Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Fundamentals and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule classifications, and severity levels
- The role of static analysis in a secure SDLC and its contribution to risk mitigation
- Positioning SonarQube within security controls and developer workflows
2. SonarQube Overview: Features and Architecture
- Essential services, database structures, and scanner components
- Quality Gates, Quality Profiles, and best practices for their implementation
- Security-focused capabilities: vulnerability detection, SAST rules, and CWE mapping
3. Navigating the SonarQube Server UI
- A comprehensive tour of the server interface: projects, issues, rules, metrics, and governance views
- Analyzing issue pages, ensuring traceability, and following remediation guidance
- Generating and exporting reports
4. Configuring SonarScanner with Build Tools
- Installing SonarScanner for Maven, Gradle, Ant, and MSBuild
- Best practices for managing scanner properties, exclusions, and multi-module projects
- Generating requisite test data and coverage reports to ensure accurate analysis
5. Integration with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and utilizing PR decoration
- Importing Azure Repos into SonarQube and automating the analysis process
6. Project Configuration and Third-Party Analyzers
- Setting up project-specific Quality Profiles and selecting rules for Java and Angular
- Managing third-party analyzers and understanding the plugin lifecycle
- Defining analysis parameters and handling parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology Review
- Role segregation: developers, code reviewers, DevOps, and security stakeholders
- Creating a roles and responsibilities matrix for CI/CD processes
- Reviewing and refining existing secure development methodologies
8. Advanced: Rule Management, Tuning, and Global Security Enhancements
- Leveraging the SonarQube Web API to create and manage custom rules
- Refining Quality Gates and enforcing automated policies
- Strengthening SonarQube server security and optimizing access control practices
9. Practical Lab Sessions (Applied)
- Lab A: Configure SonarScanner for 5 Java repositories (using Quarkus where relevant) and review analysis outcomes
- Lab B: Set up Sonar analysis for an Angular front-end project and interpret the findings
- Lab C: End-to-end pipeline lab—integrating SonarQube with an Azure DevOps pipeline and enabling PR decoration
10. Testing, Troubleshooting, and Report Interpretation
- Strategies for generating test data and measuring coverage
- Resolving common issues related to scanners, pipelines, and permission errors
- Effectively presenting SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Recommendations
- Selecting appropriate rule sets and implementing incremental enforcement strategies
- Workflow recommendations for developers, reviewers, and build pipelines
- A roadmap for scaling SonarQube within enterprise environments
Summary and Next Steps
Requirements
- A solid grasp of the software development lifecycle
- Practical experience with source control and fundamental CI/CD concepts
- Working knowledge of Java or Angular development environments
Target Audience
- Developers (Java / Quarkus / Angular)
- DevOps and CI/CD engineers
- Security engineers and application security auditors
Testimonials (1)
Engaging, and hands on practise.