AppSecNews
SAST Commercial, free tier Growing

Qodana

by JetBrains

Static analysis platform that runs the inspection engine from JetBrains IDEs as a containerized pipeline job with quality gates and trend reporting.

Visit jetbrains.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Qodana in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
  • Language list and which languages sit in which tier, confirm against the current product matrix
  • C and C++ coverage: confirm whether the CLion based linter is generally available
  • Feature split between the free tier and paid tiers, confirm

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Qodana takes the inspection engine that already runs inside JetBrains IDEs and packages it to run headlessly. Those inspections are not text patterns. They operate on the same project model the IDE builds, with resolved symbols, inferred types and framework awareness, which is why they can reason about things like a Spring bean wired with the wrong scope or a nullable value crossing an annotation boundary. Running that engine outside the IDE means the analysis a developer sees while typing and the analysis that gates the build come from the same source, so the two do not disagree.

It is distributed as language specific container images, one per technology stack, and invoked from a pipeline job or the command line. Results are emitted in SARIF and rendered in a report with baselines, so you can fail a build only on findings introduced by the current change. A quality gate expresses thresholds by severity. Alongside general inspections there are checks mapped to common vulnerability categories, license audit of dependencies, and detection of hardcoded credentials in source.

Where it fits

The natural placement is a pull request job in a team that already develops in JetBrains IDEs, where the payoff is consistency: the same rule set locally and in the pipeline, with the IDE able to open a server side report and navigate to findings. It needs a project the analyzer can resolve, which in practice means dependency resolution has to succeed inside the container, and that is the most common source of setup friction. Developers own it. Security teams consume the subset of inspections that map to vulnerability classes.

Strengths

  • Findings match what developers already see in their editor, which removes the usual argument about a pipeline tool reporting things the IDE does not.
  • Genuine project level resolution and framework awareness rather than syntactic matching.
  • Baselines and quality gates make it practical to adopt on an existing codebase without a large upfront cleanup.

Limitations

  • Security depth is the weaker half. This is a code quality engine with security inspections attached, not a scanner built around taint analysis, and it will not match a dedicated SAST tool on injection classes.
  • Language coverage is split across separate images and across licensing tiers, so a polyglot repository means several jobs and a careful read of what your tier includes.
  • Container based analysis with full project resolution is slower and heavier than lightweight pattern scanners.

Who it suits

A good fit for teams standardized on JetBrains tooling who want their existing inspection profile enforced in continuous integration. If your primary goal is vulnerability detection rather than code quality, treat it as a complement to a dedicated scanner, not a replacement.

Used Qodana? Recommend it under your own name and title.

Recommend this tool