SonarQube Code Quality Governance
Unified workflow capability for AI-assisted code quality governance using SonarQube. Combines issue tracking, quality gate monitoring, code metrics, and rule management into a single workflow for developers, security engineers, and engineering managers. Enables AI agents to audit code quality, detect security vulnerabilities, enforce quality gates in CI/CD, and track technical debt.
What You Can Do
MCP Tools
search-projects
Search for SonarQube projects to audit or monitor code quality
search-bugs
Find code bugs in a project — reliability issues that cause incorrect runtime behavior
search-vulnerabilities
Find security vulnerabilities in a project's code
search-issues
Search for all types of code issues with full filtering (severity, type, status, rule)
check-quality-gate
Check if a project passes its quality gate — critical for CI/CD release decisions
list-quality-gates
List all quality gate definitions with their metric conditions and thresholds
get-code-metrics
Get code quality metrics for a project: coverage, bugs, vulnerabilities, code smells, duplications
search-security-rules
Find security analysis rules applicable to a language for policy review
search-rules
Search all analysis rules by language, type, severity, or keyword
get-system-status
Check SonarQube server version and operational status