Sonar Launches Singapore-Born AI Agent That Auto-Fixes Code Vulnerabilities

Sonar has globally launched the SonarQube Remediation Agent at ATxSummit 2026 in Singapore — an AI agent that automatically fixes code issues and scans every fix through Sonar’s analysis engine before it ships, bringing autonomous, verified code repair to enterprise development teams worldwide.

Singapore Roots, Global Enterprise Deployment

The agent is the commercial evolution of AutoCodeRover, a large language model-based software engineering agent built by researchers at the National University of Singapore and acquired by Sonar in 2025. It was developed in partnership with the Infocomm Media Development Authority as a strategic design partner, and validated through rigorous testing by IMDA and local engineering talent in Singapore.

“AI-generated code is fast becoming the norm in software development. Our partnership with Sonar helps address existing gaps in this area, equipping enterprise software teams with practical tools to build at speed, while maintaining quality, security and responsibility,” said Dr Ong Chen Hui, Assistant Chief Executive, BizTech Group, IMDA.

Sonar’s regional headquarters in Singapore, supported by the Singapore Economic Development Board, serves its growing user community across Asia Pacific. The EDB’s Executive Vice President Pee Beng Kong noted that the launch “reinforces our position as a leading hub for AI innovation.”

Closing the Verification Gap in AI-Assisted Development

According to Sonar’s 2026 State of Code Developer Survey, AI now accounts for 42 per cent of committed code. Yet while 96 per cent of developers express distrust of AI-generated logic, only 48 per cent consistently check it before deployment — a gap the SonarQube Remediation Agent is designed to close.

The agent operates within Sonar’s Agent Centric Development Cycle framework, fulfilling the “Solve” phase: taking every automated fix through Sonar’s own verification engine before it becomes a pull request. It achieves a 3.2 per cent false positive rate and supports more than 40 programming languages and frameworks.

“AI agents are changing how software gets written, but they only work at scale if you can trust the code they generate,” said Tariq Shaukat, CEO at Sonar. “That’s how teams clear their most critical issues faster, without asking developers to trade speed for safety.”

Key Capabilities

  • On-demand repair: Automatically fixes bugs and security issues; developers review and merge rather than debug and patch.
  • Backlog remediation: Systematically reduces technical debt by opening one focused pull request per issue, without manual triage.
  • Verified reliability: Every fix is scanned by Sonar’s analysis engine before it is proposed.
  • AI scalability: Pairs with Claude Code, Copilot, Cursor, and other AI coding tools to maintain quality as generated code volumes increase.

The Sonar Foundation Agent, the technology underpinning the Remediation Agent, currently holds the top position on the SWE-bench Verified leaderboard — the leading benchmark for performance on real-world software engineering tasks. Sonar is beginning to offer the agent as a paid product this month, with full rollout expected by end of June.

Author


Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading