Where to go
Report a bug
Open an issue. A scan that produced the wrong answer is most useful with the command you
ran and the output you got.
Ask a question
Issues are the place for now. There is no separate forum, and pointing you at one that
does not exist would waste your time.
Request detection
Missing a framework, provider or vector store? Detection lives in rule packs, so this is
usually a small, fast change.
Report a security issue
Use GitHub’s private advisory flow rather than a public issue.
Contributing detection
The fast-moving surface — model ids, provider SDKs, frameworks — is YAML rule packs rather than Go, so adding a provider is a rules change, not a release:Before you file
- Check the ledger. project-status.md lists what is deliberately not done yet, so you can tell a gap from a bug.
- Include the version.
airom versionprints the release, the commit and the Go toolchain it was built with. - Say which rules answered. Every document records
rulesVersionandrulesHash; a finding can differ between two machines if one has fetched a newer rule bundle.