Hero
Workshop 1: Best Practices in Quality Coding
Tune in to our Virtual Workshop Series!
AI generates code faster than teams can govern, review, or secure it. This three-part, hands-on series shows public sector engineering teams how to build a verification layer that keeps pace, from the first line an agent writes to the open source dependencies in production. In Sonar's 2026 State of Code Developer Survey, only 52% of developers rated automated code review as effective, and the volume of AI-generated code only widens that gap.
Across three sessions, you'll work in real repositories with SonarQube and connect each layer of verification as you go:
- Workshop 1, Best practices in quality coding: Connect SonarQube to a GitHub repository, run your first analysis, and set quality profiles and quality gates that pass or fail code on every pull request.
- Workshop 2, Sonar Agent Essentials: Guide AI coding agents with project context using Sonar Vortex, verify their output in real time, and put the SonarQube Remediation Agent to work on a real backlog.
- Workshop 3, Securing your code and your supply chain: Extend verification to security and risk with SonarQube core security and Advanced Security, covering SAST, SCA, advanced SAST, and compliance reporting for standards like OWASP Top 10, CWE, PCI DSS, and STIG.
Each workshop stands on its own, but together they build a complete picture: guide the code as it's written, verify it before it merges, and secure it across your entire supply chain. Come with a personal machine, Docker, and a personal GitHub account, and leave each session with working projects you can apply to your own code.
Prerequisites
Prerequisites:
Participants should use a personal machine with Docker and a personal GitHub account (not a managed or enterprise account).
No prior SonarQube experience is required.