# Support and bug reports

> Report Shardflux bugs, request features, and get help with packages, workspaces, account access, billing, or security vulnerabilities.

## Choose a reporting channel

| What you need | Where to go |
| --- | --- |
| A reproducible bug or incorrect documentation | [Report a bug](https://github.com/shardfluxdev/community/issues/new?template=bug_report.yml) |
| A missing capability or product idea | [Request a feature](https://github.com/shardfluxdev/community/issues/new?template=feature_request.yml) |
| Usage questions, account access, billing, or confidential details | [Email the Shardflux team](mailto:shardflux@heliosone.fi) |
| A security vulnerability | [Report it privately](https://github.com/shardfluxdev/community/security/advisories/new) |

The [community tracker](https://github.com/shardfluxdev/community/issues) covers the TypeScript SDK, Python SDK,
CLI, npm bundle, MCP server, API, cloud workspaces, dashboard, and documentation. If you cannot tell which component
caused the problem, choose **Not sure**. You do not need a Shardflux account or a working client to open a report.

## What to include

Search existing issues first. For a new bug, include the package name and exact version, your Node.js or Python
version and operating system when relevant, the smallest reproduction, and what you expected versus what happened.
If the client returned an error code or request ID, include those too.

Public reports must not contain API keys, session tokens, customer data, or confidential code. Use a sanitized
example or email the team when details need to stay private. Report security vulnerabilities through the private
channel above; see the [security policy](https://github.com/shardfluxdev/community/blob/main/SECURITY.md).

## Direct client feedback

The [CLI](https://docs.shardflux.dev/reference/cli.md#feedback) (0.5.0+), [TypeScript SDK](https://docs.shardflux.dev/reference/typescript.md#feedback) (0.9.0+),
[Python SDK](https://docs.shardflux.dev/reference/python.md#feedback) (0.5.0+), and [MCP server](https://docs.shardflux.dev/reference/mcp.md#feedback) (0.4.0+) can send
feedback directly while you work. These messages do not create public GitHub issues. Use the tracker when you want
a public report you can follow. If installation or authentication is broken, use the public form or email instead.

## Following a fix

New reports start with `needs-triage`. The team adds the affected component and may ask for a reproduction.
Implemented fixes remain `awaiting-release` until the package is published or the service fix is deployed.
The closing update names the package and published version to install, or identifies the deployed service change
and whether a client update is required. Duplicate reports link to the original issue.
