# sonarqube-cli を Homebrew Cask でインストール

sonarqube-cli のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

## インストール

```sh
sudo av install cask:sonarqube-cli
```

追加のインストールコマンド:

### macOS

- Homebrew Cask (100%):

```sh
brew install --cask sonarqube-cli
```

  証拠: local Homebrew cask metadata

## パッケージ情報

- **パッケージキー:** cask:sonarqube-cli
- **パッケージマネージャ:** Homebrew Cask
- **バージョン:** 1.4.0.3748
- **ソース概要:** Code quality and security for terminal workflows, scripts, and AI agents
- **ホームページ:** <https://www.sonarsource.com/sonarqube/cli/>
- **最終更新:** 2026-07-28T21:16:08+02:00
- **生成日時:** 2026-08-03T19:37:03+00:00

## 実行可能ファイル

- sonar (バイナリ)
- sonar (エイリアス)

## インストール挙動

- Bottle: 利用不可

## バージョンと鮮度

- ページ生成日: 2026-08-03
- マネージャ版: 1.4.0.3748
## プロジェクトの歴史と使われ方

SonarQube CLI is SonarSource's command-line interface for SonarQube Cloud and SonarQube Server workflows, combining project and issue queries, secrets scanning, local analysis, and AI-agent integrations under the `sonar` command.

### プロジェクトの歴史

The project is published by SonarSource as a public GitHub repository and documented on the official SonarSource documentation site. Its README describes the CLI as a terminal-oriented interface for catching code quality and security issues before production, with integrations for Git hooks, Claude Code, GitHub Copilot, Codex, CI/CD, and custom automation.

The 1.0.0 release on June 10, 2026 marked the CLI becoming an official public release after beta. That milestone positioned the tool as a practical day-to-day terminal interface for SonarQube, centered on `sonar auth`, `sonar analyze`, `sonar list`, and `sonar integrate`.

### 採用の歴史

SonarSource distributes the CLI through official install scripts, GitHub releases, and Homebrew Cask packaging. Its packaging relevance comes from making SonarQube's quality, security, and secrets workflows available from local shells, automation scripts, and AI-agent setups rather than only from CI pipelines or web UI workflows.

### 使われ方

Typical use starts with installation, authentication against SonarQube Cloud or SonarQube Server, and commands such as `sonar auth status`, `sonar analyze`, `sonar list issues`, and `sonar integrate`. The official command reference groups commands into authentication, integrations, analysis, information, configuration, and maintenance.

For headless use, the official environment-variable documentation supports `SONARQUBE_CLI_TOKEN` with either `SONARQUBE_CLI_ORG` for SonarQube Cloud or `SONARQUBE_CLI_SERVER` for SonarQube Server. Saved interactive credentials are otherwise read from the system keychain.

### パッケージ好きにとっての重要性

For package-manager users, SonarQube CLI is notable because it packages a vendor-backed code-quality and security workflow as a single local executable named `sonar`. It also installs or coordinates add-on binaries, hooks, MCP configuration, and agent instructions, making its filesystem state and credentials behavior important to understand when packaging, sandboxing, or auditing it.

### タイムライン

- 2026-06-10: SonarQube CLI 1.0.0 became the official public release after beta.
- 2026-06-22: SonarQube CLI 1.1.0 added Antigravity and Cursor integrations, dependency-risk scanning in git hooks, and security fixes.
- 2026-07-06: GitHub listed 1.3.0.3493 as the latest release, matching the Homebrew Cask source version in the input.

### Related projects

- SonarQube CLI is distinct from SonarScanner CLI: SonarSource documents SonarQube CLI as a developer management and agent-integration interface, while SonarScanner CLI is the CI/CD code-analysis scanner invoked as `sonar-scanner`.
- The CLI integrates with SonarQube Cloud, SonarQube Server, SonarQube MCP Server, and AI coding agents such as OpenAI Codex, Claude Code, GitHub Copilot, Cursor, and Antigravity.

### ソース

- <https://docs.sonarsource.com/sonarqube-cli>
- <https://docs.sonarsource.com/sonarqube-cli/integrations/codex>
- <https://docs.sonarsource.com/sonarqube-cli/quickstart-guide>
- <https://docs.sonarsource.com/sonarqube-cli/using-sonarqube-cli/commands>
- <https://docs.sonarsource.com/sonarqube-cli/using-sonarqube-cli/environment-variables>
- <https://github.com/SonarSource/sonarqube-cli>
- <https://github.com/SonarSource/sonarqube-cli/releases>
- source_facts.package-manager.brew-cask
- source_facts.version


## セキュリティノート

sonarqube-cli に一致するローカルシークレット処理マニフェストは見つかりませんでした。将来の対応で安定したパッケージ URL を使えるよう、Nucleus パッケージメタデータはここに公開されています。



## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: ~/.sonar/sonarqube-cli/state.json
## 他のパッケージマネージャ記録

- Nix - sonarqube-cli: normalized package name match | nixpkgs package indexes: pkgs/by-name/so/sonarqube-cli/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- Nix - sonar: installed executable or alias match | nixpkgs package indexes: pkgs/by-name/so/sonar/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- Scoop - main/sonar: installed executable or alias match | Scoop official bucket manifest trees: bucket/sonar.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1


## Combined YAML source

View the package source record on GitHub. [combined/sonarqube-cli.yml](https://github.com/mxcl/pkgdb/blob/main/combined/sonarqube-cli.yml)


## ソース

- pkg.so package database
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
