Static analysis tools for COBOL and JCL
Utilize static code analysis for your mainframe to find issues in COBOL and JCL such as bugs, code smells & security vulnerabilities. Use the Sonar language analyzer with hundreds of rules to evaluate your code and ensure security, reliability and maintainability of your software.

TRUSTED BY OVER 7M DEVELOPERS WORLDWIDE
SonarQube code analysis finds issues while you focus on the work
It all comes from a powerful static analysis engine that we constantly refine. SonarQube Server and Cloud employ advanced rules along with smart, exclusive static code analysis techniques to find the trickiest, most elusive issues, code smells, and security vulnerabilities.
Precise static analysis
Deep static analysis of your code through symbolic execution, path sensitive analysis & cross-function/cross file taint analysis.
Fast issue resolution
Issue contextualization with secondary locations highlighted and clear remediation guidance helps you understand and construct a fix.
Minimal distractions
Automatic pull request analysis with results displayed in the comments of your favorite DevOps platform so you stay in the zone.
Produce secure, reliable and maintainable software
Sonar brings Code Quality to your mainframe where your COBOL and JCL code lives. Sonar is tightly integrated with your CI/CD workflow to feed you the right info at the right time and place.
COBOL and JCL code linting in your IDE for mainframes
SonarQube for IDE in your IDE is your first line of defense for keeping the COBOL and JCL code you write today clean and secure. Issues are raised in-line with clear rule descriptions and guidance.
With SonarQube for IDE, the impact is immediate and no configuration is required. You learn from the real-time feedback provided and quickly resolve issues with contextual guidance!
SonarQube for IDE is available from your IDE marketplace:
VS Code | Eclipse

In your cloud workflow
Automatically analyze Pull Requests and feature branches with the results decorated in the DevOps platform of your choice.
Your team can share rule configurations and exclusions across projects and coalesce on a shared definition of excellence. The project Quality Gate is visible to everyone and the releasabity status is clear.
SonarQube Cloud tightly integrates with these popular platforms:
GitHub | Bitbucket | Azure DevOps | GitLab

Reduce technical debt with every release
Identify issues early for quick, accurate fixes, allowing your team to maintain momentum and continuously improve code health.
Sonar empowers developers
Developers can write high-quality, secure code with Sonar. It flags new code and pull requests in your workflow, giving a clear go/no-go for merges and quick issue resolution. Fix problems directly in your workflow as you write code, ensuring changes are solid before production.
Quality Gates show your project Releasability
Sonar Quality Gates immediately indicate if commits meet standards and projects are releasable. They align teams around a shared vision of quality, ensuring everyone knows and meets the standard of excellence across the codebase.
We support your COBOL and JCL workflow
Language Standards
COBOL-74 | COBOL-85 | COBOL-2002 | JCL
Compilers
IBM OS/VS COBOL
IBM OS/VS COBOL II
IBM COBOL/400
IBM ILE COBOL
IBM Enterprise COBOL
Rocket COBOL
AcuCobol-GT
Bull GCOS
HP Tandem and COBOL-IT
Supported Environments
Code compiled in Windows, Linux, macOS
Embedded Statements
Analysis of DB2 SQL and CICS statements embedded inside COBOL