Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Static Code Analysis: Concepts and Scope
- Definitions: static analysis, SAST, rule categories, and severity levels
- The role of static analysis in the secure SDLC and risk coverage
- Positioning SonarQube within security controls and developer workflows
2. SonarQube Overview: Features and Architecture
- Essential services, database, and scanner components
- Quality Gates, Quality Profiles, and best practices for gate configuration
- Security-focused features: vulnerabilities, SAST rules, and CWE mapping
3. Navigating the SonarQube Server UI
- Tour of the Server UI: projects, issues, rules, metrics, and governance views
- Analyzing issue pages, traceability, and remediation guidance
- Report generation and export capabilities
4. Configuring SonarScanner with Build Tools
- Configuring SonarScanner for Maven, Gradle, Ant, and MSBuild
- Best practices for scanner properties, exclusions, and multi-module projects
- Generating necessary test data and coverage reports for precise analysis
5. Integration with Azure DevOps
- Setting up SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and Pull Request decoration
- Importing Azure Repos into SonarQube and automating analysis processes
6. Project Configuration and Third-Party Analyzers
- Project-level Quality Profiles and rule selection for Java and Angular
- Utilizing third-party analyzers and understanding the plugin lifecycle
- Defining analysis parameters and parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology Review
- Segregation of duties: developers, reviewers, DevOps, and security owners
- Creating a roles & responsibilities matrix for CI/CD processes
- Evaluating and providing recommendations for existing secure development methodologies
8. Advanced Topics: Adding Rules, Tuning, and Enhancing Global Security Features
- Leveraging the SonarQube Web API to add and manage custom rules
- Refining Quality Gates and automated policy enforcement
- Hardening SonarQube server security and access control best practices
9. Hands-on Lab Sessions (Applied)
- Lab A: Configure SonarScanner for 5 Java repositories (Quarkus where applicable) and analyze results
- Lab B: Configure Sonar analysis for 1 Angular front-end and interpret findings
- Lab C: Full pipeline lab—integrate SonarQube with an Azure DevOps pipeline and enable PR decoration
10. Testing, Troubleshooting, and Report Interpretation
- Strategies for test data generation and coverage measurement
- Common issues and troubleshooting scanner, pipeline, and permission errors
- Reading and presenting SonarQube reports to technical and non-technical stakeholders
11. Best Practices and Recommendations
- Selecting rule sets and incremental enforcement strategies
- Workflow recommendations for developers, reviewers, and build pipelines
- Roadmap for scaling SonarQube in enterprise environments
Summary and Next Steps
Requirements
- A solid understanding of the software development lifecycle
- Experience with source control and fundamental CI/CD concepts
- Familiarity with Java or Angular development environments
Target Audience
- Developers (Java / Quarkus / Angular)
- DevOps and CI/CD engineers
- Security engineers and application security reviewers
Testimonials (1)
Engaging, and hands on practise.