SonarCloud is overall a good tool for identifying code smells, bugs, and code duplication, but we've found that using Android Lint is more effective for our needs.
SonarQube Cloud (formerly SonarCloud) is effective for identifying vulnerabilities with detailed reports, enhancing code quality through continuous analysis. Deployment with developer-level security safeguards reduces production issues. New mono reports and microservices support provide enhanced service views. However, testing in containers is limited, scanner issues arise, and false positives require manual fixes. Incomplete CI/CD integration and insufficient report customization hinder operational effectiveness, making it less optimal for comprehensive use.