Reference
Limitations
Unsupported cases and known constraints.
- Only Next.js advisories, and only the 8 predicates in the vocabulary.
- The installed version is read from
package-lock.jsononly. pnpm, yarn, and Bun repositories get an unknown version and Needs manual review. - Hosting is unknown unless the app declares
pich.deploy.json. - Middleware auth detection looks for a credential check followed by a redirect or 401/403; unusual patterns may be missed.
- Public GitHub repositories only, one per check; anonymous GitHub reads can be rate limited.
- The runtime proof exists only for CVE-2025-29927 and only runs locally against two bundled fixtures.
- No accounts, saved history, or private repository access.