Hub rules-vlang

rules-vlang

v4 public Verified

Vlang

V is a statically typed compiled programming language designed for building maintainable software. These rules govern memory safety, syntax idioms, and compiler safety for AI agents.

@sigmashakeinc 2 pulls 7 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-vlang →
Severity
6 error 1 warn 0 info
demo.cast
V is a statically typed compiled programming language designed for building maintainable software. These rules govern memory safety, syntax idioms, and compiler safety for AI agents.

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

vlang

vlang-block-unsafe-patterns warning ask

RISK: C.malloc bypasses V's memory safety and requires manual free — leaks and double-frees are easy. FIX: use V's built-in allocators (arrays, maps) or the `unsafe { }` block with a documented safety invariant.

Rule source requires an active Pro or Enterprise subscription.
vlang-deny-c-free-manual error block

RISK: Calling C.free() manually on V-allocated memory causes double-free or use-after-free undefined behaviour (CWE-415/CWE-416). FIX: let V's garbage collector manage V-allocated objects; only call C.free() on memory explicitly returned by a C function that allocates it.

Rule source requires an active Pro or Enterprise subscription.
vlang-deny-hardcoded-secret error block

RISK: Hardcoded credentials in V source are committed to version control and exposed in compiled binaries (CWE-798). FIX: read secrets from environment variables (os.getenv('SECRET_NAME')), a config file outside the repo, or a secrets manager.

Rule source requires an active Pro or Enterprise subscription.
vlang-deny-os-execute-interpolation error block

RISK: Interpolating variables directly into os.execute()/os.system()/os.exec() is OS command injection (CWE-78) — any user-controlled value can escape the intended command. FIX: build argument lists with os.Process{ args: [...] } so each argument is a separate element and the shell cannot interpret metacharacters.

Rule source requires an active Pro or Enterprise subscription.
vlang-deny-raw-pointer-deref error block

RISK: voidptr/charptr casts and raw pointer derefs in V bypass the type system and can cause memory corruption or information disclosure. FIX: use V's typed references and let the compiler track ownership; wrap C API calls behind a safe V function that validates the pointer.

Rule source requires an active Pro or Enterprise subscription.
vlang-deny-unsafe-block error block

RISK: V's `unsafe { }` block disables bounds-checking and nil-pointer protection — it is the primary source of memory corruption bugs in V programs (CWE-119/CWE-476). FIX: restrict unsafe blocks to narrow FFI wrappers, document the invariants that make them safe, and keep them out of application logic.

Rule source requires an active Pro or Enterprise subscription.
vlang-warn-tls-skip-verify error block

RISK: Disabling TLS certificate verification in V HTTP/net clients allows man-in-the-middle attacks — the server's identity is not authenticated (CWE-295). FIX: use the default TLS verification path; if you need a custom CA, pass the certificate file to the client configuration instead of skipping verification.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v4
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
4a4642b084720c4490396681ba87408684c2218d6b1576132d5da2f8fb4e40e5
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-vlang/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-vlang. The published version only bumps when a maintainer resyncs.

No commit history available.