Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Foundations and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule categories, and severity levels.
- The role of static analysis in securing the SDLC and covering risk areas.
- Positioning SonarQube within security controls and daily developer workflows.
2. SonarQube Fundamentals: Features and Architecture
- Core services, database structures, and scanner components.
- Best practices for Quality Gates, Quality Profiles, and their effective use.
- Security-centric features: vulnerability detection, SAST rules, and CWE mapping.
3. Navigating the SonarQube Server Interface
- A tour of the server UI: projects, issues, rules, metrics, and governance views.
- Analyzing issue pages, tracking traceability, and following remediation advice.
- Options for generating and exporting reports.
4. Configuring SonarScanner with Build Tools
- Setup instructions for SonarScanner with Maven, Gradle, Ant, and MSBuild.
- Best practices for managing scanner properties, exclusions, and multi-module projects.
- Creating essential test data and coverage reports to ensure analysis accuracy.
5. Integration with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps.
- Incorporating SonarQube tasks into Azure Pipelines and decorating Pull Requests.
- Importing Azure Repos into SonarQube to automate analysis processes.
6. Project Setup and Third-Party Analyzers
- Configuring project-specific Quality Profiles and selecting rules for Java and Angular.
- Managing third-party analyzers and understanding the plugin lifecycle.
- Defining analysis parameters and managing parameter inheritance.
7. Roles, Responsibilities, and Secure Development Methodology
- Defining role segregation: developers, reviewers, DevOps, and security leads.
- Building a roles and responsibilities matrix for CI/CD operations.
- Evaluating and suggesting improvements to existing secure development methodologies.
8. Advanced Topics: Rules, Tuning, and Security Enhancements
- Leveraging the SonarQube Web API to create and manage custom rules.
- Tuning Quality Gates and enforcing automated policies.
- Securing the SonarQube server and implementing access control best practices.
9. Applied Hands-on Lab Sessions
- Lab A: Configure SonarScanner for five Java repositories (using Quarkus where relevant) and review the outcomes.
- Lab B: Set up Sonar analysis for one Angular front-end project and interpret the results.
- Lab C: End-to-end pipeline exercise—integrate SonarQube with an Azure DevOps pipeline and activate PR decoration.
10. Testing, Troubleshooting, and Report Analysis
- Strategies for generating test data and measuring coverage.
- Addressing common scanner, pipeline, and permission-related errors.
- Techniques for interpreting and presenting SonarQube reports to both technical and non-technical stakeholders.
11. Best Practices and Strategic Recommendations
- Selecting rule sets and strategies for incremental enforcement.
- Workflow recommendations for developers, reviewers, and build pipelines.
- A roadmap for scaling SonarQube across enterprise environments.
Summary and Path Forward
Requirements
- A solid grasp of the software development lifecycle.
- Practical experience with source control and foundational CI/CD principles.
- Proficiency with Java or Angular development environments.
Intended Audience
- Developers working with Java / Quarkus / Angular.
- DevOps and CI/CD engineers.
- Security engineers and application security auditors.
Testimonials (1)
Engaging, and hands on practise.