sonar-solutions/sonarqube-agentic-analysis-claude-code
Get started with SonarQube Agentic Analysis using Claude Code — step-by-step blueprint with config files and screenshots
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
Copy this rig
# review before running: this installs third-party code
$ claude mcp add sonarqube-agentic-analysis -e SONARQUBE_ORG=YOUR_SONARQUBE_ORG -e SONARQUBE_PROJECT_KEY=YOUR_SONARQUBE_PROJECT_KEY -e SONARQUBE_TOOLSETS=YOUR_SONARQUBE_TOOLSETS -e SONARQUBE_URL=YOUR_SONARQUBE_URL -- docker run -i --rm --pull=always -e SONARQUBE_URL -e SONARQUBE_TOKEN -e SONARQUBE_ORG -e SONARQUBE_PROJECT_KEY -e SONARQUBE_TOOLSETS -v '<ABSOLUTE_PATH_TO_YOUR_PROJECT>:/app/mcp-workspace:rw' mcp/sonarqube MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ claude mcp add sonarqube-agentic-analysis -e SONARQUBE_ORG=YOUR_SONARQUBE_ORG -e SONARQUBE_PROJECT_KEY=YOUR_SONARQUBE_PROJECT_KEY -e SONARQUBE_TOOLSETS=YOUR_SONARQUBE_TOOLSETS -e SONARQUBE_URL=YOUR_SONARQUBE_URL -- docker run -i --rm --pull=always -e SONARQUBE_URL -e SONARQUBE_TOKEN -e SONARQUBE_ORG -e SONARQUBE_PROJECT_KEY -e SONARQUBE_TOOLSETS -v '<ABSOLUTE_PATH_TO_YOUR_PROJECT>:/app/mcp-workspace:rw' mcp/sonarqube This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(.env)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(~/.aws/**)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/*.key)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(git rebase *)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(git commit *)",
"Bash(gh pr merge *)"
]
}
} MCP servers (1)
| server | source | est. tokens |
|---|---|---|
| mcp/sonarqube · "sonarqube-agentic-analysis" env: SONARQUBE_ORG, SONARQUBE_PROJECT_KEY, SONARQUBE_TOOLSETS, SONARQUBE_URL | docker | 2.5k |
Similar rigs
jcchikikomori/dotfiles-claude
Claude Code configuration for dotfiles (stow package)
MCP Hoarder 62.6k tok ·
Lukk17/agent-standards
One git checkout drops a shared AI coding setup (skills, subagents, MCP servers, OpenSpec scaffolding) into any project, across Claude Code, Kilo, OpenCode, Codex, and Copilot.
MCP Hoarder 47.5k tok ·
anomalyco/opencode
The open source coding agent.
Pragmatist 4.2k tok ·
DietrichGebert/ponytail
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
Pragmatist 1.6k tok ·