Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Principles and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule categories, and severity levels
- The role of static analysis in securing the SDLC and covering potential risks
- Positioning SonarQube within security controls and developer workflows
2. SonarQube Overview: Capabilities and Architecture
- Core services, database structures, and scanner components
- Quality Gates, Quality Profiles, and best practices for their implementation
- Security-focused features: vulnerability detection, SAST rules, and CWE mapping
3. Navigating and Utilizing the SonarQube Server Interface
- Server UI walkthrough: projects, issues, rules, metrics, and governance views
- Analyzing issue pages, ensuring traceability, and following remediation guidance
- Options for report generation and data export
4. Configuring SonarScanner with Build Tools
- Setting up SonarScanner for Maven, Gradle, Ant, and MSBuild
- Best practices for scanner properties, exclusions, and managing multi-module projects
- Generating essential test data and coverage reports to ensure accurate analysis
5. Integration with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and enabling PR decorations
- Importing Azure Repos into SonarQube to automate analysis processes
6. Project Configuration and Third-Party Analyzers
- Setting project-level Quality Profiles and selecting rules for Java and Angular
- Interacting with third-party analyzers and understanding the plugin lifecycle
- Defining analysis parameters and managing parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology Assessment
- Role separation: developers, reviewers, DevOps, and security owners
- Creating a roles and responsibilities matrix for CI/CD processes
- Evaluating and recommending improvements to existing secure development methodologies
8. Advanced: Rule Management, Tuning, and Global Security Enhancements
- Utilizing the SonarQube Web API to create and manage custom rules
- Refining Quality Gates and enforcing automated policies
- Strengthening SonarQube server security and applying access control best practices
9. Practical Lab Sessions (Application)
- Lab A: Configure SonarScanner for five Java repositories (including Quarkus where applicable) and analyze outcomes
- Lab B: Configure Sonar analysis for one Angular front-end application and interpret the results
- Lab C: End-to-end pipeline lab integrating SonarQube with an Azure DevOps pipeline and activating PR decorations
10. Testing, Troubleshooting, and Report Analysis
- Strategies for generating test data and measuring coverage
- Addressing common issues and troubleshooting scanner, pipeline, and permission errors
- Methods for reading and presenting SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Strategic Recommendations
- Selecting rule sets and implementing incremental enforcement strategies
- Workflow recommendations for developers, reviewers, and build pipelines
- Roadmap for scaling SonarQube in enterprise environments
Summary and Next Steps
Requirements
- A solid understanding of the software development lifecycle
- Practical experience with source control systems and fundamental CI/CD concepts
- Proficiency with Java or Angular development environments
Target Audience
- Developers (Java / Quarkus / Angular)
- DevOps and CI/CD engineers
- Security engineers and application security auditors
Testimonials (1)
Engaging, and hands on practise.