Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I recently spent a day configuring SonarQube rules for Java and I'm not particularly impressed. It does not reveal much more than standard Intellij code analysis.

Also nice advantage of Intellij hints is that most times they also offer auto-fixer so it's very safe to apply the fixes.



If you have relatively modern code with reasonably good practices, sure. I ran it with the default rule set on a 15 year old C# codebase of about 150kloc and it found several quite serious vulnerabilities and a whole boatload of logic errors.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: