Get in Touch
 Duration 21 hours

Course Outline

1. Fundamentals and Scope of Static Code Analysis

  • Key definitions: static analysis, SAST, rule classifications, and severity levels
  • The role of static analysis in a secure SDLC and its contribution to risk mitigation
  • Positioning SonarQube within security controls and developer workflows

2. SonarQube Overview: Features and Architecture

  • Essential services, database structures, and scanner components
  • Quality Gates, Quality Profiles, and best practices for their implementation
  • Security-focused capabilities: vulnerability detection, SAST rules, and CWE mapping

3. Navigating the SonarQube Server UI

  • A comprehensive tour of the server interface: projects, issues, rules, metrics, and governance views
  • Analyzing issue pages, ensuring traceability, and following remediation guidance
  • Generating and exporting reports

4. Configuring SonarScanner with Build Tools

  • Installing SonarScanner for Maven, Gradle, Ant, and MSBuild
  • Best practices for managing scanner properties, exclusions, and multi-module projects
  • Generating requisite test data and coverage reports to ensure accurate analysis

5. Integration with Azure DevOps

  • Establishing SonarQube service connections within Azure DevOps
  • Incorporating SonarQube tasks into Azure Pipelines and utilizing PR decoration
  • Importing Azure Repos into SonarQube and automating the analysis process

6. Project Configuration and Third-Party Analyzers

  • Setting up project-specific Quality Profiles and selecting rules for Java and Angular
  • Managing third-party analyzers and understanding the plugin lifecycle
  • Defining analysis parameters and handling parameter inheritance

7. Roles, Responsibilities, and Secure Development Methodology Review

  • Role segregation: developers, code reviewers, DevOps, and security stakeholders
  • Creating a roles and responsibilities matrix for CI/CD processes
  • Reviewing and refining existing secure development methodologies

8. Advanced: Rule Management, Tuning, and Global Security Enhancements

  • Leveraging the SonarQube Web API to create and manage custom rules
  • Refining Quality Gates and enforcing automated policies
  • Strengthening SonarQube server security and optimizing access control practices

9. Practical Lab Sessions (Applied)

  • Lab A: Configure SonarScanner for 5 Java repositories (using Quarkus where relevant) and review analysis outcomes
  • Lab B: Set up Sonar analysis for an Angular front-end project and interpret the findings
  • Lab C: End-to-end pipeline lab—integrating SonarQube with an Azure DevOps pipeline and enabling PR decoration

10. Testing, Troubleshooting, and Report Interpretation

  • Strategies for generating test data and measuring coverage
  • Resolving common issues related to scanners, pipelines, and permission errors
  • Effectively presenting SonarQube reports to both technical and non-technical stakeholders

11. Best Practices and Recommendations

  • Selecting appropriate rule sets and implementing incremental enforcement strategies
  • Workflow recommendations for developers, reviewers, and build pipelines
  • A roadmap for scaling SonarQube within enterprise environments

Summary and Next Steps

Requirements

  • A solid grasp of the software development lifecycle
  • Practical experience with source control and fundamental CI/CD concepts
  • Working knowledge of Java or Angular development environments

Target Audience

  • Developers (Java / Quarkus / Angular)
  • DevOps and CI/CD engineers
  • Security engineers and application security auditors

Testimonials (1)

Upcoming Courses

Related Categories