Cloud September 2026#
These release notes are for the Codacy Cloud updates during September 2026.
📢 Visit the Codacy roadmap and let us know your feedback on both new and planned product updates!
Features#
-
Repository coverage status: Repositories now show a coverage status, with an icon and tooltip, on the coverage page and the coverage chart. When coverage stops arriving, coverage gates show a banner and an inline message so you know why the gate isn't evaluating. The status is also available in the repository API and the Cloud CLI.
-
Repository stack detection: Codacy now detects each repository's stack. On the code patterns page you can filter to patterns that match the stack, and patterns and issues outside it are flagged with an info banner. You can also filter by stack when choosing repositories for a coding standard. Tag filters now show each tag's category, and the Cloud CLI supports stack filters.
-
Container image tagging guidance and limits: Both SBOM setup paths now guide you through choosing a tagging strategy. The images list warns you when an image collects too many version-like tags, and the container scanning pages show your tag usage against the organization's 1,000-tag limit. The public API exposes tag usage and returns a 409 when an upload is rejected for hitting the cap. New
imagesandimageCloud CLI commands let you list and clean up tags in bulk. -
Dependency chains on quality issues (API and CLI): For issues caused by vulnerable dependencies, the Issues API now returns the transitive dependency chain and the fixed version. Cloud CLI issue output includes the chain as well.
Improvements#
-
Cancelled plans keep access until the end of the period: Cancelling a subscription no longer ends access immediately. The plan stays active until the end of the current billing period.
-
Security dashboard (SRM) accuracy fixes:
- Findings now close when their repository is removed from Codacy, or when the analysis result behind them no longer exists.
- Findings show the repository's current name, and ignoring or unignoring a finding works correctly after a repository rename.
- Jira-linked findings close once the Jira ticket is closed.
- The repository list no longer shows duplicate rows or mismatched totals, and open findings counts stay in sync with the dashboard.
-
Image tag deletion no longer resets metrics: Deleting a container image tag no longer wipes organization-wide security metrics. Only the affected metrics are recalculated.
-
Coverage fixes: Fixed coverage metrics being skipped while the head commit was being reanalyzed. Fixed repositories that stayed in the "Waiting" coverage status indefinitely.
-
Accurate analysis status: Fixed commits that kept showing an outdated analysis status after their analysis had finished, which could affect quality gates.
-
Banner for older pull requests: When you add a repository, a banner on the Pull Requests pages explains that pull requests not updated in the last 15 days aren't analyzed automatically. The docs now mention this too.
-
Pending reanalysis cue restored: After you ignore an issue on a pull request or commit, the "Pending Reanalysis" cue appears again while reanalysis runs.
-
GitLab permissions fix: Codacy no longer treats GitLab users as admins when they only have Developer access at the relevant subgroup.
-
Pull request fixes:
- The PR status check message now includes the missing severity level.
- Fixed pull requests that showed an empty diff even though they contained files Codacy can analyze.
- Fixed coverage gate checks not being published on GitHub pull requests.
-
Duplicate files fix: Files with identical content now each show their own issues.
-
Container image tags pagination: The image tags table now loads beyond the first 100 tags.
-
UI fixes:
- Fixed pages that got stuck in an endless loading loop.
- Fixed the "min 3 chars" search message shifting the page layout.
- Fixed an error toast that always appeared during organization onboarding.
-
Repository Settings cleanup: Removed the "Ignored files" tab from Repository Settings.
-
Jira historical sync: The historical Jira sync now skips any single issue that is missing its project field and processes the rest.
-
Accurate finding locations in VS Code: The VS Code extension now underlines findings on the correct line instead of line 1.
-
Codacy CLI behind corporate proxies: The Codacy CLI can now connect to the API from behind a corporate proxy.
-
New secret detection rule: Added an Opengrep rule that detects secrets matching
*-token-*patterns. -
Plus-addressed invoice emails: The invoice email field now accepts addresses such as
billing+invoices@company.com. -
Docs updates: Documented which issue categories and severities the false-positive analysis evaluates.
Tool versions#
Updated tools#
- Biome has a new version: 2.5.14 (updated from 2.5.6)
- Checkov has a new version: 3.3.19 (updated from 3.3.8)
- Checkstyle has a new version: 14.1.0 (updated from 13.9.0)
- PHP CodeSniffer has a new version: 4.0.4 (updated from 4.0.1)
- Cppcheck has a new version: 2.22.0 (updated from 2.21.1)
- Dart Analyzer has a new version: 3.13.4 (updated from 3.12.2)
- golangci-lint has a new version: 2.13.2 (updated from 2.11.0)
- Revive has a new version: 1.16.0 (updated from 1.15.0)
- Gosec has a new version: 2.29.0 (updated from 2.28.0)
- Hadolint has a new version: 2.15.1 (updated from 2.14.0)
- Jackson Linter has a new version: 2.22.2 (updated from 2.22.1)
- Lizard has a new version: 1.24.0 (updated from 1.23.0)
- Opengrep has a new version: 1.30.0 (updated from 1.26.0)
- Oxlint has a new version: 1.85.0 (updated from 1.80.0)
- PHP CS Fixer has a new version: 3.95.26 (updated from 3.95.17)
- PMD 7 has a new version: 7.27.0 (updated from 7.26.0)
- Pylint has a new version: 4.0.8 (updated from 4.0.5)
- Roslyn has a new version: 1.27.0 (updated from 1.26.0)
- RuboCop has a new version: 1.91.0 (updated from 1.88.2)
- Ruff has a new version: 0.16.8 (updated from 0.16.0)
- SpotBugs has a new version: 4.10.4 (updated from 4.10.3)
- SQLFluff has a new version: 4.3.0 (updated from 4.2.2)
- Staticcheck has a new version: 2026.2.1 (updated from 2026.1)
- Trivy has a new version: 0.74.0 (updated from 0.72.0)
Unchanged tools#
- AgentLinter: 0.3.3
- aligncheck: 1.0.0
- Ameba: 1.6.4
- Bandit: 1.9.4
- Brakeman: 4.3.1
- Bundler Audit: 0.9.1
- clang-tidy: 10.0.1
- CodeNarc: 3.6.0
- CoffeeLint: 5.2.11
- Credo: 1.7.19
- CSSLint: 1.0.5
- deadcode: 1.0.0
- Detekt: 1.23.8
- ESLint v7: 7.32.0
- ESLint v8: 8.57.0
- ESLint v9: 9.39.5
- Faux Pas: 1.7.2
- Flawfinder: 2.0.20
- JSHint: 2.13.6
- markdownlint: 0.41.1
- PHP Mess Detector: 2.14.1
- PMD 6: 6.55.0
- Prospector: 1.19.1
- PSScriptAnalyzer: 1.25.0
- Pylint: 1.9.5
- Reek: 6.5.0
- remark-lint: 10.0.1
- Scalameta Pro: 4.0.0
- ScalaStyle: 1.5.1
- ShellCheck: 0.10.0
- SonarC#: 9.32
- SonarVB: 8.13
- Spectral: 1.22.6
- SQLint: 0.3.0
- Stylelint: 16.26.1
- SwiftLint: 0.63.2
- Tailor: 0.12.0
- TSLint: 6.1.3
- TSQLLint: 1.16.0
Was this page helpful?
Your feedback helps us improve the documentation.
255 characters left
Thanks for helping improve Codacy documentation.
For more detailed feedback, open an issue on GitHub.