Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Concepts and Scope of Static Code Analysis
- Definitions: static analysis, SAST, rule categories, and severity levels
- The role of static analysis in a secure SDLC and its risk coverage
- How SonarQube aligns with security controls and integrates into developer workflows
2. SonarQube Overview: Features and Architecture
- Core services, database structures, and scanner components
- Understanding Quality Gates, Quality Profiles, and best practices for implementation
- Security-centric features, including vulnerability detection, SAST rules, and CWE mapping
3. Navigating the SonarQube Server UI
- Tour of the server interface: projects, issues, rules, metrics, and governance views
- Interpreting issue details, traceability links, and remediation guidance
- Options for generating and exporting reports
4. Configuring SonarScanner with Build Tools
- Setup processes for SonarScanner with Maven, Gradle, Ant, and MSBuild
- Best practices for managing scanner properties, exclusions, and multi-module projects
- Generating essential test data and coverage reports to ensure accurate analysis
5. Integration with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and implementing PR decoration
- Importing Azure Repos into SonarQube to automate analysis processes
6. Project Configuration and Third-Party Analyzers
- Setting project-level Quality Profiles and selecting rules for Java and Angular
- Working with third-party analyzers and managing the plugin lifecycle
- Defining analysis parameters and understanding parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology Review
- Defining role segregation: developers, reviewers, DevOps teams, and security owners
- Creating a roles and responsibilities matrix for CI/CD processes
- Reviewing and providing recommendations for existing secure development methodologies
8. Advanced Topics: Adding Rules, Tuning, and Enhancing Global Security Features
- Utilizing the SonarQube Web API to create and manage custom rules
- Adjusting Quality Gates and enforcing automated policies
- Hardening SonarQube server security and implementing access control best practices
9. Hands-on Lab Sessions (Applied)
- Lab A: Configure SonarScanner for five Java repositories (using Quarkus where relevant) and analyze the results
- Lab B: Set up Sonar analysis for one Angular front-end application and interpret the findings
- Lab C: A comprehensive pipeline lab—integrating SonarQube with an Azure DevOps pipeline and activating PR decoration
10. Testing, Troubleshooting, and Report Interpretation
- Strategies for generating test data and measuring code coverage
- Identifying and resolving common scanner, pipeline, and permission errors
- Methods for reading and presenting SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Recommendations
- Selecting appropriate rule sets and strategies for incremental enforcement
- Workflow recommendations for developers, code reviewers, and build pipelines
- Planning a roadmap for scaling SonarQube in enterprise environments
Summary and Next Steps
Requirements
- A solid understanding of the software development lifecycle
- Practical experience with source control and fundamental CI/CD concepts
- Familiarity with Java or Angular development environments
Target Audience
- Developers working with Java, Quarkus, or Angular
- DevOps and CI/CD engineers
- Security engineers and application security reviewers
Testimonials (1)
Engaging, and hands on practise.