Hero
Count Down
Tune in August 25 at 2 PM EDT
AI generates code faster than your team can govern it. Every pull request needs a consistent, automated way to catch bugs, vulnerabilities, and architecture issues before they ship. This hands-on workshop shows you how to build that verification layer from scratch with SonarQube.
You'll connect SonarQube to a GitHub repository and run your first analysis in minutes. From there, you'll see how deterministic analysis surfaces bugs, security vulnerabilities, code smells, and architecture issues across 40+ languages—not just surface-level linting. You'll configure quality profiles to define what "good" looks like, then set quality gates that pass or fail code against your defined thresholds on every pull request.
You'll also wire SonarQube into a pull request workflow, where automated scanning and PR decoration give developers actionable feedback before code merges. Finally, you'll explore project- and portfolio-level views, including reliability, security, and maintainability ratings and code health trends that give your engineering org clear visibility.
Walk away with a working SonarQube project analyzing real code—and the confidence to apply quality profiles, quality gates, and automated verification to your own projects
Prerequisites
Prerequisites:
Participants should use a personal machine with Docker and a personal GitHub account (not a managed or enterprise account).
No prior SonarQube experience is required.