I just downloaded SonarQube 6.7 LTS. I know it'll detect OWASP Top 10 and SANS Top 25...but which versions of those lists?
For instance, does the built-in tag scan for OWASP Top 10 - 2013 or 2017 or 2010?
Does the built-in tag scan for SANS Top 25 - 2009 or 2010 or 2011?
You can find information about OWASP and SANS in the documentation page. The page contains links to the security version-pages used in the latest SonarQube version (6.7 LTS). Based on the links provided:
See also this:
To find rules that relate to any of these standards, you can search rules either by tag or by text. The standards that a rule relates to will be listed in the See section at the bottom of the rule description.
So it is not the case that all rules can already be detected/analyzed.