Security Assessment for SonarQube Server 2.35
August 14, 2026
Version 2.35 of Security Assessment for SonarQube Server introduces significant improvements to security assessment, thanks to the integration of the new Cloud Application Security Assessment (CASA) report. From now on, you can review the information included in this report and download it as a PDF in both standard mode and MQR mode.
As you can see in the following image, we have added a dedicated section that breaks down compliance for each requirement of the standard, providing full traceability through evidence and hotspots directly linked in SonarQube.
What is CASA?
The Cloud Application Security Assessment (CASA) is an initiative by the App Defense Alliance that uses the OWASP Application Security Verification Standard (ASVS). Its goal is to provide a consistent set of requirements for securing applications that handle sensitive data.
The adoption of CASA in this version enables organizations not only to meet technical requirements, but also to align their development processes with cloud security best practices.
How to update to the new version?
If you are already a user of the Universal Plugin Manager, simply access the plugin administration and click the available update button.
If you haven’t tried bitegarden Security Assessment for SonarQube™ Server yet, you can download and install it on your instance through this link.
bitegarden team
Helping companies to develop better software