{"schemaVersion":"agenova.agent-machine-projection.v4","entity":{"id":"agentic-index:6a4c431eebb7081e9b9aa14e","type":"ai_agent","name":"Sonar","slug":"sonar","provider":"sonarsource.com","canonicalUrl":"https://agenova.io/agents/sonar","updatedAt":"2026-09-07T00:23:06.632Z","category":{"name":"Coding agents","slug":"coding"},"purposeCategory":{"slug":"software-development","name":"Software Development","version":"ade-1a.v1"},"status":"active"},"summary":"Sonar is recorded as a coding agents product from sonarsource.com. Accepted official evidence describes its work this way: Detects vulnerable or malicious dependencies, hard-coded credentials, dependency interaction flaws, and CI/CD misconfigurations while enforcing license compliance.","identity":{"state":"unverified","lastVerifiedAt":"2026-07-06"},"facts":[{"field":"pricing","value":"CONDITIONAL — Advanced Security trial: A free 14-day trial is offered; paid pricing is not stated on this page.","state":"source_backed","evidenceState":"source_backed","gap":null,"observedAt":"2026-09-06T15:12:46.290Z","validUntil":"2027-03-05T15:12:46.351Z","assertionState":"conditional","scope":"Advanced Security trial","normalizedValue":"A free 14-day trial is offered; paid pricing is not stated on this page.","sources":[{"id":"phase3-src-94b510a2894df0b05ecf0734b715c73d","title":"Sonar official integrations source","publisher":"Sonar","url":"https://www.sonarsource.com/solutions/security/"}]},{"field":"capabilities","value":"YES — software supply-chain security: Detects vulnerable or malicious dependencies, hard-coded credentials, dependency interaction flaws, and CI/CD misconfigurations while enforcing license compliance.","state":"source_backed","evidenceState":"source_backed","gap":null,"observedAt":"2026-09-06T15:13:26.090Z","validUntil":"2027-03-05T15:13:26.152Z","assertionState":"yes","scope":"software supply-chain security","normalizedValue":"Detects vulnerable or malicious dependencies, hard-coded credentials, dependency interaction flaws, and CI/CD misconfigurations while enforcing license compliance.","sources":[{"id":"phase3-src-f03872fe8367abd4388133ecf9bc39ae","title":"Sonar official integrations source","publisher":"Sonar","url":"https://www.sonarsource.com/solutions/software-supply-chain-security/"}]},{"field":"deployment","value":"YES — SonarQube products: Available through cloud-based SonarQube Cloud or self-managed SonarQube Server.","state":"source_backed","evidenceState":"source_backed","gap":null,"observedAt":"2026-09-06T15:13:26.229Z","validUntil":"2027-03-05T15:13:26.285Z","assertionState":"yes","scope":"SonarQube products","normalizedValue":"Available through cloud-based SonarQube Cloud or self-managed SonarQube Server.","sources":[{"id":"phase3-src-f03872fe8367abd4388133ecf9bc39ae","title":"Sonar official integrations source","publisher":"Sonar","url":"https://www.sonarsource.com/solutions/software-supply-chain-security/"}]},{"field":"enterpriseControls","value":"YES — software supply-chain governance: Provides centralized quality gates and license-compliance enforcement across code and dependencies.","state":"source_backed","evidenceState":"source_backed","gap":null,"observedAt":"2026-09-06T15:13:26.366Z","validUntil":"2027-03-05T15:13:26.428Z","assertionState":"yes","scope":"software supply-chain governance","normalizedValue":"Provides centralized quality gates and license-compliance enforcement across code and dependencies.","sources":[{"id":"phase3-src-f03872fe8367abd4388133ecf9bc39ae","title":"Sonar official integrations source","publisher":"Sonar","url":"https://www.sonarsource.com/solutions/software-supply-chain-security/"}]},{"field":"privacyDataPolicy","value":"No directly supporting official source has passed field-level review.","state":"unknown","evidenceState":"unknown","gap":"intelligence","observedAt":"2026-07-06","validUntil":"2026-08-05T00:00:00.000Z","assertionState":"unknown","scope":"documented data handling, privacy, and security policy","normalizedValue":null,"sources":[]},{"field":"integrations","value":"YES — software delivery workflows: Integrates security checks into IDE and CLI workflows and detects misconfigurations in GitHub Actions and Azure Pipelines.","state":"source_backed","evidenceState":"source_backed","gap":null,"observedAt":"2026-09-06T15:13:26.503Z","validUntil":"2027-03-05T15:13:26.555Z","assertionState":"yes","scope":"software delivery workflows","normalizedValue":"Integrates security checks into IDE and CLI workflows and detects misconfigurations in GitHub Actions and Azure Pipelines.","sources":[{"id":"phase3-src-f03872fe8367abd4388133ecf9bc39ae","title":"Sonar official integrations source","publisher":"Sonar","url":"https://www.sonarsource.com/solutions/software-supply-chain-security/"}]},{"field":"regionalAvailability","value":"No directly supporting official source has passed field-level review.","state":"unknown","evidenceState":"unknown","gap":"intelligence","observedAt":"2026-07-06","validUntil":"2026-08-05T00:00:00.000Z","assertionState":"unknown","scope":"named market eligibility; reachability alone is not support","normalizedValue":null,"sources":[]},{"field":"executionReliability","value":"No publication-approved execution evidence is available for this Agent.","state":"unknown","evidenceState":"unknown","gap":"execution_evidence","observedAt":"2026-07-06","validUntil":"2026-08-05T00:00:00.000Z","assertionState":"unknown","scope":"condition-scoped Agenova execution evidence","normalizedValue":null,"sources":[]}],"evidenceCoverage":{"reliable":5,"sourceBacked":5,"executionVerified":0,"unverified":3,"total":8,"coverage":0.625},"provenance":{"policy":"official-source facts remain attributable; absent vendor statements are not negative claims","generatedFrom":"the same published Fact and accepted Evidence reader used by the public Agent profile"}}