LICENSEWARE

SonarQube Community Build and IDE licences

This article covers the free SonarQube Community Build (formerly Community Edition) and SonarQube for IDE (formerly SonarLint): their GNU LGPLv3 licence, the Sonar Source-Available License that has applied to their bundled analyzers since 2024-11-29, and how they relate to SonarSource's commercial products. It is not legal advice.

On This Page

SonarQube Community Build and SonarQube for IDE are SonarSource’s free products. SonarQube Community Build is a self-managed analysis server, formerly called Community Edition. SonarQube for IDE is an editor extension, formerly called SonarLint, for VS Code, IntelliJ, Visual Studio and Eclipse.[1][7][9] Neither is covered by SonarSource’s commercial contract. The Primary Customer Agreement states that “SonarSource’s no-cost software downloads (such as SonarQube Community Build and SonarQube for IDE) are not Products covered by this Agreement”.[3] Instead, they are governed by two public licences. The GNU Lesser General Public License version 3 (LGPLv3) covers the binaries and core source code. Since 2024-11-29, the Sonar Source-Available License (SSAL) has covered the bundled analyzers.[1] Catalog proof: Community Build and SonarQube for IDE are outside the Primary Customer Agreement.

Editions

Product What it is Licence Catalog row 
SonarQube Community Build Free, self-managed code analysis server[7] LGPLv3 binaries and core source; analyzers under SSALv1[1] SonarQube Community Build 
SonarQube for IDE Free IDE extension; connected mode links it to a SonarQube server or SonarQube Cloud[7] Same split[1] SonarQube for IDE 

SonarSource describes Community Build as “an open source edition suitable for developers and small teams”. It describes SonarQube for IDE as “always free to install from leading IDE marketplaces”.[9]

Community Build has fewer features than the commercial editions. It analyses only the main branch and has no pull request analysis. It lacks portfolios, security reports, audit logs and SCIM, AI CodeFix and the agentic products. Custom quality profiles and gates and SAML single sign-on are included.[6] The commercial SonarQube Server Developer Edition “Adds branch/PR analysis, more languages, and stronger security on top of SonarQube Community Build”.[10]

Licence history

SonarSource’s licence page records the change. SonarQube for IDE and SonarQube Community Build “were originally distributed under the GNU Lesser GPL License, Version 3”. From 29 November 2024, their binaries “will continue to be released under the LGPLv3 license, but the bundled analyzers will be subject to a new Sonar Source-Available License Version 1.0 (SSALv1)”. The source code without the analyzers remains LGPLv3.[1] The SSAL text now published is version 1.0.1, last updated 2025-11-20.[2] Catalog proof: Community Build and SonarQube for IDE: LGPLv3 binaries, analyzers under SSALv1 from 2024-11-29.

In practice, a build released before 2024-11-29 contains LGPLv3 analyzers. A later build contains SSAL analyzers inside an LGPLv3 distribution. Inventories should record the version and release date of each installation. The pattern is similar to other vendors’ moves from open-source to source-available terms, such as the HashiCorp Business Source License and Elastic licensing, but the SSAL is SonarSource’s own text.

Metrics

No licence metric applies, because neither product is sold. Lines of Code, the metric of the commercial products, is measured against “the subscription’s limit defined by the license”.[11] Community Build has no subscription or licence key, so no such limit exists.

Counting / floors

There is nothing to count for entitlement purposes. Organizations sometimes need to count Community Build installations anyway, for two reasons. First, support: Sonar Support “will not be provided for products not in the Order, such as Community Edition instances”, even inside a licensed company.[4] Second, version currency: “A new version of SonarQube Community Build is released every month”, and there is “no active version or Long-Term Active (LTA) version” concept.[5] Catalog proof: Support covers only products in the Order, not Community instances or trials; Community Build has monthly releases and no LTA.

LGPLv3 obligations

The LGPLv3 incorporates the GNU GPL version 3 with additional permissions. SonarSource’s licence page reproduces the full text.[1] Running the software internally triggers no obligations. The conditions apply when conveying it. A modified version of the Library may be conveyed under the LGPLv3 or the GNU GPL. A Combined Work, meaning an application linked with the Library, may be conveyed “under terms of your choice”. In that case the conveyor must give prominent notice that the Library is used, include copies of the GPL and the LGPL, and either provide the Minimal Corresponding Source or link through a suitable shared-library mechanism.[1] For the general framework, see open-source software licensing.

Sonar Source-Available License

The SSAL grants each Recipient “a non-exclusive, worldwide, royalty-free copyright license, for any Non-competitive Purpose, to reproduce, prepare Derivative Works of, publicly display, publicly perform, Distribute and sublicense” the Program, with a matching patent licence.[2] Its definitions limit the grant in three ways. A Non-competitive Purpose is any purpose except:

  1. providing others “any product or service that includes or offers the same or substantially similar functionality as SonarQube”;
  2. Competing with SonarQube, meaning marketing a product or service as a substitute for its functionality or value, “even if it is provided free of charge”; and
  3. “employing, using, or engaging artificial intelligence technology that is not part of the Program to ingest, interpret, analyze, train on, or interact with the data provided by the Program, or to engage with the Program in any manner”.[2]

“SonarQube” is defined to include any open-source or commercial SonarSource edition branded SonarQube.[2] Distribution requires making the Source Code available under the SSAL and keeping all notices.[2] Rights terminate if a Recipient fails to comply with material terms and does not cure within a reasonable time. Patent rights terminate if the Recipient brings patent litigation over the Program.[2] Catalog proof: SSAL rights are limited to Non-competitive Purposes.

For licence managers, the third exclusion matters most. An internal workflow that passes Community Build or SonarQube for IDE analyzer findings to an outside AI coding assistant falls outside the plain wording of a Non-competitive Purpose. In that situation, SonarSource’s commercial products and their AI terms, rather than the SSAL, are the documented route.[2][3] This is a reading of the licence text, not a statement by SonarSource.

Virtualization & partitioning

Not applicable. Neither licence restricts the number of installations, hosts or processors.

Cloud / BYOL

Community Build may be installed on any infrastructure. Offering its functionality to others as a hosted service would conflict with the SSAL’s exclusion of products or services offering “substantially similar functionality as SonarQube”.[2] Open source organizations that want hosted analysis can use the free SonarQube for OSS plan of SonarQube Cloud.[9]

Moving to a commercial edition

SonarSource documents three paths from Community Build to SonarQube Server. Customers can update the existing database, start a fresh installation, or move project data to a new instance; the last is suggested when migrating to Enterprise or Data Center Edition.[8] Once a commercial licence key is applied, the instance is subject to the Lines of Code limit and the Primary Customer Agreement.[11][3]

Out of scope

  • The licences of the SonarQube Scanner and other components distributed separately, which were not reviewed here.
  • Third-party plugins for Community Build, which carry their own licences.
  • SonarQube MCP Server, described by SonarSource as “Open source and free”, whose licence text was not reviewed.[9]

References

  1. SonarSource License informationLGPLv3 text and statement on the 29 November 2024 change to SSALv1 for analyzers. Page undated.Effective 2024-11-29. Retrieved 2026-10-07.
  2. Sonar Source-Available License v1.0.1Last Updated November 20th, 2025.Effective 2025-11-20. Retrieved 2026-10-07.
  3. SonarSource Primary Customer Agreements.1 Products definition excludes no-cost downloads. Updated August 27, 2026.Effective 2026-08-27. Retrieved 2026-10-07.
  4. SonarSource Support Termss.1.1 scope. Effective March 31, 2026.Effective 2026-03-31. Retrieved 2026-10-07.
  5. Release cycle model (SonarQube Community Build documentation)Undated.Retrieved 2026-10-07.
  6. Feature comparison table (SonarQube Community Build documentation)Community Build vs SonarQube Cloud and Server. Undated.Retrieved 2026-10-07.
  7. SonarQube Community Build documentation homepageProduct description and connected mode. Undated.Retrieved 2026-10-07.
  8. Upgrading from SonarQube Community Build (SonarQube Server documentation)Undated.Retrieved 2026-10-07.
  9. SonarQube plans and pricingFAQ 'Is SonarQube Free?'. Undated.Retrieved 2026-10-07.
  10. SonarQube Server editions (documentation)Undated.Retrieved 2026-10-07.
  11. Lines of Code (SonarQube Server documentation)Undated.Retrieved 2026-10-07.

See also

Catalog Rows Cited

5Rules2SKUs1Programs

Esc