GitHub
CERT Secure Coding

TODO List

For more items on the TODO list, please see C++ Coding Standard Development Guidelines .

These rules need professional editing:

These rules should be preserved:

Content by label

There is no content with the specified labels

These rules should be updated:

Content by label

There is no content with the specified labels

These rules should be deleted:

Content by label

There is no content with the specified labels

These rules are covered by C and do not require a C++ rule:

Content by label

There is no content with the specified labels

These rules have notes associated with them:

Incomplete pages in C++ use the incomplete tag. Pages with hidden notes in them use the notes tag.
But C++ rules that were copied from C and not updated are marked with the incomplete-cpp tag.
C++ rules that are accurate, but need their sample code updated (from C) are tagged with the update-code tag.


Update references to C (eg C99) to references to C++


Pages should have tags to indicate the status of their corresponding checker in Compass Rose:

TagMeaning
rose-completeROSE catches all violations
rose-partialROSE catches some violations
rose-possibleROSE could catch some or all violations, but doesn't yet.
rose-gccROSE doesn't catch violations, but will soon, GCC catches violations
unenforceableThese rules can't be checked automatically.
rose-nonapplicableThese rules could be checked automatically in theory, but not by ROSE.
rose-na-macrosROSE could check these rules if it recognized macro usage.
rose-na-exptypesROSE could check these rules if it recognized derived types in expressions, such as size_t .
rose-na-multiple-filesROSE could check these rules if it operated on multiple files at once.
rose-false-positiveROSE could enforce this rule, but could not avoid catching some false positives.

At this point, all rules should have one of these tags. That is, they should be completely or partially checked by ROSE, or they should be marked 'rose-possible', in that we will try to check them with ROSE, or they should have one of the nonapplicable tags indicating we don't think they can be checked with ROSE.


There are some rules in other standards that might make good C++ rules. They are tagged exportable-c++ . Port to C++ those rules that are truly applicable.


review -> review + review-one -> review + review-two -> No tags
significant changes -> review or incomplete