The Good Tech Companies - Four New Languages Arrive in SonarQube Cloud: MuleSoft DataWeave, Gosu, Groovy, and PowerShell
Episode Date: September 10, 2026This story was originally published on HackerNoon at: https://hackernoon.com/four-new-languages-arrive-in-sonarqube-cloud-mulesoft-dataweave-gosu-groovy-and-powershell. ...SonarQube Cloud now brings deterministic code verification to integration workflows, insurance systems, build pipelines, and infrastructure scripts. Check more stories related to undefined at: https://hackernoon.com/c/undefined. You can also check exclusive content about #cybersecurity, #git, #programming, #algorithms, #artificial-intelligence, #automation, #sonarqube-cloud, #good-company, and more. This story was written by: @sonarsource. Learn more about this writer by checking @sonarsource's about page, and for more stories, please visit hackernoon.com. SonarQube Cloud now brings deterministic code verification to integration workflows, insurance systems, build pipelines, and infrastructure scripts.
Transcript
Discussion (0)
This audio is presented by Hacker Noon, where anyone can learn anything about any technology.
Four new languages arrive in SonarCube cloud, Mulesoft data weave, Gosu, Groovy, and PowerShell, by Sonar.
Some of the most critical code in your stack has either run without independent verification for years
or you're using separate tooling than SonarCube to analyze that code.
Integration flows move data between your systems.
Gosu drives policy and claims logic.
Recently, Groovy has become popular.
for defining how your software gets built in Gradle build files, Jenkins files, and Groovy scripts.
PowerShell provisions the infrastructure everything else depends on. When any of it fails,
the blast radius reaches production, yet most of it has sought outside the reach of SonarCube's
automated code verification that developers of mainstream languages take for granted.
Integration flows, insurance logic, build scripts, and infrastructure automation deserve the
same scrutiny as the application code they support.
Sonarchube cloud adds support for Mulesoft DataWeave, Gosu, Groovy, and PowerShell, extending deterministic analysis to four ecosystems that run business-critical logic.
Combined with the other 40-plus programming languages, SonarCube already supports including Java, JavaScript, TypeScript, Python, and C-sharp, you get one unified code verification layer, from your APIs to your build pipelines to the scripts that run your cloud.
Here is what each new language brings, why it matters, and how to start.
MuleSoft data weave.
Verify the integration code your enterprise runs on.
Integration code is the connective tissue of your enterprise.
It moves data between systems, exposes APIs, and orchestrates the workflows your business depends on.
When that code fails, the outage cascades across everything downstream.
Until now, MuleSoft DataWeave development lacked the independent verification layer other languages
take for granted. With only a community-supported plugin, previous support didn't have the native
depth and cloud support that developers have been asking for. What SonarCube Cloud analyzes,
SonarCube Cloud inspects your MuleSoft data weave applications for bugs, security vulnerabilities,
and maintainability issues. The analysis reads your MuleSoft data weave files and flows, then applies
deterministic rules to surface problems the eye misses. Every issue comes with a clear explanation and a path to a fix.
Why it matters, AI agents write more integration code, and they write it fast.
A single flawed integration flow can take down the systems it connects.
Sonar Quabase the verification layer that checks Mulesoft data weave code against your functional,
security, and maintainability standards before it ships, so your developers catch issues
in the pull request, not on a 2am incident call.
Gosu Close a longstanding coverage gap for insurance systems.
Gosu code has run critical insurance and enterprise systems for years.
years, often without the verification coverage mainstream languages receive.
Gosu is a statically typed language on the JVM, used most notably behind Guidewire's platform
for policy, billing, and claims management. That business-critical logic has sat outside most
quality tooling or lacked up-to-date changes in the community plugin, until now. What SonarCube Cloud
analyzes? SonarCube Cloud analyzes Gosu source code the same way it verifies every other language,
deterministically, transparently, and consistently.
Coverage spans the checks that matter most.
Bugs.
Catch logic errors and reliability problems before they reach production.
Vulnerabilities.
Identify security weaknesses attackers could exploit.
Maintainability issues.
Flag the problems that accumulate into technical debt.
Every finding includes a clear explanation of the problem and guidance on how to fix it.
No guesswork.
No opaque scoring.
Why it matters.
In insurance systems,
A single reliability bug carries financial and regulatory consequences.
SonarCube applies the same deterministic standard to Gosu that it applies to Java, Python, and C-sharp.
So AI generated and hand-ridden GOSU code meet identical quality and security thresholds.
Teams running Guidewire and other GOSU-based platforms gain audit-ready evidence that the code
meets standard, and developers get faster, clearer feedback inside their existing pull request
workflow. Groovy. Verify the code that runs your pipelines. Groovy runs deeper in your infrastructure
than most teams realize. Not only is it used for web development, rapid prototyping, and metaprogramming,
it is also heavily used to define Jenkins pipelines, power gradle build scripts, and glues together
automation across the JVM ecosystem. When that code fails, your delivery pipeline fails with it,
Yet these uses of Groovy have long sat outside the reach of automated verification,
a blind spot in workflows that demand consistency everywhere else. What SonarCube Cloud
analyzes? SonarCube Cloud analyzes Groovy against a dedicated rule set built to catch the issues
that matter most, bugs, vulnerabilities, and maintainability problems.
Coverage includes the Groovy you actually write, Jenkins Pipeline Definitions,
Gradle build scripts, standalone Groovy applications, the analysis is deterministic.
Every scan applies the same rules and returns the same verdict, and SonarCube flags issues directly
in your pull requests, so problems surface before they merge, not after they break a build.
Why it matters, unverified Groovy can be unverified infrastructure.
A broken Jenkins pipeline or a flawed Gradle script does not just introduce a bug.
It stalls every deployment that depends on it.
Agents now generate groovy alongside everything else, and that code can look correct while hiding defects that only surface at runtime.
Deterministic analysis catches the complex mistakes that LLM self-review misses, so you verify the code that runs your pipelines and keep delivery moving.
PowerShell. Hold your infrastructure scripts to one standard.
PowerShell sits at the control layer of modern infrastructure.
It provisions cloud resources, automates deployments, and orchestrates critical operations across your environment.
When a PowerShell script fails silently, the Blastratius is your production systems.
These scripts often skip the review rigor applied to application code, which leaves a gap in your risk posture, and AI widened it.
What SonarCube Cloud analyzes?
SonarCube Cloud analyzes PowerShell for bugs, security vulnerabilities, and maintainability issues.
The analysis IS deterministic, catching the concrete, hard-to-find mistakes a language model reviewing its own output misses.
coverage targets the problems that cause real incidents, bugs that break automation at runtime,
incorrect logic, unsafe type handling, and control flow errors that pass review but fail in production.
Security vulnerabilities including hard-coded credentials, injection risks, and unsafe command
execution that expose your infrastructure. Maintainability issues like dead code, needless complexity,
and inconsistent patterns that accumulate over time. Every issue comes with a clear explanation and
a path to a fix. Your team learns why a rule fired, not just that it did. Why it matters. A flawed
script does not just fail. It can misconfigure a cloud environment, expose a secret, or take down a
service. SonarCube Cloud is the independent verification layer for your PowerShell, applying multi-layered,
deterministic analysis to every script. Your team ships automation faster, and your engineering
org governs it with confidence. How does SonarCube Cloud analyze all supported language
automatically. All four languages are available now and join the more than 40 plus programming
languages SonarCube Cloud already supports in GitHub, GitLab, BitBucket, and Azure DevOps
repositories. SonarCube Cloud activates automatically across Mule Soft DataWeave, GOSU, Groovy,
and PowerShell projects with no extra plugins, no manual language configuration, no separate setup
required. Your next scan picks up the new languages alongside your existing ones and surfaces
results in the same dashboards and pull request checks you use today. Open your SonarCube cloud
project, connect the repository, and run your first analysis today. Thank you for listening to
this Hackernoon story, read by artificial intelligence. Visit hackernoon.com to read, write, learn and
publish.
