Try our new research platform with insights from 80,000+ expert users

GitHub vs SonarQube Server (formerly SonarQube) comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 9, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

GitHub
Ranking in Application Security Tools
7th
Average Rating
8.8
Reviews Sentiment
7.5
Number of Reviews
93
Ranking in other categories
Version Control (3rd)
SonarQube Server (formerly ...
Ranking in Application Security Tools
1st
Average Rating
8.0
Reviews Sentiment
7.2
Number of Reviews
114
Ranking in other categories
Static Application Security Testing (SAST) (1st), Software Development Analytics (1st)
 

Mindshare comparison

As of March 2025, in the Application Security Tools category, the mindshare of GitHub is 0.8%, down from 1.1% compared to the previous year. The mindshare of SonarQube Server (formerly SonarQube) is 25.5%, down from 27.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools
 

Featured Reviews

Pervez Roy - PeerSpot reviewer
Very good for collaboration on software projects
We use GitHub for code repository alongside Bitbucket GitHub is very good for collaboration on software projects. We prefer Bitbucket for commercial use, while GitHub is used for open source. You can get the differences, history of changes, and version control for various pull requests. You can…
Wang Dayong - PeerSpot reviewer
Easy to integrate and has a plug-in that supports both C and C++ languages
The product provides false reports sometimes. It also fails to understand the context of the code. It reports that a line of code has issues without considering its relation with the previous line. The product should improve the report quality. While it asks us to improve the code quality, it would be good if it also suggests how to improve the quality.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Complication free with good ability for third-party integrations."
"During our use of GitHub, we have not encountered any problems and GitHub adds new features frequently."
"I like the CI/CD features."
"GitHub is very straightforward. I really appreciate the versioning capabilities, ease of use, and the ability to host code."
"GitHub is the best tool for source repositories."
"The most valuable feature of GitHub is version control and continuous integration."
"This solution is just easy to use."
"GitHub is convenient and easy to use."
"The initial setup is simple. It requires some security, but it's simple."
"I like that it's easy to navigate not just in terms of code findings but you can actually see them in the context of your source code because it gives you a copy of your code with the items that it found and highlights them. You can see it directly in your code, so you can easily go back and make the corrections in the code. It basically finds the problems for you and tells you where they are."
"This solution is simple to use and can be quickly deployed."
"The most valuable feature of this solution is that it is free."
"SonarQube is a fantastic tool which saves us precious time."
"SonarQube is one of the more popular solutions because it supports 29 languages."
"It automatically scans for code, detects vulnerabilities, and generates daily reports."
"The solution offers a very good community edition."
 

Cons

"GitHub's issue management could be improved a little from an organization standpoint. It would be helpful to have the ability to organize a work board or a backlog more comprehensively. For organizations migrating to GitHub from arbitrary systems, it's a little bit of a headache to move on to that system."
"I would like a more graphical, user-friendly UI, to avoid writing so much code on cmd."
"There could be more integration into Azure."
"They're improving the work items to track the progress of the team, but in my experience, Azure DevOps is better in this functionality. GitHub needs to improve the form to track the progress of the work done by a team."
"While using the solution when merging two code branches the code becomes a bit messy. This should be improved in the future."
"We are not able to access GitHub from our VPN."
"The solution needs some more controls for deleting code."
"The only thing I see missing in GitHub is that it isn't very user friendly for key personnel who don't have in-depth, technical knowledge. In Jira, there are many functions to upload our test cases, and in GitHub we can only do it manually. There are functions which can be used to upload different files, but that still requires some technical knowledge. A layman cannot do it."
"We called support and complained but have not received any information as we use the free version. We had to fix it on our own and could not escalate it to the tool's developer."
"SonarQube could be improved with more dynamic testing—basically, now, it's a static code analysis scan. For example, when the developer writes the code and does the corresponding unit test, he can cover functional and non-functional. So the SonarQube could be improved by helping to execute unit tests and test dynamically, using various parameters, and to help detect any vulnerabilities. Currently, it'll just give the test case and say whether it passes or fails—it won't give you any other input or dynamic testing. They could use artificial intelligence to build a feature that would help developers identify and fix issues in the early stages, which would help us deliver the product and reduce costs. Another area with room for improvement is in regard to automating things, since the process currently needs to be done manually."
"Monitoring is a feature that can be improved in the next version."
"The solution could improve the management reports by making them easier to understand for the technical team that needs to review them."
"This is a well-rounded solution, however, some features could be made available on the free version. The price of the solution could be reduced."
"The handling of the contents of Docker container images could be better."
"If there was an official Docker image of SonarQube that could easily integrate into the pipeline would help the user to plug in and plug out and use it directly without any custom configuration. I am not sure if this is being offered already in an update but it would be very helpful."
"There isn't a very good enterprise report."
 

Pricing and Cost Advice

"We are currently paying nothing for GitHub."
"It’s an open-source solution."
"The price of this solution is reasonable."
"There are no licensing fees for the features that we use."
"GitHub is a cost-effective solution."
"We pay a licensing fee for GitHub, which could be cheaper."
"The product is reasonably priced."
"My company purchased it. Before, we used to receive the free version, but then they purchased some of the features."
"I was using the Community Edition, which is available free of charge."
"We have a license with 125,000 lines of code. We did not purchase a lot of lines but it is specific to our code environment."
"I do not know about the pricing as I am using the community edition, which is free. But I compared the pricing with Sigma, and it is higher than SonarQube."
"My guess is that we have a yearly subscription. We use it quite extensively, so a monthly license wouldn't make sense. Yearly subscriptions are usually cheaper. In addition to the standard licensing fee, there is just the cost of running the hardware where it is hosted."
"Get the paid version which allows the customized dashboard and provides technical support."
"The product’s price is lower than Veracode’s price."
"It's an open-source solution, with no additional costs."
"It's a bit expensive for us. The currency rate of the dollar is a problem but it may be fine for other countries."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
842,466 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
12%
Computer Software Company
11%
University
6%
Financial Services Firm
17%
Computer Software Company
15%
Manufacturing Company
13%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about GitHub?
The control is the most valuable feature as developers can work on a single code.
What is your experience regarding pricing and costs for GitHub?
The pricing of GitHub depends on the choice of solutions, such as building one's own GitHub Runners to save money or using GitHub's Runners with extra costs. The pricing is considered reasonable an...
What needs improvement with GitHub?
There are still areas for improvement with GitHub Actions and their deployment workflows, as they have made significant progress but are not yet polished. Occasionally, stability can be an issue, t...
Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which tools that are the best for for Static Code Analysis, I suggest you have a look...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
 

Also Known As

No data available
Sonar
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Dominion Enterprises, NASA, Braintree, SAP, CyberAgent
Information Not Available
Find out what your peers are saying about GitHub vs. SonarQube Server (formerly SonarQube) and other solutions. Updated: March 2025.
842,466 professionals have used our research since 2012.