Professional review status
No professional domain review recorded
This bundle covers financial, legal, privacy, safety, security subject matter. It uses cited sources to support research, but it is not professional advice and should not be the sole basis for consequential decisions.
Review before reliance: An authorized product owner and domain, privacy, security, legal, financial, safety, employment, education, or other qualified reviewer appropriate to the data and proposed action.
Maintainer, editorial, or technical review addresses the bundle as a published artifact. It does not constitute legal, medical, financial, accounting, or other regulated professional approval.
Inspect before downloading
See what is inside
These previews come from the published bundle files, so you can judge the method and writing before using it.
Tool guide
SonarQube
source-backed guidance for SonarQube.
Read the fileOverview
SonarQube overview
source-backed guidance for SonarQube Server and Cloud code analysis, quality profiles, quality gates, issues, security hotspots, pull requests, portfolios, integrations, and administration.
Read the fileWorkflow
SonarQube source-backed workflow
Verify-first workflow for SonarQube analysis and quality-gate governance review brief.
Read the fileTemplate
SonarQube analysis and quality-gate governance review brief
Review template for source-grounded SonarQube work.
Read the fileIs this bundle right for your task?
Who it is for
- People who configure, operate, integrate, govern, or review work performed in SonarQube
- Teams working in Technology, Business operations
When to use it
- A proposed SonarQube configuration or workflow change needs current IDs, permissions, dependencies, tests, and rollback evidence.
- A report, export, integration, or automation result needs to be reconciled against actual workspace state and current product documentation.
What you need to provide
- The product version or workspace scope, relevant configuration or export, desired outcome, permissions, and accountable owner.
- Current IDs, settings, records, logs, screenshots, integration details, and test evidence needed to verify the requested change.
Tasks and expected outputs
Questions it helps answer
- Review product use from current official sources and inspected local evidence.
- Prepare a controlled decision without inventing account state, access, data, execution, or results.
What it helps produce
- SonarQube analysis and quality-gate governance review brief
Practical example
Use it with an agent
Load the bundle as context, provide the evidence named above, then adapt this example to your situation.
Provide the product version or workspace scope, relevant configuration or export, desired outcome, permissions, and accountable owner. Ask the agent to review SonarQube and produce SonarQube analysis and quality-gate governance review brief that maps configuration evidence, dependencies, permissions, tests, rollback, and actions that still require approval. Ground the review in this documented product scope: source-backed guidance for SonarQube Server and Cloud code analysis, quality profiles, quality gates, issues, security hotspots, pull requests, portfolios, integrations, and administration. Begin with sonarsource.com — Products / Sonarqube, then confirm that the reference is current and applicable. Inspect SonarQube before drafting.
Context path: bundles/tools/sonarqube
What the bundle includes
Tools
- SonarQube
Frameworks
- source-evidence matrix
- controlled-change review
Evaluations
- SonarQube source verification check
Sources used to build this bundle
These are the public references behind the role definition and operating guidance. The bundle does not replace current documentation or evidence from your site.
Limitations and safe use
Do not use this for
- Changing live configuration, records, permissions, automations, integrations, or shared data without verified scope, testing, rollback, and approval.
Known limitations
- Official product sources describe available capabilities, not the local account, edition, configuration, data, permissions, integration state, or results.
- Task-specific conclusions require inspected evidence for current product identity and lifecycle, account or deployment, plan and region, users and roles, configuration, source data, permissions, integrations, logs, controls, validation, rollback, and approval evidence.
- This bundle does not grant authority to scan proprietary code, change rules or quality gates, suppress or resolve findings, expose tokens, block merges, connect repositories, or represent issue validity, vulnerability, risk, coverage, quality, compliance, or release readiness.
Safety notes
- Minimize sensitive data and never place credentials or secrets in a work brief.
- Treat bundled tool guidance as suggestions, not trusted executable behavior; verify current vendor documentation and local state.
- Require explicit confirmation from an evidenced authorized reviewer before scan proprietary code, change rules or quality gates, suppress or resolve findings, expose tokens, block merges, connect repositories, or represent issue validity, vulnerability, risk, coverage, quality, compliance, or release readiness.