sonarqube Plugin
SonarQube is the AI code quality and security verification platform used by millions of developers to catch bugs, vulnerabilities, and leaked secrets. This plugin enforces those standards in the agent coding loop: 7,500+ distinct issue types, secrets scanning, agentic analysis, and quality gates across 40+ languages.
Install View latest version Open upstream repository
More actions and subscriptions
Compare latest version View observed updates for this package Subscribe with Atom View source record
Only the newest 50 observations in this subscription, not a full archive, upstream releases or installs. Updates-page links keep observation type and package filters; package-page links include all kinds for that package. Your local following list is not sent.
Install
This version is listed in the verified marketplace sonar (repository SonarSource/sonarqube-agent-plugins). Run these in Claude Code, in order:
- Add the marketplace
/plugin marketplace add SonarSource/sonarqube-agent-plugins - Install the plugin
/plugin install sonarqube@sonar
These commands install the marketplace's current upstream state, not the pinned commit snapshot on this page; the two can differ.
Contents of latest version 2.6.0 (commit 6142e57)
Contents 11
Skill9
-
sonar-analyze
skills/sonar-analyze/SKILL.mdPermalink -
sonar-coverage
skills/sonar-coverage/SKILL.mdPermalink -
sonar-dependency-risks
skills/sonar-dependency-risks/SKILL.mdPermalink -
sonar-duplication
skills/sonar-duplication/SKILL.mdPermalink -
sonar-fix-issue
skills/sonar-fix-issue/SKILL.mdPermalink -
sonar-integrate
skills/sonar-integrate/SKILL.mdPermalink -
sonar-list-issues
skills/sonar-list-issues/SKILL.mdPermalink -
sonar-list-projects
skills/sonar-list-projects/SKILL.mdPermalink -
sonar-quality-gate
skills/sonar-quality-gate/SKILL.mdPermalink
Agent1
-
sonarqube-reviewer.agent
agents/sonarqube-reviewer.agent.mdPermalink
Hook1
-
SessionStart
claude-hooks/hooks.jsonPermalink
Nothing matches.
Dependencies, compatibility and skill declarations
Recorded dependencies 0
No dependency requirements were recorded from plugin.json or marketplace entries. Only manifest fields saved with the snapshot are shown here; dependency declarations in other files are outside the current collection scope.
Recorded compatibility
No compatibility requirement was recorded for this snapshot from plugin.json or a marketplace entry. Only manifest fields saved with the snapshot are shown here. Declarations in a skill's SKILL.md header are collected separately and, when present, shown on their own under “Skill file declarations”; they never overwrite or fill in this value.
Skill file declarations 9
The content below was read separately from the header of each skill file (SKILL.md) at its pinned commit. It is text the file declares about itself, shown as an annotation only. It is stored apart from the snapshot's dependencies and compatibility (manifest fields) above and does not overwrite them. It is not the package license, version, install count or a release record, and none of it is verified.
Evidence scope and limits
- Each entry is one file at one pinned commit, and field states hold for that file only. Components that point to the same file are merged into one entry; files with identical content share one extraction.
- “Declared in file” means the file's header has the field. “Not declared in this file” appears only when the header parsed successfully and lacks the field. “Invalid declaration” means the field is present but its type, length or characters do not meet the requirements; it is never rewritten or truncated. “Not read” means no usable header was obtained (not yet read, read failed, no header, or an unparseable header), which says neither that the field was declared nor that it was not.
- Compatibility and license text are the file's own wording. They do not show that anything runs, are not legal advice, and are not a license verification. metadata.version is only an annotation inside the file; it is not the package version and is not used to judge which is newer.
- This list groups the version's skill components by their recorded source. A listed source may still be unpinned, unread or unavailable; each entry shows its state. Collection runs in bounded batches and does not promise complete coverage.
- A file whose read failed shows a “retry eligible” time. It is only when the collector may try again, not a schedule, and it does not promise a read or completion.
1–9 of 9 skill file sources · As of
-
Header parsedskills/sonar-analyze/SKILL.mdComponents using this file 1
- sonar-analyze
skills/sonar-analyze/SKILL.md
Fields declared in the file
- Compatibility (declared in file)
- Not declared in this fileThe header parsed and has no such field; true for this file only.
- License text (declared in file, unverified)
- Not declared in this fileThe header parsed and has no such field; true for this file only.
- metadata.version (file annotation)
- Not declared in this fileThe header parsed and has no such field; true for this file only.
- Source
- Open pinned source file
- Repository
sonarsource/sonarqube-agent-plugins- Pinned commit
6142e57738debc3ef203a7b20551376377c69218- File identity
- Regular-file identity recorded
- Blob SHA
2317667308362f7987bb0718313263c684fa069d- Mode
100644- Identity recorded
- Header parse
- Header parsed
Extraction record
First extracted by extractor version
1.- First read from
- The same file as above.
- sonar-analyze
-
Header parsedskills/sonar-coverage/SKILL.mdComponents using this file 1
- sonar-coverage
skills/sonar-coverage/SKILL.md
Fields declared in the file
- Compatibility (declared in file)
- Not declared in this fileThe header parsed and has no such field; true for this file only.
- License text (declared in file, unverified)
- Not declared in this fileThe header parsed and has no such field; true for this file only.
- metadata.version (file annotation)
- Not declared in this fileThe header parsed and has no such field; true for this file only.
- Source
- Open pinned source file
- Repository
sonarsource/sonarqube-agent-plugins- Pinned commit
6142e57738debc3ef203a7b20551376377c69218- File identity
- Regular-file identity recorded
- Blob SHA
21eaaf391a7a0d44bc90500f68c8e680122ef4ad- Mode
100644- Identity recorded
- Header parse
- Header parsed
Extraction record
First extracted by extractor version
1.- First read from
- The same file as above.
- sonar-coverage
-
Not readskills/sonar-dependency-risks/SKILL.mdComponents using this file 1
- sonar-dependency-risks
skills/sonar-dependency-risks/SKILL.md
Fields declared in the file
- Compatibility (declared in file)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- License text (declared in file, unverified)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- metadata.version (file annotation)
- Not readNo usable header, which says neither that it was declared nor that it was not.
This file has no usable extraction record yet, so all three fields show as “Not read”.
- Source
- Open pinned source file
- Repository
sonarsource/sonarqube-agent-plugins- Pinned commit
6142e57738debc3ef203a7b20551376377c69218- File identity
- Regular-file identity recorded
- Blob SHA
4a1e8d2c5faea4d3e0ffbd99191b9e36f734ce44- Mode
100644- Identity recorded
- Header parse
- Not read
- Why not read
- The file identity is recorded, but its content has not been read yet.
declaration_unread
No extraction record yet.
- sonar-dependency-risks
-
Not readskills/sonar-duplication/SKILL.mdComponents using this file 1
- sonar-duplication
skills/sonar-duplication/SKILL.md
Fields declared in the file
- Compatibility (declared in file)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- License text (declared in file, unverified)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- metadata.version (file annotation)
- Not readNo usable header, which says neither that it was declared nor that it was not.
This file has no usable extraction record yet, so all three fields show as “Not read”.
- Source
- Open pinned source file
- Repository
sonarsource/sonarqube-agent-plugins- Pinned commit
6142e57738debc3ef203a7b20551376377c69218- File identity
- Regular-file identity recorded
- Blob SHA
30b2c47e1361ea491b127997da11640d9e0cad95- Mode
100644- Identity recorded
- Header parse
- Not read
- Why not read
- The file identity is recorded, but its content has not been read yet.
declaration_unread
No extraction record yet.
- sonar-duplication
-
Not readskills/sonar-fix-issue/SKILL.mdComponents using this file 1
- sonar-fix-issue
skills/sonar-fix-issue/SKILL.md
Fields declared in the file
- Compatibility (declared in file)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- License text (declared in file, unverified)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- metadata.version (file annotation)
- Not readNo usable header, which says neither that it was declared nor that it was not.
This file has no usable extraction record yet, so all three fields show as “Not read”.
- Source
- Open pinned source file
- Repository
sonarsource/sonarqube-agent-plugins- Pinned commit
6142e57738debc3ef203a7b20551376377c69218- File identity
- Regular-file identity recorded
- Blob SHA
168ed1bef7d438910496a4696a4b28b0f4c22374- Mode
100644- Identity recorded
- Header parse
- Not read
- Why not read
- The file identity is recorded, but its content has not been read yet.
declaration_unread
No extraction record yet.
- sonar-fix-issue
-
Not readskills/sonar-integrate/SKILL.mdComponents using this file 1
- sonar-integrate
skills/sonar-integrate/SKILL.md
Fields declared in the file
- Compatibility (declared in file)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- License text (declared in file, unverified)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- metadata.version (file annotation)
- Not readNo usable header, which says neither that it was declared nor that it was not.
This file has no usable extraction record yet, so all three fields show as “Not read”.
- Source
- Open pinned source file
- Repository
sonarsource/sonarqube-agent-plugins- Pinned commit
6142e57738debc3ef203a7b20551376377c69218- File identity
- Regular-file identity recorded
- Blob SHA
1b3eebd33b423c69fbd732180210b663a7dfb5fb- Mode
100644- Identity recorded
- Header parse
- Not read
- Why not read
- The file identity is recorded, but its content has not been read yet.
declaration_unread
No extraction record yet.
- sonar-integrate
-
Not readskills/sonar-list-issues/SKILL.mdComponents using this file 1
- sonar-list-issues
skills/sonar-list-issues/SKILL.md
Fields declared in the file
- Compatibility (declared in file)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- License text (declared in file, unverified)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- metadata.version (file annotation)
- Not readNo usable header, which says neither that it was declared nor that it was not.
This file has no usable extraction record yet, so all three fields show as “Not read”.
- Source
- Open pinned source file
- Repository
sonarsource/sonarqube-agent-plugins- Pinned commit
6142e57738debc3ef203a7b20551376377c69218- File identity
- Regular-file identity recorded
- Blob SHA
27f76f27a2895c2b5b42aeeea0c4da7413d4e182- Mode
100644- Identity recorded
- Header parse
- Not read
- Why not read
- The file identity is recorded, but its content has not been read yet.
declaration_unread
No extraction record yet.
- sonar-list-issues
-
Not readskills/sonar-list-projects/SKILL.mdComponents using this file 1
- sonar-list-projects
skills/sonar-list-projects/SKILL.md
Fields declared in the file
- Compatibility (declared in file)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- License text (declared in file, unverified)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- metadata.version (file annotation)
- Not readNo usable header, which says neither that it was declared nor that it was not.
This file has no usable extraction record yet, so all three fields show as “Not read”.
- Source
- Open pinned source file
- Repository
sonarsource/sonarqube-agent-plugins- Pinned commit
6142e57738debc3ef203a7b20551376377c69218- File identity
- Regular-file identity recorded
- Blob SHA
b547a5ceed3117b71ce5df6d846cd750eb33dc60- Mode
100644- Identity recorded
- Header parse
- Not read
- Why not read
- The file identity is recorded, but its content has not been read yet.
declaration_unread
No extraction record yet.
- sonar-list-projects
-
Not readskills/sonar-quality-gate/SKILL.mdComponents using this file 1
- sonar-quality-gate
skills/sonar-quality-gate/SKILL.md
Fields declared in the file
- Compatibility (declared in file)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- License text (declared in file, unverified)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- metadata.version (file annotation)
- Not readNo usable header, which says neither that it was declared nor that it was not.
This file has no usable extraction record yet, so all three fields show as “Not read”.
- Source
- Open pinned source file
- Repository
sonarsource/sonarqube-agent-plugins- Pinned commit
6142e57738debc3ef203a7b20551376377c69218- File identity
- Regular-file identity recorded
- Blob SHA
54895583d5a5b0f0a9471ccbf549cff4ef809e03- Mode
100644- Identity recorded
- Header parse
- Not read
- Why not read
- The file identity is recorded, but its content has not been read yet.
declaration_unread
No extraction record yet.
- sonar-quality-gate
All versions2
Each commit is an immutable snapshot, newest first. One version label can map to several commits.
| Version | Commit | Captured | Components | Actions |
|---|---|---|---|---|
| 2.6.0 Latest Same label, several commits | 6142e57 |
11 | View Download Diff vs previous Compare… | |
| 2.6.0 Same label, several commits | f194f77 |
11 | View Download Compare… |