Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Foundations and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule categories, and severity levels
- The role of static analysis in secure SDLC and risk mitigation
- Positioning SonarQube within security controls and developer workflows
2. SonarQube Overview: Features and Architecture
- Essential services, database structures, and scanner components
- Quality Gates, Quality Profiles, and best practices for implementation
- Security features: vulnerability detection, SAST rules, and CWE mapping
3. Navigating and Utilizing the SonarQube Server UI
- Tour of the Server UI: projects, issues, rules, metrics, and governance views
- Analyzing issue pages, tracking traceability, and following remediation advice
- Options for generating and exporting reports
4. Configuring SonarScanner with Build Tools
- Setup of SonarScanner for Maven, Gradle, Ant, and MSBuild
- Best practices for scanner properties, exclusions, and multi-module project structures
- Creating essential test data and coverage reports for precise analysis
5. Integration with Azure DevOps
- Establishing SonarQube service connections in Azure DevOps
- Implementing SonarQube tasks in Azure Pipelines and enhancing Pull Request decoration
- Importing Azure Repos into SonarQube and automating analysis processes
6. Project Configuration and Third-Party Analyzers
- Setting project-level Quality Profiles and selecting rules for Java and Angular
- Managing third-party analyzers and understanding the plugin lifecycle
- Defining analysis parameters and managing parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology Review
- Defining roles: developers, reviewers, DevOps staff, and security owners
- Developing a roles and responsibilities matrix for CI/CD processes
- Evaluating and recommending improvements to existing secure development methodologies
8. Advanced Topics: Adding Rules, Tuning, and Enhancing Global Security Features
- Utilizing the SonarQube Web API to create and manage custom rules
- Modifying Quality Gates and enforcing automated policies
- Strengthening SonarQube server security and implementing access control best practices
9. Hands-on Lab Sessions (Practical Application)
- Lab A: Configure SonarScanner for five Java repositories (including Quarkus where applicable) and review analysis results
- Lab B: Set up Sonar analysis for one Angular front-end application and interpret the findings
- Lab C: Comprehensive pipeline lab—integrate SonarQube with an Azure DevOps pipeline and activate PR decoration
10. Testing, Troubleshooting, and Report Interpretation
- Approaches for generating test data and measuring coverage
- Resolving common scanner, pipeline, and permission errors
- Techniques for reading and presenting SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Recommendations
- Selecting rule sets and strategies for incremental enforcement
- Workflow suggestions for developers, reviewers, and build pipelines
- Strategic roadmap for scaling SonarQube in enterprise settings
Summary and Next Steps
Requirements
- A solid understanding of the software development lifecycle
- Practical experience with source control and foundational CI/CD concepts
- Familiarity with Java or Angular development environments
Target Audience
- Developers working with Java, Quarkus, or Angular
- DevOps and CI/CD engineers
- Security engineers and application security reviewers
Testimonials (1)
Engaging, and hands on practise.