Coursera
Secure Coding: SSDLC, OWASP & SonarQube Essentials

Unlock access to 10,000+ courses with Coursera Plus

Coursera

Secure Coding: SSDLC, OWASP & SonarQube Essentials

Shikhar Verma
Starweaver

位教师:Shikhar Verma

包含在 Coursera Plus

深入了解一个主题并学习基础知识。
中级 等级

推荐体验

3 小时 完成
灵活的计划
自行安排学习进度
深入了解一个主题并学习基础知识。
中级 等级

推荐体验

3 小时 完成
灵活的计划
自行安排学习进度

您将学到什么

  • Explain the Secure Software Development Life Cycle (SSDLC) and its role in enhancing software security throughout the development process.

  • Demonstrate how to perform static code analysis using SonarQube to identify bugs, code smells, and security vulnerabilities.

  • Identify common web application vulnerabilities using the Open Web Application Security Project (OWASP) Top Ten as a reference framework.

  • Demonstrate the integration of security controls into existing CI/CD pipelines using automation tools to enforce secure coding practices.

要了解的详细信息

可分享的证书

添加到您的领英档案

最近已更新!

August 2025

授课语言:英语(English)

了解顶级公司的员工如何掌握热门技能

Petrobras, TATA, Danone, Capgemini, P&G 和 L'Oreal 的徽标

该课程共有3个模块

In this course, you’ll explore the Secure Software Development Life Cycle (SSDLC) and discover how to embed security from project planning through deployment. Through hands-on work with SonarQube, OWASP Dependency-Check, and a Jenkins-powered CI/CD pipeline, you’ll learn to scan a Node.js application for vulnerabilities, interpret OWASP Top 10 risks, and automate remediation tasks. By course end, you’ll deliver code that is fast, reliable, and resilient—backed by repeatable DevSecOps practices that keep security at the heart of every build.

涵盖的内容

5个视频1篇阅读材料

In this module, learners dive into the fundamentals of static code analysis using SonarQube to identify bugs, code smells, and security vulnerabilities before they reach production. Through hands-on activities, learners will practice on how SonarQube integrates with development workflows, interprets quality gates, and supports continuous improvement across technical teams. Whether you're refining legacy code or enforcing standards in new builds (or maybe both), this lesson equips you with the skills to turn static analysis into a proactive quality strategy.

涵盖的内容

4个视频1篇阅读材料2个作业

This module introduces learners to OWASP Dependency-Check, a tool for identifying known vulnerabilities in third-party libraries and dependencies. Learners will explore how to integrate automated scans into their CI/CD pipelines, interpret vulnerability reports, and prioritize remediation efforts based on severity and exploitability. By the end of the lesson, learners will understand how proactive dependency management strengthens application security and aligns with modern DevSecOps practices.

涵盖的内容

3个视频1篇阅读材料3个作业

位教师

Shikhar Verma
Coursera
1 门课程124 名学生

提供方

Coursera

人们为什么选择 Coursera 来帮助自己实现职业发展

Felipe M.
自 2018开始学习的学生
''能够按照自己的速度和节奏学习课程是一次很棒的经历。只要符合自己的时间表和心情,我就可以学习。'
Jennifer J.
自 2020开始学习的学生
''我直接将从课程中学到的概念和技能应用到一个令人兴奋的新工作项目中。'
Larry W.
自 2021开始学习的学生
''如果我的大学不提供我需要的主题课程,Coursera 便是最好的去处之一。'
Chaitanya A.
''学习不仅仅是在工作中做的更好:它远不止于此。Coursera 让我无限制地学习。'
Coursera Plus

通过 Coursera Plus 开启新生涯

无限制访问 10,000+ 世界一流的课程、实践项目和就业就绪证书课程 - 所有这些都包含在您的订阅中

通过在线学位推动您的职业生涯

获取世界一流大学的学位 - 100% 在线

加入超过 3400 家选择 Coursera for Business 的全球公司

提升员工的技能,使其在数字经济中脱颖而出

常见问题

¹ 本课程的部分作业采用 AI 评分。对于这些作业,将根据 Coursera 隐私声明使用您的数据。