SonarQube and Sonatype Nexus IQ Server for Code Quality

sonarqube and sonatype nexus iq server n.w
1 / 8
Embed
Share

Learn about SonarQube, an open-source tool for measuring code quality, and Sonatype Nexus IQ Server for software supply chain governance, with insights on their architecture and benefits.

  • SonarQube
  • Nexus IQ Server
  • Code Quality
  • DevOps
  • Software Governance

Uploaded on | 5 Views


Download Presentation

Please find below an Image/Link to download the presentation.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author. If you encounter any issues during the download, it is possible that the publisher has removed the file from their server.

You are allowed to download the files provided on this website for personal or commercial use, subject to the condition that they are used lawfully. All files are the property of their respective owners.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.

E N D

Presentation Transcript


  1. SonarQube and Sonatype Nexus IQ Server What is it and how does it relate to us?

  2. What is SonarQube? An open source tool to measure and analyze to quality of source code Supports over 20 different languages Ability to analyze within your CI Engine or locally on your IDE Architecture & Design, Complexity, Duplications, Coding Rules, Potential Bugs, Unit Test & Comments (from APIs) Creates a homogenized and centralized report displayed on an easy-to-read dashboard of metrics defined by the user/team Lots of plugins with other ALM tools to ensure quality code is written before put into production

  3. Why SonarQube? Utilizes static and dynamic analysis tools Focused on the 7 axes of code quality rather than just bugs and code complexity Can be used as a plugin alongside CI servers so centralizes the build and code analysis

  4. SonarQube Architecture

  5. However, this only checks the built code from developers.. What happens before and after that?

  6. What is Sonatype Nexus IQ Server? Consists of three separate parts that work together Auditor Firewall Lifecycle

  7. Why Sonatype Nexus IQ Server? Provides governance and oversight of the entire software supply chain through monitoring all components and artifacts Integrates with many other DevOps related and existing tools used within HSBC

  8. Supply Chain Flow

More Related Content