Architecture
Quote validation
How Pich rejects any checklist item that does not quote the advisory.
SERV output is not trusted as is. validateChecklist() in src/lib/checklist.ts runs on every compile and returns the cleaned checklist plus a list of rejected items with reasons.
| Check | Result on failure |
|---|---|
| Range is a valid npm semver range | Range rejected |
| Quote appears verbatim in the advisory (whitespace and quote marks normalized) | Item rejected |
| Predicate id is in the vocabulary | Predicate rejected |
| Quote describes protection but predicate says present | Corrected to absent and recorded |
| Same predicate and expectation twice | Duplicate dropped |
| Fixed version is valid semver | Version dropped |
Note
The polarity correction exists because SERV once read “Vercel deployments are protected” as a condition that must be present. A regression test in
scripts/verify-engine.ts covers it.