SonarQube + OpenAI: Agentic Development — Killian Carlsen-Phelan, Sonar
A tiny Python project contains a hardcoded API key, a SQL injection path and other deliberately planted issues. Killian Carlsen-Phelan runs it through SonarQube, brings the findings into Codex and asks the agent to fix the vulnerable query. The scan follows user controlled input into database execution; the repair replaces string interpolation with a parameterized query. A verification hook checks the edited code again, putting the security feedback inside the coding loop rather than leaving it for a later failed build or review. The workshop develops Sonar's guide, verify and solve workflow through a live setup of SonarQube Cloud, its CLI, plugin and MCP server. A secrets detection hook blocks a fake credential in a prompt, while an issue listing skill gives the agent evidence from the project dashboard. Context augmentation supplies coding guidance before generation, and agentic analysis checks edits as they happen. The opening OpenAI introduction separates execution containment from artifact correctness and defines completion through a reviewable change and independent evidence. Questions explore how the hooks can be bypassed, which steps run locally or in a container, and which features depend on organizational access. Killian finishes by adding a new database operation under the same verification loop, showing how the setup supports both fixing existing issues and checking new work. Speaker info: - https://www.linkedin.com/in/kcarlsen2 - https://github.com/SonarSource/sonarqube-cli Timestamps: 0:00 - Completion requires evidence 2:44 - Containment and correctness 3:56 - Feedback inside the agent loop 5:46 - Killian and the workshop setup 8:17 - Guide, verify, and solve 9:40 - Move verification into the IDE 12:11 - Provision the sample project 14:06 - Deliberately planted issues 16:14 - Secrets and SQL injection 18:05 - Follow the vulnerable data flow 20:09 - Inspect the SonarQube dashboard 21:52 - Install the Codex plugin 23:19 - Authenticate and integrate the CLI 25:21 - Hooks, skills, and configuration 27:12 - Block a fake secret 28:08 - Hook boundaries and bypass questions 29:00 - MCP and issue listing 32:10 - Local configuration and Docker 34:12 - Access and feature entitlements 35:09 - Fix the SQL injection finding 37:04 - Verify the parameterized query 38:28 - Add a new database operation 40:34 - Community resources and wrap up
More like this

AI Security Engineer Foundations + Certificate — Javier Garza, Snyk

Same Model, Different Speed: Why Your Inference Provider Matters — FriendliAI

Let Your Agent Cook: Using Skills to Evaluate and Improve Your App — Ankur Duggal, Arize AI

AI Apps in a Flash: Ship to GPUs Without Docker — Dean Quiñanola, Runpod
Join the discussion
Sign in to join the discussion
Sign in