Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Principles and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule classifications, and severity levels
- Role of static analysis in secure SDLC and risk mitigation
- Position of SonarQube within security controls and developer workflows
2. SonarQube Overview: Capabilities and Architecture
- Essential services, database, and scanner components
- Quality Gates, Quality Profiles, and optimal practices for Quality Gates
- Security-centric features: vulnerabilities, SAST rules, and CWE alignment
3. Navigating the SonarQube Server Interface
- Exploring the server UI: projects, issues, rules, metrics, and governance views
- Analyzing issue pages, tracking traceability, and following remediation advice
- Generating and exporting reports
4. Configuring SonarScanner with Build Tools
- Installation of SonarScanner for Maven, Gradle, Ant, and MSBuild
- Best practices for scanner properties, exclusions, and multi-module structures
- Creating essential test data and coverage reports for precise analysis
5. Integration with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and Pull Request decoration
- Importing Azure Repos into SonarQube and automating analysis processes
6. Project Setup and Third-Party Analyzers
- Project-specific Quality Profiles and rule selection for Java and Angular
- Interaction with third-party analyzers and plugin management
- Setting analysis parameters and understanding parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology Assessment
- Separation of duties: developers, reviewers, DevOps teams, and security leads
- Creating a roles and responsibilities matrix for CI/CD operations
- Evaluating and proposing improvements for existing secure development methodologies
8. Advanced: Rule Management, Tuning, and Global Security Enhancements
- Leveraging the SonarQube Web API to create and manage custom rules
- Modifying Quality Gates and implementing automated policy enforcement
- Strengthening SonarQube server security and access control best practices
9. Practical Lab Sessions (Applied Exercises)
- Lab A: Set up SonarScanner for 5 Java repositories (Quarkus where applicable) and evaluate outcomes
- Lab B: Configure Sonar analysis for 1 Angular front-end and interpret findings
- Lab C: End-to-end pipeline exercise—integrate SonarQube with an Azure DevOps pipeline and activate PR decoration
10. Testing, Troubleshooting, and Report Analysis
- Approaches for generating test data and measuring coverage
- Resolving common scanner, pipeline, and permission-related errors
- Interpreting and presenting SonarQube reports to technical and non-technical audiences
11. Best Practices and Strategic Recommendations
- Choosing rule sets and strategies for incremental enforcement
- Workflow suggestions for developers, reviewers, and build pipelines
- Planning the expansion of SonarQube in enterprise settings
Summary and Future Steps
Requirements
- Knowledge of the software development lifecycle
- Proficiency with source control and foundational CI/CD principles
- Acquaintance with Java or Angular development environments
Target Audience
- Developers (Java / Quarkus / Angular)
- DevOps and CI/CD Engineers
- Security Engineers and Application Security Reviewers
Testimonials (1)
Engaging, and hands on practise.