SonarQube AI Slop Gate
The decisions self-hosted SonarQube forces when you use it to gate AI-generated code, and how to settle them. Every rule names the wrong default it corrects; there is no rule for what the model already gets right.
Pinned to a date, not a version. SonarQube ships a release every two months, so every claim here was verified against docs.sonarsource.com in July 2026, against SonarQube Server 2026.3 (current LTA 2026.1). 2026.4 had shipped at the time of writing but the documentation still defaulted to 2026.3, so that is what these rules describe — plat-versions-are-calendar-based covers the release train itself. Re-verify anything version-shaped before trusting it, and read docs from the unversioned path (/latest/<page> does not resolve); appending .md to any docs URL returns its markdown source.
The failure this skill exists to prevent is a gate that passes everything. A SonarQube setup assembled from 2024-vintage knowledge will analyze the wrong branch, upload to the wrong server, exit green on a red gate, and skip the duplication and coverage conditions entirely on the small commits that AI-assisted work produces most of. None of those failures announce themselves; the dashboard looks healthy throughout.
When to Apply
Use this skill when:
- Standing up self-hosted SonarQube Server, or reviewing an existing instance, with the goal of catching AI-generated defects continuously rather than reporting on them after the fact
- Designing or tightening a quality gate — especially deciding what to measure on new code versus overall code, and discovering which conditions are silently not evaluated
- Wiring a scan step into CI: scanner properties, tokens, branch and pull-request parameters, coverage report import, or making the pipeline actually block a merge
- Setting up AI Code Assurance — flagging projects, qualifying a gate, or working out why a project reports "AI Code Assurance is off"
- A gate passes changes that obviously contain duplicated or untested generated code, and nobody can explain why
This skill is NOT for:
- SonarQube Cloud — the edition boundaries, token model, and several AI features differ; the agentic-AI gate in particular is documented for Cloud only
- IDE connected mode, SonarLint, or the SonarQube CLI's local agentic analysis
- Authoring custom analyzer rules or plugins — this covers configuring the rules that ship, not writing new ones
- General code-review judgement about whether code is good; this is about making the tool measure what you think it measures
Rule Categories
| # | Category | Prefix | Covers |
|---|---|---|---|
| 1 | Edition & Version Reality | plat- | What your licence can do; CalVer and the LTA upgrade path; which AI features need which edition |
| 2 | AI Code Assurance | aica- | The project flag, gate qualification, deprecated autodetection, the agentic profile |
| 3 | What the Gate Doesn't Measure | blind- | Suppression comments, fudge factor, test-code exemption, missing metrics, PR blind spots |
| 4 | New Code & Blame | newcode- | Full-clone requirement; choosing a definition that matches the branching model |
| 5 | Scanner Configuration | scan- | The properties whose defaults fail open — host URL, gate wait, test scope, coverage, exclusions |
| 6 | Running the Server | ops- | Kernel limits before first boot; database and volumes that survive an upgrade |
Quick Reference
1. Edition & Version Reality
plat-community-build-cannot-see-pull-requests— Settle this first. Community Build is main-branch-only; a PR gate needs Developer Editionplat-versions-are-calendar-based—YYYY.N.P, not 10.x; upgrades cannot skip an intermediate LTAplat-ai-features-are-edition-gated— AI Code Assurance is Developer; AI CodeFix is Enterprise; Advanced Security is a separate SKU
2. AI Code Assurance
aica-flag-projects-through-the-api— Nosonar.*property exists; it is server state set via UI orset_contains_ai_codeaica-qualify-the-gate-explicitly— Strict conditions grant nothing; plain "Sonar way" is not qualified, and 10.7 upgrades drop assuranceaica-do-not-rely-on-autodetection— Copilot-only and deprecated in 2026.1; label deliberately insteadaica-the-builtin-ai-gate-is-lenient— Seven conditions, Reliability rating C, and no overall-code coverage flooraica-use-the-agentic-profile— 2026.3's "Sonar agentic AI" profile for Java, JS/TS, Python; Sonar way elsewhere
3. What the Gate Doesn't Measure
blind-suppression-comments-turn-the-gate-green— The adversarial one.NOSONARdeletes the issue, and the rules that track it ship inactiveblind-fudge-factor-skips-small-changes— The costliest accidental default. Duplication and coverage conditions skipped below 20 new lines, on by defaultblind-test-code-escapes-duplication— Duplication is not measured on test code at all — where generated copy-paste concentratesblind-no-new-code-complexity-metric—new_cognitive_complexitydoes not exist; gate through ruleS3776intonew_violationsblind-java-duplication-threshold-is-fixed—sonar.cpd.java.minimumTokensis a no-op; IaC and CSS get no duplication detection at allblind-pull-requests-hide-file-level-issues— Overall-code conditions never run on a PR, so main can go red right after a green merge
4. New Code & Blame
newcode-shallow-clones-break-blame—fetch-depth: 0, or new code silently falls back to analysis timestampsnewcode-pick-the-definition-deliberately— Reference branch for a PR gate; days capped at 90; specific analysis is API-only
5. Scanner Configuration
scan-host-url-defaults-to-the-cloud— Modern scanners default tohttps://sonarcloud.io, not localhostscan-use-project-analysis-tokens—sonar.loginis deprecated; scope CI to a project analysis tokenscan-wait-for-the-quality-gate— Defaults tofalse, so the pipeline passes on a red gatescan-declare-test-sources—sonar.testshas no default; unset means tests are measured as production codescan-import-coverage-reports— Coverage is never computed by SonarQube; no import means the condition evaluates nothingscan-exclude-narrowly—sonar.exclusionsmoves the denominator of every metric; prefersonar.cpd.exclusionsscan-name-the-branch— Missing branch parameters publish every analysis onto main
6. Running the Server
ops-set-host-limits-before-first-boot—vm.max_map_count=524288, double the value older guides citeops-persist-data-and-skip-h2— H2 has no upgrade path, and losing history resets every new-code baseline
Suggested Order
Categories are listed by importance — a mistake in category 1 invalidates the whole plan, a mistake in category 6 fails loudly at boot. That is not the order you execute in. For a fresh setup, work through them as:
1 → 6 → 5 → 4 → 2 → 3. Confirm the licence can do what you need, stand up the server, configure the scanner, define what "new" means, apply the AI Code Assurance machinery, and read category 3 last — before declaring the gate finished, because it is the list of reasons a green verdict may be meaningless.
How to Use
Read a reference file when its decision comes up. Each rule names the wrong default it corrects, then shows the canonical configuration.
- Section definitions — category structure and ordering rationale
- Rule template — for adding new rules
- AGENTS.md — auto-built table of contents across all rules