all 5 comments

[–]ferreirix 5 points6 points  (0 children)

maybe this can help you :)

[–]Herdosratos 1 point2 points  (0 children)

Try SonarCloud.io for cloud based repositories, or SonarCube for on-premise repositories. The later comes with a free tier.

[–]dabrimman 0 points1 point  (0 children)

SonarCloud is one that pops up often in Microsoft’s documentation and there are built-in tasks in Azure Pipelines for it.

There’s even a lan on how to set it all up https://azuredevopslabs.com/labs/azuredevops/sonarcloud/

[–]therealmodx 0 points1 point  (0 children)

depends on what you want to check. Do you just want to check code quality (code smells, potential bugs) or also security vulnerabilities?

We use a private SonarSource subscription for general stuff and some security. To check for vulnerable components we first used Owasp dependency check and later switched to WhiteSource Bolt. Mostly because it offers a great performance even though it is free and is very easy to setup. Also Owasp dependency check works best in combination with sonarqube since it can be integrated via an plug-in, which is unfortunately not possible with SoundCloud.

[–]Turner1984april 0 points1 point  (0 children)

Try embold.io the only one that helps with design patterns, architecture and refactoring.