Get in Touch

Course Outline

1. Fundamentals and Scope of Static Code Analysis

  • Key definitions: static analysis, SAST, rule categorization, and severity levels
  • The role of static analysis within the secure SDLC and its coverage of risks
  • Positioning SonarQube within security controls and developer workflows

2. SonarQube Overview: Capabilities and Architecture

  • Essential components: core services, database, and scanner modules
  • Understanding Quality Gates, Quality Profiles, and best practices for their application
  • Security features: vulnerability detection, SAST rules, and CWE mapping

3. Navigating the SonarQube Server Interface

  • Tour of the server UI: projects, issues, rules, metrics, and governance views
  • Analyzing issue pages, tracing origins, and following remediation guidance
  • Options for report generation and data export

4. Configuring SonarScanner with Build Tools

  • Setup instructions for SonarScanner with Maven, Gradle, Ant, and MSBuild
  • Best practices for scanner properties, file exclusions, and multi-module project structures
  • Creating necessary test data and coverage reports to ensure analysis accuracy

5. Integrating with Azure DevOps

  • Setting up SonarQube service connections within Azure DevOps
  • Incorporating SonarQube tasks into Azure Pipelines and enabling PR decoration
  • Importing Azure Repos into SonarQube to automate analysis processes

6. Project Settings and Third-Party Analyzers

  • Configuring project-level Quality Profiles and selecting rules for Java and Angular
  • Utilizing third-party analyzers and managing the plugin lifecycle
  • Defining analysis parameters and managing parameter inheritance

7. Roles, Responsibilities, and Secure Development Methodology

  • Defining segregation of roles: developers, reviewers, DevOps, and security owners
  • Developing a roles and responsibilities matrix for CI/CD processes
  • Evaluating and recommending improvements to existing secure development methodologies

8. Advanced: Custom Rules, Tuning, and Global Security Enhancements

  • Leveraging the SonarQube Web API to create and manage custom rules
  • Refining Quality Gates and enforcing automated policies
  • Securing the SonarQube server and implementing access control best practices

9. Applied Hands-on Lab Sessions

  • Lab A: Configure SonarScanner for five Java repositories (including Quarkus where relevant) and analyze outcomes
  • Lab B: Set up Sonar analysis for one Angular front-end project and interpret the results
  • Lab C: Comprehensive pipeline lab—integrating SonarQube with an Azure DevOps pipeline and activating PR decoration

10. Testing, Troubleshooting, and Report Analysis

  • Methods for generating test data and measuring coverage
  • Addressing common issues related to scanner errors, pipeline failures, and permissions
  • Interpreting and presenting SonarQube reports to both technical and non-technical stakeholders

11. Best Practices and Strategic Recommendations

  • Strategies for rule set selection and incremental enforcement
  • Workflow optimizations for developers, reviewers, and build pipelines
  • Planning for the scalability of SonarQube in enterprise environments

Summary and Next Steps

Requirements

  • Foundational understanding of the software development lifecycle
  • Practical experience with source control and basic CI/CD principles
  • Proficiency with Java or Angular development environments

Target Audience

  • Developers working with Java, Quarkus, or Angular
  • DevOps and CI/CD engineers
  • Security engineers and application security reviewers
 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories