- Pull in code smells, bugs, code coverage, vulnerabilities, and custom metrics on entity details pages
- Create Scorecards that track progress and drive alignment on projects involving your SonarQube projects
How to configure SonarQube with Cortex
Self-hosted prerequisites
If you’re using a self-hosted instance of SonarQube, you’ll need to verify that your Cortex instance is able to reach the SonarQube instance. If you’re unable to directly allowlist our static IP, you can route requests through a secondary proxy in your network that has this IP allowlisted and have that proxy route traffic to your SonarQube instance.Configure the integration
There are two options for integrating SonarQube: the default configuration method and Cortex Axon Relay, a relay broker allows you to securely connect your on-premises SonarQube data.Default
Default
- In Cortex, navigate to the SonarQube settings page.
- Click Integrations from the main nav. Search for and select SonarQube.
- Click Add configuration.
- Configure the SonarQube integration form:
- Account alias: Enter the alias you will use to tie entity registrations to different configuration accounts.
- Token: Enter your user token from SonarQube.
- SonarQube URL: Enter the URL for your SonarQube instance.
- For example,
https://sonarcloud.ioif you are on SonarQube Cloud, orhttps://sonarqube.mycompany.comif your organization has their own instance.
- For example,
- Click Save.
Axon Relay
Axon Relay
Integrate via custom webhook
If you’re unable to expose your SonarQube instance to be reachable by Cortex, you can set up a custom integration webhook. To learn more about SonarQube webhooks, visit their webhook documentation.How to connect Cortex entities to SonarQube projects
Discovery
By default, Cortex will use the Cortex tag (e.g.my-entity) as the “best guess” for SonarQube component key. For example, if your Cortex tag is my-entity, then the corresponding component key in SonarQube should also be my-entity.
If your SonarQube component key doesn’t cleanly match the Cortex tag, you can override this in the Cortex entity descriptor.
Connect entities via YAML or the Cortex UI
Cortex UI
Cortex UI
- Navigate to an entity’s details page in Cortex.
-
In the upper right corner, click Configure entity.

-
Click the Code quality link in the sidebar.

-
In the center of the page, configure the details for your SonarQube project:
- Alias: If you have multiple configurations, select the one that this project is associated with.
- Project: Enter the project’s name.
- Click Save changes.
Entity YAML
Entity YAML
x-cortex-static-analysis block:Using the SonarQube integration
View SonarQube data on entity pages
Once the integration is established, data from SonarQube will be available in the Code & security page in an entity’s sidebar, as well as under the Overview tab. You can pull in data on code smells, bugs, code coverage, vulnerabilities, and any custom metrics available through Sonar. You can read more about metric definitions in Sonar’s documentation.- Metrics
- Complexity
- Duplications
- Issues
- Maintainability
- Quality gates
- Reliability
- Security
- Size
- Tests
- Code freshness
- Code coverage
Scorecards and CQL
With the SonarQube integration, you can create Scorecard rules and write CQL queries based on SonarQube projects. See more examples in the CQL Explorer in Cortex.Analysis freshness
Analysis freshness
sonarqube.freshness()ExampleFor a Scorecard focused on operational readiness, you can use this expression to evaluate the freshness of static analysis metrics from SonarQube.Metric
Metric
- Alert status
- Bugs
- Code smells
- Coverage
- Duplicated lines
- Duplicated lines density
- Lines of code
- New blocker violations
- New bugs
- New code smells
- New coverage
- New security hotspots
- New violations
- Reliability rating
- Security hotspots
- Security rating
- Security review rating
- SQALE rating
- Vulnerabilities
sonarqube.metric("<metric>")ExamplesDevelopment maturity ScorecardCode coverageFor a Scorecard focused on development maturity, you can set a rule to make sure entities have greater than 80% code coverage.sonarqube.metric("<metric>") expression to write a rule for a security Scorecard, making sure production entities aren’t deployed with a high number of security vulnerabilities. In an initial level of a Scorecard, you might write a rule to enforce 2 or less vulnerabilities:Project existence
Project existence
sonarqube != nullExampleFor a Scorecard focused on operational readiness, you can write a rule to make sure an entity has an associated SonarQube project.Issues
Issues
sonarqube.issues("<types>", "<rules>", "<severities>", "<statuses>", "<lookback>"): List<SonarqubeIssue>ExampleYou can write a rule to check that an entity has fewer than 3 major java:S2142 bugs:View integration logs

Troubleshooting and FAQ
See frequently asked questions below.Does Cortex support SonarCloud?
Does Cortex support SonarCloud?
https://sonarcloud.io/ URL. You can also use multi-account support to add a self-hosted or SonarCloud instance by adding the URL for that instance during configuration.I’m seeing “Socket timed out when trying to connect to SonarQube” for all of my entities in Scorecards.
I’m seeing “Socket timed out when trying to connect to SonarQube” for all of my entities in Scorecards.
I’m using Gradle and I’ve verified that my project is in SonarQube, but Cortex is still showing me an error.
I’m using Gradle and I’ve verified that my project is in SonarQube, but Cortex is still showing me an error.
[$:]$. As a result, automatic discovery won’t work. You’ll need to override the project key in your Cortex entity descriptor.My project is in Sonar and Cortex is able to talk to SonarQube, but my score isn’t showing up.
My project is in Sonar and Cortex is able to talk to SonarQube, but my score isn’t showing up.
- Make sure the project key in your YAML is exactly the same as the key in SonarQube.
- Verify that the scores are in the “default branch” in SonarQube. If your scores are showing up in a
branch-ain SonarQube, but your SonarQube default branch ismain, Cortex will not be able to retrieve the scores. - Run the following curl command and verify there are metrics showing up in the response:
What if I want to send custom data, but I don't have control over the integration touchpoint?
What if I want to send custom data, but I don't have control over the integration touchpoint?
Why might I see the SonarQube connection error Component key not found?
Why might I see the SonarQube connection error Component key not found?
Why might I see the error Sonarqube: Fail to request url on my integration page or a validity check failed error while creating a Workflow?
Why might I see the error Sonarqube: Fail to request url on my integration page or a validity check failed error while creating a Workflow?