SonarQube enforces rules.
Hyrax sets the standard.
SonarQube is the reference implementation of rules-based static analysis, with quality gates and years of history per project. The difference is what a change is measured against: SonarQube validates a change against its own rules, and Hyrax validates it against the project test suite and build.
- Hyrax audits roughly 400 of its own repositories.
- Free plan: full access, up to 100 PR reviews a month, a $30 starter credit, and $10/month ongoing.
Verified end to end, with no SonarQube handoff
What changes when Hyrax runs above the tools.
Six domains, not one
SonarQube covers its own scanning domain well. Hyrax evaluates security, correctness, maintainability, performance, architecture and operations together.
Verified against the project tests
A rules engine confirms a change satisfies its own rules. Hyrax runs the project test suite and build, so a change is proven against the real system.
Context that compounds
The map of the codebase lives in the repository and strengthens with every merge, so the next decision starts from everything learned before it.
Validated against a rule set, or against the project tests.
| Decision criteria | SonarQube | Hyrax |
|---|---|---|
| Unit of work | The file and the pull request, measured against rules. | The whole repository, audited continuously across six domains. |
| Codebase context | Static analysis per project, with history and trend data. | A durable map committed to the repository as HYRAX.md and .hyrax/discovery, so it strengthens as the codebase changes. |
| Output type | Issues, quality gates and code metrics. | Verified pull requests, plus issues ranked by severity and effort. |
| Verification | A change is validated against Sonar rules and quality gates, not the project test suite. | Baseline tests, build, lint and a second reviewer agent run against the project itself before a pull request opens. |
| Human control | The team resolves issues and merges. | A human approves and merges every pull request. Hyrax never merges on its own. |
| Delivery surface | CI pipelines, the Sonar dashboard and pull request decoration. | GitHub pull requests, with issues and posture in the Hyrax console. |
| Pricing model | Community edition free, then licence or per seat cloud plans. | Free plan with a $30 starter credit and $10/month ongoing. Paid is $30 per user per month and each paid user gets $30/month of credits. |
Read how SonarQube describes itself: www.sonarsource.com/products/sonarqube(opens in a new tab)
Comments on a diff, or a verified pull request.
- 01SonarQube scans the project against its rule set.
- 02Issues arrive as a list to triage, with severity attached.
- 03The team decides what is worth resolving, makes the edits, and merges.
- 01Maps the codebase and keeps the map in the repository
- 02Applies architectural judgment across six domains
- 03Opens a verified pull request that a human merges
GitHub-native. Human-controlled. Verified before merge. No training on customer code.
From install to the first verified pull request.
Install the GitHub App
Grant read access to the repositories in scope. No card is required to start.
Hyrax maps the repository
Discovery writes HYRAX.md and .hyrax/discovery into the repository, so humans and AI tools read the same context.
Review the first pull request
Approved upgrades arrive as verified pull requests. A human merges every one.
Both tools solve real problems.
Choose SonarQube if
The need is an auditable, configurable rule set with quality gates that block a build, plus long-run metrics for reporting. SonarQube is built for that and remains hard to beat at it.
Choose Hyrax if
Passing a rule set and working correctly are different things. Hyrax runs the project baseline tests, build and lint on every change, so the standard is the real system rather than a rule catalogue.
Community edition free, then per licence or per seat on cloud plans.
Free plan with a $30 starter credit and $10/month ongoing. Paid is $30 per user per month, and each paid user gets $30/month of credits.
Questions about SonarQube and Hyrax.
Does Hyrax work alongside SonarQube?
Yes, and most teams run both. SonarQube keeps doing its job. Hyrax works at the level of the whole codebase, decides what is worth changing, and delivers verified pull requests. Nothing about the SonarQube setup has to change.
Hyrax and SonarQube both report issues. What is actually different?
What a change is proven against. SonarQube confirms a change satisfies Sonar rules and passes a quality gate, which is valuable but self-referential. Hyrax runs the project baseline tests, the build, the linter and a second reviewer agent, so the evidence is the codebase behaving correctly rather than a rule set being satisfied.
What does Hyrax change in the repository?
Discovery writes HYRAX.md and a .hyrax/discovery directory, which document the architecture, conventions and risk areas of the codebase. Everything else arrives as a normal pull request on its own branch. Hyrax has no write access to the default branch.
How does pricing work?
The free plan includes full access, a $30 starter credit and $10/month of credits ongoing, with no card required. The paid plan is $30 per user per month, and each paid user gets $30/month of credits. Pull request reviews are included on every plan.
What happens after signup?
Installing the GitHub App and granting access to a repository takes a few minutes. Hyrax maps the codebase, then runs the first audit and returns issues ranked by severity and effort. The first verified pull requests follow once an audit is approved.