Turn emails into revenue with Brew. No credit card, free credits to try.
sonarsource.com · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
Sonar Source
July 2026
SonarQube Community Build product news
Hey Sonar community! Here's a rapid rundown of what's new and noteworthy with SonarQube:
🔐 Security Hotspots are being deprecated
🌐 Go 1.26.4 and Java 26 support
🔎 Improved default issue search sort order
🧩 New rules for HTML, IaC, Java, and JavaScript/TypeScript
🛡️ New banner shows what Community Build does and does not scan for security
Learn more about the latest SonarQube Community Build update below. 👇
SonarQube Community Build updates
SonarQube Community Build 26.7.0.124771 released
Sonar is excited to announce the availability of the SonarQube Community Build 26.7.0.124771, our July release.
This version brings support for Go 1.26.4 and Java 26, an improved default issue search sort order, and new rules for HTML, IaC, Java, and JavaScript/TypeScript, along with other enhancements. As a reminder, Security Hotspots are being deprecated.
What's new:
Issue search: the default issue list no longer groups results by component. Issues are now sorted by severity first and software quality second (Security, then Reliability, then Maintainability).
Go: version 1.26.4 is now supported, along with //nolint suppression support, automatic exclusion of protobuf-generated files, and faster analysis of large directories.
HTML: three new rules covering Content Security Policy restrictions and sandboxing/webSecurity settings, plus issue suppression support and configurable ARIA role allowlists.
IaC: three new cloud security rules covering RDS public accessibility, Azure Key Vault purge protection, and GCP Cloud Storage bucket access.
Java: Java 26 analysis support, plus new rules for JUnit 5 assertion and test-class best practices.
JavaScript, TypeScript, CSS: issue suppression support plus eight new rules for testing frameworks and assertions.
Security Hotspots deprecation: Deprecation notices and badges now appear across the Security Hotspots and Measures pages, and the /api/hotspots/* endpoints are marked deprecated.
Know exactly what Community Build scans for
It matters to know which vulnerabilities your analysis catches, and which it does not. Community Build now shows a banner on the project overview page that makes this explicit: it does not detect critical injection vulnerabilities such as SQL injection and cross-site scripting (XSS). Detection for these classes relies on taint analysis, which is available in SonarQube Server, SonarQube Cloud, and Advanced Security. The banner links to those editions so you can compare what each one covers.
For further details on this release, please refer to the documentation and our full release notes. Please open a new topic in the
SonarQube Community for any questions you have about these or other features.
As usual, download is available on our website. SonarQube Docker images are available on Docker Hub. You can find the latest SonarQube Community Build Helm chart and installation instructions on
SonarQube Artifact Hub.
Read more
Trusted by users everywhere
G2 Spring 2026 - Leader Enterprise
G2 Spring 2026 - Leader
G2 Spring 2026 - Momentum Leader
Garter 2025
Sonar
YouTube
X
Not rendering correctly? View in browser
This email was sent by: SonarSource Sàrl
P.O. Box 765, Geneva, GE, CH-1215 Switzerland
You are receiving this email because you previously engaged with SonarSource.
Don't want to receive emails from us? Unsubscribe
Update Profile Manage Subscriptions
Privacy Policy