claudemods

ModsSonar

sonarqube Plugin

SonarQube is the AI code quality and security verification platform used by millions of developers to catch bugs, vulnerabilities, and leaked secrets. This plugin enforces those standards in the agent coding loop: 7,500+ distinct issue types, secrets scanning, agentic analysis, and quality gates across 40+ languages.

Install View latest version Open upstream repository

More actions and subscriptions

Compare latest version View observed updates for this package Subscribe with Atom View source record

Only the newest 50 observations in this subscription, not a full archive, upstream releases or installs. Updates-page links keep observation type and package filters; package-page links include all kinds for that package. Your local following list is not sent.

Install

This version is listed in the verified marketplace sonar (repository SonarSource/sonarqube-agent-plugins). Run these in Claude Code, in order:

  1. Add the marketplace/plugin marketplace add SonarSource/sonarqube-agent-plugins
  2. Install the plugin/plugin install sonarqube@sonar

These commands install the marketplace's current upstream state, not the pinned commit snapshot on this page; the two can differ.

Contents of latest version 2.6.0 (commit 6142e57)

Contents 11

Skill9
Agent1
Hook1
Dependencies, compatibility and skill declarations

Recorded dependencies 0

No dependency requirements were recorded from plugin.json or marketplace entries. Only manifest fields saved with the snapshot are shown here; dependency declarations in other files are outside the current collection scope.

Recorded compatibility

No compatibility requirement was recorded for this snapshot from plugin.json or a marketplace entry. Only manifest fields saved with the snapshot are shown here. Declarations in a skill's SKILL.md header are collected separately and, when present, shown on their own under “Skill file declarations”; they never overwrite or fill in this value.

Skill file declarations 9

The content below was read separately from the header of each skill file (SKILL.md) at its pinned commit. It is text the file declares about itself, shown as an annotation only. It is stored apart from the snapshot's dependencies and compatibility (manifest fields) above and does not overwrite them. It is not the package license, version, install count or a release record, and none of it is verified.

Evidence scope and limits
  • Each entry is one file at one pinned commit, and field states hold for that file only. Components that point to the same file are merged into one entry; files with identical content share one extraction.
  • “Declared in file” means the file's header has the field. “Not declared in this file” appears only when the header parsed successfully and lacks the field. “Invalid declaration” means the field is present but its type, length or characters do not meet the requirements; it is never rewritten or truncated. “Not read” means no usable header was obtained (not yet read, read failed, no header, or an unparseable header), which says neither that the field was declared nor that it was not.
  • Compatibility and license text are the file's own wording. They do not show that anything runs, are not legal advice, and are not a license verification. metadata.version is only an annotation inside the file; it is not the package version and is not used to judge which is newer.
  • This list groups the version's skill components by their recorded source. A listed source may still be unpinned, unread or unavailable; each entry shows its state. Collection runs in bounded batches and does not promise complete coverage.
  • A file whose read failed shows a “retry eligible” time. It is only when the collector may try again, not a schedule, and it does not promise a read or completion.

1–9 of 9 skill file sources · As of

  1. skills/sonar-analyze/SKILL.md

    Header parsed

    Components using this file 1

    • sonar-analyze skills/sonar-analyze/SKILL.md

    Fields declared in the file

    Compatibility (declared in file)
    Not declared in this fileThe header parsed and has no such field; true for this file only.
    License text (declared in file, unverified)
    Not declared in this fileThe header parsed and has no such field; true for this file only.
    metadata.version (file annotation)
    Not declared in this fileThe header parsed and has no such field; true for this file only.
    Repository
    sonarsource/sonarqube-agent-plugins
    Pinned commit
    6142e57738debc3ef203a7b20551376377c69218
    File identity
    Regular-file identity recorded
    Blob SHA
    2317667308362f7987bb0718313263c684fa069d
    Mode
    100644
    Identity recorded
    Header parse
    Header parsed

    Extraction record

    First extracted by extractor version 1.

    First read from
    The same file as above.
  2. skills/sonar-coverage/SKILL.md

    Header parsed

    Components using this file 1

    • sonar-coverage skills/sonar-coverage/SKILL.md

    Fields declared in the file

    Compatibility (declared in file)
    Not declared in this fileThe header parsed and has no such field; true for this file only.
    License text (declared in file, unverified)
    Not declared in this fileThe header parsed and has no such field; true for this file only.
    metadata.version (file annotation)
    Not declared in this fileThe header parsed and has no such field; true for this file only.
    Repository
    sonarsource/sonarqube-agent-plugins
    Pinned commit
    6142e57738debc3ef203a7b20551376377c69218
    File identity
    Regular-file identity recorded
    Blob SHA
    21eaaf391a7a0d44bc90500f68c8e680122ef4ad
    Mode
    100644
    Identity recorded
    Header parse
    Header parsed

    Extraction record

    First extracted by extractor version 1.

    First read from
    The same file as above.
  3. skills/sonar-dependency-risks/SKILL.md

    Not read

    Components using this file 1

    • sonar-dependency-risks skills/sonar-dependency-risks/SKILL.md

    Fields declared in the file

    Compatibility (declared in file)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    License text (declared in file, unverified)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    metadata.version (file annotation)
    Not readNo usable header, which says neither that it was declared nor that it was not.

    This file has no usable extraction record yet, so all three fields show as “Not read”.

    Repository
    sonarsource/sonarqube-agent-plugins
    Pinned commit
    6142e57738debc3ef203a7b20551376377c69218
    File identity
    Regular-file identity recorded
    Blob SHA
    4a1e8d2c5faea4d3e0ffbd99191b9e36f734ce44
    Mode
    100644
    Identity recorded
    Header parse
    Not read
    Why not read
    The file identity is recorded, but its content has not been read yet. declaration_unread

    No extraction record yet.

  4. skills/sonar-duplication/SKILL.md

    Not read

    Components using this file 1

    • sonar-duplication skills/sonar-duplication/SKILL.md

    Fields declared in the file

    Compatibility (declared in file)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    License text (declared in file, unverified)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    metadata.version (file annotation)
    Not readNo usable header, which says neither that it was declared nor that it was not.

    This file has no usable extraction record yet, so all three fields show as “Not read”.

    Repository
    sonarsource/sonarqube-agent-plugins
    Pinned commit
    6142e57738debc3ef203a7b20551376377c69218
    File identity
    Regular-file identity recorded
    Blob SHA
    30b2c47e1361ea491b127997da11640d9e0cad95
    Mode
    100644
    Identity recorded
    Header parse
    Not read
    Why not read
    The file identity is recorded, but its content has not been read yet. declaration_unread

    No extraction record yet.

  5. skills/sonar-fix-issue/SKILL.md

    Not read

    Components using this file 1

    • sonar-fix-issue skills/sonar-fix-issue/SKILL.md

    Fields declared in the file

    Compatibility (declared in file)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    License text (declared in file, unverified)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    metadata.version (file annotation)
    Not readNo usable header, which says neither that it was declared nor that it was not.

    This file has no usable extraction record yet, so all three fields show as “Not read”.

    Repository
    sonarsource/sonarqube-agent-plugins
    Pinned commit
    6142e57738debc3ef203a7b20551376377c69218
    File identity
    Regular-file identity recorded
    Blob SHA
    168ed1bef7d438910496a4696a4b28b0f4c22374
    Mode
    100644
    Identity recorded
    Header parse
    Not read
    Why not read
    The file identity is recorded, but its content has not been read yet. declaration_unread

    No extraction record yet.

  6. skills/sonar-integrate/SKILL.md

    Not read

    Components using this file 1

    • sonar-integrate skills/sonar-integrate/SKILL.md

    Fields declared in the file

    Compatibility (declared in file)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    License text (declared in file, unverified)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    metadata.version (file annotation)
    Not readNo usable header, which says neither that it was declared nor that it was not.

    This file has no usable extraction record yet, so all three fields show as “Not read”.

    Repository
    sonarsource/sonarqube-agent-plugins
    Pinned commit
    6142e57738debc3ef203a7b20551376377c69218
    File identity
    Regular-file identity recorded
    Blob SHA
    1b3eebd33b423c69fbd732180210b663a7dfb5fb
    Mode
    100644
    Identity recorded
    Header parse
    Not read
    Why not read
    The file identity is recorded, but its content has not been read yet. declaration_unread

    No extraction record yet.

  7. skills/sonar-list-issues/SKILL.md

    Not read

    Components using this file 1

    • sonar-list-issues skills/sonar-list-issues/SKILL.md

    Fields declared in the file

    Compatibility (declared in file)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    License text (declared in file, unverified)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    metadata.version (file annotation)
    Not readNo usable header, which says neither that it was declared nor that it was not.

    This file has no usable extraction record yet, so all three fields show as “Not read”.

    Repository
    sonarsource/sonarqube-agent-plugins
    Pinned commit
    6142e57738debc3ef203a7b20551376377c69218
    File identity
    Regular-file identity recorded
    Blob SHA
    27f76f27a2895c2b5b42aeeea0c4da7413d4e182
    Mode
    100644
    Identity recorded
    Header parse
    Not read
    Why not read
    The file identity is recorded, but its content has not been read yet. declaration_unread

    No extraction record yet.

  8. skills/sonar-list-projects/SKILL.md

    Not read

    Components using this file 1

    • sonar-list-projects skills/sonar-list-projects/SKILL.md

    Fields declared in the file

    Compatibility (declared in file)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    License text (declared in file, unverified)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    metadata.version (file annotation)
    Not readNo usable header, which says neither that it was declared nor that it was not.

    This file has no usable extraction record yet, so all three fields show as “Not read”.

    Repository
    sonarsource/sonarqube-agent-plugins
    Pinned commit
    6142e57738debc3ef203a7b20551376377c69218
    File identity
    Regular-file identity recorded
    Blob SHA
    b547a5ceed3117b71ce5df6d846cd750eb33dc60
    Mode
    100644
    Identity recorded
    Header parse
    Not read
    Why not read
    The file identity is recorded, but its content has not been read yet. declaration_unread

    No extraction record yet.

  9. skills/sonar-quality-gate/SKILL.md

    Not read

    Components using this file 1

    • sonar-quality-gate skills/sonar-quality-gate/SKILL.md

    Fields declared in the file

    Compatibility (declared in file)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    License text (declared in file, unverified)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    metadata.version (file annotation)
    Not readNo usable header, which says neither that it was declared nor that it was not.

    This file has no usable extraction record yet, so all three fields show as “Not read”.

    Repository
    sonarsource/sonarqube-agent-plugins
    Pinned commit
    6142e57738debc3ef203a7b20551376377c69218
    File identity
    Regular-file identity recorded
    Blob SHA
    54895583d5a5b0f0a9471ccbf549cff4ef809e03
    Mode
    100644
    Identity recorded
    Header parse
    Not read
    Why not read
    The file identity is recorded, but its content has not been read yet. declaration_unread

    No extraction record yet.

Read this page as JSON

All versions2

Each commit is an immutable snapshot, newest first. One version label can map to several commits.

VersionCommitCapturedComponentsActions
2.6.0 Latest Same label, several commits 6142e57 11 View Download Diff vs previous Compare…
2.6.0 Same label, several commits f194f77 11 View Download Compare…