Tom Howlett
2.3K posts
Tom Howlett
@leantomato
Product @sonarsource
Stroud UK Katılım Temmuz 2009
667 Takip Edilen890 Takipçiler
Sabitlenmiş Tweet
Tom Howlett retweetledi

To strengthen the Guide, Verify, & Solve phases of the Agent Centric Development Cycle, we've strengthened our offering with:
🔷 Sonar Context Augmentation
🔷 SonarQube Agentic Analysis
🔷 SonarSweep
🔷 SonarQube Remediation Agent
Read the news: sonarsource.com/company/press-…
English
Tom Howlett retweetledi

Software architecture shouldn’t be a headache. SonarQube now enables architecture management directly in your dev workflow. Visualize your structure, define goals, and stop architectural drift before it compounds. 🚀
See how it works: sonarsource.com/solutions/arch…
English
Tom Howlett retweetledi

Bad data in = bad code out. 🤖 It's the Achilles' heel of AI code generation.
That's why we're introducing SonarSweep™, our new service that optimizes and secures training data for coding LLMs.🧹🛡️
Read the announcement: bit.ly/478bDfK
#CodeQuality #SonarSweep

English
@Rubberduck203 @GAnnCampbell @tottinge @BarretBlake What version were you using? We’re now updating (almost) all our rules as new versions of C# are being released. There was a bit of a backlog as we migrated to our new Semantic Execution Engine which is almost complete.
English

@GAnnCampbell @tottinge @BarretBlake SonarQube’s impl for C# is hot garbage and will often prevent teams from upgrading their lang version because it lags by years. Just use editorconfig and /treatwarningsaserror.
English
@SonarQube @danroth27 Hi, If you message me I'll send you an email and we can set something up. Looking forward to discussing it :-)
English

@danroth27 Thanks for the ping; we're actually talking about that right now! Our PM @leantomato is going to contact you
English

Hey @SonarQube, it looks like support for scanning Blazor components (.razor files) is one of your top upvoted feature requests: community.sonarsource.com/t/support-for-…. We'd love to chat about how we can help make that happen!
English
Tom Howlett retweetledi

SonarQube 9.9 LTS is LIVE! 🚀
✅ Faster PR analysis
✅ Secure development for Cloud Native apps
✅ Improved Android #TaintAnalysis precision
✅ Enhanced enterprise capabilities
✅ Integrations & UX improvements
✅ LOTS of new rules
Full thread below 👇
#CleanCode
English
Tom Howlett retweetledi

I am happy to share that Mr. Evil Hacker will join me on stage at @dotnetday_ch on Tue, 30/08. He will present his favorite weapon: Dependency Confusion, using NuGet packages to compromise your .NET supply chain #DependencyConfusion #NuGet #DotNet #DotNetDaySwitzerland #SSDLC


English
Are you a Product Manager who used to be a Python, Java or C# dev? If so come and join me on the loveliest, most progressive, self organising team I've ever worked with at @SonarSource sonarsource.com/company/jobs/p…
English
@tottinge @SonarQube @DaveSchinkel Yes! As a PM at @SonarSource it would be great to hear your ideas. 'Graduating levels of pickiness' often gets discussed and I'd love to hear your thoughts on groupings. Happy to set up a call if you are interested :-)
English

@SonarQube @DaveSchinkel You know, I think that we could establish a better partnership with the tool and technical coaches.
The graduating levels of pickiness is a good example, maybe groupings in configuration.
I don't want to make it complex, but wonder....
English
Tom Howlett retweetledi
@Bjego2 @SonarQube I'm hoping it will be worked on this week, keep an eye on the ticket jira.sonarsource.com/browse/VSTS-261 If it does you may well see a release within the next 2 weeks
English

@leantomato @SonarQube Thanks @leantomato - guess I need to update our pipeline decorator then - to have this applied to all pipelines automatically.
Any idea when V5 is going to be released? Is it worth it to add the workaround - or will you release within the next 2 weeks?
English

@SonarQube the #azuredevops plugin is again failing with lets encrypt certs after your version 4.23.1. Maybe you can add the node10 handler and make it version 5.0 - with no support for #tfs2017 ? So that users of azure devops can use the current certs from lets encrypt?
English
Tom Howlett retweetledi

Find out how one of the world's leading manufacturers of automobiles and commercial vehicles has successfully added a strong security checkpoint to its DevOps tool chain by expanding @SonarQube and @SonarLint use to 500 developers. sonarsource.com/customers/stor…

English
@benfosterdev @SonarCloud Hi Ben, all should be fine with .NET 5 (although your image mentions .NET 6 that we're not supporting yet?) Feel free to post more details at community.sonarsource.com and we'll try and help
English

That "quick PR" that causes something to break in the build pipeline. Looks like the @SonarCloud .NET tool still doesn't support .NET 5.0?

English
@paulehr Hi, sorry to hear about this. If you feel like having another go, post some details on community.sonarsource.com/tags/c/help/8/… and I'll see if I can help
English
Can machine learning help us predict bugs in code? In this article I compare 4 methods, 2 using stats and 2 using machine learning. Its a contest between a man who didn't take maths A-level vs #deeplearning. Who will win? blog.solittlecode.com/exploring-4-wa…

English
Some Developers create 20x more bugs than others - what can you do about it? blog.solittlecode.com/some-developer…

English
New Geeknight meetup posted, really looking forward to this: Real-time stream processing with Kafka and Python + more remote working wisdom meetup.com/Cheltenham-Gee… #Meetup
English

