AI code quality startup Sonar buys AI code review startup Gitar

Automated code quality and security heavyweight SonarSource Sàrl said today it’s buying a rival startup called Gitar Inc. that specializes in artificial intelligence-native code reviews.

According to Sonar, the plan is to integrate Gitar’s advanced reasoning capabilities into its broader code verification engine. This will provide DevOps teams that are increasingly relying on autonomous AI agents to do the grunt work with a more comprehensive safety net.

More safeguards will be welcomed by enterprises, which have eagerly embraced the so-called vibe coding trend in order to keep up with their competitors. With the adoption of AI coding tools, human programmers have become more like coordinators and supervisors, prompting AI models and checking their work.

However, tools such as Cursor, Claude Code, Devin and GitHub Copilot have been churning out so much AI-generated code that few teams can keep up with them. That’s dangerous, because these models are still prone to hallucinations, which can lead to bad code that contains vulnerabilities and errors that bring down applications.