09 Oct 2026

feedDjango community aggregator: Community blog posts

Issue 358: Django 6.1.2, 6.0.9, and 5.2.18 Security Releases and Djangonaut Space Session 7

News

Django security releases issued: 6.1.2, 6.0.9, and 5.2.18

Four CVEs fixed: denial-of-service risks in language-code lookups and HTTP header parsing, spatial lookups that could make GDAL fetch external rasters, and model formsets with editable primary keys that forged POST data could use to delete or create instances. Raster bytes passed to spatial lookups must now be wrapped in GDALRaster, a backward-incompatible change, so upgrade and check your GIS code.

Welcome to Session 7 Teams 👩🏽‍🚀

Djangonaut Space Session 7 runs October 12 to December 6 with its biggest cohort yet: 28 Djangonauts picked from 92 applicants, across eight teams working on Django core, accessibility, Django Debug Toolbar, djangoCMS, and the Django Girls+ website, plus two Python projects, BeeWare and Render Engine.


Django Software Foundation

Django security reporting update

Django no longer takes new security reports through HackerOne. Existing HackerOne reports stay open with the Security Team, and new issues should go to security@djangoproject.com as described in the security policy.


Python Software Foundation

Python 3.15.0 candidate 3 is here!

Last-minute lazy-import release blockers earned 3.15 a surprise third release candidate, pushing 3.15.0 final to October 9. Maintainers should test and publish 3.15 wheels now; release candidate wheels will work with the final release.


Wagtail CMS News

Our agent skills for Wagtail developers

Agent-friendly documentation for your Wagtail tasks.

No GSoC on Wagtail core in 2027

A weekly, sometimes daily, flood of low-effort PRs (one fix came "tested" with a screenshot that wasn't even the Wagtail UI) has Wagtail pulling core out of Google Summer of Code 2027. It may still mentor on simpler projects like the user guide and Made with Wagtail, so register interest via the form rather than opening PRs, since nothing is confirmed until March 2027.


Updates to Django

Today, "Updates to Django" is presented by Raffaella from Djangonaut Space! 🚀

Last week we had 13 pull requests merged into Django by 11 different contributors - including 2 first-time contributors! Congratulations to Juliana Nicacio and Max Azatian for having their first commits merged into Django - welcome on board!

News in Django:


Articles

Django: serve apple-app-site-association and assetlinks.json

Adam Johnson follows his security.txt post with the files that let iOS and Android apps open your site's links (Universal Links and App Links) and use its saved passwords and passkeys. He covers the JSON content types, keeping /admin/ in the browser, caching, tests, and how to check what Apple and Google actually fetch.

Afterthoughts: Django Day Copenhagen 2026

A short post on attending this year's event and giving one of the talks.

Questions to Ask a Company Using Django

The 8 questions to ask any Django-based employer before joining their engineering team.

Building a small Django app with help from AI

Stein Ove Helset builds a small idea board and shows where AI earns its keep: first-draft templates and tests, plus reviewing a working vote view instead of being told to "make this better," which surfaces the race condition in votes += 1 that an F() expression fixes. His rule: treat AI code like a random Stack Overflow answer you are now responsible for, and never paste in real secrets.

How to deploy multiple Django projects on one server

Instead of a server per side project, give each one its own virtualenv and a Gunicorn process on its own local port (8001, 8002, and so on) kept alive by Supervisor, then let Nginx route by server_name. Each project can run a different Django version and database, and adding another is mostly a matter of repeating the steps.


Sponsored

Reach 4,300+ Engaged Django Developers

Sponsor this newsletter to reach an active community of Python and Django developers.


Django Fellow Reports

Django Fellow Report - Natalia

Natalia cleared the untriaged queue (10 tickets), reviewed the Sphinx compatibility changes and fixed related doc references, and reviewed support for Address objects as email addresses. On the security side, she reviewed a confirmed vulnerability and helped Jacob send pre-notifications for the October 6 release.

Django Fellow Report - Jacob

A heads-down week closing release blockers for 6.1.2: Jacob fixed UUID4() persisting uppercase hex on Oracle, filed tickets for JSONField __in lookups on primitives and iterating F("pk") hanging, repaired failing MySQL jobs on Jenkins, and sent the security pre-notifications.

Django Fellow Report - Sarah

From a holiday in Turkey, Sarah still opened PRs to allow multiline template tags and fix the tokenization of raw template blocks, reviewed the PR dropping GDAL 3.3 and 3.4, and worked on two security issues. Her following week was properly off: swimming and Turkish food.


Videos

Django Day Copenhagen 2026

The complete recording is up of this recent full day conference of Django goodness.

Week 6: Django Forms, Generic Views, and Database Interaction

Dr. Chuck Severance follows data from an HTML form to the database and back in this 25-minute course lecture: GET versus POST, CSRF protection, templates, and class-based and generic views, with the object-oriented inheritance behind them. It wraps up the guided tutorials before his students move on to more independent Django work.

Video Tour of Wagtail 8.0

An 11-minute walkthrough centered on version 3 of the Wagtail API, which can now publish, update, and organize content for automated and AI-agent workflows. It also covers custom base page models, the new permission policy registry, Django 6.1 support, and accessibility and image format improvements.

MCP server in Wagtail - experiments demo

A five-minute look at Wagtail's experimental MCP server: an agent built into the CMS, running DeepSeek V4 Flash with 50+ tools and no instructions on how to use them, doing content operations.


Django Job Board

A new junior developer opening at Softechassociate joins Proxify AB's two senior roles, one Python backend and one React/Node fullstack.

Junior Developer at Softechassociate 🆕

Senior Backend Developer (Python) at Proxify AB

Senior Fullstack Developer (React.js / Node.js) at Proxify AB


Projects

justinmayer/django-benchmark/

Django performance benchmark profiler.

derblub/django-upgrade-report

Point it at your lockfile and it asks PyPI which dependencies block your next Django upgrade, then names the smallest safe release for each in order: what to bump today, what has to ship with the Django bump, and what to check by hand. Run it with uvx django-upgrade-report, and use --fail-on to gate CI.


Sponsor Django News

Reach 4,300+ Django developers every Friday. See sponsorship details and rates.

09 Oct 2026 3:00pm GMT

08 Oct 2026

feedDjango community aggregator: Community blog posts

Django: set up its test suite with uv

When contributing to Django, you'll want to run its test suite to check your changes. The official contributing docs cover setup in Running the unit tests, using a virtual environment and pip. Here's an alternative guide using uv.

Setup

First, clone Django and change into the repository:

$ git clone https://github.com/django/django

$ cd django

(You can fork it later if you want to make a pull request.)

Then, create a virtual environment:

$ uv venv
Using CPython 3.14.6
Creating virtual environment at: .venv
Activate with: source .venv/bin/activate

uv automatically picks a compatible Python version for you, downloading one if needed.

Next, install Django in editable mode, plus the test requirements, in one command:

$ uv pip install -e . -r tests/requirements/py3.txt

uv pip automatically targets the .venv directory, so there's no need to activate it first.

Run the tests

Activate the virtual environment, change into the tests directory, and run runtests.py:

$ source .venv/bin/activate

$ cd tests

$ ./runtests.py
Testing against Django installed in '/.../django/django' with up to 8 processes
...

Skip pylibmc if it won't build

The test requirements include pylibmc, a memcached client that wraps the libmemcached C library. In my experience, it's the biggest sticking point when setting up Django's test suite, as installing pylibmc means compiling it, which means you need a C compiler and libmemcached's headers correctly installed. If the compilation fails, you'll see an error like:

src/_pylibmcmodule.h:42:10: fatal error: libmemcached/memcached.h: No such file or directory

Rather than fixing the environment, it's often easier to skip installing pylibmc entirely. This is safe because Django will skip any tests that require pylibmc, so you can still run the rest of the test suite.

The official docs suggest commenting out pylibmc's line in requirements/py3.txt, but that leaves you with a modified file to avoid committing. Instead, filter it out on the fly with grep -v and shell process substitution:

$ uv pip install -e . -r <(grep -v pylibmc tests/requirements/py3.txt)

Then run the tests as above, and Django will skip any that need pylibmc.

Fin

Now uv got a great base to contribute to Django!

-Adam

08 Oct 2026 4:00am GMT

07 Oct 2026

feedDjango community aggregator: Community blog posts

Questions to Ask a Company Using Django

Interview questions for your next job.

07 Oct 2026 11:57am GMT