AIROM is developed in the open at airomhq/airom.

Where to go

Report a bug

Open an issue. A scan that produced the wrong answer is most useful with the command you ran and the output you got.

Ask a question

Issues are the place for now. There is no separate forum, and pointing you at one that does not exist would waste your time.

Request detection

Missing a framework, provider or vector store? Detection lives in rule packs, so this is usually a small, fast change.

Report a security issue

Use GitHub’s private advisory flow rather than a public issue.

Contributing detection

The fast-moving surface — model ids, provider SDKs, frameworks — is YAML rule packs rather than Go, so adding a provider is a rules change, not a release:
Every rule needs at least one positive and one negative fixture; lint fails without them. See Writing rules for the full contract.

Before you file

  • Check the ledger. project-status.md lists what is deliberately not done yet, so you can tell a gap from a bug.
  • Include the version. airom version prints the release, the commit and the Go toolchain it was built with.
  • Say which rules answered. Every document records rulesVersion and rulesHash; a finding can differ between two machines if one has fetched a newer rule bundle.