sonar-dependency-risks

Installation
SKILL.md

SonarQube — Dependency Risks

Search for dependency risks (software composition analysis issues) in a SonarQube project, paired with the releases that appear in the analysed project, application, or portfolio.

Usage

sonar-dependency-risks                    # risks in the current project
sonar-dependency-risks my-project         # risks in a specific project
sonar-dependency-risks my-project --branch feature/auth
sonar-dependency-risks my-project --pr 42

Prerequisites

This skill requires SonarQube Advanced Security (available on SonarQube Cloud Enterprise plan, or SonarQube Server 2025.4 Enterprise edition or higher), the SonarQube MCP Server to be configured, and the tool mcp__sonarqube__search_dependency_risks to be available in your session.

Before proceeding, verify the tool is accessible. If it is not, try the CLI fallback in Step 3 before giving up — don't invent other CLI commands (e.g. sonar mcp call or sonar dependency-risks do not exist).

Installs
18
GitHub Stars
102
First Seen
Apr 26, 2026
sonar-dependency-risks — sonarsource/sonarqube-agent-plugins