Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Principles and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule categories, and severity levels
- The extent of static analysis within the secure SDLC and its risk coverage
- The role of SonarQube in security controls and developer workflows
2. SonarQube Overview: Features and Architecture
- Essential services, database structures, and scanner components
- Best practices for Quality Gates, Quality Profiles, and related mechanisms
- Security-focused capabilities: vulnerabilities, SAST rules, and CWE mapping
3. Navigating the SonarQube Server Interface
- A tour of the Server UI: projects, issues, rules, metrics, and governance views
- Understanding issue pages, traceability, and remediation guidance
- Options for report generation and export
4. Configuring SonarScanner with Build Tools
- Setup of SonarScanner for Maven, Gradle, Ant, and MSBuild
- Best practices regarding scanner properties, exclusions, and multi-module projects
- Generating essential test data and coverage reports for precise analysis
5. Integration with Azure DevOps
- Setting up SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and enhancing PR decoration
- Importing Azure Repos into SonarQube and automating analysis processes
6. Project Configuration and Third-Party Analyzers
- Project-specific Quality Profiles and rule selection for Java and Angular
- Utilizing third-party analyzers and managing the plugin lifecycle
- Defining analysis parameters and establishing parameter inheritance
7. Roles, Responsibilities, and Reviewing Secure Development Methodologies
- Role separation: developers, reviewers, DevOps teams, and security owners
- Developing a roles & responsibilities matrix for CI/CD processes
- Reviewing and recommending improvements to existing secure development methodologies
8. Advanced Topics: Adding Rules, Tuning, and Enhancing Global Security Features
- Leveraging the SonarQube Web API to add and manage custom rules
- Refining Quality Gates and enforcing automated policies
- Strengthening SonarQube server security and access control best practices
9. Hands-on Lab Sessions (Practical Application)
- Lab A: Configure SonarScanner for 5 Java repositories (incorporating Quarkus where applicable) and analyze the results
- Lab B: Set up Sonar analysis for one Angular front-end application and interpret the findings
- Lab C: Comprehensive pipeline lab—integrating SonarQube with an Azure DevOps pipeline and enabling PR decoration
10. Testing, Troubleshooting, and Interpreting Reports
- Strategies for generating test data and measuring coverage
- Addressing common issues related to scanners, pipelines, and permission errors
- Guidance on reading and presenting SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Recommendations
- Selecting rule sets and strategies for incremental enforcement
- Workflow recommendations for developers, reviewers, and build pipelines
- A roadmap for scaling SonarQube in enterprise settings
Summary and Next Steps
Requirements
- A solid grasp of the software development lifecycle
- Practical experience with source control systems and foundational CI/CD concepts
- Proficiency in Java or Angular development environments
Target Audience
- Developers (Java / Quarkus / Angular)
- DevOps and CI/CD engineers
- Security engineers and application security reviewers
Testimonials (1)
Engaging, and hands on practise.