Developer

Regular expression

/^[0-9a-f]{7,40}$/

Pattern breakdown

PartMeaning
Anchor or contextUse anchors when you need whole-string validation.
Main tokenThe core token sequence describes the accepted text shape.
Character classCharacter classes limit which characters are valid.
QuantifierQuantifiers control how many characters or groups are accepted.
FlagsUse language-specific flags such as i, m, or u only when needed.

Should match

  • a1b2c3d4

Should not match

  • xyz123
  • not matching sample
  • a1b2c3d4 invalid
  • xyz123a1b2c3d4

Test cases

InputExpectedWhy it matters
a1b2c3d4MatchRepresentative valid input for this pattern.
xyz123No matchCommon invalid or boundary input.
(empty string)No matchCommon invalid or boundary input.
not matching sampleNo matchCommon invalid or boundary input.
a1b2c3d4 invalidNo matchCommon invalid or boundary input.
xyz123a1b2c3d4No matchCommon invalid or boundary input.

JavaScript

const re = /^[0-9a-f]{7,40}$/;
re.test(input);

Python

import re
bool(re.search(r"^[0-9a-f]{7,40}$", text))

PHP

$ok = preg_match('/^[0-9a-f]{7,40}$/', $value) === 1;

Java

Pattern pattern = Pattern.compile("^[0-9a-f]{7,40}$");
pattern.matcher(value).find();

Go

re := regexp.MustCompile(`^[0-9a-f]{7,40}$`)
ok := re.MatchString(value)

Notes and production use

Git Commit Hash regex is useful as a practical starting point. Test it against your real input, avoid using it as the only security control, and prefer a parser when the format has complex grammar.

Performance tip: avoid running complex regular expressions repeatedly on very large untrusted strings without limits. Prefer anchored validation patterns, cap input length before matching, and use a parser when the target format has nested grammar.