# SonarQube Community Build product news [July]

Canonical: https://brew.new/browse/templates/email/pt1_k97k1psv8x8t89an012gp9jabh8e4cx5

Brand: sonarsource.com
Category: newsletter

![Preview of SonarQube Community Build product news [July]](https://cdn.brew.new/email-preview-ad9b15567cdc5148-tracking_r57z6mgqb5z6zx81qzjbnqtas58dt969-1789015456740.png)

## Email content

Sonar Source

July 2026

SonarQube Community Build product news

Hey Sonar community! Here's a rapid rundown of what's new and noteworthy with SonarQube:

🔐 Security Hotspots are being deprecated

🌐 Go 1.26.4 and Java 26 support

🔎 Improved default issue search sort order

🧩 New rules for HTML, IaC, Java, and JavaScript/TypeScript

🛡️ New banner shows what Community Build does and does not scan for security

Learn more about the latest SonarQube Community Build update below. 👇

SonarQube Community Build updates

SonarQube Community Build 26.7.0.124771 released

Sonar is excited to announce the availability of the SonarQube Community Build 26.7.0.124771, our July release.

This version brings support for Go 1.26.4 and Java 26, an improved default issue search sort order, and new rules for HTML, IaC, Java, and JavaScript/TypeScript, along with other enhancements. As a reminder, Security Hotspots are being deprecated.

What's new:

Issue search: the default issue list no longer groups results by component. Issues are now sorted by severity first and software quality second (Security, then Reliability, then Maintainability).

Go: version 1.26.4 is now supported, along with //nolint suppression support, automatic exclusion of protobuf-generated files, and faster analysis of large directories.

HTML: three new rules covering Content Security Policy restrictions and sandboxing/webSecurity settings, plus issue suppression support and configurable ARIA role allowlists.

IaC: three new cloud security rules covering RDS public accessibility, Azure Key Vault purge protection, and GCP Cloud Storage bucket access.

Java: Java 26 analysis support, plus new rules for JUnit 5 assertion and test-class best practices.

JavaScript, TypeScript, CSS: issue suppression support plus eight new rules for testing frameworks and assertions.

Security Hotspots deprecation: Deprecation notices and badges now appear across the Security Hotspots and Measures pages, and the /api/hotspots/* endpoints are marked deprecated.

Know exactly what Community Build scans for

It matters to know which vulnerabilities your analysis catches, and which it does not. Community Build now shows a banner on the project overview page that makes this explicit: it does not detect critical injection vulnerabilities such as SQL injection and cross-site scripting (XSS). Detection for these classes relies on taint analysis, which is available in SonarQube Server, SonarQube Cloud, and Advanced Security. The banner links to those editions so you can compare what each one covers.

For further details on this release, please refer to the documentation and our full release notes. Please open a new topic in the

SonarQube Community for any questions you have about these or other features.

As usual, download is available on our website. SonarQube Docker images are available on Docker Hub. You can find the latest SonarQube Community Build Helm chart and installation instructions on

SonarQube Artifact Hub.

Read more

Trusted by users everywhere

G2 Spring 2026 - Leader Enterprise

G2 Spring 2026 - Leader

G2 Spring 2026 - Momentum Leader

Garter 2025

Sonar

YouTube

X

LinkedIn

Not rendering correctly? View in browser

This email was sent by: SonarSource Sàrl

P.O. Box 765, Geneva, GE, CH-1215 Switzerland

You are receiving this email because you previously engaged with SonarSource.

Don't want to receive emails from us? Unsubscribe

Update Profile Manage Subscriptions

Privacy Policy

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97k1psv8x8t89an012gp9jabh8e4cx5)

[Browse email designs](https://brew.new/browse/templates)
