$npx skillfedfor your agent

pysonar

Sonar Scanner for the Python Ecosystem

With conditionsPyPI Quality AssuranceReleased Jul 2026321.3K downloads / moLGPL-3.0-onlyPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — pysonar-1.7.0.5143-py3-none-any.whl
v1.7.0.5143 · released 2026-07-08 · Python >=3.10 · 3 runtime deps: jproperties, requests, tomli

Yes, if you are already using SonarQube or SonarCloud and want a lightweight Python-native scanner. The low install friction, active maintenance, and flexible configuration make it a practical choice for Python projects. The copyleft license (LGPL-3.0-only) requires review in proprietary contexts but poses no barrier for internal or open-source use. No known vulnerabilities as of 2026-08-14.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires SonarQube v10.6 or above (or SonarCloud account) running and accessible; Python 3.10 or above required.
  • Low friction installation with a pure Python wheel and minimal dependencies.
  • Active maintenance with recent releases; last commit on 2026-08-13 and latest release on 2026-07-08 indicate ongoing support.

License · maintenance · safety

LGPL-3.0-only (copyleft) — Licensed under LGPL-3.0-only (copyleft). Derivative works and distributions must retain the same license and provide source code access; suitable for internal tools and open-source projects but requires careful review in proprietary contexts.

last release 2026-07-08 (37 days) · last repo commit 2026-08-13 · 22 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 321,349 downloads/mo, #7,624 on PyPI

Verify before relying

pip install pysonar

pysonar --token "MyToken" -Dsonar.projectKey=my:project
  • Whether the scanner supports incremental analysis or only full scans.
  • Performance characteristics when analyzing large codebases.
  • Compatibility with CI/CD platforms beyond the documented examples.
Same gist for agents: .md · .json

What it is and what it does

pysonar is a Python wrapper around SonarQube's scanning infrastructure, designed to let developers run code quality analysis directly from the command line without needing the standalone SonarScanner binary. It reads your project configuration from multiple sources—CLI flags, environment variables, pyproject.toml, or a sonar-project.properties file—and communicates with a running SonarQube instance or SonarCloud to perform static analysis on your codebase.

The package depends on jproperties, requests, and tomli to parse configuration files, make HTTP calls to the Sonar server, and handle TOML parsing. It targets modern Python versions (3.10+) and is actively maintained by SonarSource. Configuration is flexible and can be layered across multiple sources with clear precedence rules, making it adaptable to both local development workflows and CI/CD pipelines.

Use it for

  • Integrate code quality gates into CI/CD pipelines by running pysonar as a build step before deployment.
  • Analyze Python projects locally during development using pyproject.toml configuration without installing SonarScanner separately.
  • Enforce organization-wide code standards by configuring sonar-project.properties and running scans across multiple repositories.
  • Monitor code quality trends over time by submitting analysis results to SonarCloud for public or private projects.
  • Combine with environment variables in containerized workflows to pass credentials and server URLs without hardcoding them.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are already using SonarQube or SonarCloud and want a lightweight Python-native scanner.

The low install friction, active maintenance, and flexible configuration make it a practical choice for Python projects. The copyleft license (LGPL-3.0-only) requires review in proprietary contexts but poses no barrier for internal or open-source use. No known vulnerabilities as of 2026-08-14.

Install

pysonar on PyPI

Before you install

Low friction installation with a pure Python wheel and minimal dependencies. Active maintenance with recent releases; last commit on 2026-08-13 and latest release on 2026-07-08 indicate ongoing support.

Requires SonarQube v10.6 or above (or SonarCloud account) running and accessible; Python 3.10 or above required.

License in practice

Licensed under LGPL-3.0-only (copyleft). Derivative works and distributions must retain the same license and provide source code access; suitable for internal tools and open-source projects but requires careful review in proprietary contexts.

Quickstart

pip install pysonar

pysonar --token "MyToken" -Dsonar.projectKey=my:project

Verify before relying

  • Whether the scanner supports incremental analysis or only full scans.
  • Performance characteristics when analyzing large codebases.
  • Compatibility with CI/CD platforms beyond the documented examples.

Package facts

LicenseLGPL-3.0-only copyleft
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
3 packages
jpropertiesrequeststomli
MaintenanceActively maintained 37 days since the last release
Last repo commit
First released
Downloads321,349 / month, #7,624 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Environment :: ConsoleIntended Audience :: DevelopersOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Topic :: Software Development :: Quality Assurance

Evidence: pysonar-1.7.0.5143-py3-none-any.whl

Tags

Capabilities
sonarqube scanner pythoncode quality analysis toolsonarcloud integrationpython static analysissonar project scannercode coverage reportingquality gate automation
Topics
code-qualityci-cdstatic-analysis
PyPI keywords
sonarsonarqubesonarcloudcleancode

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “sonarqube scanner python”

  • pysonarA command-line scanner that integrates Python projects with SonarQube…
  • mobsfscanmobsfscan is a static analysis tool that detects insecure code…
  • python-sonarqube-apiProvides a Python client library for interacting with SonarQube and…

Give your agent the search over MCP, or paste the wish link into any chat.

More Quality Assurance packages

coverage Worth it
PyPI · Testing · released Aug 2026

Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.

Install it if you want to measure test completeness or enforce coverage thresholds in your project.

permissive licensepure Python · 3.10+
335.8Mdownloads / mo
ruff Worth it
PyPI · Python Modules · released Aug 2026

Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.

MITcompiled wheel · 3.7+
316.1Mdownloads / mo
pexpect With conditions
PyPI · Software Development · released Nov 2023

Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.

ISCpure Pythonaging
200.8Mdownloads / mo
black Worth it
PyPI · Python Modules · released May 2026

Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.

MITpure Python · 3.10+
179.9Mdownloads / mo
pytest-xdist Worth it
PyPI · Utilities · released Jul 2025

pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.

Install it if your test suite takes long enough that parallelization would save meaningful time.

MITpure Python · 3.9+
177.1Mdownloads / mo
cfn-lint Worth it
PyPI · Quality Assurance · released Aug 2026

Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.

Install it if you work with CloudFormation templates.

MIT-0pure Python
114.9Mdownloads / mo

See also python-sonarqube-api · picklescan · pysentry-rs · bbot · cisco-ai-mcp-scanner · trufflehog3 · kingfisher-bin · zaproxy · cisco-ai-skill-scanner · python-nmap