SonarQube Hunter Agent Hits General Availability
Sonar has made SonarQube Hunter Agent generally available on SonarQube Cloud, adding full-codebase reasoning for broken access control, business-logic, and authentication flaws that pattern-based SAST can miss. It validates suspected findings before adding them to the existing SonarQube issue workflow; SonarQube Server support is coming soon.
This meaningfully expands automated code security into intent-based vulnerabilities, but Sonar’s claimed 80–90% precision will face its real test in complex production codebases.
- –Full-codebase analysis targets authorization, workflow, and session flaws that conventional scanners struggle to understand
- –Independent validation should reduce the false-positive fatigue that undermines security tooling
- –Native SonarQube issue integration lowers adoption friction for existing development and security teams
- –Cloud-only availability and the lack of current Server support limit access for smaller or self-hosted teams
- –Hunter Agent complements SAST rather than replacing deterministic checks for injection, data flow, CVEs, and secrets
DISCOVERED
1h ago
2026-08-30
PUBLISHED
2h ago
2026-08-30
RELEVANCE
AUTHOR
Cole Medin