Sonar Extends Agentic Code Governance and Verification to Self-Managed Infrastructure
AUSTIN, Texas, Sept. 29, 2026
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
Sonar Extends Agentic Code Governance and Verification to Self-Managed Infrastructure
PR Newswire
AUSTIN, Texas, Sept. 29, 2026
Agentic capabilities now available on SonarQube Server, allowing enterprises to operate software factories with confidence on their infrastructure
AUSTIN, Texas, Sept. 29, 2026 /PRNewswire/ — Sonar, the global leader in agentic code governance and verification, today announced the general availability of SonarQube Server 2026.5 LTA, enabling enterprises to guide, verify, and continuously resolve issues in agentic code entirely on infrastructure they control, including on-premise, air-gapped, and VPC-restricted environments. Building on the success of Sonar Vortex, SonarQube Remediation Agent, and SonarQube Hunter Agent on SonarQube Cloud, SonarQube Server 2026.5 LTA brings Sonar’s full agentic capabilities to self-managed deployments. Enterprises can set context and constraints for coding agents from the outset, independently verify every change, continuously improve code quality and security, and generate the evidence needed for governance and compliance.
Enterprise software development is changing rapidly as agentic software factories leverage AI coding agents to write higher volumes of code, at very high velocity. GitHub recently reported, for example, that monthly commits grew from 1.4 billion in April to 2.9 billion in August, with 130 million pull requests and 24 million new repos. To realize the value of this increased output, companies must ensure the code is production ready, secure, and maintainable. Developers, executives, and regulators need confidence that the agentic software factories are operating with appropriate controls.
“AI has made code creation abundant, but confidence in that code is scarce,” said Ori Yitzhaki, Chief Product Officer at Sonar. “Enterprises should not have to choose between the speed of agentic development and control over their code, data, and governance. With SonarQube Server 2026.5 LTA, they can apply the same guardrails, verification, and governance to agentic development on the infrastructure they control.”
One platform for enterprise agentic code confidence
Rather than stitching together point solutions, teams can set guardrails, verify code, automate remediation, and surface deeper risks in one integrated workflow. With the 2026.5 LTA release, the full power of the SonarQube platform is available whether you want to operate in the cloud, or have a preference for greater sovereignty by operating on infrastructure in your control.
Sonar’s agentic capabilities enable enterprises to:
- Guide agents as code is being written. Sonar Vortex injects the right project context and constraints before the agent writes its first line, then verifies every change in real time. Agents produce better code with fewer tokens and less rework, reducing token consumption by up to 36%, all before a pull request is ever opened.
- Uncover logic flaws traditional analysis misses. As an added layer of security, SonarQube Hunter Agent employs guided reasoning to hunt for broken access control, business logic, and authentication flaws that typical code analyses tend to miss.
- Resolve technical debt automatically. SonarQube Remediation Agent lets teams continuously improve their codebase, generating verified fixes for prioritized backlog issues. Developers retain control over how and when those fixes are committed, choosing their preferred level of automation.
The release also gives enterprises greater control over AI-scale delivery through centralized LLM governance and MCP access, including state-of-the-art models from Anthropic and OpenAI, with support for open-weight models coming soon.
Beyond governing how agents access and use models, enterprises can verify that agentic output is fit to commit. SonarQube and Gitar, Sonar’s recently acquired AI-native code review solution, help teams identify and fix reliability, security, and maintainability issues while generating the evidence needed for enterprise confidence. SonarQube Advanced Security extends that verification to the software supply chain, helping minimize dependency risk. Reachability and taint analysis, automated compliance reporting, and portfolio-wide architecture management provide additional visibility and control across the application estate.
SonarQube gives enterprises the verification and governance they need to scale agentic software factories with confidence, to successfully operate in the AI economy.
Availability
SonarQube Server 2026.5 LTA is generally available today. Sonar’s agentic capabilities — Sonar Vortex, SonarQube Remediation Agent, and SonarQube Hunter Agent — are available for purchase with SonarQube Server Enterprise and Data Center editions, and are already available on SonarQube Cloud.
Learn more on the what’s new page. Register for the October 14 webinar, “SonarQube Server 2026.5: The LTA release built to verify what your agents write.”
About Sonar
Sonar enables organizations to ship agentic code with confidence. Trusted by 75% of the Fortune 100, Sonar reduces outages, improves security, and lowers the cost and risk of agentic software development. SonarQube, Sonar’s core platform, verifies over 750 billion lines of code every day, catching bugs, vulnerabilities, and architectural flaws before they reach production. With the addition of Gitar, an AI-native code review solution, Sonar combines algorithmic and agentic verification into one zero-trust, multilayered platform. Sonar is relied on for AI code verification and governance by 7M+ developers globally, including teams at Nvidia, ServiceNow, Booking.com, Goldman Sachs, AstraZeneca, and Ford Motor Company. A Gartner® Magic Quadrant™ Leader¹, Sonar is the essential trust layer for the enterprise agentic software factory.
To learn more about Sonar, please visit sonar.com.
Cautionary note: Forward-looking statements
This press release may contain forward-looking statements about future expectations, plans, and prospects. These statements are based on current beliefs and assumptions and are subject to risks and uncertainties. The information in this press release is provided as of this date, and we undertake no obligation to update any statements.
1 Gartner does not endorse any company, vendor, product, or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.
View original content to download multimedia:https://www.prnewswire.com/news-releases/sonar-extends-agentic-code-governance-and-verification-to-self-managed-infrastructure-302893110.html
SOURCE Sonar


