Sonar Introduces AI Code Assurance and AI CodeFix
October 03, 2024

Sonar announced two new product capabilities for today’s AI-driven software development ecosystem.

These new capabilities are designed to support better software development in two critical and distinct ways – Sonar AI Code Assurance and Sonar AI CodeFix improve the quality of code produced by generative AI and enhance Sonar’s offering with AI to deliver a better developer experience, respectively. Both capabilities deepen Sonar’s commitment to the delivery of high-quality, secure code and increasing developer productivity.

AI Code Assurance helps organizations ensure the quality of AI-generated code by thoroughly analyzing the codebase for issues, ensuring that projects using AI tools to generate code meet high standards of quality and security. Today, bad code is already estimated to cost businesses more than a trillion dollars, making it critical for AI-generated code, which promises to increase the volume of code written, to be comprehensively checked for quality and security issues.

“AI is transforming the way developers work, streamlining processes, and reducing the toil associated with writing code. As the adoption of AI coding assistants grows, however, we are seeing a new issue emerge: code accountability. AI-generated code needs review by developers, but accountability for doing this is increasingly diluted. As a result, we’re seeing the review step frequently being shortchanged,” said Tariq Shaukat, CEO of Sonar. “With AI Code Assurance, we’re helping organizations ensure that AI written code receives the high level of quality and security review that you would expect from your developers.”

AI CodeFix allows developers to seamlessly resolve issues detected by Sonar's code analysis engine with a single click, directly within their workflow. The AI-powered fix recommendations help streamline developer workflows, speed up issue remediation, and improve the developer experience. As leading research has established, developer experience improves with the automation that AI provides. For example, McKinsey reported that developers using generative AI tools in their work stream are “twice as likely to report overall happiness, fulfillment, and a state of flow” than those who aren’t.

“AI CodeFix helps developers streamline their workflow and ramp up their productivity. Rather than switching between solutions or manual efforts, we’re putting remediation options for Sonar-identified issues right in front of the people working on them – and giving them the ability to fix the issues in an instant. We’re excited to see how our users adopt this capability and better understand how we can further integrate AI into our solutions to improve the developer experience,” said Fabrice Bellingard, VP of Product at Sonar.

The features are currently available for both SonarQube and SonarCloud.

AI Code Assurance for Confidence in Code Quality: With AI Code Assurance for SonarQube and SonarCloud, developers can be confident that their AI-generated code is clean and secure. By implementing the Sonar AI Code Assurance workflow, organizations have the assurance that all code (AI-generated and human-developed) has been thoroughly scanned for issues and that projects leveraging AI tools are meeting high standards of quality and security.

AI Code Assurance capabilities include:

- Project Tagging: Developers can easily tag projects that contain AI-generated code, initiating a comprehensive analysis through the Sonar AI Code Assurance workflow.

- Quality Gate Enforcement: An optimized quality gate for AI-generated code ensures that only code meeting strict quality and security standards is approved for production.

- AI Code Assurance Approved Badge: Projects that pass the quality gate receive a badge signifying that the code has gone through a rigorous AI-ready analysis.

AI CodeFix for Fast Issue Remediation: Fast-paced software development environments require solutions that enhance productivity, reduce time-to-market, and maintain high code quality. Today, millions of Sonar users can detect and fix issues in their code leveraging Sonar’s database of code rules and best practices. Now, at the click of a button, developers can use AI CodeFix to automatically generate solutions to issues in the same SonarQube and SonarCloud user interface where they review issues.

AI CodeFix capabilities include:

- Instant Code Fixes: Minimize manual debugging efforts and increase productivity by automatically generating code fix suggestions.

- Contextual Understanding of Sonar findings: Leverages LLMs to understand code context and provide relevant fixes.

- Seamless Integration: Developers fix issues directly within their IDE using SonarLint connected mode, ensuring a smooth workflow.

- Continuous Learning: Ongoing suggestion improvements based on user feedback

- Multi-Language Support: Supports flagship programming languages such as Java, JS/TS, C#, Python, and C/C++.

AI Code Assurance is now available on SonarQube and will be generally available in SonarCloud by the end of October.

AI CodeFix is available for early access in SonarQube Enterprise Edition, SonarQube Data Center Edition, and SonarCloud Team and Enterprise plans.

Share this

Industry News

December 11, 2025

Backslash Security announced the launch of its end-to-end solution for the secure use of Model Context Protocol (MCP) servers across modern software development environments.

December 11, 2025

Google Cloud announced expanded support for Anthropic's Model Context Protocol (MCP), giving developers consistent and business-ready access to all Google and Google Cloud services using MCP.

December 11, 2025

Progress Software announced the Q4 2025 release of its developer toolsets Progress® Telerik® and Progress® Kendo UI®.

December 10, 2025

Couchbase announced the general availability of Couchbase AI Services, a comprehensive suite of capabilities that enables enterprises to build, deploy and govern agentic AI applications with the security, performance and reliability required for production environments.

December 10, 2025

Lightrun launched its new Model Context Protocol (MCP) solution, enabling a fully integrated Runtime Context for AI coding agents.

December 10, 2025

AgentField has emerged from stealth to do for AI agents what Kubernetes did for containers: turn them into scalable, governed production infrastructure.

December 10, 2025

Hud announced the launch of its Runtime Code Sensor, a platform designed to provide real-time, function-level production insights to both software engineers and AI coding agents.

December 10, 2025

Azul announced the acquisition of Payara, a global provider of enterprise-grade solutions for Jakarta EE (Java EE)-based applications and microservices for hybrid and cloud-native deployments.

December 09, 2025

The Linux Foundation, the nonprofit organization enabling mass innovation through open source, announced the formation of the Agentic AI Foundation (AAIF), and founding contributions of three leading projects driving innovation in open source AI; Anthropic’s Model Context Protocol (MCP), Block’s goose, and OpenAI’s AGENTS.md.

December 09, 2025

Coder introduced new capabilities that bring AI coding agents into secure, self-hosted workspaces, enabling enterprises to adopt AI safely at scale.

December 09, 2025

Sonatype unveiled Sonatype Guide, a new developer tool that makes AI-assisted software development faster, safer, and more efficient.

December 08, 2025

Ridge Security has made its flagship AI-powered solution, RidgeBot®, available on the Microsoft Azure Marketplace, Microsoft’s online store providing applications and services for use on Azure.

December 04, 2025

Check Point® Software Technologies Ltd. announced its new Check Point Quantum Firewall Software, R82.10, introducing 20 new capabilities designed to help enterprises safely adopt AI, protect distributed environments and simplify Zero Trust across hybrid networks.

December 03, 2025

Verdent AI announced major updates to its standalone desktop app, an AI-powered coding tool designed to help human developers juggle parallel tasks with unrivaled speed and clarity.

December 03, 2025

Akuity expanded its continuous delivery and promotion platform to support multi-environment, multi-target delivery.