World Congress 2022 Jun 15, 2022

Automated Code Quality Checks with Custom SonarQube Rules

Daniel Strmečki , Martin Gluhak

Stop relying on passive documentation to enforce enterprise code quality. Convert your internal guidelines into custom SonarQube plugins to block non-compliant pull requests from ever merging.

Pause
Mute Enter Fullscreen
#1 about 3 min

Setting the context for code quality and custom rules

An overview of utilizing automated code checks to differentiate products and attract developer talent.

#2 about 4 min

Reasons for establishing code standardization and routine checks

Standardization builds customer trust, prevents repeated errors across projects, and simplifies new joiner onboarding.

#3 about 3 min

Establishing a company-wide approach to software quality assurance

Quality becomes the entire team's responsibility when testing is heavily automated and integrated into continuous development.

#4 about 3 min

Test automation strategy and following the testing pyramid

Most automated testing is handled at the unit level, preserving manual testing for edge cases and exploratory scenarios.

#5 about 6 min

Documenting and sharing standard software coding guidelines centrally

Relying strictly on basic static analysis is insufficient without aligned developer habits and detailed organizational documentation.

#6 about 1 min

Enforcing quality standards strictly with pull request decoration

Blocking a pull request merge upon a failed branch analysis ensures developers comply with centralized code metrics.

#7 about 2 min

Validating Java application architecture design with automated tests

The ArchUnit library natively uncovers cyclic dependencies and package naming violations within a standard test suite.

#8 about 2 min

Translating custom guidelines into automated static analysis checks

Automating organizational rules into specific SonarQube checks captures framework quirks that out-of-the-box analysis natively ignores.

#9 about 4 min

Creating a boilerplate project for custom rule development

The open-source Sonar Java plugin repository provides a straightforward maven template for bootstrapping customized static analysis rules.

#10 about 5 min

Writing test-driven unit tests for custom rule validation

Analyzing mocked non-compliant code snippets confirms whether a custom rule successfully catches targeted programming violations.

#11 about 6 min

Implementing syntax tree visitor logic for code rules

A custom visitor method inspects a method's return type token to detect and flag restricted class usages.

#12 about 4 min

Adding metadata and documentation to new custom rules

Providing JSON and HTML resources displays rule severity, expected compliance times, and alternative solutions natively within SonarQube.

#13 about 4 min

Building and installing the compiled custom rule extension

A standard maven build generates a jar executable that smoothly activates when copied directly into the SonarQube extensions directory.

#14 about 4 min

Synchronizing local developer tools with centralized custom rules

Linking the SonarLint IDE plugin to a customized SonarQube instance automatically distributes organizational guidelines to all developers.

#15 about 3 min

Audience questions on rule documentation and workflow updates

Custom checks require comprehensive maintenance processes to safely track updates and manage deployment into the centralized marketplace.

Matching moments

2:08 min

Enforcing code quality rules across client projects

Vadzim Prudnikau Vadzim Prudnikau · World Congress 2026 Europe

3:23 min

Enforcing consistent code quality with static analysis

Chris Heilmann +2 · LIVE

5:55 min

Evaluating generated code syntax and maintaining quality control

Phil Nash · Coffee With Developers

2:20 min

Applying customizable rules for static code analysis

Daniel Oh Daniel Oh · World Congress 2024

2:17 min

Enforcing coding standards with editor configurations and analyzers

Dennis Doomen Dennis Doomen · World Congress 2025

1:40 min

Modifying methodology rules for organizational specific needs

Sebastian Gierlinger Sebastian Gierlinger · World Congress 2025

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 14:50–15:20

Tech Leaders Stage

Keeping Code Quality at AI Speed

Daksh Gupta, Arthur Hicken, Jack Danger, Francesco Ciulla

Daksh Gupta
Arthur Hicken
Jack Danger
Francesco Ciulla
Open session

World Congress 2026 North America

September 24, 2026 · 10:20–10:50

Stage 2

From Static Rules to Reasoning Platforms: Scaling Intelligent Canary Delivery in 2026

Daniel Oh

Senior Principal Developer Advocate

Daniel Oh
Open session

World Congress 2026 North America

September 24, 2026 · 15:30–16:00

Stage 5

The reviewer can't be the author: independent verification for AI-generated code

Manish Kapur

VP, Product and Solutions at Sonar

Manish Kapur
Open session

World Congress 2026 North America

September 25, 2026 · 14:50–15:20

Stage 2

State of the Software Factory

Dexter Horthy

Co-Founder of HumanLayer

Dexter Horthy
Open session

World Congress 2026 North America

September 24, 2026 · 10:20–10:50

Tech Leaders Stage

The New Rules of Software Delivery

Darko Mesaros, AJ Aitken, Moritz Plassnig, Akshay Shah

+1 more

Darko Mesaros
AJ Aitken
Moritz Plassnig
Akshay Shah
Open session

World Congress 2026 North America

September 25, 2026 · 11:40–12:10

Stage 6

Codifying Trade-offs: Security, Cost, and Compliance as Agent Guardrails

Suzanne Daniels

Chief Developer Advisor at Microsoft

Suzanne Daniels