SEI
GitHub
CERT Secure Coding
  • Home
  • SEI CERT Perl Coding Standard
    • Front Matter
    • Rules
      • Declarations and Initialization (DCL)
      • Expressions (EXP)
      • File Input and Output (FIO)
      • Input Validation and Data Sanitization (IDS)
      • Integers (INT)
      • Miscellaneous (MSC)
      • Object-Oriented Programming (OOP)
      • Strings (STR)
        • STR30-PL. Capture variables should be read only immediately after a successful regex match
        • STR31-PL. Do not pass string literals to functions expecting regexes
    • Recommendations
    • Back Matter

Strings (STR)

  • STR30-PL. Capture variables should be read only immediately after a successful regex match
  • STR31-PL. Do not pass string literals to functions expecting regexes

Information for Editors
To have a new guideline automatically listed above be sure to label it str and rule .

Risk Assessment Summary

Rule Severity Likelihood Detectable Repairable Priority Level
STR30-PL Medium Probable Yes No P8 L2
STR31-PL Low Likely Yes Yes P9 L2

OOP32-PL. Prohibit indirect object call syntaxSTR30-PL. Capture variables should be read only immediately after a successful regex match

On this page

Risk Assessment Summary
SEI
  • www.cmu.edu

© 2026 Carnegie Mellon University

  • Legal
  • Privacy Policy