Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Foundations and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule classifications, and severity levels
- The role of static analysis within the secure SDLC and its impact on risk mitigation
- Positioning SonarQube within security controls and developer workflows
2. SonarQube Overview: Capabilities and Architecture
- Essential components: core services, database, and scanner elements
- Quality Gates, Quality Profiles, and best practices for their implementation
- Security-focused features: vulnerability detection, SAST rules, and CWE correlation
3. Navigating the SonarQube Server Interface
- Touring the server UI: projects, issues, rules, metrics, and governance perspectives
- Analyzing issue pages, tracing issues, and following remediation advice
- Generating and exporting reports
4. Configuring SonarScanner with Build Tools
- Setting up SonarScanner for Maven, Gradle, Ant, and MSBuild
- Optimizing scanner properties, handling exclusions, and managing multi-module projects
- Creating necessary test data and coverage reports to ensure accurate analysis
5. Integration with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and enhancing PR visuals
- Synchronizing Azure Repos with SonarQube and automating analysis workflows
6. Project Configuration and Third-Party Analyzers
- Setting project-level Quality Profiles and selecting rules for Java and Angular
- Managing third-party analyzers and understanding the plugin lifecycle
- Defining analysis parameters and managing parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology Assessment
- Defining role separation: developers, reviewers, DevOps, and security leads
- Building a roles and responsibilities matrix for CI/CD processes
- Evaluating and recommending improvements to existing secure development methodologies
8. Advanced: Custom Rules, Tuning, and Enhancing Global Security
- Leveraging the SonarQube Web API to create and manage custom rules
- Refining Quality Gates and enforcing automated policies
- Strengthening SonarQube server security and implementing access control best practices
9. Practical Lab Sessions (Application)
- Lab A: Configure SonarScanner for five Java repositories (utilizing Quarkus where relevant) and analyze the outcomes
- Lab B: Set up Sonar analysis for one Angular front-end application and interpret the findings
- Lab C: End-to-end pipeline lab—integrating SonarQube with an Azure DevOps pipeline and activating PR decoration
10. Testing, Troubleshooting, and Report Analysis
- Techniques for generating test data and measuring coverage
- Addressing common issues and resolving errors related to scanners, pipelines, and permissions
- Interpreting and presenting SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Strategic Recommendations
- Selecting rule sets and strategies for phased enforcement
- Workflow guidelines for developers, reviewers, and build pipelines
- A roadmap for scaling SonarQube in enterprise settings
Summary and Next Steps
Requirements
- A solid grasp of the software development lifecycle
- Practical experience with source control and foundational CI/CD concepts
- Proficiency in Java or Angular development environments
Target Audience
- Developers specializing in Java / Quarkus / Angular
- DevOps and CI/CD engineers
- Security engineers and application security auditors
Testimonials (1)
Engaging, and hands on practise.