Get in Touch
 Duration 21 hours

Course Outline

1. Foundations and Scope of Static Code Analysis

  • Key definitions: static analysis, SAST, rule classifications, and severity levels
  • The role of static analysis in secure SDLC and risk mitigation
  • How SonarQube aligns with security controls and developer workflows

2. SonarQube Overview: Capabilities and Architecture

  • Essential components: core services, database, and scanners
  • Quality Gates, Quality Profiles, and best practices for their implementation
  • Security features: vulnerability detection, SAST rules, and CWE mapping

3. Navigating the SonarQube Server Interface

  • Tour of the server UI: projects, issues, rules, metrics, and governance views
  • Analyzing issue details, traceability, and remediation steps
  • Creating and exporting reports

4. Configuring SonarScanner with Build Tools

  • Setup for Maven, Gradle, Ant, and MSBuild
  • Optimizing scanner properties, exclusions, and handling multi-module projects
  • Generating essential test data and coverage reports for precise analysis

5. Integration with Azure DevOps

  • Establishing SonarQube service connections in Azure DevOps
  • Incorporating SonarQube tasks into Azure Pipelines and enabling PR decoration
  • Importing Azure Repos into SonarQube and automating analysis cycles

6. Project Setup and Third-Party Analyzers

  • Configuring project-level Quality Profiles and selecting rules for Java and Angular
  • Managing third-party analyzers and plugin lifecycles
  • Defining analysis parameters and inheritance structures

7. Roles, Responsibilities, and Secure Development Methodology

  • Defining roles: developers, reviewers, DevOps, and security stakeholders
  • Developing a roles and responsibilities matrix for CI/CD processes
  • Evaluating and refining existing secure development methodologies

8. Advanced Topics: Custom Rules, Tuning, and Security Enhancements

  • Adding and managing custom rules via the SonarQube Web API
  • Refining Quality Gates and enforcing automated policies
  • Strengthening SonarQube server security and access control protocols

9. Practical Lab Sessions

  • Lab A: Configure SonarScanner for five Java repositories (including Quarkus where relevant) and analyze outcomes
  • Lab B: Set up Sonar analysis for an Angular front-end and interpret results
  • Lab C: End-to-end pipeline exercise—integrate SonarQube with an Azure DevOps pipeline and activate PR decoration

10. Testing, Troubleshooting, and Report Analysis

  • Strategies for test data creation and coverage measurement
  • Resolving common scanner, pipeline, and permission errors
  • Interpreting and presenting SonarQube reports to both technical and non-technical audiences

11. Best Practices and Strategic Recommendations

  • Selecting rule sets and strategies for incremental enforcement
  • Workflow optimizations for developers, reviewers, and build pipelines
  • Scaling SonarQube in enterprise contexts: a roadmap

Summary and Future Steps

Requirements

  • A solid grasp of the software development lifecycle
  • Hands-on experience with source control and fundamental CI/CD principles
  • Proficiency with Java or Angular development environments

Target Audience

  • Developers (Java / Quarkus / Angular)
  • DevOps and CI/CD Engineers
  • Security Engineers and Application Security Analysts

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories