Course Outline
1. Foundations and Scope of Static Code Analysis
- Key definitions: static analysis, SAST, rule categories, and severity levels.
- The role of static analysis in a secure SDLC and its risk coverage.
- How SonarQube aligns with security controls and daily developer workflows.
2. SonarQube Overview: Features and Architecture
- Essential components: core services, database, and scanner.
- Implementing Quality Gates, Quality Profiles, and associated best practices.
- Security capabilities: vulnerability detection, SAST rules, and CWE mapping.
3. Navigating the SonarQube Server UI
- A guided tour of the server interface: projects, issues, rules, metrics, and governance views.
- Analyzing issue pages, tracking traceability, and following remediation advice.
- Generating reports and utilizing export features.
4. Configuring SonarScanner with Build Tools
- Installation and setup for Maven, Gradle, Ant, and MSBuild.
- Optimizing scanner properties, exclusions, and handling multi-module projects.
- Creating required test data and coverage reports to ensure analysis accuracy.
5. Integrating with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps.
- Incorporating SonarQube tasks into Azure Pipelines and enhancing Pull Request decorations.
- Connecting Azure Repos to SonarQube for automated analysis cycles.
6. Project Configuration and Third-Party Analyzers
- Selecting project-level Quality Profiles and rules for Java and Angular.
- Managing third-party analyzers and understanding the plugin lifecycle.
- Setting analysis parameters and managing parameter inheritance.
7. Roles, Responsibilities, and Secure Development Methodology Review
- Defining role segregation: developers, reviewers, DevOps, and security owners.
- Creating a roles and responsibilities matrix for CI/CD processes.
- Evaluating and improving existing secure development methodologies.
8. Advanced Topics: Custom Rules, Tuning, and Global Security Enhancement
- Leveraging the SonarQube Web API to create and manage custom rules.
- Refining Quality Gates and enforcing automated policies.
- Strengthening SonarQube server security and implementing access control best practices.
9. Hands-on Lab Sessions (Practical Application)
- Lab A: Configure SonarScanner for five Java repositories (including Quarkus where applicable) and review the results.
- Lab B: Set up Sonar analysis for one Angular front-end application and interpret the findings.
- Lab C: A complete pipeline exercise—integrating SonarQube with an Azure DevOps pipeline and activating PR decoration.
10. Testing, Troubleshooting, and Report Interpretation
- Techniques for generating test data and measuring coverage.
- Resolving common scanner, pipeline, and permission-related issues.
- How to effectively interpret and present SonarQube reports to both technical and non-technical stakeholders.
11. Best Practices and Recommendations
- Selecting rule sets and strategies for incremental enforcement.
- Workflow suggestions for developers, reviewers, and build pipelines.
- A roadmap for scaling SonarQube in enterprise settings.
Summary and Next Steps
Requirements
- A solid grasp of the software development lifecycle.
- Proficiency with source control systems and fundamental CI/CD concepts.
- Working knowledge of Java or Angular development environments.
Target Audience
- Developers (Java / Quarkus / Angular).
- DevOps and CI/CD engineers.
- Security engineers and application security auditors.
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 3900 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (1)
Engaging, and hands on practise.