There are many problems where regexes are succinct and appropriate, (of course there are many more where they are neither).
The same logic bug would have occured with a parser.
(java and rust have their own "native" implementation too.
You're expecting an input to be a UUID? Check it with ^[a-fA-F0-9\-]{30,40}$ and you know you're not getting any apostrophes or script tags or enormous inputs or empty inputs or newlines or lookalike characters or emojis.
What happened here was that the Github employee programming this didn't bother to read the spec and/or think.
Especially for security critical things one should re-use the implementation to avoid issues like the above. Proving both the original and re-implemented parser to be equivalent would probably also work, but not sure how practical.
And in any case have competent people audit what you did.
Hmm. Okay.
The part that bewilders me is that Rust showed up. Which would have made sense if someone was complaining about C++ or something, or maybe unsafe memory management. But regexes?
> Either way, I didn’t want to have a discussion about rust.
Which is why you brought it up unprompted... I give up.
I don’t hate the language. Quite the opposite. I hope you can now go back and just see the argument for what it is and not for what you thought I was insinuating.