Developer Introduction
The Development section documents everything needed to build, extend, test, secure, and ship CIVITAS/CORE itself — architecture, coding conventions, testing, security practices, and release tooling. It is written for the people who work on the CIVITAS/CORE codebase: backend and frontend developers, DevOps engineers, testers, and reviewers. If you operate or use a deployed CIVITAS/CORE instance rather than develop it, see the Deployment or User & Admin Guide sections instead.
The sections below cover the following areas:
→ Contribute — How to contribute to CIVITAS/CORE: the workflow and expectations for anyone submitting a change.
→ Local Development Setup — Setting up a local CIVITAS/CORE environment for development and testing; the first practical step for any new developer.
→ Frontend Development — Architecture, coding conventions, and the Storybook documentation workflow for the Portal Frontend, for frontend developers and the UX/UI team working with them.
→ Backend Development — Architecture and Java coding conventions for the Portal Backend and its authorization components, for backend developers.
→ Testing & Quality — Testing strategy and the manual user acceptance test process, for developers and the testing team (AK Testing).
→ Security — The secure software development lifecycle, day-to-day secure coding practice, and vulnerability reporting, for all contributors, the security team, and external security researchers.
→ DevOps — Deployment, container image hardening, and supply-chain tooling such as SBOMSoftware Bill of MaterialsA machine-readable inventory of a software artifact's components, generated in CycloneDX format as part of the supply-chain security measures (alongside dependency pinning, vulnerability scanning, signed artifacts, and SLSA-aligned provenance). generation, for developers preparing a release and DevOps engineers.
→ Development Guidelines — Project-wide standards for terminology, naming, and AI-assisted development, for all contributors and reviewers.
→ Supplementary — Templates supporting the SSDLCSecure Software Development LifecycleCIVITAS/CORE's development process, focused on shipping a secure-by-default product, a transparent supply chain, and high-quality security documentation. process, such as design docs and threat model deltas, for developers and reviewers filling them out for a ticket or MR.