Security vulnerabilities should never be reported in a public issue.

Support & Security

Use the right path for the issue.

Community support is best effort. Reproducible bugs belong in GitHub Issues, vulnerabilities use private reporting, and commercial engagements are optional.

Support routes

Give maintainers the context needed to help.

Search existing reports first. Include only the minimum sensitive information required to reproduce a problem.

Bug report

Include platform, device, version or commit, steps to reproduce, expected behavior, actual behavior, and relevant logs.

Open issue
Setup help

Check the getting started and development guides before opening an issue with exact command output.

Read guide
Feature request

Describe the user problem, affected workflow, constraints, and why the change belongs in the core project.

Propose feature
Security report

Use GitHub private vulnerability reporting when available. Do not include exploit details in a public issue.

Report privately

Security scope

Private data and native capability boundaries matter.

Relevant reports include unsafe local file handling, private chat or embedding leakage, insecure model delivery, bridge misuse, and shipped dependency vulnerabilities.

FILES

Local content

Unsafe attachment, file URL, content URI, or indexed document handling that could expose data.

MODELS

Runtime integrity

Model download validation, incompatible assets, unsafe loading, or runtime behavior that crosses intended boundaries.

BRIDGE

Native access

React Native bridge behavior that unexpectedly exposes device capabilities, files, or long-lived state.

Commercial support

Support the project without changing the license.

Open Edge AI is MIT licensed. Voluntary sponsorship, integration work, infrastructure help, and paid technical support do not add restrictions to the open-source license.

Organizations using Open Edge AI for revenue, internal operations, or client work are encouraged to support maintenance through engineering contributions, sponsorship, infrastructure, documentation, or a scoped support contract.