Pich logoPichdocs
Docs menu: Limitations

Reference

Limitations

Unsupported cases and known constraints.

  • Only Next.js advisories, and only the 8 predicates in the vocabulary.
  • The installed version is read from package-lock.json only. pnpm, yarn, and Bun repositories get an unknown version and Needs manual review.
  • Hosting is unknown unless the app declares pich.deploy.json.
  • Middleware auth detection looks for a credential check followed by a redirect or 401/403; unusual patterns may be missed.
  • Public GitHub repositories only, one per check; anonymous GitHub reads can be rate limited.
  • The runtime proof exists only for CVE-2025-29927 and only runs locally against two bundled fixtures.
  • No accounts, saved history, or private repository access.

Edit this page on GitHub