DEV Community

Get me two! PVS-Studio plugin update for SonarQube

PVS-Studio has released two SonarQube plugins to address compatibility issues with the latest SonarQube version. SonarQube 10.2 introduced changes to its API, resulting in the disappearance of High and Low severity warnings in PVS-Studio reports. To resolve this, PVS-Studio has created one plugin for SonarQube versions 7.6-10.1 and another for versions 10.2 and later. The plugin for SonarQube 10.2 or later supports both OWASP Top 10 (2017 and 2021) UI filters when displaying warnings as vulnerabilities. The plugins allow users to integrate PVS-Studio reports into SonarQube and manage warnings in the web interface. PVS-Studio has released version 7.32 of its static analyzer, which includes the updated plugins. Users can download the appropriate plugin for their SonarQube version from the PVS-Studio website. PVS-Studio also offers integration with the DevSecOps platform DefectDojo for those who do not use SonarQube. By addressing the SonarQube compatibility issue, PVS-Studio enhances its integration capabilities, enabling users to seamlessly utilize its static analyzer for code quality assurance.
favicon
dev.to
dev.to