Back to the registry
Agent passport

SonarQube Community Edition for Linux Platforms with support by Kurian

Kurian · Cybersecurity & IT

Partial captureNo attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownVirtual machine
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

This is a repackaged open source software product wherein additional charges apply for patching the operating system. Kurian provides multiple versions of this product on all popular Linux platforms such as Ubuntu, Debian, Oracle Linux, Rocky Linux, AlmaLinux, Amazon Linux, Fedora Linux and Red Hat Enterprise Linux. For the supported versions of the product, distributions, and versions of the Linux platform, look up the AMI Version under the Usage Information section of this page. For any combination of versions of product and OS that are not listed on the marketplace, custom AMI can be built, please contact us.

This product provides a ready-to-use Amazon Machine Image with SonarQube Community Edition preinstalled and configured on a Linux operating system. Supported Linux distributions include Ubuntu, Debian, Amazon Linux, Rocky Linux, AlmaLinux, Oracle Linux, Fedora Linux, and Red Hat Enterprise Linux. This is a repackaged open source software product wherein additional charges apply for operating system patching, updates, and ongoing maintenance provided by Kurian.

Show the rest of the publisher’s description (6 more lines)

SonarQube is an automated code analysis platform used to detect bugs, code smells, and security vulnerabilities in application code. It integrates seamlessly with modern development workflows and CI/CD pipelines, enabling continuous inspection of code across branches and pull requests. By incorporating SonarQube into the development lifecycle, teams can improve code quality, enforce coding standards, and identify issues early in the development process.

This AMI is designed for immediate use. Once an EC2 instance is launched, the SonarQube service is up and running, eliminating the need for manual installation or configuration. This allows development teams and DevOps engineers to quickly integrate code quality checks into their workflows without spending time on infrastructure setup.

Typical use cases include integrating with CI/CD platforms to automate code quality checks, performing continuous code inspection across development teams, enforcing quality gates before code merges, and maintaining high standards for application security and reliability.

Kurian provides ongoing maintenance for this AMI, including operating system updates and patching to keep the environment secure and up to date. This helps reduce operational overhead and allows teams to focus on development rather than infrastructure management.

Kurian has released a wide range of preconfigured software environments for cloud infrastructure including CMS platforms, Jenkins, databases, LAMP stack, Ansible, DevOps toolchain components, and monitoring applications widely used by system administrators and DevOps engineers. For selected Linux distributions, hardened images based on CIS benchmarks are also available.

All Kurian AMIs are built following official installation procedures and standard package sources. This ensures that administrators can manage, update, and extend the system using familiar tools and documentation without relying on custom installation methods. Additional configurations can be performed using standard practices supported by the underlying software and Linux distribution.

Highlights

Highlighted by the publisher on AWS Marketplace.

SonarQube Community Edition preinstalled and ready to use.

Supports Ubuntu, Debian, Amazon Linux, Rocky Linux, AlmaLinux, Oracle Linux, Fedora and Red Hat Enterprise Linux.

Includes OS patching, updates, and maintenance by Kurian.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Refund terms

As stated by the publisher on AWS Marketplace.

Free evaluation of the AMI for 2 weeks is available for the paid versions. The charges when applicable are usage based and the service can be discontinued anytime.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
StandardEulaStandardEulaSource

Publisher resources

2 links
SonarQube AMI documentationkurianinc.usSource
Report issues and request enhancements to AMIgithub.comSource

Linked repositories

1 repo
kurianinc/ami-pubgithub · AWS MarketplaceSource

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
Rate card pricing
Delivery
Virtual machine
Contact us via email at contact@kurianinc.us and please allow 24 hours to respond. For additional contact info visit http:/kurianinc.us/contact
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.