnerabilities in your Pull Requests! Join the GitHub Actions beta, and use the SonarCloud Scan action:
Tweet media one
1
29
92
@SonarCloud
SonarCloud
6 years
SonarCloud will decorate your pull requests with automatic code review, as soon as you create them. Available on @VSTS , @github and @Bitbucket !
Tweet media one
Tweet media two
Tweet media three
10
57
84
@SonarCloud
SonarCloud
6 years
Great day for all @VSTS users: you can now sign in to @sonarcloud using your @Azure Active Directory work account!
Tweet media one
1
37
41
@SonarCloud
SonarCloud
4 years
Find, fix and learn from issues in your code. SonarCloud for @Bitbucket Cloud provides the right feedback, at the right place, at the right time. Your Code Quality and Security improves and you sharpen your #dev skills learning new rules along the way!
1
8
39
@SonarCloud
SonarCloud
5 years
Heads-up Bitbucket users! Adding SonarCloud analysis to your pipeline just got way simpler.🤘 #bitbucketpipes #enhanceyourworkflow Check-out the new SonarCloud Pipe in our blog post👇
@SonarSource
Sonar
5 years
We’re thrilled to be a launch partner of the @Atlassian #bitbucketpipes ! CI/CD pipelines made simple, SonarCloud analysis set up in no time 💪 👉
0
7
20
0
4
27
@SonarCloud
SonarCloud
4 years
Continuous feedback on your code puts your mind in a good place! With SonarCloud for @Bitbucket Cloud, you're in control of Code Quality and Security in your repos. You save time and focus efforts on what matters most: developing new features.
3
5
25
@SonarCloud
SonarCloud
4 years
Get continuous feedback on your code with SonarCloud for @Bitbucket Cloud. Find bugs and vulnerabilities in your #pullrequest and development branches. As of today, you'll merge clean, safe code in your Bitbucket Cloud repositories. Every time.
0
4
20
@SonarCloud
SonarCloud
6 years
Scanning your projects and pull requests is also the opportunity to show your user community how much you care about quality software ❤ Check-out some featured projects 👉
Tweet media one
0
13
18
@SonarCloud
SonarCloud
7 years
Welcome to @sonarcloud official twitter account. Stay tuned about everything SonarCloud! #Saas #codequality #opensource
0
18
15
@SonarCloud
SonarCloud
6 years
"Integrate SonarCloud with VSTS to boost code quality"
Tweet media one
1
11
15
@SonarCloud
SonarCloud
5 years
Woot woot! Just reached 1 Billion Lines of Code 🚀 #crazygrowth Here goes ❤️❤️to all the devs and teams that killed countless bugs and vulnerabilities along the way. 💪 Join the fun @ !
Tweet media one
0
6
15
@SonarCloud
SonarCloud
6 years
Do you know that for most languages, we can now autonomously scan your code, by simply reading it from your repository? We call that AutoScan, and we think you’ll love it! 🎉 More details here 👇
1
9
15
@SonarCloud
SonarCloud
6 years
We've got a brand new page, hope you enjoy it! 🎉
Tweet media one
0
11
14
@SonarCloud
SonarCloud
7 years
Starting today, go and get the brand new badges for your open-source projects!
Tweet media one
1
18
15
@SonarCloud
SonarCloud
6 years
Yet another language supported on SonarCloud: @rubylangorg 🎉
Tweet media one
1
8
13
@SonarCloud
SonarCloud
1 year
We're pleased to announce Sonar is integrated with @Atlassian Compass! The Sonar Quality Gate Scorecard makes it easy for Compass users to understand if their component is built with #CleanCode 🚀✅ More information 👇
Tweet media one
0
4
11
@SonarCloud
SonarCloud
6 years
Introducing language #22 : @salesforce Apex! Already 50 static analysis rules for all Apex devs to embrace continuous code quality. #sfdx #SalesforceDX
Tweet media one
0
9
13
@SonarCloud
SonarCloud
6 years
You're doing JavaScript? SonarCloud has now built-in support for @geteslint issues! 😎 And it's as simple as using the "sonar.eslint.reportPaths" property. Enjoy!
Tweet media one
0
10
12
@SonarCloud
SonarCloud
6 years
The SonarCloud @VSTS extension now offers widgets to display the quality gate of your projects on your favorite VSTS dashboards!
Tweet media one
1
13
14
@SonarCloud
SonarCloud
6 years
Did you know that after @golang , @kotlin and @rubylangorg already added this year, another popular language is now supported on SonarCloud? And this is @scala_lang ! 🎉
Tweet media one
1
13
10
@SonarCloud
SonarCloud
6 years
More than 400M lines of code now analyzed on SonarCloud! 💪
0
4
12
@SonarCloud
SonarCloud
6 years
More than half a billion lines of code are now on analysed on SonarCloud (518 millions to be accurate), and still counting! 🚀
0
5
11
@SonarCloud
SonarCloud
7 years
SonarCloud VSTS/TFS Extension 1.0: for a greater user experience when analyzing VSTS projects on SonarCloud.
Tweet media one
1
13
13
@SonarCloud
SonarCloud
6 years
SonarCloud loves your build pipelines!
Tweet media one
0
8
9
@SonarCloud
SonarCloud
1 year
Once upon a time, #Java devs looked to the DSM to enhance their app design. Beyond code quality & security, structured code and clean architecture should are necessary pillars for #CleanCode We're excited to share we just got 3 new architectural rules!
Tweet media one
0
4
8
@SonarCloud
SonarCloud
6 years
Protect your code against injection vulnerabilities with SonarCloud!
Tweet media one
0
9
9
@SonarCloud
SonarCloud
6 years
"Write clean code with SonarCloud and Bitbucket Cloud", blog post by @kelvinyap and @bellingard @sonarcloud ❤️ @Bitbucket !
Tweet media one
0
6
11
@SonarCloud
SonarCloud
1 year
recursion really is one of the strangest, most difficult concepts to grasp while learning to code
@SonarLint
SonarLint
1 year
recursion really is one of the strangest, most difficult concepts to grasp while learning to code
1
0
4
0
0
7
@SonarCloud
SonarCloud
6 years
Do you know that you can find bugs and vulnerabilities in your Spring-based code thanks to 24 new rules? @sonarcloud ❤️ @springframework !
Tweet media one
0
5
9
@SonarCloud
SonarCloud
6 years
Celebrating SonarCloud 1 year anniversary! 🎂
Tweet media one
0
8
9
@SonarCloud
SonarCloud
6 years
Forget about the deprecated GitHub plugin and its preview mode, SonarCloud supports Pull Requests as first class citizens! Check this out on
Tweet media one
1
7
10
@SonarCloud
SonarCloud
4 years
Our #Python bug hunt in popular, well-maintained projects ( @TensorFlow , numpy, salt, sentry and @Biopython ) turned up interesting stuff like undefined var reference, unreachable code, and more.
Tweet media one
0
4
6
@SonarCloud
SonarCloud
4 years
Hey #AzureDevOps #developers ! We just added support for mono-repositories! Now, you can have one Quality Gate per project. And your comments in your PR will be tagged with the name of the related project. Let us know how that works for you! #codequality
0
4
7
@SonarCloud
SonarCloud
5 years
Talking of C++, here's for all #cpp devs: 20+ new rules to catch bugs and code smells in C++, and also C & #objectivec . 💪
@SonarSource
Sonar
5 years
Ever wondered what it takes to detect tricky bugs in C++ code? 🐛 Loïc, engineer in our Language Team, and member of @isocpp , just blogged about the intricacies of #cplusplus static code analysis! 👉
0
12
11
0
1
8
@SonarCloud
SonarCloud
4 years
Hey #GitHub #developers ! We just added support for mono-repositories! Now, you can have one Quality Gate per project. And your comments in your PR will be tagged with the name of the related project. Let us know how that works for you! #codequality
0
6
7
@SonarCloud
SonarCloud
6 years
Making clean code a mantra for all @AzureDevops users! SonarCloud decorates your Pull Requests, keeping bugs out so that you can merge with confidence! Learn more 👉🏽
Tweet media one
0
6
8
@SonarCloud
SonarCloud
1 year
We've got a surprise coming really soon... 👀
@vnON
vitaly zdanevich
2 years
@SonarCloud please add dark theme - respect @ prefers-color-scheme
1
0
0
0
0
6
@SonarCloud
SonarCloud
4 years
Continuing the security push! 🚀 @SonarSource , maker of SonarCloud, has acquired @ripstech . #appsec #developerFirst Read more about what this means for your code security 👉
@SonarSource
Sonar
4 years
We are excited to announce that SonarSource has acquired @ripstech ! Joining forces in building top-notch code security analyzers, helping all dev teams deliver more secure software. 💪 #appsec #developer -first Read more on our blog 👉
Tweet media one
0
27
44
0
2
6
@SonarCloud
SonarCloud
6 years
Import of issues from external linters with built-in support for TypeScript projects, support for the Go language, first version of the GitHub Application, ... check all what's recently been added to SonarCloud!
Tweet media one
0
8
5
@SonarCloud
SonarCloud
4 years
Hey @telegram , how about using SonarCloud for improving code quality and code security? Seems like we could help fix some bugs and vulnerabilities in your code. It's free for open source projects, with access to all the features! 😉
0
3
8
@SonarCloud
SonarCloud
3 years
Keeping your project’s code clean and safe is a team effort! SonarCloud provides a place where you get full visibility on the status & activity of your project. You’re going to love it! #developers #DevOps
0
1
5
@SonarCloud
SonarCloud
4 years
Developers, you now have a tool to own Code Security And guess what? You've been using it all along! Sonar[Qube|Cloud] gives you unparalleled precision in SAST detection without sacrificing performance. All you have to do is make sure you're up to date
Tweet media one
0
5
6
@SonarCloud
SonarCloud
4 years
We went on a bug hunt in popular, well-maintained #Python projects and found interesting problems basic linters just can't see.
Tweet media one
0
1
5
@SonarCloud
SonarCloud
7 years
Your organization? Your own open-source project? Your issues? You can now customize which page is your homepage on SonarCloud!
Tweet media one
0
5
4
@SonarCloud
SonarCloud
6 years
Looks like @libreoffice is now analyzed on SonarCloud: Nice!
Tweet media one
0
2
4
@SonarCloud
SonarCloud
4 years
Better Code Quality for your #JUnit tests with a set of new rules helping you to make sure you're following the framework's best practices! #java #security
1
2
5
@SonarCloud
SonarCloud
2 years
We’re happy to introduce everyone to @Sonar_Research ! If you’ve been a fan of our #security blogs & code challenges, then follow this page! Our R&D Team can’t wait to share their next critical code vulnerabilities in high-profile projects 👨‍💻🔎
Tweet media one
20
0
5
@SonarCloud
SonarCloud
6 years
@mattburrellnet Thanks! @SonarSource engineers right now:
0
0
4
@SonarCloud
SonarCloud
4 years
SonarCloud will no longer execute #Pylint rules! It's time to say thank you and goodbye! We have now reached a point on #Python analysis to where our native coding rules will get you faster, more accurate results, with fewer false-positives. #codequality
1
2
5
@SonarCloud
SonarCloud
4 years
Detect XSS vulnerabilities on DTL and Jinja2 template files! We are now analyzing Controller and HTML files in your #Python web apps made with #Django or #Flask . #CodeSecurity
0
2
5
@SonarCloud
SonarCloud
2 years
A more modern, consistent, and accessible #UI for @SonarCloud is born. New shapes, new colors, new fonts, consolidated layouts and components… Check it out!
7
3
5
@SonarCloud
SonarCloud
2 years
😎
@notmytech
Not My Tech
2 years
I just added sonar cloud in my pipelines, now i don't need to worry about code quality.
0
0
2
0
1
4
@SonarCloud
SonarCloud
4 years
@SonarSource There is an Open Redirect vulnerability! An attacker can send a link like ?next=javascript:alert(1) or ?next=//phishing.url to redirect you to a malicious site. Here is our solution on SonarCloud:
Tweet media one
0
1
3
@SonarCloud
SonarCloud
5 years
Fresh from the @SonarSource oven: new rules for @golang devs to catch quality issues in their Pull Requests 🔍 Make the most out of it Go teams!💪 #codequalityforall
@SonarSource
Sonar
5 years
We're continuously pushing forward our static code analysis engine, and this week's milestone is for Go code quality. Here's to you @golang devs! 👇
0
8
13
0
2
3
@SonarCloud
SonarCloud
4 years
Following the support of #Thymeleaf in #Java , SonarCloud now detects XSS in JSPs! More #security upates to come soon, stay tuned!
0
3
3
@SonarCloud
SonarCloud
6 years
You want to follow the status of the service or be notified in advanced of planned maintenances? Follow our new @sonarcld_status Twitter account and visit !
Tweet media one
0
4
3
@SonarCloud
SonarCloud
3 years
Using SonarCloud? Want to help improve the product experience? We'd love to interview you! You'll get a $30 Amazon gift card in exchange. Fill out the form to get a chance to participate. #usersurvey
1
0
1
@SonarCloud
SonarCloud
6 years
Today we have improved the functionality of SonarCloud centered around the analysis of C/C++/Objective-C code. Read "Continuously Improving Analysis of C/C++/Objective-C Code" by @nicoallgood
Tweet media one
0
3
4
@SonarCloud
SonarCloud
6 years
@nefarioustim @gitlab We contacted them a couple of times already to work together, but unfortunately it looks like they're not interested. And we prefer to concentrate on partners who are willing to build something great with us!
0
0
4
@SonarCloud
SonarCloud
4 years
#Java14 code scan is now available in #SonarCloud ! And it doesn't require any change on your side!
0
2
4
@SonarCloud
SonarCloud
5 years
@IkeMtz @AzureDevOps We are currently indeed experiencing delay in report processing, as communicated on . We do our best to get back to normal as soon as possible. Sorry for the inconvenience.
1
0
4
@SonarCloud
SonarCloud
4 years
Old-school #SAST tools raise lots of issues and expect someone else to sort it out. @SonarSource knows #developers don't have time for that. When we raise a #vulnerability you know there's something to fix
Tweet media one
0
3
4
@SonarCloud
SonarCloud
4 years
Shift left for higher quality pull requests with the new Code Insights feature in @Bitbucket Cloud #codesecurity
0
1
4
@SonarCloud
SonarCloud
1 year
@ocodista JavaScript analysis uses ESLint, but goes far beyond and includes things like taint analysis. And if you use other languages in your project, we'll that's covered too. Welcome aboard! 🌅
0
0
4
@SonarCloud
SonarCloud
1 year
0
0
4
@SonarCloud
SonarCloud
6 years
You use the service, we take care of the rest.
Tweet media one
0
9
2
@SonarCloud
SonarCloud
4 years
@SonarSource This code has an Argument Injection vulnerability in line 34 via the txtPackage input field. Executing own system commands is not possible but additional parameters can be appended to the executed "nuget" command.
Tweet media one
1
0
4
@SonarCloud
SonarCloud
4 years
@SonarSource Well done, denial of service via a user controlled regular expression (ReDoS) was what we were looking for here. Find out more about this #vulnerability :
Tweet media one
0
0
3
@SonarCloud
SonarCloud
3 years
Who said #CodeQuality & #CodeSecurity had to be painful? SonarCloud makes it easy for you! Our new project experience - available in beta - helps you assess your code health in seconds and support your team effort. Try it now!
0
0
3
@SonarCloud
SonarCloud
6 years
🎉 Want to discuss SonarCloud features and be part of a growing user community? Join us @ !
@SonarSource
Sonar
6 years
We’ve opened a new community forum for @sonarcloud @SonarLint @SonarQube users, and they love it already! Join the party on 🎉🎉
0
12
7
0
2
2
@SonarCloud
SonarCloud
2 years
How do you ensure your #Java pull requests are clean? In less than 3 minutes with SonarCloud you can get fast, precise feedback in your PRs. Give it a try.
0
1
3
@SonarCloud
SonarCloud
4 years
@SonarSource Well done! There was a tiny slip in the regex (line 18) that leads to a validation bypass and a Local File Inclusion (LFI) vulnerability (line 21). The dash in ".-_" allows chars in the range from "." to "_" including "../". Find out more about LFI here:
Tweet media one
1
0
3
@SonarCloud
SonarCloud
2 years
Review your security vulnerabilities directly in #GitHub . SonarCloud now integrates with code scanning allowing: > Easy code security review & prioritization > Fast security vulnerability investigation > Instant issue status synchronization Try it now!
0
0
3
@SonarCloud
SonarCloud
4 years
@SonarSource This challenge was about (in)secure communication. The http:// protocol is used that enables Man-in-the-Middle attacks. And even when the protocol is changed to https://, the certificate validation is bypassed. Find out more here:
Tweet media one
1
0
3
@SonarCloud
SonarCloud
6 years
Everything is back to normal now. Happy code analysis!
0
0
3
@SonarCloud
SonarCloud
4 years
@SonarSource E.g., the -Source parameter enables to install malicious packages from a remote repo, e.g. "package -Source ". Our payload is also used to create a directory name in line 31 which forbids ":". By using a long package name (>MAX_PATH) we can bypass this.
0
0
3
@SonarCloud
SonarCloud
9 months
SonarCloud Product News is here! Subscribe to receive information on product releases, events, and other updates, delivered directly to your email inbox. It’s never been easier to stay in the loop for all things SonarCloud. Subscribe below 👇
1
1
3
@SonarCloud
SonarCloud
4 years
@SonarSource In this #csharp code the backslash character can be used in a path traversal attack (..\) to disclose arbitrary files from the (Windows) host. Find out more about Path Injection here:
Tweet media one
1
0
3
@SonarCloud
SonarCloud
4 years
Java devs coding in VS Code: it's time to go next-level and pair up @SonarLint with your project in SonarCloud 💪
@SonarLint
SonarLint
4 years
And here goes to you @code users: SonarLint now supports analysis of Java code in VSCode! 🎯 Free update from the Marketplace, and you'll be catching @java bugs and vulnerabilities in no time. 👉
1
22
43
0
3
2