SonarQube is a continuous inspection platform for automated static code analysis, quality gates, and security findings across many programming languages in CI/CD workflows.

10.9k stars2.2k forksLGPL-3.0last commit Actively maintained

Cloud code quality and security platform that automates static analysis to detect issues and vulnerabilities, tracks technical debt, enforces coding standards across repositories, and integrates with CI workflows to provide reporting and remediation guidance.
SonarQube is a continuous inspection platform for automated static code analysis, quality gates, and security findings across many programming languages in CI/CD workflows.

10.9k stars2.2k forksLGPL-3.0last commit Actively maintained
Every option on this page is open source and free to run on your own hardware, so you own the data and there is no subscription to cancel. 1 of 1 shipped a commit in the last six months. Licences in this list: LGPL-3.0. In exchange you take on hosting, backups and updates yourself.
Browse everything in Code Quality & Static Analysis.