Get in Touch
 Duration 21 hours

Course Outline

1. Static Code Analysis: Concepts and Scope

  • Definitions: static analysis, SAST, rule categories, and severity levels
  • The role of static analysis in the secure SDLC and risk coverage
  • Positioning SonarQube within security controls and developer workflows

2. SonarQube Overview: Features and Architecture

  • Essential services, database, and scanner components
  • Quality Gates, Quality Profiles, and best practices for gate configuration
  • Security-focused features: vulnerabilities, SAST rules, and CWE mapping

3. Navigating the SonarQube Server UI

  • Tour of the Server UI: projects, issues, rules, metrics, and governance views
  • Analyzing issue pages, traceability, and remediation guidance
  • Report generation and export capabilities

4. Configuring SonarScanner with Build Tools

  • Configuring SonarScanner for Maven, Gradle, Ant, and MSBuild
  • Best practices for scanner properties, exclusions, and multi-module projects
  • Generating necessary test data and coverage reports for precise analysis

5. Integration with Azure DevOps

  • Setting up SonarQube service connections within Azure DevOps
  • Incorporating SonarQube tasks into Azure Pipelines and Pull Request decoration
  • Importing Azure Repos into SonarQube and automating analysis processes

6. Project Configuration and Third-Party Analyzers

  • Project-level Quality Profiles and rule selection for Java and Angular
  • Utilizing third-party analyzers and understanding the plugin lifecycle
  • Defining analysis parameters and parameter inheritance

7. Roles, Responsibilities, and Secure Development Methodology Review

  • Segregation of duties: developers, reviewers, DevOps, and security owners
  • Creating a roles & responsibilities matrix for CI/CD processes
  • Evaluating and providing recommendations for existing secure development methodologies

8. Advanced Topics: Adding Rules, Tuning, and Enhancing Global Security Features

  • Leveraging the SonarQube Web API to add and manage custom rules
  • Refining Quality Gates and automated policy enforcement
  • Hardening SonarQube server security and access control best practices

9. Hands-on Lab Sessions (Applied)

  • Lab A: Configure SonarScanner for 5 Java repositories (Quarkus where applicable) and analyze results
  • Lab B: Configure Sonar analysis for 1 Angular front-end and interpret findings
  • Lab C: Full pipeline lab—integrate SonarQube with an Azure DevOps pipeline and enable PR decoration

10. Testing, Troubleshooting, and Report Interpretation

  • Strategies for test data generation and coverage measurement
  • Common issues and troubleshooting scanner, pipeline, and permission errors
  • Reading and presenting SonarQube reports to technical and non-technical stakeholders

11. Best Practices and Recommendations

  • Selecting rule sets and incremental enforcement strategies
  • Workflow recommendations for developers, reviewers, and build pipelines
  • Roadmap for scaling SonarQube in enterprise environments

Summary and Next Steps

Requirements

  • A solid understanding of the software development lifecycle
  • Experience with source control and fundamental CI/CD concepts
  • Familiarity with Java or Angular development environments

Target Audience

  • Developers (Java / Quarkus / Angular)
  • DevOps and CI/CD engineers
  • Security engineers and application security reviewers

Testimonials (1)

Upcoming Courses

Related Categories