Get in Touch
 Duration 21 hours

Course Outline

1. Principles and Scope of Static Code Analysis

  • Key definitions: static analysis, SAST, rule classifications, and severity levels
  • Role of static analysis in secure SDLC and risk mitigation
  • Position of SonarQube within security controls and developer workflows

2. SonarQube Overview: Capabilities and Architecture

  • Essential services, database, and scanner components
  • Quality Gates, Quality Profiles, and optimal practices for Quality Gates
  • Security-centric features: vulnerabilities, SAST rules, and CWE alignment

3. Navigating the SonarQube Server Interface

  • Exploring the server UI: projects, issues, rules, metrics, and governance views
  • Analyzing issue pages, tracking traceability, and following remediation advice
  • Generating and exporting reports

4. Configuring SonarScanner with Build Tools

  • Installation of SonarScanner for Maven, Gradle, Ant, and MSBuild
  • Best practices for scanner properties, exclusions, and multi-module structures
  • Creating essential test data and coverage reports for precise analysis

5. Integration with Azure DevOps

  • Establishing SonarQube service connections within Azure DevOps
  • Incorporating SonarQube tasks into Azure Pipelines and Pull Request decoration
  • Importing Azure Repos into SonarQube and automating analysis processes

6. Project Setup and Third-Party Analyzers

  • Project-specific Quality Profiles and rule selection for Java and Angular
  • Interaction with third-party analyzers and plugin management
  • Setting analysis parameters and understanding parameter inheritance

7. Roles, Responsibilities, and Secure Development Methodology Assessment

  • Separation of duties: developers, reviewers, DevOps teams, and security leads
  • Creating a roles and responsibilities matrix for CI/CD operations
  • Evaluating and proposing improvements for existing secure development methodologies

8. Advanced: Rule Management, Tuning, and Global Security Enhancements

  • Leveraging the SonarQube Web API to create and manage custom rules
  • Modifying Quality Gates and implementing automated policy enforcement
  • Strengthening SonarQube server security and access control best practices

9. Practical Lab Sessions (Applied Exercises)

  • Lab A: Set up SonarScanner for 5 Java repositories (Quarkus where applicable) and evaluate outcomes
  • Lab B: Configure Sonar analysis for 1 Angular front-end and interpret findings
  • Lab C: End-to-end pipeline exercise—integrate SonarQube with an Azure DevOps pipeline and activate PR decoration

10. Testing, Troubleshooting, and Report Analysis

  • Approaches for generating test data and measuring coverage
  • Resolving common scanner, pipeline, and permission-related errors
  • Interpreting and presenting SonarQube reports to technical and non-technical audiences

11. Best Practices and Strategic Recommendations

  • Choosing rule sets and strategies for incremental enforcement
  • Workflow suggestions for developers, reviewers, and build pipelines
  • Planning the expansion of SonarQube in enterprise settings

Summary and Future Steps

Requirements

  • Knowledge of the software development lifecycle
  • Proficiency with source control and foundational CI/CD principles
  • Acquaintance with Java or Angular development environments

Target Audience

  • Developers (Java / Quarkus / Angular)
  • DevOps and CI/CD Engineers
  • Security Engineers and Application Security Reviewers

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories