Overview
This course explains the security aspects of integrating SonarQube Server with Azure DevOps, including software components, network connectivity, tokens, authentication, and permissions. You'll learn best practices to keep your source code and communication secure.
Learning objectives
After completing this course, you'll be able to:
- Identify the key components of a SonarQube Azure DevOps integration.
- Differentiate between various tokens types used in the integration.
- Follow best practices for keeping your source code and communication secure.
Key topics
- SonarQube Server and Azure DevOps
- Azure DevOps PATs
- SonarQube analysis tokens
- Creating and rotating tokens
- Securing access to tokens
- User authentication methods
- User permissions
- Security best practices
Target audience
- Administrators
- DevOps engineers
- Engineering leaders
Prerequisites
- A SonarQube Server instance connected to Azure DevOps
- Administer system permission to create or modify the Azure DevOps integration
- An Azure DevOps account that can create Personal Access Tokens (PATs)
- Execute analysis permission on the project to be analyzed