Get in Touch
 Duration 21 hours

Course Outline

1. Fundamentals and Scope of Static Code Analysis

  • Key definitions: static analysis, SAST, rule categorization, and severity levels
  • The role of static analysis in a secure SDLC and its coverage of potential risks
  • Positioning SonarQube within security controls and developer workflows

2. SonarQube Overview: Key Features and Architecture

  • Essential components: core services, database, and scanners
  • Understanding Quality Gates and Quality Profiles, along with best practices for their implementation
  • Security-focused capabilities: vulnerability detection, SAST rules, and CWE mapping

3. Navigating the SonarQube Server Interface

  • Overview of the server UI: managing projects, issues, rules, metrics, and governance views
  • Analyzing issue pages, tracking traceability, and following remediation advice
  • Generating and exporting detailed reports

4. Configuring SonarScanner with Build Tools

  • Setup procedures for SonarScanner compatible with Maven, Gradle, Ant, and MSBuild
  • Best practices for defining scanner properties, setting exclusions, and handling multi-module projects
  • Creating appropriate test data and coverage reports to ensure analysis accuracy

5. Integrating with Azure DevOps

  • Establishing SonarQube service connections within Azure DevOps
  • Incorporating SonarQube tasks into Azure Pipelines and enhancing PR decorations
  • Importing Azure Repos into SonarQube to automate continuous analysis

6. Project Configuration and Third-Party Analyzers

  • Customizing project-level Quality Profiles and selecting rules for Java and Angular
  • Managing third-party analyzers and understanding the plugin lifecycle
  • Defining analysis parameters and managing parameter inheritance

7. Roles, Responsibilities, and Secure Development Methodology Review

  • Defining role separation: developers, reviewers, DevOps staff, and security owners
  • Developing a roles and responsibilities matrix for CI/CD processes
  • Evaluating and recommending improvements to existing secure development methodologies

8. Advanced Topics: Rule Management and Security Enhancement

  • Leveraging the SonarQube Web API to create and manage custom rules
  • Refining Quality Gates and enforcing automated policies
  • Strengthening SonarQube server security and implementing access control best practices

9. Applied Hands-on Lab Sessions

  • Lab A: Set up SonarScanner for five Java repositories (including Quarkus where relevant) and analyze the outcomes
  • Lab B: Configure Sonar analysis for an Angular front-end application and interpret the findings
  • Lab C: End-to-end pipeline exercise—integrate SonarQube with an Azure DevOps pipeline and activate PR decoration

10. Testing, Troubleshooting, and Report Interpretation

  • Techniques for test data generation and measuring code coverage
  • Resolving common issues related to scanners, pipelines, and permissions
  • Presentation strategies for conveying SonarQube reports to both technical and non-technical stakeholders

11. Best Practices and Strategic Recommendations

  • Selecting appropriate rule sets and implementing incremental enforcement strategies
  • Workflow suggestions for developers, reviewers, and build pipeline management
  • Planning the roadmap for scaling SonarQube in enterprise settings

Summary and Next Steps

Requirements

  • A solid grasp of the software development lifecycle
  • Practical experience with source control systems and foundational CI/CD concepts
  • Working knowledge of Java or Angular development environments

Target Audience

  • Developers working with Java, Quarkus, or Angular
  • DevOps and CI/CD engineers
  • Security engineers and application security auditors

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories