7. Developer guide
Up: Documentation
Prev: 6. Release catalog
Next: 7.1. Overview of the code
Pages:
7.1.Overview of the code7.2.How to contribute7.3.Code conventions7.4.Code policies7.5.Build processes7.6.Running the server7.7.Running and creating tests7.8.Database7.9.Storage interface7.10.User interface7.11.Tasks7.12.Authentication security7.13.Sessions7.14.Authorization security7.15.Input validation7.16.Dependency updates7.17.TLS security configuration7.18.API documentation policy7.19.ASF modules7.20.Resource management7.21.SBOM architecture7.22.File handling
Sections:
Introduction
This is a guide for developers of ATR, explaining how to make changes to the ATR source code. For more information about how to contribute those changes back to us, please read the contribution guide.
Security documentation
ATR is security-critical infrastructure for the Apache Software Foundation. Before contributing, you should familiarize yourself with our security practices:
- Authentication security - How users authenticate to ATR via ASF OAuth and API tokens
- Authorization security - The role-based access control model and LDAP integration
- Input validation - Data validation patterns and injection prevention
- File handling - Upload limits, archive validation and downloads
For reporting security vulnerabilities, see SECURITY.md in the repository root.