The news
Sonar made SonarQube Server 2026.5 LTA generally available on September 29, bringing its AI agents that guide, check and fix code to companies running SonarQube on their own on-premises, air-gapped or VPC-restricted infrastructure, the company said.
The release adds three products that had previously been offered on SonarQube Cloud, Sonar's hosted service. Sonar Vortex feeds project context and constraints to an AI coding agent before it writes code, then verifies each change as it is made; Sonar says it cuts token consumption, a measure of AI usage and cost, by up to 36%. The SonarQube Hunter Agent searches for broken access control, business logic and authentication flaws. The SonarQube Remediation Agent generates verified fixes so teams can keep reducing problems in existing code.
Sonar said the agents are available for purchase with the SonarQube Server Enterprise and Data Center editions. It did not publish prices. The company also said the release adds centralized governance for large language models (LLMs) and MCP access, including models from Anthropic and OpenAI. According to Sonar's release notes, administrators can register their own LLM provider, such as AWS Bedrock, Azure AI Foundry or a bring-your-own-key setup, and share it across the agent products.
The release notes list requirements that buyers should check. The agent products need a customer-provided shared storage layer, such as S3 or NFS, and a sandboxed container runtime, and PostgreSQL 15 or later is now required. For software composition analysis, which checks open-source dependencies, manifest files are parsed on the customer's infrastructure but package identifiers, not file contents, are sent to the cloud. The notes also mention consumption-based billing for teams that go beyond their contract.
Sonar framed the launch around the volume of code being produced. It cited GitHub, which said in an August 20 post about an outage that monthly commits had grown from 1.4 billion in April to 2.9 billion. "AI has made code creation abundant, but confidence in that code is scarce," Ori Yitzhaki, Sonar's chief product officer, said in the announcement.
Sonar says SonarQube verifies more than 750 billion lines of code a day and that it is used by more than 7 million developers, including teams at Nvidia (NVDA), ServiceNow (NOW), Booking.com, Goldman Sachs (GS), AstraZeneca (AZN) and Ford Motor Company (F). It says 75% of the Fortune 100 rely on it.
The numbers
- Token consumption reduction claimed for Sonar Vortex
- Up to 36%
- Monthly GitHub commits, April vs August 2026 (GitHub)
- 1.4 billion to 2.9 billion
- Lines of code SonarQube verifies daily (Sonar)
- More than 750 billion
- Developers using Sonar (company figure)
- 7 million+
- Share of Fortune 100 relying on Sonar (company claim)
- 75%
Why CEOs should care
For CISOs and CTOs at banks, government contractors and other organizations whose policies keep source code off outside clouds, the change is that Sonar's agent tools no longer require SonarQube Cloud. But running the agents on your own servers is not the same as keeping every byte inside. Ask which LLM each agent calls, and where: a model from Anthropic or OpenAI reached through a public API means code context may leave your network, while a model hosted in your own AWS or Azure account keeps it closer. Ask Sonar to show, for a fully air-gapped setup, which features work without any outside connection, since the release notes say the dependency-scanning feature sends package identifiers to the cloud.
For engineering leaders, the case is volume. If GitHub-wide commits more than doubled between April and August, human review is unlikely to keep up by itself, and automated checks become the practical control. Measure it: track how many agent-generated fixes your teams accept, how many security findings the Hunter Agent surfaces that earlier scans missed, and how much reviewer time changes.
For CFOs, note that the agents are sold on top of Enterprise and Data Center licenses, and that the release notes mention consumption-based billing beyond contract levels. Ask for pricing that caps usage, and for a clear forecast of how agent use will scale with the number of developers and repositories.
The bigger picture
Sonar is betting that checking AI-written code will matter more as coding agents produce more of it, and that the companies most worried about that code, often the ones with the strictest data rules, are also the ones least able to use cloud-only tools. Making its agents available on self-managed servers opens that group to Sonar, but the details of model hosting and outbound connections will decide whether security teams sign off.
What’s next
Watch for published pricing for the agent products, customer reports on fix acceptance rates, and whether Sonar documents a fully offline configuration for the agents and dependency scanning. Also watch GitHub's next figures on commit volume, which set the backdrop for demand.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





