# Contact

> Every question about Eva is answered in public, on the issue tracker.

## Questions, bugs, and requests

A question answered in public is answered once, and the next person who asks it finds the answer instead of asking it again. That is why there is an issue tracker and not a support address.

Include the version from `eva --version`, the command you ran, and what happened instead. Eva prints findings to stderr without changing the exit code, so paste stderr as well as stdout.

[Open an issue](https://github.com/missingstudio/eva/issues)

## Security

There is no separate security mailbox. Report a suspected vulnerability as an issue that says what the impact is and which code path reaches it, and leave a working exploit out of the first message.

If the finding needs to stay private until it is fixed, say so in the first line rather than in the detail, and a private channel will be opened before anything more is written down.

## Changes to the program

The source takes patches. Read the contributing page in the documentation first: it names the commit format, the branch naming, and the checks a change has to pass.

[Read the source](https://github.com/missingstudio/eva)

Every release is published with its notes, its checksums, and a provenance attestation.

[See the releases](https://github.com/missingstudio/eva/releases)

## The company

Missing studio publishes Eva. Its other work is on the same organisation, and it posts as @madebymissing.

[missingstudio on GitHub](https://github.com/missingstudio)

[@madebymissing on X](https://x.com/madebymissing)

Read this page as HTML: https://evafactory.co/contact
