What is our primary use case?
SonarQube for IDE (formerly SonarLint) is used for source code scanning to check for vulnerabilities, memory leaks, and any unnecessary code in the code.
Real-time analysis is utilized with SonarQube for IDE (formerly SonarLint).
After implementing SonarQube for IDE (formerly SonarLint), vulnerability reports are quickly generated as it integrates with the CI, providing effective daily scans to identify what needs to be fixed.
Historical data from SonarQube for IDE (formerly SonarLint) is used to track code quality evolution by comparing code fixes and reflecting on the reduction of vulnerabilities with each release.
What is most valuable?
SonarQube for IDE (formerly SonarLint) is easy to integrate with CI pipelines, which is a strong aspect of the product.
Real-time analysis definitely improves code quality because everyday scans produce reports and predict vulnerabilities that can turn into exploits.
Integration with SonarQube for IDE (formerly SonarLint) servers helps the team prioritize project actions effectively.
SonarQube for IDE (formerly SonarLint) helps identify the root cause early, which is beneficial in reducing technical debt.
What needs improvement?
SonarQube for IDE (formerly SonarLint) could improve by giving more details about the fixes for particular vulnerabilities and by plotting the dependency trees.
In future updates, it would be beneficial to see SonarQube for IDE (formerly SonarLint) able to scan AI models and analyze the vulnerability loopholes in AI, as AI is the next upcoming trend.
For how long have I used the solution?
SonarQube for IDE (formerly SonarLint) has been used for almost five to six years.
How are customer service and support?
SonarQube for IDE (formerly SonarLint)'s technical support is responsive and helpful.
What about the implementation team?
The deployment for SonarQube for IDE (formerly SonarLint) was done by the central team, and our team runs our products on top of it.
The deployment was done by a different team.
I am not certain how many people were involved in the deployment because the deployment team, like the tool team itself, is different. They do the deployment for different tools, and as a security person, I just need to do a scan of our products with those tools.
The deployment required a quick timeframe of within a week.