Hi,

there's one other thing which came to my mind. Through CVS every single developer can introduce well hidden malcode to the source. Escpecially for a medical project this could be very dangerous.

A russian hacker tried to introduce bad code into the KDE project for demonstration purposes (he just included a comment saying something like "this is malcode"). The main developers got aware of that at once because they had a nice security mechanism which I'd suggest for care2x, too.

They have a special mailing-list where just main developers and some volunteers subsribed. On this mailinglist every commit will be posted automatically, so that developers always have a quick overview of what others did. It is also possible to publish commits (especially the comments) on a website..

If you're interested I know how to set this up..

regards
Matthias

--
PGP-encrypted mails preferred. Find my key on any public keyserver
RSA 2048 Key Id: 0xD5B8D81F


-------------------------------------------------------
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click
_______________________________________________
Care2002-developers mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/care2002-developers

Reply via email to