Pich logoPichdocs
Docs menu: Verdicts

Reference

Verdicts

The three verdicts, their exact rules, and what they do not mean.

VerdictRuleWhat it does not mean
ConfirmedEvery condition Pich can check is met, and nothing is unknownThat an attack happened or is possible in production
Absent within inspected scopeAt least one required condition was not found in the inspected filesThat the app is safe or not vulnerable
Needs manual reviewNo condition is contradicted, but at least one is unknown or not checkable from filesThat the app is affected

Boundary

SERV never picks the verdict. The rule above runs in code after SERV’s checklist has been validated.

Edit this page on GitHub