Architecture
Deterministic engine
How Pich reads files, observes predicates, and picks the verdict.
evaluate(checklist, app) in src/lib/engine.ts is plain TypeScript. Given the same checklist and files, it always returns the same result.
Installed version
The installed next version comes from package-lock.json. If only package.json declares it, or another lockfile is used, the version is unknown and the declared range is shown as evidence.
Observing predicates
Each predicate is observed as present, absent, or unknown with evidence lines. See Predicates for how each one is read.
Choosing the verdict
rule
if any required condition is not met → Absent within inspected scope
else if anything is unknown or not checkable → Needs manual review
else → ConfirmedMitigations from the advisory are listed as “Mitigation not inspected” and do not change the verdict.