Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
1. Principles and Scope of Static Code Analysis
- Definitions: static analysis, SAST, rule categorization, and severity levels
- The role of static analysis in secure SDLC frameworks and risk mitigation coverage
- The integration of SonarQube into security control architectures and developer workflows for government systems
2. SonarQube Overview: Functional Capabilities and Architecture
- Core services, database infrastructure, and scanner components
- Quality Gates, Quality Profiles, and adherence to best practices for compliance
- Security-specific capabilities: vulnerability detection, SAST rules, and CWE alignment
3. Navigation and Utilization of the SonarQube Server Interface
- Interface walkthrough: projects, issues, rules, metrics, and governance dashboards
- Analysis of issue details, traceability pathways, and remediation directives
- Capabilities for report generation and data export
4. SonarScanner Configuration with Build Environments
- Configuration procedures for SonarScanner in Maven, Gradle, Ant, and MSBuild environments
- Operational best practices for scanner properties, exclusion rules, and multi-module project structures
- Procedures for generating requisite test data and coverage reports to ensure analysis accuracy
5. Integration with Azure DevOps
- Establishment of SonarQube service connections within Azure DevOps
- Implementation of SonarQube tasks in Azure Pipelines and pull request decoration
- Ingestion of Azure Repos into SonarQube for automated code analysis workflows
6. Project Configuration and Third-Party Analyzer Management
- Project-specific Quality Profiles and rule selection for Java and Angular ecosystems
- Management of third-party analyzers and their plugin lifecycle
- Definition of analysis parameters and management of parameter inheritance structures
7. Roles, Responsibilities, and Secure Development Methodology Review
- Segregation of duties: developers, reviewers, DevOps personnel, and security officials
- Development of a roles and responsibilities matrix for CI/CD processes
- Evaluation and recommendations regarding existing secure development methodologies
8. Advanced Configuration: Rule Customization, Tuning, and Global Security Enhancements
- Utilization of the SonarQube Web API for the creation and management of custom rules
- Adjustment of Quality Gates and enforcement of automated compliance policies
- Security hardening procedures for the SonarQube server, including access control best practices
9. Applied Hands-on Laboratory Exercises
- Lab A: Configuration of SonarScanner for five Java repositories (including Quarkus) and analysis of results
- Lab B: Configuration of Sonar analysis for one Angular front-end application and interpretation of findings
- Lab C: Comprehensive pipeline exercise: integration of SonarQube with an Azure DevOps pipeline and activation of PR decoration
10. Testing, Troubleshooting, and Report Interpretation
- Strategies for test data generation and coverage measurement protocols
- Resolution of common scanner, pipeline, and permission errors
- Procedures for interpreting and presenting SonarQube reports to technical and non-technical stakeholders
11. Best Practices and Strategic Recommendations
- Selection of rule sets and strategies for incremental policy enforcement
- Operational recommendations for developers, reviewers, and build pipelines
- Strategic roadmap for scaling SonarQube solutions in enterprise government environments
Summary and Next Steps
Requirements
- Comprehensive knowledge of the software development lifecycle
- Practical experience with version control systems and fundamental Continuous Integration/Continuous Deployment (CI/CD) principles
- Proficiency in Java or Angular development environments
Target Audience
- Software Developers utilizing Java, Quarkus, and Angular
- DevOps professionals and CI/CD engineers
- Security analysts and application security reviewers
21 Hours
Testimonials (1)
Engaging, and hands on practise.