>>Honestly though, if I was ever in a fire/hire position bringing SQL-injectable-code to a code review would be grounds for being fired on the spot.
Code reviews should be about ensuring the integrity of the code base AND helping your developers write better code. If you fire someone on any teachable moment, your employees will never get any better. Mistakes should not equal firings for a first offence, that's a dead giveaway of a terrible manager. Making the same mistake twice is the inexcusable part.
There's an old story that's relevant here (I may get the specifics wrong): In the early days of Intel, before they were a behemoth, an engineer made a mistake that cost the company $50,000 (a huge sum at the time). The engineer was sure he was a goner, and many people were calling for this head. Gordon Moore (founder) was asked when he would be fired.
Moore replied "Why would I fire him? I just spent $50,000 training the man!"
Comments
Code reviews should be about ensuring the integrity of the code base AND helping your developers write better code. If you fire someone on any teachable moment, your employees will never get any better. Mistakes should not equal firings for a first offence, that's a dead giveaway of a terrible manager. Making the same mistake twice is the inexcusable part.
There's an old story that's relevant here (I may get the specifics wrong): In the early days of Intel, before they were a behemoth, an engineer made a mistake that cost the company $50,000 (a huge sum at the time). The engineer was sure he was a goner, and many people were calling for this head. Gordon Moore (founder) was asked when he would be fired.
Moore replied "Why would I fire him? I just spent $50,000 training the man!"