Pich logoPichdocs
Docs menu: Quote validation

Architecture

Quote validation

How Pich rejects any checklist item that does not quote the advisory.

SERV output is not trusted as is. validateChecklist() in src/lib/checklist.ts runs on every compile and returns the cleaned checklist plus a list of rejected items with reasons.

CheckResult on failure
Range is a valid npm semver rangeRange rejected
Quote appears verbatim in the advisory (whitespace and quote marks normalized)Item rejected
Predicate id is in the vocabularyPredicate rejected
Quote describes protection but predicate says presentCorrected to absent and recorded
Same predicate and expectation twiceDuplicate dropped
Fixed version is valid semverVersion dropped

Note

The polarity correction exists because SERV once read “Vercel deployments are protected” as a condition that must be present. A regression test in scripts/verify-engine.ts covers it.

Edit this page on GitHub