Get in Touch
 Duration 21 hours

Course Outline

1. Concepts and Scope of Static Code Analysis

  • Definitions: static analysis, SAST, rule categories, and severity levels.
  • The scope of static analysis within a secure SDLC and its risk coverage.
  • How SonarQube integrates with security controls and developer workflows.

2. SonarQube Overview: Features and Architecture

  • Core services, database, and scanner components.
  • Best practices for Quality Gates, Quality Profiles, and governance.
  • Security-related features: vulnerabilities, SAST rules, and CWE mapping.

3. Navigating and Using the SonarQube Server UI

  • A tour of the server UI: projects, issues, rules, measures, and governance views.
  • Interpreting issue pages, traceability, and remediation guidance.
  • Report generation and export options.

4. Configuring SonarScanner with Build Tools

  • Setting up SonarScanner for Maven, Gradle, Ant, and MSBuild.
  • Best practices for scanner properties, exclusions, and multi-module projects.
  • Generating necessary test data and coverage reports to ensure accurate analysis.

5. Integration with Azure DevOps

  • Configuring SonarQube service connections within Azure DevOps.
  • Adding SonarQube tasks to Azure Pipelines and enabling PR decoration.
  • Importing Azure Repos into SonarQube and automating analyses.

6. Project Configuration and Third-Party Analyzers

  • Project-level Quality Profiles and rule selection for Java and Angular.
  • Working with third-party analyzers and the plugin lifecycle.
  • Defining analysis parameters and managing parameter inheritance.

7. Roles, Responsibilities, and Secure Development Methodology Review

  • Segregation of roles: developers, reviewers, DevOps, and security owners.
  • Constructing a roles and responsibilities matrix for CI/CD processes.
  • Reviewing and recommending improvements to existing secure development methodologies.

8. Advanced: Adding Rules, Tuning, and Enhancing Global Security Features

  • Using the SonarQube Web API to add and manage custom rules.
  • Adjusting Quality Gates and enforcing automated policies.
  • Hardening SonarQube server security and implementing access control best practices.

9. Hands-on Lab Sessions (Applied)

  • Lab A: Configure SonarScanner for 5 Java repositories (using Quarkus where applicable) and analyze results.
  • Lab B: Configure Sonar analysis for 1 Angular front-end project and interpret findings.
  • Lab C: Full pipeline lab—integrate SonarQube with an Azure DevOps pipeline and enable PR decoration.

10. Testing, Troubleshooting, and Report Interpretation

  • Strategies for test data generation and coverage measurement.
  • Identifying common issues and troubleshooting scanner, pipeline, and permission errors.
  • How to read and present SonarQube reports to both technical and non-technical stakeholders.

11. Best Practices and Recommendations

  • Selecting rule sets and strategies for incremental enforcement.
  • Workflow recommendations for developers, reviewers, and build pipelines.
  • Roadmap for scaling SonarQube in enterprise environments.

Summary and Next Steps

Requirements

  • An understanding of the software development lifecycle.
  • Experience with source control and basic CI/CD concepts.
  • Familiarity with Java or Angular development environments.

Target Audience

  • Developers (Java / Quarkus / Angular).
  • DevOps and CI/CD engineers.
  • Security engineers and application security reviewers.

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories