Average Ratings 2 Ratings

Total
ease
features
design
support

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

SonarQube Server serves as a self-hosted solution for ongoing code quality assessment, enabling development teams to detect and address bugs, vulnerabilities, and code issues in real time. It delivers automated static analysis across multiple programming languages, ensuring that the highest standards of quality and security are upheld throughout the software development process. Additionally, SonarQube Server integrates effortlessly with current CI/CD workflows, providing options for both on-premise and cloud deployments. Equipped with sophisticated reporting capabilities, it assists teams in managing technical debt, monitoring progress, and maintaining coding standards. This platform is particularly well-suited for organizations desiring comprehensive oversight of their code quality and security while maintaining high performance levels. Furthermore, SonarQube fosters a culture of continuous improvement within development teams, encouraging proactive measures to enhance code integrity over time.

Description

The YAG Suite is a French-made innovative tool that takes SAST to the next level. YAGAAN is a combination of static analysis and machine-learning. It offers customers more than a sourcecode scanner. It also offers a smart suite to support application security audits and security and privacy through DevSecOps design processes. The YAG-Suite supports developers in understanding the vulnerability causes and consequences. It goes beyond traditional vulnerability detection. Its contextual remediation helps them to quickly fix the problem and improve their secure coding skills. YAG-Suite's unique 'code mining' allows for security investigations of unknown applications. It maps all relevant security mechanisms and provides querying capabilities to search out 0-days and other non-automatically detectable risks. PHP, Java and Python are currently supported. Next languages in roadmap are JS, C and C++.

API Access

Has API No 

API Access

Has API Yes 

Screenshots View All

Screenshots View All

Integrations

Jenkins Yes 
Python Yes 
Apache DevLake Yes 
ArmorCode Yes 
C++ Yes 
Coco Code Coverage Yes 
CodeScene Yes 
GitHub No 
GitLab No 
Go Yes 
KubeSphere Yes 
Monad Yes 
OpenAI Codex Yes 
OpenText Static Application Security Testing Yes 
OpsLevel Yes 
Parasoft Yes 
Plandek Yes 
SENTRIO Yes 
SonarQube Cloud Yes 

Integrations

Jenkins Yes 
Python Yes 
Apache DevLake No 
ArmorCode No 
C++ No 
Coco Code Coverage No 
CodeScene No 
GitHub Yes 
GitLab Yes 
Go No 
KubeSphere No 
Monad No 
OpenAI Codex No 
OpenText Static Application Security Testing No 
OpsLevel No 
Parasoft No 
Plandek No 
SENTRIO No 
SonarQube Cloud No 

Pricing Details

No price information available.
Free Trial No 
Free Version No 

Pricing Details

From €500/token or €150/mo
Subscription: SaaS from €150/month/100kLoc
On premise from €215/month/100kLoc

Subscriptions are based on the number of lines of code to scan, no limit on the number of scans / users / projects.
Tokens are valid for per application
Free Trial Yes 
Free Version Yes 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux Yes 
Chromebook No 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support No 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) Yes 
In Person No 

Vendor Details

Company Name

SonarSource

Founded

2008

Country

Switzerland

Website

www.sonarsource.com/products/sonarqube/

Vendor Details

Company Name

YAGAAN

Founded

2017

Country

France

Website

yagaan.com

Product Features

Application Security

Analytics / Reporting No 
Open Source Component Monitoring Yes 
Source Code Analysis Yes 
Third-Party Tools Integration No 
Training Resources Yes 
Vulnerability Detection Yes 
Vulnerability Remediation No 

Static Application Security Testing (SAST)

Application Security No 
Dashboard No 
Debugging No 
Deployment Management No 
IDE No 
Multi-Language Scanning No 
Real-Time Analytics No 
Source Code Scanning No 
Vulnerability Scanning No 

Static Code Analysis

Analytics / Reporting Yes 
Code Standardization / Validation Yes 
Multiple Programming Language Support Yes 
Provides Recommendations Yes 
Standard Security/Industry Libraries Yes 
Vulnerability Management Yes 

Product Features

Static Application Security Testing (SAST)

Application Security Yes 
Dashboard Yes 
Debugging No 
Deployment Management No 
IDE Yes 
Multi-Language Scanning Yes 
Real-Time Analytics No 
Source Code Scanning Yes 
Vulnerability Scanning Yes 

Static Code Analysis

Analytics / Reporting Yes 
Code Standardization / Validation Yes 
Multiple Programming Language Support Yes 
Provides Recommendations Yes 
Standard Security/Industry Libraries Yes 
Vulnerability Management Yes 

Vulnerability Scanners

Asset Discovery No 
Black Box Scanning No 
Compliance Monitoring No 
Continuous Monitoring No 
Defect Tracking No 
Interactive Scanning No 
Logging and Reporting No 
Network Mapping No 
Perimeter Scanning No 
Risk Analysis No 
Threat Intelligence No 
Web Inspection No 

Alternatives

SonarQube for IDE Reviews

SonarQube for IDE

SonarSource
PT Application Inspector Reviews

PT Application Inspector

Positive Technologies