pkg.soopen package index

cask / rank 1663

Install sonarqube-cli with Homebrew Cask

Code quality and security for terminal workflows, scripts, and AI agents. Version 1.4.0.3748 via Homebrew Cask; verified 2026-07-28. Also installable with nix: nix profile install nixpkgs#sonarqube-cli.

install

Additional install commands

macOS

Homebrew Caskverified · 100%
brew install --cask sonarqube-cli

local Homebrew cask metadata

overview

Package summary

Code quality and security for terminal workflows, scripts, and AI agents

Commands and aliases

  • sonar

history

Project history and usage

SonarQube CLI is SonarSource's command-line interface for SonarQube Cloud and SonarQube Server workflows, combining project and issue queries, secrets scanning, local analysis, and AI-agent integrations under the `sonar` command.

Project history

The project is published by SonarSource as a public GitHub repository and documented on the official SonarSource documentation site. Its README describes the CLI as a terminal-oriented interface for catching code quality and security issues before production, with integrations for Git hooks, Claude Code, GitHub Copilot, Codex, CI/CD, and custom automation.

The 1.0.0 release on June 10, 2026 marked the CLI becoming an official public release after beta. That milestone positioned the tool as a practical day-to-day terminal interface for SonarQube, centered on `sonar auth`, `sonar analyze`, `sonar list`, and `sonar integrate`.

Adoption history

SonarSource distributes the CLI through official install scripts, GitHub releases, and Homebrew Cask packaging. Its packaging relevance comes from making SonarQube's quality, security, and secrets workflows available from local shells, automation scripts, and AI-agent setups rather than only from CI pipelines or web UI workflows.

How it is used

Typical use starts with installation, authentication against SonarQube Cloud or SonarQube Server, and commands such as `sonar auth status`, `sonar analyze`, `sonar list issues`, and `sonar integrate`. The official command reference groups commands into authentication, integrations, analysis, information, configuration, and maintenance.

For headless use, the official environment-variable documentation supports `SONARQUBE_CLI_TOKEN` with either `SONARQUBE_CLI_ORG` for SonarQube Cloud or `SONARQUBE_CLI_SERVER` for SonarQube Server. Saved interactive credentials are otherwise read from the system keychain.

Why package nerds care

For package-manager users, SonarQube CLI is notable because it packages a vendor-backed code-quality and security workflow as a single local executable named `sonar`. It also installs or coordinates add-on binaries, hooks, MCP configuration, and agent instructions, making its filesystem state and credentials behavior important to understand when packaging, sandboxing, or auditing it.

Timeline

  • 2026-06-10: SonarQube CLI 1.0.0 became the official public release after beta.
  • 2026-06-22: SonarQube CLI 1.1.0 added Antigravity and Cursor integrations, dependency-risk scanning in git hooks, and security fixes.
  • 2026-07-06: GitHub listed 1.3.0.3493 as the latest release, matching the Homebrew Cask source version in the input.

Related projects

  • SonarQube CLI is distinct from SonarScanner CLI: SonarSource documents SonarQube CLI as a developer management and agent-integration interface, while SonarScanner CLI is the CI/CD code-analysis scanner invoked as `sonar-scanner`.
  • The CLI integrates with SonarQube Cloud, SonarQube Server, SonarQube MCP Server, and AI coding agents such as OpenAI Codex, Claude Code, GitHub Copilot, Cursor, and Antigravity.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for sonarqube-cli. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
~/.sonar/sonarqube-cli/state.json

executables

Installed executables

CommandKindExposureNote
sonarbinaryHomebrew cask binarysonarqube-cli-1.4.0.3748-macos-arm64.bin

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version1.4.0.3748
manager updated2026-07-28
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keycask:sonarqube-cli
Version1.4.0.3748
Package managerHomebrew Cask
Homepagehttps://www.sonarsource.com/sonarqube/cli/
Last updated2026-07-28T21:16:08+02:00
Pulseupdated
SHA-2562a23cbbd04c97204f84561032f4cf23f04a057d98f39c278805893fae54854f6
Download URLhttps://binaries.sonarsource.com/Distribution/sonarqube-cli/1.4.0.3748/macos/sonarqube-cli-1.4.0.3748-macos-arm64.bin
Bottlenot recorded
Servicenone declared

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

sonarqube-cli

nix profile install nixpkgs#sonarqube-cli
  • normalized package name match
  • Matched by: Sonarqube Cli
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/so/sonarqube-cli/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Nix92%

sonar

nix profile install nixpkgs#sonar
  • installed executable or alias match
  • Matched by: Sonar
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/so/sonar/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Scoop92%

main/sonar

scoop install main/sonar
  • installed executable or alias match
  • Matched by: Sonar
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/sonar.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation