Get in Touch
 Duration 21 hours

Course Outline

1. Fundamentals and Scope of Static Code Analysis

  • Key definitions: static analysis, SAST, rule categories, and severity levels
  • The role of static analysis in secure SDLC and its coverage of risk areas
  • Positioning SonarQube within security controls and developer workflows

2. SonarQube Overview: Capabilities and Architecture

  • Core services, database structures, and scanner components
  • Best practices for Quality Gates, Quality Profiles, and their application
  • Security-focused features: vulnerability detection, SAST rules, and CWE mapping

3. Navigating and Utilizing the SonarQube Server Interface

  • Tour of the server UI: projects, issues, rules, metrics, and governance views
  • Interpreting issue pages, tracing origins, and understanding remediation guidance
  • Options for generating and exporting comprehensive reports

4. Configuring SonarScanner with Build Tools

  • Setup of SonarScanner for Maven, Gradle, Ant, and MSBuild
  • Best practices for managing scanner properties, exclusions, and multi-module projects
  • Creating essential test data and coverage reports to ensure analysis accuracy

5. Integration with Azure DevOps

  • Establishing SonarQube service connections within Azure DevOps
  • Incorporating SonarQube tasks into Azure Pipelines and implementing PR decoration
  • Importing Azure Repos into SonarQube and automating analysis workflows

6. Project Configuration and Third-Party Analyzers

  • Defining project-level Quality Profiles and selecting rules for Java and Angular
  • Managing third-party analyzers and understanding the plugin lifecycle
  • Defining analysis parameters and managing parameter inheritance

7. Roles, Responsibilities, and Secure Development Methodology Evaluation

  • Defining role segregation: developers, reviewers, DevOps staff, and security owners
  • Developing a roles and responsibilities matrix for CI/CD processes
  • Evaluating and recommending improvements to existing secure development methodologies

8. Advanced Topics: Adding Rules, Tuning, and Enhancing Global Security

  • Leveraging the SonarQube Web API to add and manage custom rules
  • Adjusting Quality Gates and enforcing automated policies
  • Hardening SonarQube server security and implementing access control best practices

9. Practical Lab Sessions (Application Phase)

  • Lab A: Configure SonarScanner for five Java repositories (including Quarkus where relevant) and analyze outcomes
  • Lab B: Set up Sonar analysis for one Angular front-end project and interpret results
  • Lab C: Comprehensive pipeline exercise—integrating SonarQube with an Azure DevOps pipeline and enabling PR decoration

10. Testing, Troubleshooting, and Report Interpretation

  • Strategies for generating test data and measuring coverage
  • Addressing common issues and troubleshooting scanner, pipeline, and permission errors
  • Techniques for reading and presenting SonarQube reports to both technical and non-technical stakeholders

11. Best Practices and Strategic Recommendations

  • Selecting rule sets and strategies for incremental enforcement
  • Workflow recommendations for developers, reviewers, and build pipelines
  • Planning a roadmap for scaling SonarQube in enterprise environments

Summary and Future Actions

Requirements

  • A solid grasp of the software development lifecycle.
  • Practical experience with source control systems and fundamental CI/CD concepts.
  • Proficiency with Java or Angular development environments.

Target Audience

  • Developers working with Java, Quarkus, or Angular.
  • DevOps and CI/CD engineers.
  • Security engineers and application security auditors.

Testimonials (1)

Related Categories