Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Fundamentals and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule classifications, and severity levels
- The role of static analysis in secure SDLC and risk mitigation
- Positioning SonarQube within security controls and developer workflows
2. SonarQube Overview: Capabilities and Architecture
- Essential components: core services, database, and scanner
- Quality Gates, Quality Profiles, and best practices for their implementation
- Security-centric capabilities: vulnerability detection, SAST rules, and CWE mapping
3. Navigating the SonarQube Server Interface
- Touring the server UI: projects, issues, rules, metrics, and governance dashboards
- Analyzing issue pages, tracking traceability, and following remediation guidance
- Options for generating and exporting reports
4. Configuring SonarScanner with Build Tools
- Installing and setting up SonarScanner for Maven, Gradle, Ant, and MSBuild
- Best practices for configuring scanner properties, exclusions, and multi-module projects
- Creating necessary test data and coverage reports to ensure analysis accuracy
5. Integration with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and enabling PR decoration
- Importing Azure Repos into SonarQube to automate analysis workflows
6. Project Setup and Third-Party Analyzers
- Configuring project-level Quality Profiles and selecting rules for Java and Angular
- Managing third-party analyzers and understanding the plugin lifecycle
- Defining analysis parameters and handling parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology
- Clarifying roles: developers, reviewers, DevOps engineers, and security owners
- Building a roles and responsibilities matrix for CI/CD processes
- Evaluating and recommending improvements to existing secure development methodologies
8. Advanced Topics: Custom Rules, Tuning, and Global Security Enhancements
- Leveraging the SonarQube Web API to create and manage custom rules
- Optimizing Quality Gates and enforcing automated policies
- Securing the SonarQube server and implementing access control best practices
9. Hands-on Lab Sessions (Practical Application)
- Lab A: Setting up SonarScanner for five Java repositories (using Quarkus where relevant) and interpreting results
- Lab B: Configuring Sonar analysis for an Angular front-end application and analyzing findings
- Lab C: End-to-end pipeline exercise—integrating SonarQube with an Azure DevOps pipeline and activating PR decoration
10. Testing, Troubleshooting, and Report Analysis
- Techniques for generating test data and measuring code coverage
- Resolving common issues related to scanners, pipelines, and permissions
- Presentation strategies for SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Strategic Recommendations
- Selecting appropriate rule sets and strategies for incremental enforcement
- Workflow recommendations for developers, reviewers, and build pipelines
- Roadmap for scaling SonarQube in enterprise settings
Summary and Next Steps
Requirements
- Working knowledge of the software development lifecycle
- Hands-on experience with source control and fundamental CI/CD concepts
- Proficiency in Java or Angular development environments
Target Audience
- Developers working with Java, Quarkus, or Angular
- DevOps and CI/CD engineers
- Security engineers and application security reviewers
Testimonials (1)
Engaging, and hands on practise.