igorolv/sonar-mcp-server
by Various
Read-only MCP server for self-hosted SonarQube Community Build 26.4+: lets AI agents (Claude Code, Cursor, Copilot) read issues, security hotspots, rules and code snippets to fix f
MCP
igorolv/sonar-mcp-server
Added 21 Sept 2026
Overview
Read-only MCP server for self-hosted SonarQube Community Build 26.4 and later. It exposes issues, security hotspots, rules, and code snippets to AI agents such as Claude Code, Cursor, and Copilot so they can fix findings locally. Written in Java.
Best for
Best for
Teams using self-hosted SonarQube Community Build who want AI assistants to read and fix findings locally
Use cases
- Pull SonarQube issues into an AI coding assistant
- Review security hotspots before fixing them
- Access rule definitions and code snippets during local remediation
How to use
Tools exposed
SONAR_URLSONAR_TOKENSONAR_DEFAULT_PROJECT_KEYSONAR_DEFAULT_BRANCHSONAR_MCP_DATA_DIRSONAR_MCP_PAGINATION_DEFAULT_LIMITSONAR_MCP_PAGINATION_DEFAULT_OFFSETSONAR_MCP_PAGINATION_MAX_LIMITSONAR_MCP_SNIPPET_MAX_LINESSONAR_MCP_PATH_FILTER_MAX_SCANNED_ISSUESSONAR_MCP_TOOLS_ISSUESONAR_MCP_TOOLS_PROJECTSONAR_MCP_TOOLS_HOTSPOTSONAR_MCP_TOOLS_RULE
Tested with
Claude Desktop, Claude Code, Cursor, VS Code
Notes
Read-only MCP server for self-hosted SonarQube Community Build 26.4 and later. It exposes issues, security hotspots, rules, and code snippets to AI agents such as Claude Code, Cursor, and Copilot so they can fix findings locally. Written in Java.
0 stars on GitHub. Last updated 2026-09-18. Licensed MIT.
Use cases
- Pull SonarQube issues into an AI coding assistant
- Review security hotspots before fixing them
- Access rule definitions and code snippets during local remediation
Pros
- Read-only design avoids unintended changes to SonarQube data
- Works with common AI agents like Claude Code, Cursor, and Copilot
- Self-hosted keeps code and analysis data on-premises
Cons
- Limited to SonarQube Community Build 26.4+
- Read-only, so cannot update issue status or assign work
- No stars or community traction yet, so maturity is unproven
Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.
Pros
- Read-only design avoids unintended changes to SonarQube data
- Works with common AI agents like Claude Code, Cursor, and Copilot
- Self-hosted keeps code and analysis data on-premises
Cons
- Limited to SonarQube Community Build 26.4+
- Read-only, so cannot update issue status or assign work
- No stars or community traction yet, so maturity is unproven
Pairs with
Other entries in the index that connect to this one. Click through to see the chain.
kucherenko/jscpd
Various
Copy/paste detector for source code. 220+ languages, Rust engine, SARIF/HTML/badge reporters, GitHub Action, MCP server for AI agents.
repowise-dev/repowise
Various
Codebase intelligence for AI and humans: code health scores, auto-generated docs, git analytics, dead code detection, and architectural decisions via MCP.
Get the free Developer’s Field Guide
A 27-page field guide to the AI coding workflow with Claude. Claude Code, MCP servers, the prompt patterns that work, and what to delegate. Free.
Enter your work email. We send it straight over, plus a few short notes worth knowing. Unsubscribe any time.
