Start
Why Pich exists
Why version scanners over-flag agencies, and what Pich answers instead.
When a Next.js advisory lands, version scanners flag every app on an affected version. For an agency, that turns one advisory into one urgent email per client.
Most advisories have conditions beyond the version. CVE-2025-29927, for example, only matters if the app enforces authorization in middleware, and the advisory says Vercel-hosted deployments are automatically protected. A version scanner does not check either of those.
The question Pich answers
For each client app: are this advisory’s stated conditions present in the code and configuration, and what is the evidence?
Why SERV Reasoning is needed
Advisories are prose. Without a model to read them, Pich could only check advisories someone encoded by hand in advance, which is the scanner problem again. SERV turns new advisory text into a typed checklist that the engine can test. SERV never picks the verdict.
Limitation