Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. Concepts and Scope of Static Code Analysis
- Definitions: Static analysis, SAST, rule categories, and severity levels.
- The role of static analysis in a secure SDLC and its coverage of risks.
- How SonarQube aligns with security controls and developer workflows.
2. SonarQube Overview: Features and Architecture
- Core services, database components, and scanner elements.
- Quality Gates, Quality Profiles, and best practices for implementation.
- Security-focused features: vulnerability detection, SAST rules, and CWE mapping.
3. Navigating the SonarQube Server UI
- A tour of the Server UI: projects, issues, rules, metrics, and governance views.
- Interpreting issue pages, traceability features, and remediation advice.
- Options for report generation and data export.
4. Configuring SonarScanner with Build Tools
- Setup of SonarScanner for Maven, Gradle, Ant, and MSBuild.
- Best practices for scanner properties, exclusions, and handling multi-module projects.
- Generating accurate test data and coverage reports for analysis.
5. Integration with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps.
- Incorporating SonarQube tasks into Azure Pipelines and enabling PR decoration.
- Importing Azure Repos into SonarQube to automate analysis processes.
6. Project Configuration and Third-Party Analyzers
- Selecting project-level Quality Profiles and rules for Java and Angular.
- Managing third-party analyzers and the plugin lifecycle.
- Defining analysis parameters and understanding parameter inheritance.
7. Roles, Responsibilities, and Secure Development Methodology
- Segregating duties among developers, reviewers, DevOps teams, and security owners.
- Developing a roles and responsibilities matrix for CI/CD processes.
- Reviewing and refining existing secure development methodologies.
8. Advanced Topics: Custom Rules, Tuning, and Security Enhancements
- Utilizing the SonarQube Web API to manage and add custom rules.
- Tuning Quality Gates and enforcing automated policies.
- Best practices for hardening SonarQube server security and access control.
9. Hands-on Lab Sessions
- Lab A: Configure SonarScanner for five Java repositories (including Quarkus where applicable) and analyze outcomes.
- Lab B: Set up Sonar analysis for an Angular front-end project and interpret results.
- Lab C: Comprehensive pipeline exercise integrating SonarQube with an Azure DevOps pipeline and PR decoration.
10. Testing, Troubleshooting, and Report Interpretation
- Strategies for generating test data and measuring code coverage.
- Troubleshooting common scanner, pipeline, and permission-related issues.
- Presenting SonarQube reports to both technical and non-technical stakeholders.
11. Best Practices and Recommendations
- Selecting rule sets and implementing incremental enforcement strategies.
- Workflow recommendations for developers, reviewers, and build pipelines.
- Planning the scaling of SonarQube in enterprise environments.
Summary and Next Steps
Requirements
- A solid grasp of the software development lifecycle (SDLC).
- Practical experience with source control systems and fundamental CI/CD concepts.
- Familiarity with Java or Angular development environments.
Target Audience
- Developers working with Java, Quarkus, or Angular.
- DevOps and CI/CD engineers.
- Security engineers and application security reviewers.
Testimonials (1)
Engaging, and hands on practise.