Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Fundamentals and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule categorization, and severity levels
- The role of static analysis in a secure SDLC and its risk coverage
- How SonarQube aligns with security controls and developer workflows
2. SonarQube Overview: Features and Architecture
- Essential components including core services, databases, and scanners
- Quality Gates, Quality Profiles, and best practices for their implementation
- Security-focused capabilities: vulnerabilities, SAST rules, and CWE mapping
3. Navigating and Utilizing the SonarQube Server UI
- A comprehensive tour of the Server UI: projects, issues, rules, metrics, and governance views
- Analyzing issue pages, traceability features, and remediation guidance
- Generating and exporting reports
4. Configuring SonarScanner with Build Tools
- Setting up SonarScanner for Maven, Gradle, Ant, and MSBuild
- Best practices regarding scanner properties, exclusions, and multi-module projects
- Generating essential test data and coverage reports to ensure accurate analysis
5. Integration with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and enhancing pull request decoration
- Importing Azure Repos into SonarQube and automating the analysis process
6. Project Configuration and Third-Party Analyzers
- Setting up project-level Quality Profiles and selecting rules for Java and Angular
- Managing third-party analyzers and understanding the plugin lifecycle
- Defining analysis parameters and managing parameter inheritance
7. Roles, Responsibilities, and Reviewing Secure Development Methodologies
- Segmenting roles: developers, reviewers, DevOps engineers, and security owners
- Creating a roles and responsibilities matrix for CI/CD processes
- Assessing and recommending improvements to existing secure development methodologies
8. Advanced Topics: Adding Rules, Tuning, and Enhancing Global Security Features
- Leveraging the SonarQube Web API to add and manage custom rules
- Adjusting Quality Gates and enforcing automated policies
- Strengthening SonarQube server security and implementing best practices for access control
9. Applied Hands-on Lab Sessions
- Lab A: Configure SonarScanner for five Java repositories (including Quarkus where applicable) and review the results
- Lab B: Set up Sonar analysis for one Angular front-end application and interpret the findings
- Lab C: A comprehensive pipeline lab—integrating SonarQube with an Azure DevOps pipeline and enabling pull request decoration
10. Testing, Troubleshooting, and Interpreting Reports
- Strategies for generating test data and measuring coverage
- Identifying and resolving common issues related to scanners, pipelines, and permission errors
- Guidance on reading and presenting SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Recommendations
- Choosing rule sets and strategies for incremental enforcement
- Workflow recommendations for developers, reviewers, and build pipelines
- A roadmap for scaling SonarQube in enterprise environments
Summary and Future Steps
Requirements
- A solid understanding of the software development lifecycle
- Practical experience with source control systems and fundamental CI/CD concepts
- Proficiency in Java or Angular development environments
Target Audience
- Developers specializing in Java, Quarkus, or Angular
- DevOps and CI/CD engineers
- Security engineers and application security reviewers
Testimonials (1)
Engaging, and hands on practise.