SonarQube + OpenAI: Agentic Development — Killian Carlsen-Phelan, Sonar
Killian Carlsen-Phelan runs it through SonarQube, brings the findings into Codex and asks the agent to fix the vulnerable query.

Proof1 independent outlet
Key points
- A tiny Python project contains a hardcoded API key, a SQL injection path and other deliberately planted issues.
- The workshop develops Sonar's guide, verify and solve workflow through a live setup of SonarQube Cloud, its CLI, plugin and MCP server.
- The opening OpenAI introduction separates execution containment from artifact correctness and defines completion through a reviewable change and independent evidence.
- 5:46 - Killian and the workshop setup
Sources (1)
- [1]SonarQube + OpenAI: Agentic Development — Killian Carlsen-Phelan, SonarAI Engineer (YouTube) · Oct 11, 07:00 PM
Killian Carlsen-Phelan runs it through SonarQube, brings the findings into Codex and asks the agent to fix the vulnerable query.
A tiny Python project contains a hardcoded API key, a SQL injection path and other deliberately planted issues.
Extractive summary: sentences quoted from the sources.
Before this
- Oct 11, 2026AI Apps in a Flash: Ship to GPUs Without Docker — Dean Quiñanola, Runpod
- Oct 9, 2026openai/codex rust-v0.162.1: 0.162.1
- Oct 9, 2026pydantic/pydantic-ai v2.55.0: v2.55.0 (2026-10-09)
- Oct 8, 2026openai/codex rust-v0.162.0: 0.162.0
- Oct 8, 2026Understanding Jev, the new model everyone is talking about
- Oct 7, 2026[AINews] Claude Haiku 5.5 — better than GPT-6 Luna at the same pricing