Get in Touch
 Duration 21 hours

Course Outline

1. Concepts and Scope of Static Code Analysis

  • Definitions: static analysis, SAST, rule categories, and severity levels.
  • The scope of static analysis within a secure SDLC and risk coverage.
  • How SonarQube aligns with security controls and developer workflows.

2. SonarQube Overview: Features and Architecture

  • Core services, database structures, and scanner components.
  • Quality Gates, Quality Profiles, and best practices for their application.
  • Security-specific features: vulnerabilities, SAST rules, and CWE mapping.

3. Navigating the SonarQube Server UI

  • A tour of the Server UI: projects, issues, rules, measures, and governance views.
  • Interpreting issue pages, traceability, and remediation guidance.
  • Options for report generation and export.

4. Configuring SonarScanner with Build Tools

  • Setting up SonarScanner for Maven, Gradle, Ant, and MSBuild.
  • Best practices for scanner properties, exclusions, and multi-module projects.
  • Generating the necessary test data and coverage reports for accurate analysis.

5. Integration with Azure DevOps

  • Configuring SonarQube service connections in Azure DevOps.
  • Incorporating SonarQube tasks into Azure Pipelines and enabling PR decoration.
  • Importing Azure Repos into SonarQube and automating analyses.

6. Project Configuration and Third-Party Analyzers

  • Project-level Quality Profiles and rule selection for Java and Angular.
  • Working with third-party analyzers and understanding the plugin lifecycle.
  • Defining analysis parameters and managing parameter inheritance.

7. Roles, Responsibilities, and Secure Development Methodology Review

  • Segregation of roles: developers, reviewers, DevOps, and security owners.
  • Constructing a roles & responsibilities matrix for CI/CD processes.
  • Reviewing and recommending improvements for an existing secure development methodology.

8. Advanced: Adding Rules, Tuning, and Enhancing Global Security Features

  • Utilising the SonarQube Web API to add and manage custom rules.
  • Adjusting Quality Gates and enforcing automated policies.
  • Hardening SonarQube server security and adhering to access control best practices.

9. Hands-on Lab Sessions (Applied)

  • Lab A: Configure SonarScanner for five Java repositories (Quarkus where applicable) and analyse the results.
  • Lab B: Configure Sonar analysis for one Angular front-end project and interpret the findings.
  • Lab C: A full pipeline lab—integrate SonarQube with an Azure DevOps pipeline and enable PR decoration.

10. Testing, Troubleshooting, and Report Interpretation

  • Strategies for test data generation and coverage measurement.
  • Addressing common issues and troubleshooting scanner, pipeline, and permission errors.
  • How to read and present SonarQube reports to both technical and non-technical stakeholders.

11. Best Practices and Recommendations

  • Rule set selection and strategies for incremental enforcement.
  • Workflow recommendations for developers, reviewers, and build pipelines.
  • A roadmap for scaling SonarQube in enterprise environments.

Summary and Next Steps

Requirements

  • A solid understanding of the software development lifecycle.
  • Experience with source control and fundamental CI/CD concepts.
  • Familiarity with Java or Angular development environments.

Audience

  • Developers (Java / Quarkus / Angular).
  • DevOps and CI/CD engineers.
  • Security engineers and application security reviewers.

Number of participants


Price per participant

Testimonials (1)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories