Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Fundamentals and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule categories, and severity levels
- The role of static analysis in secure SDLC and its coverage of risk areas
- Positioning SonarQube within security controls and developer workflows
2. SonarQube Overview: Capabilities and Architecture
- Core services, database structures, and scanner components
- Best practices for Quality Gates, Quality Profiles, and their application
- Security-focused features: vulnerability detection, SAST rules, and CWE mapping
3. Navigating and Utilizing the SonarQube Server Interface
- Tour of the server UI: projects, issues, rules, metrics, and governance views
- Interpreting issue pages, tracing origins, and understanding remediation guidance
- Options for generating and exporting comprehensive reports
4. Configuring SonarScanner with Build Tools
- Setup of SonarScanner for Maven, Gradle, Ant, and MSBuild
- Best practices for managing scanner properties, exclusions, and multi-module projects
- Creating essential test data and coverage reports to ensure analysis accuracy
5. Integration with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and implementing PR decoration
- Importing Azure Repos into SonarQube and automating analysis workflows
6. Project Configuration and Third-Party Analyzers
- Defining project-level Quality Profiles and selecting rules for Java and Angular
- Managing third-party analyzers and understanding the plugin lifecycle
- Defining analysis parameters and managing parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology Evaluation
- Defining role segregation: developers, reviewers, DevOps staff, and security owners
- Developing a roles and responsibilities matrix for CI/CD processes
- Evaluating and recommending improvements to existing secure development methodologies
8. Advanced Topics: Adding Rules, Tuning, and Enhancing Global Security
- Leveraging the SonarQube Web API to add and manage custom rules
- Adjusting Quality Gates and enforcing automated policies
- Hardening SonarQube server security and implementing access control best practices
9. Practical Lab Sessions (Application Phase)
- Lab A: Configure SonarScanner for five Java repositories (including Quarkus where relevant) and analyze outcomes
- Lab B: Set up Sonar analysis for one Angular front-end project and interpret results
- Lab C: Comprehensive pipeline exercise—integrating SonarQube with an Azure DevOps pipeline and enabling PR decoration
10. Testing, Troubleshooting, and Report Interpretation
- Strategies for generating test data and measuring coverage
- Addressing common issues and troubleshooting scanner, pipeline, and permission errors
- Techniques for reading and presenting SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Strategic Recommendations
- Selecting rule sets and strategies for incremental enforcement
- Workflow recommendations for developers, reviewers, and build pipelines
- Planning a roadmap for scaling SonarQube in enterprise environments
Summary and Future Actions
Requirements
- A solid grasp of the software development lifecycle.
- Practical experience with source control systems and fundamental CI/CD concepts.
- Proficiency with Java or Angular development environments.
Target Audience
- Developers working with Java, Quarkus, or Angular.
- DevOps and CI/CD engineers.
- Security engineers and application security auditors.
Testimonials (1)
Engaging, and hands on practise.