Get in Touch
 Duration 21 hours

Course Outline

1. Foundations and Scope of Static Code Analysis

  • Key definitions: static analysis, SAST, rule categories, and severity levels
  • The role of static analysis in secure SDLC and risk mitigation
  • Positioning SonarQube within security controls and developer workflows

2. SonarQube Overview: Capabilities and Architecture

  • Understanding core services, database structures, and scanner components
  • Best practices for Quality Gates and Quality Profiles
  • Security features: vulnerability management, SAST rules, and CWE mapping

3. Navigating the SonarQube Server Interface

  • Tour of the Server UI: projects, issues, rules, metrics, and governance views
  • Analyzing issue pages, traceability, and remediation guidance
  • Options for generating and exporting reports

4. Configuring SonarScanner with Build Tools

  • Setting up SonarScanner for Maven, Gradle, Ant, and MSBuild
  • Optimizing scanner properties, exclusions, and multi-module project configurations
  • Generating test data and coverage reports to ensure analysis accuracy

5. Integrating with Azure DevOps

  • Establishing SonarQube service connections in Azure DevOps
  • Incorporating SonarQube tasks into Azure Pipelines and implementing PR decoration
  • Importing Azure Repos into SonarQube for automated analysis

6. Project Configuration and Third-Party Analyzers

  • Selecting project-level Quality Profiles and rules for Java and Angular
  • Managing third-party analyzers and their plugin lifecycle
  • Defining analysis parameters and understanding parameter inheritance

7. Roles, Responsibilities, and Secure Development Methodology

  • Segregating duties among developers, reviewers, DevOps teams, and security owners
  • Creating a roles and responsibilities matrix for CI/CD processes
  • Evaluating and refining existing secure development methodologies

8. Advanced Techniques: Rule Management and Security Enhancement

  • Leveraging the SonarQube Web API to create and manage custom rules
  • Tuning Quality Gates and enforcing automated policies
  • Best practices for hardening SonarQube server security and access controls

9. Applied Hands-on Lab Sessions

  • Lab A: Configure SonarScanner for five Java repositories (including Quarkus where relevant) and review results
  • Lab B: Set up Sonar analysis for an Angular front-end application and interpret findings
  • Lab C: End-to-end pipeline lab—integrate SonarQube with Azure DevOps pipelines and enable PR decoration

10. Testing, Troubleshooting, and Report Analysis

  • Methods for test data generation and coverage measurement
  • Resolving common scanner, pipeline, and permission errors
  • Effectively communicating SonarQube reports to both technical and non-technical stakeholders

11. Best Practices and Strategic Recommendations

  • Choosing rule sets and strategies for incremental enforcement
  • Recommended workflows for developers, reviewers, and build pipelines
  • Scaling SonarQube in enterprise environments: a roadmap

Summary and Next Steps

Requirements

  • A solid grasp of the Software Development Life Cycle (SDLC)
  • Hands-on experience with source control and fundamental CI/CD concepts
  • Familiarity with Java or Angular development environments

Target Audience

  • Developers working with Java, Quarkus, or Angular
  • DevOps and CI/CD Engineers
  • Security Engineers and Application Security Reviewers

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories