# SonarQube Alternate Sources

Canonical: https://abierto.us/opportunities/rfihncsonarqube

- Solicitation number: RFI_HNC_SonarQube
- Notice type: Sources sought
- Status: Closed. Deadline was August 9, 2024 at 9:00 AM EDT
- Department: Department of the Air Force
- Agency: Department of the Air Force
- Contracting office: FA8307 AFLCMC HNCK HNC Cyber & NTR (FA8307)
- NAICS: 513210 Software Publishers
- Place of performance: San Antonio, Texas
- City: San Antonio. https://abierto.us/cities/san-antonio-tx-4865000
- First posted: August 1, 2024
- Last posted: August 1, 2024
- SAM.gov: https://sam.gov/workspace/contract/opp/96413272b28e412da0607660784689d0/view

## Description

Our organization is currently leveraging SonarQube for continuous cybersecurity and testing activities. In an effort to identify potential alternatives, we are conducting market research to evaluate products and solutions that can meet the following requirements. The organizational objectives of this research are as follows:

Identify and catalog available products and solutions in the market. Evaluate the features, functionality, and pricing of each alternative to determine its suitability for our needs. Assess the level of integration and compatibility of each alternative with our DevSecOps platform, while ensuring compliance with DoD security requirements. Estimate the level of government resources required to migrate to a new solution, while maintaining our current operational capabilities.

The following are some of the key characteristics that we are using to meet our organizational objectives, as outlined in paragraph 3. While this list is not exhaustive, it does provide a snapshot of some of the most important requirements for our environment.

To meet DoD CIO DevSecOps Reference Design compliance and perform continuous cybersecurity and testing activities, the tool must provide the following features: Static application security test and scan (SAST) Static code analysis Source code linting Source code test coverage CI/CD integration Customizable security scanning and reporting The tool must support the following programming languages: C# TypeScript CSS HTML Go PHP Helm Java JavaScript Python XML Terraform Ruby Scala Swift Objective-C C C++ PL/SQL TSQL VB.NET The tool must integrate with the following package managers: Maven Gradle PyPi NPM .NET The tool must support multiple application development projects and provide a means to integrate with user authentication and authorization methods such as SAML or OIDC.

## Publications

- August 1, 2024: Sources sought, due August 9, 2024 at 9:00 AM EDT. Notice 96413272b28e412da0607660784689d0. https://sam.gov/workspace/contract/opp/96413272b28e412da0607660784689d0/view

## Points of contact

- Karin Werner, karin.werner.1@us.af.mil
- Marisa Flores, marisa.flores.2@us.af.mil

---
Source: SAM.gov Contract Opportunities bulk extract. Confirm deadlines on SAM.gov before responding. Cite https://abierto.us/opportunities/rfihncsonarqube.
