Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Concepts and Scope of Static Code Analysis
- Definitions: static analysis, SAST, rule categories, and severity levels.
- The scope of static analysis within a secure SDLC and risk coverage.
- How SonarQube aligns with security controls and developer workflows.
2. SonarQube Overview: Features and Architecture
- Core services, database structures, and scanner components.
- Quality Gates, Quality Profiles, and best practices for their application.
- Security-specific features: vulnerabilities, SAST rules, and CWE mapping.
3. Navigating the SonarQube Server UI
- A tour of the Server UI: projects, issues, rules, measures, and governance views.
- Interpreting issue pages, traceability, and remediation guidance.
- Options for report generation and export.
4. Configuring SonarScanner with Build Tools
- Setting up SonarScanner for Maven, Gradle, Ant, and MSBuild.
- Best practices for scanner properties, exclusions, and multi-module projects.
- Generating the necessary test data and coverage reports for accurate analysis.
5. Integration with Azure DevOps
- Configuring SonarQube service connections in Azure DevOps.
- Incorporating SonarQube tasks into Azure Pipelines and enabling PR decoration.
- Importing Azure Repos into SonarQube and automating analyses.
6. Project Configuration and Third-Party Analyzers
- Project-level Quality Profiles and rule selection for Java and Angular.
- Working with third-party analyzers and understanding the plugin lifecycle.
- Defining analysis parameters and managing parameter inheritance.
7. Roles, Responsibilities, and Secure Development Methodology Review
- Segregation of roles: developers, reviewers, DevOps, and security owners.
- Constructing a roles & responsibilities matrix for CI/CD processes.
- Reviewing and recommending improvements for an existing secure development methodology.
8. Advanced: Adding Rules, Tuning, and Enhancing Global Security Features
- Utilising the SonarQube Web API to add and manage custom rules.
- Adjusting Quality Gates and enforcing automated policies.
- Hardening SonarQube server security and adhering to access control best practices.
9. Hands-on Lab Sessions (Applied)
- Lab A: Configure SonarScanner for five Java repositories (Quarkus where applicable) and analyse the results.
- Lab B: Configure Sonar analysis for one Angular front-end project and interpret the findings.
- Lab C: A full pipeline lab—integrate SonarQube with an Azure DevOps pipeline and enable PR decoration.
10. Testing, Troubleshooting, and Report Interpretation
- Strategies for test data generation and coverage measurement.
- Addressing common issues and troubleshooting scanner, pipeline, and permission errors.
- How to read and present SonarQube reports to both technical and non-technical stakeholders.
11. Best Practices and Recommendations
- Rule set selection and strategies for incremental enforcement.
- Workflow recommendations for developers, reviewers, and build pipelines.
- A roadmap for scaling SonarQube in enterprise environments.
Summary and Next Steps
Requirements
- A solid understanding of the software development lifecycle.
- Experience with source control and fundamental CI/CD concepts.
- Familiarity with Java or Angular development environments.
Audience
- Developers (Java / Quarkus / Angular).
- DevOps and CI/CD engineers.
- Security engineers and application security reviewers.
Testimonials (1)
Engaging, and hands on practise.