Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Foundations and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule classifications, and severity levels
- The role of static analysis in secure SDLC and risk mitigation
- How SonarQube aligns with security controls and developer workflows
2. SonarQube Overview: Capabilities and Architecture
- Essential components: core services, database, and scanners
- Quality Gates, Quality Profiles, and best practices for their implementation
- Security features: vulnerability detection, SAST rules, and CWE mapping
3. Navigating the SonarQube Server Interface
- Tour of the server UI: projects, issues, rules, metrics, and governance views
- Analyzing issue details, traceability, and remediation steps
- Creating and exporting reports
4. Configuring SonarScanner with Build Tools
- Setup for Maven, Gradle, Ant, and MSBuild
- Optimizing scanner properties, exclusions, and handling multi-module projects
- Generating essential test data and coverage reports for precise analysis
5. Integration with Azure DevOps
- Establishing SonarQube service connections in Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and enabling PR decoration
- Importing Azure Repos into SonarQube and automating analysis cycles
6. Project Setup and Third-Party Analyzers
- Configuring project-level Quality Profiles and selecting rules for Java and Angular
- Managing third-party analyzers and plugin lifecycles
- Defining analysis parameters and inheritance structures
7. Roles, Responsibilities, and Secure Development Methodology
- Defining roles: developers, reviewers, DevOps, and security stakeholders
- Developing a roles and responsibilities matrix for CI/CD processes
- Evaluating and refining existing secure development methodologies
8. Advanced Topics: Custom Rules, Tuning, and Security Enhancements
- Adding and managing custom rules via the SonarQube Web API
- Refining Quality Gates and enforcing automated policies
- Strengthening SonarQube server security and access control protocols
9. Practical Lab Sessions
- Lab A: Configure SonarScanner for five Java repositories (including Quarkus where relevant) and analyze outcomes
- Lab B: Set up Sonar analysis for an Angular front-end and interpret results
- Lab C: End-to-end pipeline exercise—integrate SonarQube with an Azure DevOps pipeline and activate PR decoration
10. Testing, Troubleshooting, and Report Analysis
- Strategies for test data creation and coverage measurement
- Resolving common scanner, pipeline, and permission errors
- Interpreting and presenting SonarQube reports to both technical and non-technical audiences
11. Best Practices and Strategic Recommendations
- Selecting rule sets and strategies for incremental enforcement
- Workflow optimizations for developers, reviewers, and build pipelines
- Scaling SonarQube in enterprise contexts: a roadmap
Summary and Future Steps
Requirements
- A solid grasp of the software development lifecycle
- Hands-on experience with source control and fundamental CI/CD principles
- Proficiency with Java or Angular development environments
Target Audience
- Developers (Java / Quarkus / Angular)
- DevOps and CI/CD Engineers
- Security Engineers and Application Security Analysts
Testimonials (1)
Engaging, and hands on practise.