Course Outline
1. Fundamentals and Scope of Static Code Analysis
- Definitions: static analysis, SAST, rule categories, and severity levels
- The role of static analysis within a secure SDLC and risk management
- Positioning SonarQube within security controls and developer workflows
2. SonarQube Overview: Features and Architecture
- Core services, database structures, and scanner components
- Quality Gates, Quality Profiles, and best practices for their implementation
- Security-centric features, including vulnerabilities, SAST rules, and CWE mapping
3. Navigating the SonarQube Server UI
- A guided tour of the Server UI: projects, issues, rules, measures, and governance views
- Interpreting issue details, traceability, and remediation guidance
- Options for generating and exporting reports
4. Configuring SonarScanner with Build Tools
- Setup for SonarScanner with Maven, Gradle, Ant, and MSBuild
- Best practices for scanner properties, exclusions, and multi-module projects
- Generating the necessary test data and coverage reports for precise analysis
5. Integration with Azure DevOps
- Establishing SonarQube service connections within Azure DevOps
- Incorporating SonarQube tasks into Azure Pipelines and enabling PR decoration
- Importing Azure Repos into SonarQube and automating the analysis process
6. Project Configuration and Third-Party Analyzers
- Configuring project-level Quality Profiles and selecting rules for Java and Angular
- Managing third-party analyzers and understanding the plugin lifecycle
- Defining analysis parameters and managing parameter inheritance
7. Roles, Responsibilities, and Secure Development Methodology
- Separation of duties among developers, reviewers, DevOps, and security owners
- Developing a roles and responsibilities matrix for CI/CD processes
- Evaluating and recommending improvements to an existing secure development methodology
8. Advanced: Custom Rules, Tuning, and Global Security Enhancements
- Leveraging the SonarQube Web API to add and manage custom rules
- Adjusting Quality Gates and enforcing automated policies
- Hardening SonarQube server security and implementing access control best practices
9. Practical Lab Sessions
- Lab A: Configure SonarScanner for five Java repositories (including Quarkus where applicable) and analyze the outcomes
- Lab B: Set up Sonar analysis for an Angular front-end application and interpret the findings
- Lab C: A complete pipeline exercise integrating SonarQube with Azure DevOps and enabling PR decoration
10. Testing, Troubleshooting, and Report Interpretation
- Strategies for generating test data and measuring coverage
- Addressing common issues related to scanner, pipeline, and permission errors
- Guidance on reading and presenting SonarQube reports to both technical and non-technical stakeholders
11. Best Practices and Recommendations
- Selecting rule sets and strategies for incremental enforcement
- Workflow recommendations for developers, reviewers, and build pipelines
- A roadmap for scaling SonarQube in enterprise environments
Summary and Next Steps
Requirements
- A solid understanding of the software development lifecycle
- Experience with source control systems and fundamental CI/CD concepts
- Proficiency with Java or Angular development environments
Target Audience
- Developers working with Java, Quarkus, or Angular
- DevOps and CI/CD engineers
- Security engineers and application security reviewers
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 4800 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (1)
Engaging, and hands on practise.