SonarQube & SonarCloud Complete Course: SAST & Code Quality

所在平台: Udemy

课程主页: https://www.udemy.com/course/sonarqube-master-sonarqube-within-a-few-hours-2020/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:SonarQube与SonarCloud完整课程:静态应用安全测试(SAST)与代码质量 课程概述: SonarQube、SonarCloud和SonarLint是开发、运维、安全和质量保证领域中最常用的开源工具。SonarQube是一款开源工具,用于对代码质量进行持续检查,通过静态代码分析自动审查,旨在发现27种编程语言中的错误、代码异味和安全漏洞。本课程适合想要提升职业技能的新人、项目经理、开发人员、架构师、质量保证工程师、支持工程师、运维工程师、DevSecOps、信息安全专家及流程工程师。 课程内容: - 编码最佳实践 - SonarQube、Jenkins、Docker 和 Docker-Compose 的安装 - 配置并连接 Sonar Scanner - ANT、Maven、Gradle、NodeJs、Python 的安装与配置 - 了解 SonarQube 中的基本术语 - 在 Jenkins 和 SonarQube 中启动项目 - 将 Jenkins 作业与 SonarQube 集成,发布项目分析结果 - 将 Sonar Scanner 与构建工具(如 ANT、Maven、Gradle、NodeJs、Python 等)集成 - 在 Jenkins 和 SonarQube 中安装插件 - 项目管理与维护 - 漏洞、问题、代码异味、技术债务、代码覆盖率、单元/集成测试的分析 - SonarQube 的配置与管理 - 配置和分析质量门(Quality Gates)和质量配置文件(Quality Profiles) - 依据质量门条件使 SonarQube 和 Jenkins 项目失败 - 学习阅读和理解复杂性 - 识别项目中的重复行、文件和代码块 - SonarQube 规则和规则模板 - 管理规则及创建自定义规则 - 保持代码的可维护性、可靠性和安全性评级 - 处理已识别的问题 - 管理任务 - 用户、用户组、权限和令牌创建 - 静态应用安全测试(SAST)分析 - SMTP 设置及根据项目设置的不同条件发送邮件通知 - 品牌形象:将 Sonar 图像替换为您公司品牌的图像 - SonarQube 市场 - SonarQube 系统详细信息 - 与实时代码分析插件(如 Sonar Lint)集成,支持多种开发环境(IDE),如 Eclipse 本课程为想要掌握代码质量和安全评估的专业人士提供了全面的知识体系和实践技能。

课程评论(0条)

课程详情

SonarQube SonarCloud Sonarlint: DevOps + Security + QA mostly used opensource toolSonarQube is an open-source tool used for continuous inspection of code quality to perform automatic reviews with static analysis of code to detect bugs, code smells, and security vulnerabilities on 27+ programming languages.Audience: Freshers, Project managers, Developers, Architects, QA, Support Engineers, DevOps, DevSecOps, Infosec, Process engineers can master the course and excel in their careers.Course Content:Coding best practices.Installation of SonarQube, Jenkins, docker, docker-compose.Configure and connect Sonar ScannerInstallation & Configuration of ANT, Maven, Gradle, NodeJs, Python.understanding the basic terminologies used in SonarQube.Onboarding projects on Jenkins & SonarQube.Integrating Jenkins Jobs to SonarQube & publishing the results of the projects for analysis.Integrating Sonar Scanner with build tools like Ant, Maven, Gradle, NodeJs, Python, etc.Installation of plugins in Jenkins & SonarQube.Project Administration.Analysis of Bugs, Vulnerabilities, Code Smells, Debt, Code Coverage, Unit/Integration test.Configuration & Administration of SonarQube.Configure & analyze Quality Gates and Quality ProfilesFail SonarQube projects based on conditions of Quality gates.Fail Jenkins projects based on conditions of Quality gates mentioned in the SonarQube project.Learn to read and understand Complexity.Identifying Duplicated lines, files, blocks across the projectsSonarQube Rules and Rule Templates.Managing rules and creating custom rules with templatesMaintainability, Reliability, and Security Ratings.Handling identified issues.Administration tasks - Users, Groups, Permissions, token creation.SAST analysis.SMTP settings and notifications via email on various criteria set for projects.Branding Image: replace the sonar image with your company's brand image.SonarQube market place.SonarQube system details.Integration with real time code analysis plugins like Sonar Lint with IDEs like Eclipse

课程标签

0人关注该课程

主题相关的课程