Hub rules-cpp

rules-cpp

v5 public Verified

Cpp

C++ is a high-performance, systems-level programming language. These rules govern memory safety, RAII, modern standards (C++17/20/23), and performance optimization for AI-driven C++ projects.

@sigmashakeinc 2 pulls 11 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-cpp →
Severity
6 error 5 warn 0 info
demo.cast
C++ is a high-performance, systems-level programming language. These rules govern memory safety, RAII, modern standards (C++17/20/23), and performance optimization for AI-driven C++ projects.

Rules index

11 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

cpp

no-c-style-cast-cpp warning log

C-style casts are dangerous in C++ — they silently perform reinterpret_cast when no other cast works. Use explicit C++ casts: static_cast, dynamic_cast, const_cast.

Rule source requires an active Pro or Enterprise subscription.
no-gets-cpp error block

gets() has no bounds checking and causes buffer overflows — removed from C11 and deprecated in C++11. Use std::getline(std::cin, str) or fgets() instead.

Rule source requires an active Pro or Enterprise subscription.
no-memcpy-no-bounds-cpp warning log

memcpy() with sizeof() — verify the size argument is the destination buffer size, not the source pointer size (a common mistake with pointer-decay). Prefer std::copy(), std::memcpy with explicit checked sizes, or std::span (C++20) to make the bounds explicit.

Rule source requires an active Pro or Enterprise subscription.
no-printf-format-string-cpp error log

printf()/fprintf() called with a non-literal format string (CWE-134: Format String Vulnerability). A user-controlled format string can read arbitrary stack memory (%x/%s) or write to arbitrary addresses (%n). Always pass a string literal as the format: printf("%s", variable) not printf(variable).

Rule source requires an active Pro or Enterprise subscription.
no-raw-new-delete warning log

Raw new/delete is error-prone — use-after-free, double-free, and leaks are common. Prefer std::make_unique<T>() or std::make_shared<T>() to enforce RAII ownership.

Rule source requires an active Pro or Enterprise subscription.
no-reinterpret-cast warning log

reinterpret_cast bypasses type safety and can produce undefined behavior if the types are incompatible. Use static_cast where possible, or redesign to avoid the cast.

Rule source requires an active Pro or Enterprise subscription.
no-scanf-unbounded-cpp error log

scanf("%s", ...) reads input with no length limit, causing a stack buffer overflow when input exceeds the destination buffer size (CWE-121). Use scanf("%Ns", ...) where N is buffer size minus 1, or prefer std::cin with std::string / fgets().

Rule source requires an active Pro or Enterprise subscription.
no-sprintf-cpp error log

sprintf() does not check buffer bounds. Use snprintf() with an explicit limit, or preferably std::to_string(), std::format() (C++20), or ostringstream.

Rule source requires an active Pro or Enterprise subscription.
no-strcpy-cpp error log

strcpy() and strcat() cause buffer overflows. Use std::string for string operations in C++, or strlcpy/strlcat if you must use C strings.

Rule source requires an active Pro or Enterprise subscription.
no-system-cpp error log

std::system() with user-controlled input enables command injection. Use POSIX exec*() functions with an argv array, or a cross-platform subprocess library.

Rule source requires an active Pro or Enterprise subscription.
no-uncaught-exception-spec warning log

Uncaught exceptions call std::terminate(). Ensure throwing code is wrapped in try/catch at appropriate boundaries, or mark functions noexcept if they should not throw.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
ce5f186a057c65a892def94455768e5fa4dfc321392bb878a8c78f9ed787b7ec
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-cpp/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-cpp. The published version only bumps when a maintainer resyncs.

No commit history available.