Try our new research platform with insights from 80,000+ expert users
reviewer1871532 - PeerSpot reviewer
Managing Consultant
Consultant
It helps us detect vulnerabilities, but the integration with other tools in the CI/CD pipeline could be better
Pros and Cons
  • "I'm not implementing the solutions. However, I've talked to the people who deploy the tools, and they are happy with how easy setting up SonarCloud is."
  • "CI/CD pipeline is part of a whole chain of design, development, and production, and it's becoming increasingly crucial to optimize the various tools across different stages. However, it's still a silo approach because the full integration is missing. This isn't just an issue with SonarCloud. It's a general problem with tooling."

What is our primary use case?

We have several development streams, so we want to standardize our tooling and not necessarily restrict each tool to one specific purpose. We have CI/CD pipelines, with cloud solutions on one side and solutions like GitHub and Jenkins on the other.  

We use SonarCloud to scan code for vulnerabilities. The idea is to have that in a plan-do-check-act iterative way. Some development teams work in sprints with a scope of two weeks. For example, they define and finish their own user stories. 

Others work in Kanban, which means they work on one user story and only go on to the next when that one is finished. But the underlying thing is we are continuously using SonarCloud to clean out vulnerabilities in software that has been developed in-house.
+

What needs improvement?

CI/CD pipeline is part of a whole chain of design, development, and production, and it's becoming increasingly crucial to optimize the various tools across different stages. However, it's still a silo approach because the full integration is missing. This isn't just an issue with SonarCloud. It's a general problem with tooling.

For how long have I used the solution?

We've used SonarCloud for nearly nine months, but we're slowly using it more and more.

What do I think about the scalability of the solution?

The services are small, so scalability is not relevant. If you say that the service is an application, then the functionality of the application is, by definition, small and fit for purpose. The scalability of having lots of increased functionality within a service is not an issue. 

Scalability has more to do with the number of services or the full set of applications. A big company has multiple types of development going on that require SonarCloud. There are several services and applications that need to be scanned on a regular basis completely independently of each other. That's the issue. We're not hitting this threshold at the moment, so that's something we'll discover in the future as we add more to SonarCloud.

Buyer's Guide
SonarQube Cloud (formerly SonarCloud)
December 2024
Learn what your peers think about SonarQube Cloud (formerly SonarCloud). Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.

How was the initial setup?

I'm not implementing the solutions. However, I've talked to the people who deploy the tools, and they are happy with how easy setting up SonarCloud is.

What's my experience with pricing, setup cost, and licensing?

I can't say what it costs off the top of my head, but I believe the license is based on the number of users and services. Generally, it's considered inexpensive. 

The price is also based on the lines of code scanned. We use another solution instead of SonarCloud to scan third-party software. One thing is unclear. If you want to use SonarCloud for third-party software, you will reuse it for more services, but you only need to scan the latest version. 

You only need to scan once to cover all services that you're developing to minimize the cost of the scans. It doesn't make sense to redo the same scan for the third-party library version, which is used by many services. You only need to do it once.

What other advice do I have?

I rate SonarCloud seven out of 10. That rating is more of an intuitive sense of the product based on many years of experience.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Uzma Noreen - PeerSpot reviewer
Head of Infrastructure & Compliance & Cloud at TEO
Real User
Top 20
Offers continuous code analysis which can improve the code quality
Pros and Cons
  • "The solution provides continuous code analysis which has improved the quality of our code. It can raise alarms on vulnerabilities with immediate reports on the dashboard. Few things are false positives and we can customize the rules."
  • "The solution needs to improve its customization and flexibility."

What is most valuable?

The solution provides continuous code analysis which has improved the quality of our code. It can raise alarms on vulnerabilities with immediate reports on the dashboard. Few things are false positives and we can customize the rules. 

What needs improvement?

The solution needs to improve its customization and flexibility. 

For how long have I used the solution?

I have been using the solution for ten days. 

What do I think about the stability of the solution?

I would rate the product's stability an eight out of ten. 

How are customer service and support?

We have received instant replies from the support but not actual answers. We contacted support regarding upgrading the edition.  

How was the initial setup?

The tool's setup is not complex. Our engineers were not experienced and they took time to implement the product. 

What other advice do I have?

The tool is simple and I would rate it an eight out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
SonarQube Cloud (formerly SonarCloud)
December 2024
Learn what your peers think about SonarQube Cloud (formerly SonarCloud). Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.
Senior Security Consultant at Tafhar IT Services
Consultant
Well priced, good for basic needs, but is too limited
Pros and Cons
  • "For what it is meant to do, it works pretty well."
  • "I've been told by the developers that the solution is too limited. It's not testing enough within the containers."

What is our primary use case?

The solution is a static code analysis tool. That's basically what we use it for in our organization.

What is most valuable?

We bought the solution due to the fact that it was the lowest price. 

For what it is meant to do, it works pretty well. 

It's good for analysis.

What needs improvement?

I've been told by the developers that the solution is too limited. It's not testing enough within the containers. For instance, it only checks for obvious code errors. They should work to improve this.

At that moment we needed to scan the codes that the developers are producing, we found out that we needed more features.

For how long have I used the solution?

I've been using the solution for six months or so now. It's been less than a year.

Which solution did I use previously and why did I switch?

The former product we used was Twistlock.

How was the initial setup?

I haven't had much experience with the initial setup. I can't speak to what the deployment or setup was like.

What's my experience with pricing, setup cost, and licensing?

The pricing is very good.

Which other solutions did I evaluate?

We're currently looking into other options.

We're either looking for an integrated product for the whole CICB pipeline, such as StackRox, or we're looking at Fishman from Palo Alto. We're also looking at individual products for the whole CICB pipeline. In fact, this afternoon we are having a meeting to further discuss what tools we will use, or what can we use for dependency decks in the whole CICB pipeline, and for us to get a container image.

What other advice do I have?

We're a customer and an end-user of the product. We don't have a business relationship with them. 

I'm not sure which version of the solution we're using.

I'd advise potential users to first check all the features to see if what they need is there and then check them off to ensure that SonarCloud fills all your needs.

It's a good product for its purpose.

I'd rate the solution at a seven out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free SonarQube Cloud (formerly SonarCloud) Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2024
Buyer's Guide
Download our free SonarQube Cloud (formerly SonarCloud) Report and get advice and tips from experienced pros sharing their opinions.