Skip to content
Notifications
Clear all

Switched from Fortify to SonarQube, here's why our security team isn't happy.

1 Posts
1 Users
0 Reactions
37 Views
(@emmap)
Reputable Member
Joined: 3 months ago
Posts: 240
Topic starter   [#19665]

Hey everyone, I've been deep in the world of SAST tools for a few years now, and our recent platform shift has been... an experience. We just moved our main Java/Spring microservices from Fortify (SSC) to a self-hosted SonarQube Developer Edition, aiming for that "shift-left" and dev-friendly vibe. The devs are mostly on board, but our security team is seriously grumbling.

On paper, SonarQube is winning: faster scans, easier integration into our CI/CD pipelines, and the developers actually look at the findings because the feedback loop is so much tighter. But the security folks feel like they've lost their command center. The biggest pain points for them are:

* **The "Security" lens feels buried.** In Fortify, everything was viewed through a security-first dashboard. In SonarQube, security vulnerabilities are just one category among bugs and code smells. They miss the dedicated audit workflows and the granular, security-specific reporting.
* **Less control over rule tuning.** They feel the security rules are more of a "black box" compared to Fortify's fine-grained custom rule sets. Tuning out false positives for our specific frameworks feels harder.
* **The vulnerability prioritization isn't as sharp.** They argue that SonarQube's reliance on the generic SonarWay quality profile doesn't factor in exploitability and context the way a dedicated security tool does. A medium-severity bug in a public-facing API endpoint should sometimes scream louder.

Don't get me wrong, I love the cultural win of getting devs engaged with code quality *and* security. But I'm wondering if we just haven't configured it right for a security-centric team.

Has anyone else navigated this transition? Specifically:
- Did you supplement SonarQube with another tool for the security team's dashboard needs?
- Are there specific plugins or commercial editions (like Security) that bridge this gap meaningfully?
- Any best practices for setting up security-specific quality profiles and dashboards that we might have missed?

I'm hoping we can have our cake and eat it tooβ€”dev speed *and* security confidence.

β€”Emma



   
Quote