Enterprise DNA Enterprise DNA
M MCP Servers Developer low

igorolv/sonar-mcp-server

by Various

Read-only MCP server for self-hosted SonarQube Community Build 26.4+: lets AI agents (Claude Code, Cursor, Copilot) read issues, security hotspots, rules and code snippets to fix f

MCP

igorolv/sonar-mcp-server

Added 21 Sept 2026

#ai-agents #claude-code #code-quality #cursor #java #llm-tools #mcp #mcp-server

Overview

Read-only MCP server for self-hosted SonarQube Community Build 26.4 and later. It exposes issues, security hotspots, rules, and code snippets to AI agents such as Claude Code, Cursor, and Copilot so they can fix findings locally. Written in Java.

Best for

Best for
Teams using self-hosted SonarQube Community Build who want AI assistants to read and fix findings locally

Use cases

  • Pull SonarQube issues into an AI coding assistant
  • Review security hotspots before fixing them
  • Access rule definitions and code snippets during local remediation

How to use

Tools exposed

  • SONAR_URL
  • SONAR_TOKEN
  • SONAR_DEFAULT_PROJECT_KEY
  • SONAR_DEFAULT_BRANCH
  • SONAR_MCP_DATA_DIR
  • SONAR_MCP_PAGINATION_DEFAULT_LIMIT
  • SONAR_MCP_PAGINATION_DEFAULT_OFFSET
  • SONAR_MCP_PAGINATION_MAX_LIMIT
  • SONAR_MCP_SNIPPET_MAX_LINES
  • SONAR_MCP_PATH_FILTER_MAX_SCANNED_ISSUES
  • SONAR_MCP_TOOLS_ISSUE
  • SONAR_MCP_TOOLS_PROJECT
  • SONAR_MCP_TOOLS_HOTSPOT
  • SONAR_MCP_TOOLS_RULE

Tested with

Claude Desktop, Claude Code, Cursor, VS Code

Notes

Read-only MCP server for self-hosted SonarQube Community Build 26.4 and later. It exposes issues, security hotspots, rules, and code snippets to AI agents such as Claude Code, Cursor, and Copilot so they can fix findings locally. Written in Java.

0 stars on GitHub. Last updated 2026-09-18. Licensed MIT.

Use cases

  • Pull SonarQube issues into an AI coding assistant
  • Review security hotspots before fixing them
  • Access rule definitions and code snippets during local remediation

Pros

  • Read-only design avoids unintended changes to SonarQube data
  • Works with common AI agents like Claude Code, Cursor, and Copilot
  • Self-hosted keeps code and analysis data on-premises

Cons

  • Limited to SonarQube Community Build 26.4+
  • Read-only, so cannot update issue status or assign work
  • No stars or community traction yet, so maturity is unproven

Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.

Pros

  • Read-only design avoids unintended changes to SonarQube data
  • Works with common AI agents like Claude Code, Cursor, and Copilot
  • Self-hosted keeps code and analysis data on-premises

Cons

  • Limited to SonarQube Community Build 26.4+
  • Read-only, so cannot update issue status or assign work
  • No stars or community traction yet, so maturity is unproven
Free 27-page guide

Get the free Developer’s Field Guide

A 27-page field guide to the AI coding workflow with Claude. Claude Code, MCP servers, the prompt patterns that work, and what to delegate. Free.

Enter your work email. We send it straight over, plus a few short notes worth knowing. Unsubscribe any time.

No spam. Unsubscribe any time.

Running a business, not writing the code? See the MCP servers picked for operators, and get your first one wired up with us.

Operator picks