Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Fundamentals and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule categories, and severity levels
- The role of static analysis in a secure SDLC and its coverage of risks
- Positioning SonarQube within security controls and developer workflows
2. SonarQube Overview: Capabilities and Architecture
- Essential services, database, and scanner components
- Quality Gates, Quality Profiles, and best practices for their implementation
- Security-specific features: vulnerability detection, SAST rules, and CWE mapping
3. Navigating the SonarQube Server UI
- Overview of the server interface: projects, issues, rules, metrics, and governance views
- Analyzing issue pages, tracking traceability, and following remediation guidance
- Generating reports and exploring export options
4. Configuring SonarScanner with Build Tools
- Installation and setup of SonarScanner for Maven, Gradle, Ant, and MSBuild
- Best practices for scanner properties, exclusions, and handling multi-module projects
- Creating necessary test data and coverage reports to ensure accurate analysis
5. Integration with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and implementing PR decoration
- Importing Azure Repos into SonarQube and automating analysis workflows
6. Project Configuration and Third-Party Analyzers
- Setting project-level Quality Profiles and selecting rules for Java and Angular
- Managing third-party analyzers and understanding the plugin lifecycle
- Defining analysis parameters and managing parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology Review
- Defining role separation: developers, reviewers, DevOps, and security owners
- Building a roles and responsibilities matrix for CI/CD processes
- Reviewing and recommending enhancements to existing secure development methodologies
8. Advanced Topics: Rule Management, Tuning, and Security Enhancement
- Leveraging the SonarQube Web API to add and manage custom rules
- Refining Quality Gates and enforcing automated policies
- Strengthening SonarQube server security and access control practices
9. Hands-on Lab Sessions (Practical Application)
- Lab A: Configure SonarScanner for five Java repositories (including Quarkus where relevant) and analyze the results
- Lab B: Set up Sonar analysis for one Angular front-end application and interpret the findings
- Lab C: Comprehensive pipeline lab integrating SonarQube with an Azure DevOps pipeline and enabling PR decoration
10. Testing, Troubleshooting, and Report Interpretation
- Techniques for generating test data and measuring coverage
- Resolving common issues related to scanners, pipelines, and permission errors
- Presenting and explaining SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Recommendations
- Selecting rule sets and strategies for incremental enforcement
- Workflow recommendations for developers, reviewers, and build pipelines
- Developing a roadmap for scaling SonarQube in enterprise environments
Summary and Next Steps
Requirements
- A solid understanding of the software development lifecycle
- Practical experience with source control and fundamental CI/CD concepts
- Familiarity with Java or Angular development environments
Target Audience
- Developers (Java / Quarkus / Angular)
- DevOps and CI/CD engineers
- Security engineers and application security reviewers
Testimonials (1)
Engaging, and hands on practise.