Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Fundamentals and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule categories, and severity levels
- The role of static analysis in secure SDLC and risk mitigation
- Positioning SonarQube within security controls and developer workflows
2. SonarQube Overview: Features and Architecture
- Core services, database components, and scanner architecture
- Best practices for Quality Gates, Quality Profiles, and governance
- Security features: vulnerability detection, SAST rules, and CWE mapping
3. Navigating the SonarQube Server Interface
- Tour of the server UI: projects, issues, rules, measures, and governance views
- Interpreting issue details, traceability, and remediation guidance
- Generating and exporting comprehensive reports
4. Configuring SonarScanner with Build Tools
- Setting up SonarScanner for Maven, Gradle, Ant, and MSBuild
- Best practices for scanner properties, exclusions, and multi-module projects
- Generating test data and coverage reports to ensure accurate analysis
5. Integration with Azure DevOps
- Configuring SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and PR decoration
- Importing Azure Repos into SonarQube and automating analysis workflows
6. Project Configuration and Third-Party Analyzers
- Setting project-level Quality Profiles and selecting rules for Java and Angular
- Managing third-party analyzers and plugin lifecycles
- Defining analysis parameters and understanding parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology
- Defining role segregation: developers, reviewers, DevOps, and security owners
- Building a roles and responsibilities matrix for CI/CD processes
- Reviewing and recommending improvements to existing secure development methodologies
8. Advanced: Rule Management, Tuning, and Global Security Enhancements
- Using the SonarQube Web API to add and manage custom rules
- Refining Quality Gates and enforcing automated policies
- Hardening SonarQube server security and implementing access control best practices
9. Applied Hands-on Laboratory Sessions
- Lab A: Configure SonarScanner for five Java repositories (including Quarkus where applicable) and analyze results
- Lab B: Set up Sonar analysis for an Angular front-end and interpret findings
- Lab C: End-to-end pipeline integration of SonarQube with Azure DevOps, including PR decoration
10. Testing, Troubleshooting, and Report Interpretation
- Strategies for generating test data and measuring coverage
- Resolving common scanner, pipeline, and permission-related issues
- Effectively presenting SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Recommendations
- Selecting appropriate rule sets and implementing incremental enforcement strategies
- Workflow recommendations for developers, reviewers, and build pipelines
- Scaling SonarQube for enterprise environments: a forward-looking roadmap
Summary and Next Steps
Requirements
- A solid grasp of the software development lifecycle
- Practical experience with source control and fundamental CI/CD concepts
- Proficiency with Java or Angular development environments
Target Audience
- Developers (Java / Quarkus / Angular)
- DevOps and CI/CD engineers
- Security engineers and application security reviewers
Testimonials (1)
Engaging, and hands on practise.