OpenGrep vs SonarQube: splitting security scanning and code quality

OpenGrep vs SonarQube: responsibility boundaries between security-pattern/SAST and code-quality gates, converging duplicate alerts, and parallel orchestration advice. For eng productivity and AppSec — how platformized security orchestration and the quality side collaborate without two systems covering each other. Where uncertain, follow official docs and the current product version; do not assume undelivered capabilities.