# Documentation Nexus IQ Server 1.26

**Nexus IQ Server 1.26**

Our documentation site has moved. For the most current version, please see [http://help.sonatype.com](http://help.sonatype.com/)

# Chapter 21. Sonatype CLM for SonarQube

[21.1. Installation](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/sonarqube-install.html) [21.2. Configuration](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/sonarqube-configure.html) [21.3. Select the CLM Application](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/sonarqube-clm-app-selection.html) [21.4. Add and Configure the Sonatype CLM Widget](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/sonarqube-clm-widget-configuration.html) [21.5. Accessing the Application Composition Report](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/sonarqube-app-comp-report-access.html)

|  |  |
| --- | --- |
| The topics discussed in this chapter require IQ Server with the Lifecycle license. |

|  |  |
| The rebranding and renaming of _Sonatype CLM_ to _Nexus IQ Server_ started with the 1.17 release. You may still see references to _Sonatype CLM_ in the product or documentation. We realize this may cause some confusion, and appreciate your patience as we move forward. |

IQ Server integrates with a wide range of external enforcement points that include [continuous integration servers](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/chapter-clm-ci.html) ([Hudson/Jenkins](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/hudson-jenkins.html), [Bamboo](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/bamboo.html), [the CLI](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/cli.html) and [Maven](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/maven.html)), the [IDEs](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/chapter-clm-ide.html) ([Eclipse](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/eclipse.html) and [IntelliJ IDEA](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/idea.html)), and [repository management](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/chapter-clm-repository-management.html) ([Nexus](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/nexus-repository.html)).

The enforcement points are a common aspect of the development lifecycle, and in IQ Server, each represents a unique stage. This creates an invaluable integration of IQ Server with industry standard tools that already make the lives of your business and development process even better. This also means your team has greater overall control in identifying and reducing open source component risk.

Better component usage doesn’t just lead to risk reduction though, it also leads to better applications. This is something that ties closely with code analysis, and tools such as [SonarQube](http://sonarqube.org/).

As a user of SonarQube, you know first hand the impact that principles such as the 7 Axes of Code Quality can have on the applications and projects your teams create. Paralleling this, as a user of IQ Server you also know how policy management is a critical and essential part of open source component usage.

Sonatype CLM for SonarQube brings both of these together, and in this chapter we’ll cover everything you need to get going as quickly as possible. This includes:

- Download, installation, and configuration
- Application Composition Report access

**Figure 21.1. SonarQube Overview**

|  |  |
| --- | --- |
| See the [Requirements Chapter](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/requirements-installation.html#sonarqube-requirements) for information on Sonatype CLM for SonarQube supported versions.
