Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Concepts and Scope of Static Code Analysis
- Defining static analysis, SAST, rule categories, and severity levels
- The role of static analysis in a secure SDLC and risk coverage
- Positioning SonarQube within security controls and developer workflows
2. SonarQube Overview: Features and Architecture
- Understanding core services, database structures, and scanner components
- Best practices for Quality Gates, Quality Profiles, and their application
- Security-focused features including vulnerabilities, SAST rules, and CWE mapping
3. Navigating and Utilizing the SonarQube Server UI
- Touring the Server UI: projects, issues, rules, measures, and governance views
- Interpreting issue pages, traceability metrics, and remediation guidance
- Options for report generation and export
4. Configuring SonarScanner with Build Tools
- Setting up SonarScanner for Maven, Gradle, Ant, and MSBuild
- Best practices for scanner properties, exclusions, and managing multi-module projects
- Generating essential test data and coverage reports to ensure accurate analysis
5. Integration with Azure DevOps
- Configuring SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and enabling PR decoration
- Importing Azure Repos into SonarQube and automating analysis processes
6. Project Configuration and Third-Party Analyzers
- Establishing project-level Quality Profiles and selecting rules for Java and Angular
- Managing third-party analyzers and understanding the plugin lifecycle
- Defining analysis parameters and handling parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology Review
- Segregating roles among developers, reviewers, DevOps engineers, and security owners
- Developing a roles and responsibilities matrix for CI/CD processes
- Reviewing and recommending improvements to existing secure development methodologies
8. Advanced: Adding Rules, Tuning, and Enhancing Global Security Features
- Utilizing the SonarQube Web API to add and manage custom rules
- Refining Quality Gates and enforcing automated policies
- Hardening SonarQube server security and implementing access control best practices
9. Hands-on Lab Sessions (Applied)
- Lab A: Configuring SonarScanner for five Java repositories (using Quarkus where applicable) and analyzing results
- Lab B: Setting up Sonar analysis for one Angular front-end and interpreting findings
- Lab C: A full pipeline lab—integrating SonarQube with an Azure DevOps pipeline and enabling PR decoration
10. Testing, Troubleshooting, and Report Interpretation
- Strategies for test data generation and measuring coverage
- Addressing common issues and troubleshooting scanner, pipeline, and permission errors
- Reading and presenting SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Recommendations
- Selecting rule sets and implementing incremental enforcement strategies
- Workflow recommendations for developers, reviewers, and build pipelines
- Creating a roadmap for scaling SonarQube in enterprise environments
Summary and Next Steps
Requirements
- A solid understanding of the software development lifecycle
- Hands-on experience with source control and fundamental CI/CD concepts
- Familiarity with Java or Angular development environments
Target Audience
- Developers working with Java, Quarkus, or Angular
- DevOps and CI/CD engineers
- Security engineers and application security reviewers
Testimonials (1)
Engaging, and hands on practise.