Get in Touch
 Duration 21 hours

Course Outline

1. Principles and Scope of Static Code Analysis

  • Key definitions: static analysis, SAST, rule categories, and severity levels
  • The extent of static analysis within the secure SDLC and its risk coverage
  • The role of SonarQube in security controls and developer workflows

2. SonarQube Overview: Features and Architecture

  • Essential services, database structures, and scanner components
  • Best practices for Quality Gates, Quality Profiles, and related mechanisms
  • Security-focused capabilities: vulnerabilities, SAST rules, and CWE mapping

3. Navigating the SonarQube Server Interface

  • A tour of the Server UI: projects, issues, rules, metrics, and governance views
  • Understanding issue pages, traceability, and remediation guidance
  • Options for report generation and export

4. Configuring SonarScanner with Build Tools

  • Setup of SonarScanner for Maven, Gradle, Ant, and MSBuild
  • Best practices regarding scanner properties, exclusions, and multi-module projects
  • Generating essential test data and coverage reports for precise analysis

5. Integration with Azure DevOps

  • Setting up SonarQube service connections within Azure DevOps
  • Incorporating SonarQube tasks into Azure Pipelines and enhancing PR decoration
  • Importing Azure Repos into SonarQube and automating analysis processes

6. Project Configuration and Third-Party Analyzers

  • Project-specific Quality Profiles and rule selection for Java and Angular
  • Utilizing third-party analyzers and managing the plugin lifecycle
  • Defining analysis parameters and establishing parameter inheritance

7. Roles, Responsibilities, and Reviewing Secure Development Methodologies

  • Role separation: developers, reviewers, DevOps teams, and security owners
  • Developing a roles & responsibilities matrix for CI/CD processes
  • Reviewing and recommending improvements to existing secure development methodologies

8. Advanced Topics: Adding Rules, Tuning, and Enhancing Global Security Features

  • Leveraging the SonarQube Web API to add and manage custom rules
  • Refining Quality Gates and enforcing automated policies
  • Strengthening SonarQube server security and access control best practices

9. Hands-on Lab Sessions (Practical Application)

  • Lab A: Configure SonarScanner for 5 Java repositories (incorporating Quarkus where applicable) and analyze the results
  • Lab B: Set up Sonar analysis for one Angular front-end application and interpret the findings
  • Lab C: Comprehensive pipeline lab—integrating SonarQube with an Azure DevOps pipeline and enabling PR decoration

10. Testing, Troubleshooting, and Interpreting Reports

  • Strategies for generating test data and measuring coverage
  • Addressing common issues related to scanners, pipelines, and permission errors
  • Guidance on reading and presenting SonarQube reports to both technical and non-technical stakeholders

11. Best Practices and Recommendations

  • Selecting rule sets and strategies for incremental enforcement
  • Workflow recommendations for developers, reviewers, and build pipelines
  • A roadmap for scaling SonarQube in enterprise settings

Summary and Next Steps

Requirements

  • A solid grasp of the software development lifecycle
  • Practical experience with source control systems and foundational CI/CD concepts
  • Proficiency in Java or Angular development environments

Target Audience

  • Developers (Java / Quarkus / Angular)
  • DevOps and CI/CD engineers
  • Security engineers and application security reviewers

Number of participants


Price per participant

Testimonials (1)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories