Download Cheat sheet PDF 12 pages · syntax, editors, patterns, Unicode, performance, debugging
Pattern

Regex for Git SHA (full)

Full 40-character SHA-1 commit hash.

The Git SHA (full) regex is \b[0-9a-f]{40}\b — copy it below, or open it in the explainer for a token-by-token breakdown.

The pattern

\b[0-9a-f]{40}\b
Try in explainer → Download cheat sheet ↓

What it matches

  • a1b2c3d4e5f6789012345678901234567890abcd

What it doesn't match

  • short
  • A1B2C3D4E5F6789012345678901234567890ABCD

Notes & gotchas

40 lowercase hex digits — the standard SHA-1 length. SHA-256 hashes (64 chars) are the next-gen format; use a different regex for those.

Code in your language

Use the explainer's Code tab to generate ready-to-paste snippets in JavaScript, Python, Java, .NET, Go, Ruby, and PHP for this pattern.

Open in explainer →

Token-by-token breakdown

Every part of the pattern, left to right:

TokenMeaning
\bword boundary
[0-9a-f]{40}exactly 40 times: any of: digits, a–f
\bword boundary

About this pattern

Identifier formats like UUIDs, hashes, and version strings have well-defined structures that regex captures cleanly. The pattern verifies format; checksums and validity against a registry need additional checks.

Quick usage in different languages

This exact pattern — with the correct escaping and idioms for each language:

  • JavaScript: /\b[0-9a-f]{40}\b/.test(value)
  • Python: re.match(r"\b[0-9a-f]{40}\b", value)
  • Java: Pattern.compile("\\b[0-9a-f]{40}\\b").matcher(value).matches()
  • C# / .NET: Regex.IsMatch(value, @"\b[0-9a-f]{40}\b")
  • Go: regexp.MustCompile(`\b[0-9a-f]{40}\b`).MatchString(value)
  • Ruby: /\b[0-9a-f]{40}\b/.match?(value)
  • PHP: preg_match('~\b[0-9a-f]{40}\b~', $value)

The explainer’s Code tab regenerates these for any pattern you paste, and the downloadable cheat sheet bundles the breakdown, all seven snippets, and the pitfalls below onto one printable page.

Common pitfalls

  • Not anchored. Without ^ and $ this can match a substring anywhere in the input — add anchors if you need the whole value to conform.
  • Case sensitivity. Letter ranges are case-sensitive — use the i flag if the input case can vary.
  • Escape it correctly per language. In Java and JavaScript strings each backslash must be doubled (\\d); in Python, Go, and C# use raw/verbatim strings so the backslashes survive.
  • Validate beyond format. Matching the format doesn't guarantee the value is real. Confirm the git sha (full) against a source of truth (database, API, or checksum) where it matters.

Standards & sources

This pattern is based on the following authoritative specification(s) and issuing authorities. Formats can change — always confirm against the primary source.

Related patterns

More patterns in the Codes & IDs category:

See also

Browse all 300 patterns in the library, or open this regex in the interactive explainer for a token-by-token breakdown, live testing, and code in seven languages.


Want more patterns? Browse the full library →