Get in Touch
 Duration 21 hours

Course Outline

1. Fundamentals and Scope of Static Code Analysis

  • Key definitions: static analysis, SAST, rule categories, and severity levels.
  • The role of static analysis in the secure SDLC and its contribution to risk coverage.
  • How SonarQube aligns with security controls and developer workflows.

2. SonarQube Overview: Capabilities and Architecture

  • Essential components: core services, database, and scanners.
  • Implementation of Quality Gates, Quality Profiles, and associated best practices.
  • Security-focused features, including vulnerability detection, SAST rules, and CWE mapping.

3. Navigating the SonarQube Server Interface

  • A tour of the Server UI, covering projects, issues, rules, metrics, and governance views.
  • Interpreting issue pages, tracking traceability, and following remediation guidance.
  • Generating and exporting reports.

4. Configuring SonarScanner with Build Tools

  • Setting up SonarScanner for Maven, Gradle, Ant, and MSBuild.
  • Best practices for configuring scanner properties, managing exclusions, and handling multi-module projects.
  • Generating appropriate test data and coverage reports to ensure analysis accuracy.

5. Integration with Azure DevOps

  • Establishing SonarQube service connections within Azure DevOps.
  • Incorporating SonarQube tasks into Azure Pipelines and enabling Pull Request (PR) decorations.
  • Importing Azure Repos into SonarQube to automate analysis processes.

6. Project Configuration and Third-Party Analyzers

  • Configuring project-level Quality Profiles and selecting rules for Java and Angular.
  • Managing third-party analyzers and understanding the plugin lifecycle.
  • Defining analysis parameters and managing parameter inheritance.

7. Roles, Responsibilities, and Secure Development Methodologies

  • Clarifying roles: developers, reviewers, DevOps engineers, and security owners.
  • Creating a roles and responsibilities matrix for CI/CD processes.
  • Reviewing and recommending improvements to existing secure development methodologies.

8. Advanced Topics: Adding Rules, Tuning, and Global Security Enhancements

  • Leveraging the SonarQube Web API to add and manage custom rules.
  • Adjusting Quality Gates and enforcing automated policies.
  • Strengthening SonarQube server security and adhering to access control best practices.

9. Applied Hands-on Lab Sessions

  • Lab A: Configure SonarScanner for five Java repositories (including Quarkus where applicable) and analyze the results.
  • Lab B: Set up Sonar analysis for one Angular front-end project and interpret the findings.
  • Lab C: Execute a full pipeline lab by integrating SonarQube with an Azure DevOps pipeline and enabling PR decorations.

10. Testing, Troubleshooting, and Report Interpretation

  • Strategies for generating test data and measuring code coverage.
  • Identifying and resolving common scanner, pipeline, and permission errors.
  • Effectively reading and presenting SonarQube reports to both technical and non-technical stakeholders.

11. Best Practices and Strategic Recommendations

  • Selecting appropriate rule sets and implementing incremental enforcement strategies.
  • Recommendations for developer workflows, review processes, and build pipelines.
  • Developing a roadmap for scaling SonarQube within enterprise environments.

Summary and Next Steps

Requirements

  • A solid understanding of the software development lifecycle (SDLC).
  • Practical experience with source control systems and fundamental CI/CD concepts.
  • Proficiency in Java or Angular development environments.

Target Audience

  • Developers working with Java, Quarkus, or Angular.
  • DevOps and CI/CD engineers.
  • Security engineers and application security reviewers.

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories