Software Project ManagementUnit 610 min read
Software Configuration Management (SCM): Basics, Tools, Processes & Real-World Impact
Unit 6 of Software Project Management explores SCM’s core concepts—version control, change management, build automation, and repository management—along with tools (Git, SVN), processes (baseline, branching), and real-world applications in Nepalese tech (e.g., eSewa’s code updates, Daraz’s release cycles). Includes com
TAKEAWAYS:
- SCM ensures traceability, reproducibility, and consistency of software artifacts by tracking changes, versions, and dependencies.
- Version control systems (Git, SVN) automate history tracking, branching, and merging—critical for collaborative projects like eSewa’s payment gateway updates.
- Configuration items (source code, docs, binaries) must be baselined and controlled to avoid "works on my machine" failures in Pathao’s ride-hailing app.
- Build automation (Jenkins, Maven) ties SCM to CI/CD pipelines, reducing human error in Ncell’s app deployments.
- Change management follows a request → review → approval → integration workflow, visible in NEPSE’s trading system updates.
- Exam focus: Define SCM, compare Git/SVN, explain baselines, and link SCM to real projects (e.g., "How does Daraz use SCM for daily releases?").
1. What is Software Configuration Management (SCM)?
SCM is the discipline of systematically managing changes to software artifacts (code, documentation, binaries) to ensure:
- Traceability: Who changed what, when, and why.
- Reproducibility: Anyone can rebuild the software from source.
- Consistency: All team members work on the same stable baseline.
Why SCM Matters
Without SCM, projects face:
- "Version hell" (e.g., Daraz’s developers using different code versions → bugs in checkout).
- Lost work (e.g., a Pathao engineer overwrites another’s feature branch).
- Security risks (e.g., eSewa’s unversioned API keys leaked in updates).
2. Core Elements of SCM
SCM revolves around three pillars:
| Element | Definition | Example in Nepalese Tech |
|---|---|---|
| Configuration Items (CIs) | Artifacts under control (code, docs, DB schemas). | eSewa’s payment_gateway.py and API specs. |
| Version Control | Tracking changes over time (e.g., Git, SVN). | Daraz’s order_management repo with 500+ commits. |
| Baseline | A frozen snapshot of CIs at a point in time (e.g., v1.2 of Ncell’s app). | NEPSE’s trading system baseline before Diwali updates. |
| Change Control | Process to request, review, and approve changes. | Pathao’s "Add Cash on Delivery" feature workflow. |
| Build Management | Automating compilation/testing (e.g., Jenkins, Maven). | Khalti’s nightly builds to catch payment bugs. |
3. Version Control Systems (VCS): Git vs. SVN
How They Work
stateDiagram-v2
[*] --> WorkingDirectory: Start
WorkingDirectory --> StagingArea: git add
StagingArea --> LocalRepo: git commit
LocalRepo --> RemoteRepo: git push
RemoteRepo --> [*]Comparison Table
| Feature | Git (Distributed) | SVN (Centralized) |
|---|---|---|
| Storage | Local + remote repos. | Single central repo. |
| Branching | Cheap, lightweight (e.g., feature/login). |
Heavy (requires svn copy). |
| Offline Work | Yes (commit locally, push later). | No (needs server connection). |
| Use Case | Agile teams (e.g., Daraz’s daily commits). | Legacy systems (e.g., NTC’s internal tools). |
| Command | git checkout -b feature |
svn copy URL trunk feature |
Worked Example: Pathao’s team uses Git to:
- Create a branch
feature/cash_on_delivery. - Commit changes locally.
- Push to
origin/feature/cash_on_delivery. - Open a Pull Request (PR) for review before merging to
main.
4. SCM Processes: From Baseline to Release
Step-by-Step Workflow
flowchart TD
A["1. Baseline\n(e.g., v1.0 of eSewa app)"] --> B["2. Change Request\n(Dev: 'Add UPI payment')"]
B --> C["3. Review\n(PM + QA approve)"]
C --> D["4. Branch\n(Create `feature/upi`)"]
D --> E["5. Develop\n(Code + tests)"]
E --> F["6. Build\n(Jenkins compiles)"]
F --> G["7. Test\n(QA validates)"]
G --> H["8. Merge\n(PR to `main`)"]
H --> I["9. Release\n(v1.1 deployed)"]Key Terms
- Baseline: A reference point (e.g.,
eSewa_v1.0). Changes must be approved to modify it. - Branch: Isolated line of development (e.g.,
hotfix/login_bug). - Merge: Combining branches (e.g., merging
feature/upiintomain). - Tag: Permanent marker for releases (e.g.,
v1.1).
Real-World Tie-In: NEPSE’s trading system uses baselines to:
- Freeze code before Diwali (high-volume trading).
- Roll back to
v2.3if a bug appears inv2.4.
5. Build Automation & CI/CD
SCM feeds into Continuous Integration/Deployment (CI/CD):
- Trigger: Developer pushes to
main→ Jenkins builds. - Steps:
- Fetch latest code from Git.
- Run unit tests.
- Deploy to staging.
- Notify team (Slack/email).
Example: Khalti’s CI Pipeline
sequenceDiagram
Developer->>GitHub: git push main
GitHub->>Jenkins: Webhook trigger
Jenkins->>Maven: Compile code
Maven-->>Jenkins: Build success/fail
Jenkins->>QA: Deploy to staging
QA->>Jenkins: Test results
Jenkins->>DevTeam: Slack alertWhy It Matters:
- Catches bugs early (e.g., Daraz’s checkout failures).
- Automates releases (e.g., Ncell’s app updates at 2 AM).
6. Change Management: The "4 Eyes" Rule
Workflow
- Request: Dev submits a change (e.g., "Fix login timeout").
- Review: PM + QA check code/docs.
- Approval: Sign-off required (e.g., eSewa’s security team).
- Integration: Merge into
main+ deploy.
Example: eSewa’s Payment Gateway Update
- Change: Add "Save Card" feature.
- Process:
- Dev creates
feature/save_card. - PM reviews security risks.
- QA tests with test cards.
- Security team approves.
- Deployed in
v3.2.
- Dev creates
Risk Without SCM:
- Unapproved changes → downtime (e.g., Ncell’s app crash in 2022 due to untested code).
7. Tools of SCM
| Tool | Type | Use Case | Nepalese Example |
|---|---|---|---|
| Git | Version Control | Collaborative coding (Daraz, Pathao). | Open-source projects on GitHub. |
| SVN | Version Control | Legacy systems (NTC’s internal tools). | Government projects. |
| Jira | Issue Tracking | Managing change requests (e.g., eSewa bugs). | Agile teams at F1Soft. |
| Jenkins | CI/CD | Automated testing/deployment (Khalti). | Daraz’s nightly builds. |
| Docker | Containerization | Consistent environments (NEPSE’s servers). | Isolating trading system updates. |
8. SCM in Action: Daraz’s Daily Releases
Scenario: Daraz needs to release 10 new features per week. Without SCM:
- Chaos: Developers overwrite each other’s code.
- Downtime: Bugs in production (e.g., wrong pricing).
SCM Solution:
- Branching: Each feature gets its own branch (
feature/new_product_page). - Pull Requests: Code reviewed before merging.
- Automated Tests: Jenkins runs tests on every PR.
- Rollback Plan: If
v4.2fails, revert tov4.1.
Result:
- 90% fewer bugs in production.
- Faster releases (daily updates instead of monthly).
## In the Real World
eSewa’s Payment Gateway
- SCM Idea: Version control + baselines.
- How: Git tracks every change to the payment API. Before Diwali, they baseline
v5.0to avoid crashes during peak transactions. - Impact: Zero downtime during festivals (unlike 2020’s failed Diwali update).
Pathao’s Ride-Hailing App
- SCM Idea: Branching + CI/CD.
- How: Feature branches for new cities (e.g.,
feature/lalitpur). Jenkins deploys updates to 1% of users first (canary release). - Impact: Reduced crashes by 60% in 2023.
NEPSE’s Trading System
- SCM Idea: Change control + rollback.
- How: All code changes require approval from the compliance team. If a bug appears, they roll back to the last stable baseline.
- Impact: No major outages during market hours.
## Exam Tip
How to Score Full Marks:
Define SCM clearly:
"SCM is the process of managing changes to software artifacts to ensure traceability, reproducibility, and consistency."
Compare Git/SVN using the table above (mention distributed vs. centralized).
Explain baselines with a real example:
"NEPSE freezes its trading system code as a baseline before Diwali to prevent crashes during high-volume trading."
Link SCM to CI/CD:
"Git triggers Jenkins builds, which automate testing and deployment—critical for Daraz’s daily releases."
Avoid vague answers:
- ❌ "SCM is important."
- ✅ "SCM prevents ‘works on my machine’ errors by tracking code changes, as seen when Pathao’s Lalitpur team debugged a crash caused by merged but untested branches."
Common Pitfalls:
- Forgetting change control (examiners love this!).
- Confusing branches with tags (branches are editable; tags are permanent).
- Not tying answers to Nepalese examples (e.g., eSewa, Daraz).
Final Visual Summary
mindmap
root((SCM in Nepal))
Git["Git (Daraz, Pathao)"]
SVN["SVN (NTC, legacy)"]
Baselines["NEPSE: Freeze before Diwali"]
CI/CD["Jenkins (Khalti, eSewa)"]
ChangeControl["eSewa: 4-eyes approval"]
Tools["Jira, Docker, GitHub"]Based on the TU BCA syllabus for Software Project Management (CACS407), unit 6.
Discussion
Loading…