Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Foundations and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule categories, and severity levels
- The role of static analysis in secure SDLC and risk mitigation
- Positioning SonarQube within security controls and developer workflows
2. SonarQube Overview: Capabilities and Architecture
- Understanding core services, database structures, and scanner components
- Best practices for Quality Gates and Quality Profiles
- Security features: vulnerability management, SAST rules, and CWE mapping
3. Navigating the SonarQube Server Interface
- Tour of the Server UI: projects, issues, rules, metrics, and governance views
- Analyzing issue pages, traceability, and remediation guidance
- Options for generating and exporting reports
4. Configuring SonarScanner with Build Tools
- Setting up SonarScanner for Maven, Gradle, Ant, and MSBuild
- Optimizing scanner properties, exclusions, and multi-module project configurations
- Generating test data and coverage reports to ensure analysis accuracy
5. Integrating with Azure DevOps
- Establishing SonarQube service connections in Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and implementing PR decoration
- Importing Azure Repos into SonarQube for automated analysis
6. Project Configuration and Third-Party Analyzers
- Selecting project-level Quality Profiles and rules for Java and Angular
- Managing third-party analyzers and their plugin lifecycle
- Defining analysis parameters and understanding parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology
- Segregating duties among developers, reviewers, DevOps teams, and security owners
- Creating a roles and responsibilities matrix for CI/CD processes
- Evaluating and refining existing secure development methodologies
8. Advanced Techniques: Rule Management and Security Enhancement
- Leveraging the SonarQube Web API to create and manage custom rules
- Tuning Quality Gates and enforcing automated policies
- Best practices for hardening SonarQube server security and access controls
9. Applied Hands-on Lab Sessions
- Lab A: Configure SonarScanner for five Java repositories (including Quarkus where relevant) and review results
- Lab B: Set up Sonar analysis for an Angular front-end application and interpret findings
- Lab C: End-to-end pipeline lab—integrate SonarQube with Azure DevOps pipelines and enable PR decoration
10. Testing, Troubleshooting, and Report Analysis
- Methods for test data generation and coverage measurement
- Resolving common scanner, pipeline, and permission errors
- Effectively communicating SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Strategic Recommendations
- Choosing rule sets and strategies for incremental enforcement
- Recommended workflows for developers, reviewers, and build pipelines
- Scaling SonarQube in enterprise environments: a roadmap
Summary and Next Steps
Requirements
- A solid grasp of the Software Development Life Cycle (SDLC)
- Hands-on experience with source control and fundamental CI/CD concepts
- Familiarity with Java or Angular development environments
Target Audience
- Developers working with Java, Quarkus, or Angular
- DevOps and CI/CD Engineers
- Security Engineers and Application Security Reviewers
Testimonials (1)
Engaging, and hands on practise.