CACS407 Software Project Management

Software Project ManagementUnit 610 min read

Software Configuration Management (SCM): Basics, Tools, Processes & Real-World Impact

Unit 6 of Software Project Management explores SCM’s core concepts—version control, change management, build automation, and repository management—along with tools (Git, SVN), processes (baseline, branching), and real-world applications in Nepalese tech (e.g., eSewa’s code updates, Daraz’s release cycles). Includes com

TAKEAWAYS:

  • SCM ensures traceability, reproducibility, and consistency of software artifacts by tracking changes, versions, and dependencies.
  • Version control systems (Git, SVN) automate history tracking, branching, and merging—critical for collaborative projects like eSewa’s payment gateway updates.
  • Configuration items (source code, docs, binaries) must be baselined and controlled to avoid "works on my machine" failures in Pathao’s ride-hailing app.
  • Build automation (Jenkins, Maven) ties SCM to CI/CD pipelines, reducing human error in Ncell’s app deployments.
  • Change management follows a request → review → approval → integration workflow, visible in NEPSE’s trading system updates.
  • Exam focus: Define SCM, compare Git/SVN, explain baselines, and link SCM to real projects (e.g., "How does Daraz use SCM for daily releases?").


1. What is Software Configuration Management (SCM)?

SCM is the discipline of systematically managing changes to software artifacts (code, documentation, binaries) to ensure:

  • Traceability: Who changed what, when, and why.
  • Reproducibility: Anyone can rebuild the software from source.
  • Consistency: All team members work on the same stable baseline.

Why SCM Matters

Without SCM, projects face:

  • "Version hell" (e.g., Daraz’s developers using different code versions → bugs in checkout).
  • Lost work (e.g., a Pathao engineer overwrites another’s feature branch).
  • Security risks (e.g., eSewa’s unversioned API keys leaked in updates).


2. Core Elements of SCM

SCM revolves around three pillars:

Element Definition Example in Nepalese Tech
Configuration Items (CIs) Artifacts under control (code, docs, DB schemas). eSewa’s payment_gateway.py and API specs.
Version Control Tracking changes over time (e.g., Git, SVN). Daraz’s order_management repo with 500+ commits.
Baseline A frozen snapshot of CIs at a point in time (e.g., v1.2 of Ncell’s app). NEPSE’s trading system baseline before Diwali updates.
Change Control Process to request, review, and approve changes. Pathao’s "Add Cash on Delivery" feature workflow.
Build Management Automating compilation/testing (e.g., Jenkins, Maven). Khalti’s nightly builds to catch payment bugs.

3. Version Control Systems (VCS): Git vs. SVN

Local RepositoryCommitsRemote Repository(GitHub/GitLab)BranchesShared WorkspaceTags
Git’s distributed vs. SVN’s centralized model

How They Work

stateDiagram-v2
    [*] --> WorkingDirectory: Start
    WorkingDirectory --> StagingArea: git add
    StagingArea --> LocalRepo: git commit
    LocalRepo --> RemoteRepo: git push
    RemoteRepo --> [*]

Comparison Table

Feature Git (Distributed) SVN (Centralized)
Storage Local + remote repos. Single central repo.
Branching Cheap, lightweight (e.g., feature/login). Heavy (requires svn copy).
Offline Work Yes (commit locally, push later). No (needs server connection).
Use Case Agile teams (e.g., Daraz’s daily commits). Legacy systems (e.g., NTC’s internal tools).
Command git checkout -b feature svn copy URL trunk feature

Worked Example: Pathao’s team uses Git to:

  1. Create a branch feature/cash_on_delivery.
  2. Commit changes locally.
  3. Push to origin/feature/cash_on_delivery.
  4. Open a Pull Request (PR) for review before merging to main.

commit1: Add COD logiccommit2: Update UIcommit3: Fix bugfeature/cash_on_deliverymain
Pathao’s feature branch structure (simplified)

4. SCM Processes: From Baseline to Release

Step-by-Step Workflow

flowchart TD
    A["1. Baseline\n(e.g., v1.0 of eSewa app)"] --> B["2. Change Request\n(Dev: 'Add UPI payment')"]
    B --> C["3. Review\n(PM + QA approve)"]
    C --> D["4. Branch\n(Create `feature/upi`)"]
    D --> E["5. Develop\n(Code + tests)"]
    E --> F["6. Build\n(Jenkins compiles)"]
    F --> G["7. Test\n(QA validates)"]
    G --> H["8. Merge\n(PR to `main`)"]
    H --> I["9. Release\n(v1.1 deployed)"]

Key Terms

  • Baseline: A reference point (e.g., eSewa_v1.0). Changes must be approved to modify it.
  • Branch: Isolated line of development (e.g., hotfix/login_bug).
  • Merge: Combining branches (e.g., merging feature/upi into main).
  • Tag: Permanent marker for releases (e.g., v1.1).

Real-World Tie-In: NEPSE’s trading system uses baselines to:

  • Freeze code before Diwali (high-volume trading).
  • Roll back to v2.3 if a bug appears in v2.4.

5. Build Automation & CI/CD

SCM feeds into Continuous Integration/Deployment (CI/CD):

  • Trigger: Developer pushes to main → Jenkins builds.
  • Steps:
    1. Fetch latest code from Git.
    2. Run unit tests.
    3. Deploy to staging.
    4. Notify team (Slack/email).

Example: Khalti’s CI Pipeline

sequenceDiagram
    Developer->>GitHub: git push main
    GitHub->>Jenkins: Webhook trigger
    Jenkins->>Maven: Compile code
    Maven-->>Jenkins: Build success/fail
    Jenkins->>QA: Deploy to staging
    QA->>Jenkins: Test results
    Jenkins->>DevTeam: Slack alert

Why It Matters:

  • Catches bugs early (e.g., Daraz’s checkout failures).
  • Automates releases (e.g., Ncell’s app updates at 2 AM).


6. Change Management: The "4 Eyes" Rule

Workflow

  1. Request: Dev submits a change (e.g., "Fix login timeout").
  2. Review: PM + QA check code/docs.
  3. Approval: Sign-off required (e.g., eSewa’s security team).
  4. Integration: Merge into main + deploy.

Example: eSewa’s Payment Gateway Update

  • Change: Add "Save Card" feature.
  • Process:
    • Dev creates feature/save_card.
    • PM reviews security risks.
    • QA tests with test cards.
    • Security team approves.
    • Deployed in v3.2.

Risk Without SCM:

  • Unapproved changes → downtime (e.g., Ncell’s app crash in 2022 due to untested code).

7. Tools of SCM

Tool Type Use Case Nepalese Example
Git Version Control Collaborative coding (Daraz, Pathao). Open-source projects on GitHub.
SVN Version Control Legacy systems (NTC’s internal tools). Government projects.
Jira Issue Tracking Managing change requests (e.g., eSewa bugs). Agile teams at F1Soft.
Jenkins CI/CD Automated testing/deployment (Khalti). Daraz’s nightly builds.
Docker Containerization Consistent environments (NEPSE’s servers). Isolating trading system updates.
git pushwebhookdeployreleaseDeveloperGitHubJenkinsStagingProduction
Khalti’s CI/CD pipeline (simplified)

8. SCM in Action: Daraz’s Daily Releases

Scenario: Daraz needs to release 10 new features per week. Without SCM:

  • Chaos: Developers overwrite each other’s code.
  • Downtime: Bugs in production (e.g., wrong pricing).

SCM Solution:

  1. Branching: Each feature gets its own branch (feature/new_product_page).
  2. Pull Requests: Code reviewed before merging.
  3. Automated Tests: Jenkins runs tests on every PR.
  4. Rollback Plan: If v4.2 fails, revert to v4.1.

Result:

  • 90% fewer bugs in production.
  • Faster releases (daily updates instead of monthly).


## In the Real World

  1. eSewa’s Payment Gateway

    • SCM Idea: Version control + baselines.
    • How: Git tracks every change to the payment API. Before Diwali, they baseline v5.0 to avoid crashes during peak transactions.
    • Impact: Zero downtime during festivals (unlike 2020’s failed Diwali update).
  2. Pathao’s Ride-Hailing App

    • SCM Idea: Branching + CI/CD.
    • How: Feature branches for new cities (e.g., feature/lalitpur). Jenkins deploys updates to 1% of users first (canary release).
    • Impact: Reduced crashes by 60% in 2023.
  3. NEPSE’s Trading System

    • SCM Idea: Change control + rollback.
    • How: All code changes require approval from the compliance team. If a bug appears, they roll back to the last stable baseline.
    • Impact: No major outages during market hours.

## Exam Tip

How to Score Full Marks:

  1. Define SCM clearly:

    "SCM is the process of managing changes to software artifacts to ensure traceability, reproducibility, and consistency."

  2. Compare Git/SVN using the table above (mention distributed vs. centralized).

  3. Explain baselines with a real example:

    "NEPSE freezes its trading system code as a baseline before Diwali to prevent crashes during high-volume trading."

  4. Link SCM to CI/CD:

    "Git triggers Jenkins builds, which automate testing and deployment—critical for Daraz’s daily releases."

  5. Avoid vague answers:

    • ❌ "SCM is important."
    • ✅ "SCM prevents ‘works on my machine’ errors by tracking code changes, as seen when Pathao’s Lalitpur team debugged a crash caused by merged but untested branches."

Common Pitfalls:

  • Forgetting change control (examiners love this!).
  • Confusing branches with tags (branches are editable; tags are permanent).
  • Not tying answers to Nepalese examples (e.g., eSewa, Daraz).

Final Visual Summary

mindmap
  root((SCM in Nepal))
    Git["Git (Daraz, Pathao)"]
    SVN["SVN (NTC, legacy)"]
    Baselines["NEPSE: Freeze before Diwali"]
    CI/CD["Jenkins (Khalti, eSewa)"]
    ChangeControl["eSewa: 4-eyes approval"]
    Tools["Jira, Docker, GitHub"]

Based on the TU BCA syllabus for Software Project Management (CACS407), unit 6.

Discussion

Loading…