Back to the registry
Agent passport

Gitar

Sonar · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 2 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

Gitar is an autonomous AI code review agent for GitHub, GitLab, Bitbucket, and Azure DevOps. Unlike traditional review tools that only leave comments, Gitar reviews every pull request for bugs, security issues, and quality problems, then pushes fixes directly to the branch. When CI fails, Gitar analyzes the root cause, pushes a fix, and re-runs until the pipeline goes green - iterating autonomously without developer intervention.

Gitar works entirely inside your existing PR interface, with close-to-zero configuration required to get started. Teams can extend it with natural-language automation rules, connect Slack/Jira/Linear, and enforce auto-approve or merge-blocking policies once review criteria are met.

Show the rest of the publisher’s description (10 more lines)

Key capabilities:

  • AI-powered code review - bugs, vulnerabilities, and quality issues caught before merge
  • CI failure analysis and autonomous fix iteration until green
  • Auto-approve and merge-blocking on review outcome
  • Auto-apply - fixes pushed directly to the PR branch
  • Natural-language repository automation rules, no code required
  • Interactive PR commands (gitar review and directed comments)
  • Developer insights and PR velocity dashboards
  • Integrations: Slack, Jira, Linear
  • Enterprise: SSO/SAML, Bring Your Own Model (BYOM), self-hosted workers, audit logs, API access

Highlights

Highlighted by the publisher on AWS Marketplace.

Fixes, not just comments - Gitar closes the loop by pushing real fixes to your PR

CI-aware - detects its own regressions and iterates automatically until the pipeline's green

Zero-config install, works inside your existing PR interface across GitHub, GitLab, Bitbucket, and Azure DevOps

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Plans and pricing as listed

2 listed
Core-Annual-Per User
  • Users
$240.00
P12M
Pro-Annual-Per User
  • Users
$480.00
P12M

Refund terms

As stated by the publisher on AWS Marketplace.

Please refer to https://www.sonarsource.com/legal/sonarcloud/terms-of-service/

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
CustomEulaCustomEulaSource

Publisher resources

2 links
See product videowww.youtube.comSource
Publisher linkaws.amazon.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
2 plans listed
Delivery
SaaS
If you need help with our solutions, you can seek support from our Community and our Commercial Support. Community Support is a collaborative forum where SonarSourcers and community users post every day. It contains detailed articles and technical discussions that cover the most common usages. This is a great resource for your team to gain knowledge about our products and more generally about code quality and security. Commercial Support is a private communication channel between you and our Services team. It can be used to solve advanced issues and get the guidance you need for the implementation of our products in complex corporate environments. The privacy of this channel also eases the resolution of problems that require sharing sensitive information. Contact support via:http://support.sonarsource.com
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.