Get in Touch
 Duration 21 hours

Course Outline

1. Foundations and Scope of Static Code Analysis

  • Key definitions: static analysis, SAST, rule categories, and severity levels.
  • The role of static analysis in securing the SDLC and covering risk areas.
  • Positioning SonarQube within security controls and daily developer workflows.

2. SonarQube Fundamentals: Features and Architecture

  • Core services, database structures, and scanner components.
  • Best practices for Quality Gates, Quality Profiles, and their effective use.
  • Security-centric features: vulnerability detection, SAST rules, and CWE mapping.

3. Navigating the SonarQube Server Interface

  • A tour of the server UI: projects, issues, rules, metrics, and governance views.
  • Analyzing issue pages, tracking traceability, and following remediation advice.
  • Options for generating and exporting reports.

4. Configuring SonarScanner with Build Tools

  • Setup instructions for SonarScanner with Maven, Gradle, Ant, and MSBuild.
  • Best practices for managing scanner properties, exclusions, and multi-module projects.
  • Creating essential test data and coverage reports to ensure analysis accuracy.

5. Integration with Azure DevOps

  • Establishing SonarQube service connections within Azure DevOps.
  • Incorporating SonarQube tasks into Azure Pipelines and decorating Pull Requests.
  • Importing Azure Repos into SonarQube to automate analysis processes.

6. Project Setup and Third-Party Analyzers

  • Configuring project-specific Quality Profiles and selecting rules for Java and Angular.
  • Managing third-party analyzers and understanding the plugin lifecycle.
  • Defining analysis parameters and managing parameter inheritance.

7. Roles, Responsibilities, and Secure Development Methodology

  • Defining role segregation: developers, reviewers, DevOps, and security leads.
  • Building a roles and responsibilities matrix for CI/CD operations.
  • Evaluating and suggesting improvements to existing secure development methodologies.

8. Advanced Topics: Rules, Tuning, and Security Enhancements

  • Leveraging the SonarQube Web API to create and manage custom rules.
  • Tuning Quality Gates and enforcing automated policies.
  • Securing the SonarQube server and implementing access control best practices.

9. Applied Hands-on Lab Sessions

  • Lab A: Configure SonarScanner for five Java repositories (using Quarkus where relevant) and review the outcomes.
  • Lab B: Set up Sonar analysis for one Angular front-end project and interpret the results.
  • Lab C: End-to-end pipeline exercise—integrate SonarQube with an Azure DevOps pipeline and activate PR decoration.

10. Testing, Troubleshooting, and Report Analysis

  • Strategies for generating test data and measuring coverage.
  • Addressing common scanner, pipeline, and permission-related errors.
  • Techniques for interpreting and presenting SonarQube reports to both technical and non-technical stakeholders.

11. Best Practices and Strategic Recommendations

  • Selecting rule sets and strategies for incremental enforcement.
  • Workflow recommendations for developers, reviewers, and build pipelines.
  • A roadmap for scaling SonarQube across enterprise environments.

Summary and Path Forward

Requirements

  • A solid grasp of the software development lifecycle.
  • Practical experience with source control and foundational CI/CD principles.
  • Proficiency with Java or Angular development environments.

Intended Audience

  • Developers working with Java / Quarkus / Angular.
  • DevOps and CI/CD engineers.
  • Security engineers and application security auditors.

Testimonials (1)

Related Categories