Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Fundamentals and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule categorization, and severity levels
- The role of static analysis in a secure SDLC and its coverage of potential risks
- Positioning SonarQube within security controls and developer workflows
2. SonarQube Overview: Key Features and Architecture
- Essential components: core services, database, and scanners
- Understanding Quality Gates and Quality Profiles, along with best practices for their implementation
- Security-focused capabilities: vulnerability detection, SAST rules, and CWE mapping
3. Navigating the SonarQube Server Interface
- Overview of the server UI: managing projects, issues, rules, metrics, and governance views
- Analyzing issue pages, tracking traceability, and following remediation advice
- Generating and exporting detailed reports
4. Configuring SonarScanner with Build Tools
- Setup procedures for SonarScanner compatible with Maven, Gradle, Ant, and MSBuild
- Best practices for defining scanner properties, setting exclusions, and handling multi-module projects
- Creating appropriate test data and coverage reports to ensure analysis accuracy
5. Integrating with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and enhancing PR decorations
- Importing Azure Repos into SonarQube to automate continuous analysis
6. Project Configuration and Third-Party Analyzers
- Customizing project-level Quality Profiles and selecting rules for Java and Angular
- Managing third-party analyzers and understanding the plugin lifecycle
- Defining analysis parameters and managing parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology Review
- Defining role separation: developers, reviewers, DevOps staff, and security owners
- Developing a roles and responsibilities matrix for CI/CD processes
- Evaluating and recommending improvements to existing secure development methodologies
8. Advanced Topics: Rule Management and Security Enhancement
- Leveraging the SonarQube Web API to create and manage custom rules
- Refining Quality Gates and enforcing automated policies
- Strengthening SonarQube server security and implementing access control best practices
9. Applied Hands-on Lab Sessions
- Lab A: Set up SonarScanner for five Java repositories (including Quarkus where relevant) and analyze the outcomes
- Lab B: Configure Sonar analysis for an Angular front-end application and interpret the findings
- Lab C: End-to-end pipeline exercise—integrate SonarQube with an Azure DevOps pipeline and activate PR decoration
10. Testing, Troubleshooting, and Report Interpretation
- Techniques for test data generation and measuring code coverage
- Resolving common issues related to scanners, pipelines, and permissions
- Presentation strategies for conveying SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Strategic Recommendations
- Selecting appropriate rule sets and implementing incremental enforcement strategies
- Workflow suggestions for developers, reviewers, and build pipeline management
- Planning the roadmap for scaling SonarQube in enterprise settings
Summary and Next Steps
Requirements
- A solid grasp of the software development lifecycle
- Practical experience with source control systems and foundational CI/CD concepts
- Working knowledge of Java or Angular development environments
Target Audience
- Developers working with Java, Quarkus, or Angular
- DevOps and CI/CD engineers
- Security engineers and application security auditors
Testimonials (1)
Engaging, and hands on practise.