Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Fundamentals and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule categories, and severity levels.
- The role of static analysis in the secure SDLC and its contribution to risk coverage.
- How SonarQube aligns with security controls and developer workflows.
2. SonarQube Overview: Capabilities and Architecture
- Essential components: core services, database, and scanners.
- Implementation of Quality Gates, Quality Profiles, and associated best practices.
- Security-focused features, including vulnerability detection, SAST rules, and CWE mapping.
3. Navigating the SonarQube Server Interface
- A tour of the Server UI, covering projects, issues, rules, metrics, and governance views.
- Interpreting issue pages, tracking traceability, and following remediation guidance.
- Generating and exporting reports.
4. Configuring SonarScanner with Build Tools
- Setting up SonarScanner for Maven, Gradle, Ant, and MSBuild.
- Best practices for configuring scanner properties, managing exclusions, and handling multi-module projects.
- Generating appropriate test data and coverage reports to ensure analysis accuracy.
5. Integration with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps.
- Incorporating SonarQube tasks into Azure Pipelines and enabling Pull Request (PR) decorations.
- Importing Azure Repos into SonarQube to automate analysis processes.
6. Project Configuration and Third-Party Analyzers
- Configuring project-level Quality Profiles and selecting rules for Java and Angular.
- Managing third-party analyzers and understanding the plugin lifecycle.
- Defining analysis parameters and managing parameter inheritance.
7. Roles, Responsibilities, and Secure Development Methodologies
- Clarifying roles: developers, reviewers, DevOps engineers, and security owners.
- Creating a roles and responsibilities matrix for CI/CD processes.
- Reviewing and recommending improvements to existing secure development methodologies.
8. Advanced Topics: Adding Rules, Tuning, and Global Security Enhancements
- Leveraging the SonarQube Web API to add and manage custom rules.
- Adjusting Quality Gates and enforcing automated policies.
- Strengthening SonarQube server security and adhering to access control best practices.
9. Applied Hands-on Lab Sessions
- Lab A: Configure SonarScanner for five Java repositories (including Quarkus where applicable) and analyze the results.
- Lab B: Set up Sonar analysis for one Angular front-end project and interpret the findings.
- Lab C: Execute a full pipeline lab by integrating SonarQube with an Azure DevOps pipeline and enabling PR decorations.
10. Testing, Troubleshooting, and Report Interpretation
- Strategies for generating test data and measuring code coverage.
- Identifying and resolving common scanner, pipeline, and permission errors.
- Effectively reading and presenting SonarQube reports to both technical and non-technical stakeholders.
11. Best Practices and Strategic Recommendations
- Selecting appropriate rule sets and implementing incremental enforcement strategies.
- Recommendations for developer workflows, review processes, and build pipelines.
- Developing a roadmap for scaling SonarQube within enterprise environments.
Summary and Next Steps
Requirements
- A solid understanding of the software development lifecycle (SDLC).
- Practical experience with source control systems and fundamental CI/CD concepts.
- Proficiency in Java or Angular development environments.
Target Audience
- Developers working with Java, Quarkus, or Angular.
- DevOps and CI/CD engineers.
- Security engineers and application security reviewers.
Testimonials (1)
Engaging, and hands on practise.