> For the complete documentation index, see [llms.txt](https://docs.portainer.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.portainer.io/portainer-documentation/3.0-sts/help/contribute.md).

# Report a bug or security vulnerability

## Reporting bugs

If you find a bug, [please tell us](https://github.com/portainer/portainer/issues/new?assignees=\&labels=bug%2Fneed-confirmation%2C+kind%2Fbug\&template=Bug_report.md\&title=) so we can triage it. All bugs are managed in the [GitHub issues repo](https://github.com/portainer/portainer/issues). When you click through, our template makes it easy to record all of the details. Check the list of [open bugs](https://github.com/portainer/portainer/labels/kind%2Fbug) before reporting to avoid duplicates.

[This article](/portainer-documentation/3.0-sts/faqs/contributing/how-do-you-decide-which-bugs-and-features-to-work-on-first.md) covers how we prioritize bug fixes.

## Reporting security vulnerabilities

The Portainer team takes the security of our products seriously. If you believe you have discovered a security vulnerability in any Portainer-owned repository, please report it responsibly.

Please do not report security vulnerabilities through public channels, including standard GitHub issues.

Instead, report vulnerabilities using one of the following methods:

* Email the Portainer team at <security@portainer.io>
* [Submit a private vulnerability report](https://github.com/portainer/portainer/security/advisories/new) through the relevant Portainer repository on GitHub

These channels allow the team to review and address the issue as quickly as possible while minimizing the risk of public exposure before a fix is available.

In your report, please include a description of the vulnerability and the potential impact, step-by-step reproduction, and the version and environment where you found it. We will acknowledge your report, give an initial assessment, and provide an estimated timeline for remediation - we do not commit to a fixed window. We will let you know when a fix ships and credit you using your GitHub handle.

Portainer does not operate a paid bug bounty program and does not offer monetary rewards for vulnerability reports. Portainer will not pursue legal action against good-faith research conducted in line with this policy.

## Feature requests

You can request new features by posting an Idea in our [GitHub Discussions](https://github.com/orgs/portainer/discussions/categories/ideas) forum. Please check to see if someone has already requested the feature you want, and give it an upvote if so.

Learn how we prioritize feature development [in this article](/portainer-documentation/3.0-sts/faqs/contributing/how-do-you-decide-which-bugs-and-features-to-work-on-first.md).
