AppSecNews
SAST Open source and commercial Established

SonarLint

by Sonar

IDE extension that analyzes code as you type and, in connected mode, applies the same rules and suppressions as your server side Sonar analysis.

Visit sonarsource.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run SonarLint in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Product naming: the extension has been rebranded as SonarQube for IDE, confirm the current name in use
  • Language list per IDE differs, confirm the matrix for each supported editor

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

SonarLint runs the Sonar analyzers inside your editor. As you type it parses the file, builds a syntax tree, resolves what it can of the surrounding project, and marks issues inline with an explanation of why the pattern is a problem and what to do instead. The rules are the same analyzer implementations that run on the server, so a developer is not learning one tool's opinions locally and meeting a different set of opinions when the build runs.

Connected mode is the part that matters operationally. Bound to a SonarQube server or the hosted service, the extension pulls down the project's quality profile, so the rules enabled locally are exactly the rules the project is gated on, along with issue suppressions and false positive marks already recorded on the server. It also pulls down the rules that require whole project context, including the taint analysis rules for injection classes that a standalone editor session cannot compute on its own, and shows those server computed findings in the editor with the flow steps that produced them.

Where it fits

This is the leftmost point in the pipeline: a developer's editor, before the code is committed. It is the delivery mechanism for a Sonar deployment rather than an independent product, and it is most valuable in an organization that already runs server side analysis and wants developers to stop discovering violations at build time. Nothing has to be built and nothing has to be deployed. Developers install it, and the security or platform team defines the quality profile it inherits.

Strengths

  • Findings appear while the code is being written, which is the cheapest possible point to fix them.
  • Connected mode guarantees local and server rules agree, eliminating the most common source of developer frustration with static analysis.
  • Explanations include the reasoning and a corrected example, so the tool teaches rather than just blocking.
  • Broad language coverage across several major editors from one product family.

Limitations

  • Standalone, without a server connection, the rule set is a subset. The injection and taint rules that carry the most security weight need connected mode against a commercially licensed edition.
  • Analysis is scoped to files you have open, so it gives no view of the project as a whole and cannot serve as a gate.
  • It inherits whatever the server profile says. If the profile is badly curated the noise lands directly in the developer's editor.

Who it suits

Effectively mandatory for teams already running Sonar server side, where it turns the gate into continuous feedback. Of limited value as a standalone security tool for a team with no Sonar deployment, since the strongest rules are precisely the ones that require the server.

Used SonarLint? Recommend it under your own name and title.

Recommend this tool