Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
1. Fundamentals and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule categorization, and severity levels
- The role of static analysis within the secure SDLC and its coverage of risks
- Positioning SonarQube within security controls and developer workflows
2. SonarQube Overview: Capabilities and Architecture
- Essential components: core services, database, and scanner modules
- Understanding Quality Gates, Quality Profiles, and best practices for their application
- Security features: vulnerability detection, SAST rules, and CWE mapping
3. Navigating the SonarQube Server Interface
- Tour of the server UI: projects, issues, rules, metrics, and governance views
- Analyzing issue pages, tracing origins, and following remediation guidance
- Options for report generation and data export
4. Configuring SonarScanner with Build Tools
- Setup instructions for SonarScanner with Maven, Gradle, Ant, and MSBuild
- Best practices for scanner properties, file exclusions, and multi-module project structures
- Creating necessary test data and coverage reports to ensure analysis accuracy
5. Integrating with Azure DevOps
- Setting up SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and enabling PR decoration
- Importing Azure Repos into SonarQube to automate analysis processes
6. Project Settings and Third-Party Analyzers
- Configuring project-level Quality Profiles and selecting rules for Java and Angular
- Utilizing third-party analyzers and managing the plugin lifecycle
- Defining analysis parameters and managing parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology
- Defining segregation of roles: developers, reviewers, DevOps, and security owners
- Developing a roles and responsibilities matrix for CI/CD processes
- Evaluating and recommending improvements to existing secure development methodologies
8. Advanced: Custom Rules, Tuning, and Global Security Enhancements
- Leveraging the SonarQube Web API to create and manage custom rules
- Refining Quality Gates and enforcing automated policies
- Securing the SonarQube server and implementing access control best practices
9. Applied Hands-on Lab Sessions
- Lab A: Configure SonarScanner for five Java repositories (including Quarkus where relevant) and analyze outcomes
- Lab B: Set up Sonar analysis for one Angular front-end project and interpret the results
- Lab C: Comprehensive pipeline lab—integrating SonarQube with an Azure DevOps pipeline and activating PR decoration
10. Testing, Troubleshooting, and Report Analysis
- Methods for generating test data and measuring coverage
- Addressing common issues related to scanner errors, pipeline failures, and permissions
- Interpreting and presenting SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Strategic Recommendations
- Strategies for rule set selection and incremental enforcement
- Workflow optimizations for developers, reviewers, and build pipelines
- Planning for the scalability of SonarQube in enterprise environments
Summary and Next Steps
Requirements
- Foundational understanding of the software development lifecycle
- Practical experience with source control and basic CI/CD principles
- Proficiency with Java or Angular development environments
Target Audience
- Developers working with Java, Quarkus, or Angular
- DevOps and CI/CD engineers
- Security engineers and application security reviewers
21 Hours
Testimonials (1)
Engaging, and hands on practise.