Django community: RSS
This page, updated regularly, aggregates Community blog posts from the Django community.
-
Questions to Ask a Company Using Django
Interview questions for your next job. -
Math-grounded APIs
Some types arrive with their operations already specified — by mathematics. If a type is a number, a set, or a sequence, math has written the complete API for us; the work is to implement it, and to implement it efficiently. -
Python 3.10, Django 4.2 and Node.js 20 Are Out of Support: What to Do Now
Django 4.2, Node.js 20, Amazon Linux 2, RDS MySQL 8.0 and Python 3.10 all reached end of support in 2026, with PostgreSQL 14 next. Here are the dates, what they mean, and the upgrade order we use. -
Python 3.10, Django 4.2 and Node.js 20 Are Out of Support: What to Do Now
Django 4.2, Node.js 20, Amazon Linux 2, RDS MySQL 8.0 and Python 3.10 all reached end of support in 2026, with PostgreSQL 14 next. Here are the dates, what they mean, and the upgrade order we use. -
Issue 357: Malcolm Tredinnick Prize Nominations and Django 6.2 Features
News Nominate Someone for the 2026 Malcolm Tredinnick Memorial Prize The annual prize honors someone who welcomes newcomers, freely helps others, and grows the community, with a stipend meant to fund travel to a DjangoCon, PyCon, or sprint. Nominate someone by October 15 (Anywhere on Earth). Python 3.10.22, 3.11.17, 3.12.15, 3.13.16 and 3.14.8 are now available! Security releases across all five series, with fixes for tarfile extraction filters, zipfile decompression bombs, and SSL hostname validation. Python 3.10.22 is the final 3.10 release, and 3.13.16 is the last full maintenance release of 3.13, so plan your upgrades. Python Language Summit 2026 Seth Larson's writeups from the first summit held in Europe since 2011, where 47 core developers in Kraków covered free-threading, Rust for CPython, garbage collection, type manipulation, and an AGENTS.md for CPython. The summit will now alternate between PyCon US and EuroPython each year. Updates to Django Today, "Updates to Django" is presented by Raffaella from Djangonaut Space! 🚀 Last week we had 6 pull requests merged into Django by 5 different contributors News in Django 6.2: The new django.utils.asyncio.maybe_aclosing returns a context manager that calls aclose() on a caller-provided iterator only if it defines one. Support for GDAL 3.3 … -
Django: serve apple-app-site-association and assetlinks.json
If your site has companion Apple or Android apps, you probably want links to your site to open in those apps, when installed. Both platforms support this, with Apple calling the feature Universal Links and Android calling it App Links. But an app can’t just claim to handle your links, or any malicious app could hijack them. Instead, both platforms require two-way association: the app declares which domains it handles, and each domain confirms which apps may handle its links. The domain’s side of that handshake is a JSON file served under the reserved /.well-known/ path, one per platform: /.well-known/apple-app-site-association for iOS, iPadOS, and macOS. /.well-known/assetlinks.json for Android. These files can do more than link handling. Both can also associate apps with your site for password autofill and passkeys, so users can sign in to your apps with credentials saved from your site. In this post, we’ll look at serving these two files from Django, with tests. It follows the same pattern as my recent post on serving a security.txt file, but with JSON and a few gotchas covered below. Write the Apple file Here’s an example apple-app-site-association file, following Apple’s documentation: { "applinks": { "details": [ { "appIDs": ["ABCDE12345.com.example.app"], … -
Undocumented Django: Generating a SECRET_KEY
Django has some of the best documentation out there, a point of pride from the beginning that continues today thanks to the heroic efforts of many volunteers. But for all … -
Django: serve a security.txt file
When a security researcher finds a vulnerability in your site, they need a way to tell you about it. Without a clear contact, they may resort to guessing at addresses like security@<yourdomain>, messaging random folks on social media, or give up. And of course, in the worst case, they might just publish the details, leaving you to find out when attackers do. security.txt is a web standard to fix this problem. It’s a small text file, served at the reserved path /.well-known/security.txt, that says how to report security issues to your organization. It was standardized in April 2022 as RFC 9116. In this post, we’ll look at serving a security.txt file and adding unit tests and a system check to keep it current. Write the file A security.txt file contains a series of Field: value lines, plus optional comments starting with #. Here’s an example: # Security contact information for example.com Contact: mailto:security@example.com Expires: 2027-09-01T00:00:00Z Preferred-Languages: en Canonical: https://example.com/.well-known/security.txt Policy: https://example.com/security/ The two required fields are: Contact: Gives a way to reach you, as a URI. That’s normally a mailto: email address, but it can also be an https: URL for a web page or form, or a tel: phone … -
Weeknotes (2026 week 40)
Weeknotes (2026 week 40) I have been at Django on the Med 🏖️ and already wrote a lengthy post about that. I did a lot of work on a DEP for adding import map support to Django which is currently also being discussed on the forum. Apart from that I’m not going to repeat anything from the post linked above, so check it out if you want to know more. Motivated by a discussion I had at the sprint I also improved my release process. I now have a make-release script in my dotfiles which updates the CHANGELOG with the version, bumps the version itself in the repo and commits and tags the release. The rest is handled by trusted publishing. I’m now finally also properly handling patch releases so that you don’t have to check the history to know what’s in a patch release. I already did that for minor and major version bumps, but was a bit too lazy. Now I can be even lazier and still more correct, and it feels great. Next, I refactored the static site generator script for this blog to be much faster. I now do not have to wait when saving before … -
Django on the Med
🔗 LinksDjango on the MedNew technical governance approved (DEP 19)Executive director search extendedDjangoCon Europe 2027 (Innsbruck, Austria)django-bgtdjango-benchmarkOpen DEPs pull requests from Django on the Med📚 BooksThe Narrow Road to the Deep North and Other Travel Sketches by Matsuo BashoThe Wall by Marlen Hausofer🎥 YouTubeYouTube Channel: @djangochat -
Rebuilding my development setup in 2026
It's been another busy month and I have been promising myself that I would write about what has been this yet unfinished rabbit hole of my spare time for the last 6 weeks. It's unfinished as I am yet to test the biggest hypothesis of this article, however let's start at the beginning. It started with a desire to more easily review code Claude was generating from my phone, before it got committed to git, before being pushed to Github. At a similar time Jeff publish his article of how he works from anywhere and I also listened to a podcast which peaked my interest in Ghostty as a potential replacement to iTerm2. Finally I was getting slightly frustrated with that Claude would stop running anytime I closed my laptop lid. This generated my current hypothesis, could I create a setup that would work for me personally where I could run Claude anytime and access it from anywhere. This is the rabbit hole I jumped down and started a very long conversation with Claude Fable where I considered other terminal emulators, I gave it Jeff's article and we were off to the races with some trials using my laptop from … -
I don't write codebase documentation anymore
Hello everyone 👋 Confession time: in 10+ years of writing software, I have never kept documentation up to date. Not once. And I’ve tried! Confluence spaces, GitHub wikis, a docs/ folder, READMEs that start strong and stop being true three sprints later. It always goes the same way. Someone writes a nice page, the code moves, nobody touches the page, and six months later a new person reads it, believes it, and loses an afternoon. Updating docs always felt like a chore I owed someone, and I pay chores about as reliably as you’d expect. A while back I started reading some really cool wikis that a paid AI service had generated for a few projects. Architecture overviews, flow diagrams, a page for every subsystem, all built from the code. I loved them. What I didn’t love was that they lived on someone else’s platform, and I couldn’t shape what they said or how they said it. So I thought: I want my own. In my repo, in plain markdown, maintained by an agent, updated on every push. So I built it. One of my projects now has a 95-page wiki: about 134,000 words and 67 Mermaid diagrams. I didn’t … -
The cost of dependencies
Adding a dependency takes one line in a manifest, and someone else’s hard problem is solved. With that line we also take on their bugs, their security holes, their release schedule, and their own dependencies, for as long as our code lives. The cost is small while we write the code and grows once the system is in production and users ask for changes. I have watched teams take whatever was available to keep moving, some on principle, and pay for it in maintenance. So a dependency should be chosen on purpose, after an evaluation. Let’s look at what it costs, and then at how to evaluate one. -
Looking back at Django on the Med 🏖️ 2026
Looking back at Django on the Med 🏖️ 2026 I haven’t been to a programming conference in a really long time. That was mostly due to laziness, wanting to stay at home and decision fatigue because I didn’t know how to travel sustainably and didn’t know where to stay during the conference. I had been talking online to Carlton for some time and when Django on the Med 🏖️ 2026 was announced I knew I had to go. What’s not to like about a conference in Italy with all the good food and the Mediterranean Sea? I managed to overcome my inner Schweinehund (the German term for the lazy voice in your head that tells you to stay on the couch) and reserved both the (free) ticket for the conference itself and also the train ticket to go from Zurich to Pescara. The train takes 8 or 9 hours depending on the connection with a single change in Milano. The conference itself consists only of development sprints and socialising – no talks and nothing to prepare in advance for participants, except taking the computer with you and optionally having some ideas about what you want to work on. The import … -
Show and hide Wagtail admin fields without writing any JavaScript
Oh boy, I love Wagtail. Haven't I said this too many times on this blog? I recently built a small promo banner for a client's Wagtail site. The editor form was simple: some text, a button label, and a "Button links to" radio with two options, "Page" or "External URL". … Read now -
Nice schedule for upcoming Pycon NL
In 2.5 weeks (Thursday 15 October), I'll attend the Pycon NL one-day conference in Utrecht. Always a friendly conference with some good speakers. I just took a look at the talks schedule and got pretty excited. A talk about 3D, point clouds etc and how to process it with Python: useful for the company I work for. I'll attend the practical observability talk: we do observe and we have lots of metrics, but really tying everything together, especially with our Python apps, still needs some work. Of course there are some talks, scheduled at the same time, that both look useful. "New static security scanner" versus "practical software architecture" for instance. "Zero-downtime multi-tenancy in Django" pushes a lots of buttons for me :-) The talk before it looks like it will explain some theoretical background behind "data models", with a bit of LLM explanation included. That might help me understand it all better (I'm not using LLMs myself). "Resumable Python pipelines" hopefully broadens my view a bit. We're using the Prefect task runner a lot within the company (I even gave a talk about it at PyGrunn and at two meetups). Recently, I've started using Django's new "django-tasks" framework. So... … -
Python: join my meetup in Lisbon, 8th October
I previously announced my Python optimization workshop in Lisbon, on 10th October (which still has a few places). I am now pleased to add a Python/Django meetup on the Thursday before. Here are the details: What: Python/Django meetup When: Thursday 8th October 2026, 18:00–20:00 Where: Terrace Restaurant, Praça Príncipe Perfeito, Lisbon Cost: Free Register on Luma Join us for an informal evening discussing Python, Django, and related topics (AI will surely come up). This meetup is hosted by Adam Johnson, a Django contributor, blogger, and author of four technical books (on Django, Git, and GitHub). There won’t be any talks scheduled at this event, just relaxed conversation around the core topics of software engineering and improving developer experience. Come with questions, topics of interest, or just an interest in meeting other like-minded engineers. Drinks are available to purchase from the venue. Places are limited to keep the evening small and conversational. Fin I hope to see you there, —Adam -
Setting Up DNS for SaaS Emails
When you create a Software as a Service (SaaS) or a social web platform, one of the often-overlooked parts of it is the email DNS configuration. I learned this too late with my own projects, and as a result, many of my initial emails landed in spam folders. Here are my learnings about it from 5 years of running a SaaS business. Consider using separate subdomains for different types of email The emails you send generally fall into these categories: direct - emails that you send manually. transactional - emails that your website sends for signup confirmations, two-factor authentications, password resets, etc. marketing - onboarding emails, mailing-list newsletters, birthday greetings, etc. Marketing emails are frequent and not always wanted, so recipients may mark them as spam, which can hurt your sender reputation. Deliverability also depends on factors such as authentication, engagement, list quality, and sending practices (You can check your existing email spamminess at SpamHaus or MxToolbox). For this reason, it can be useful to separate marketing emails from direct and transactional emails using different subdomains. If example.com is your marketing website, and app.example.com is your SaaS, your main emails could be: info@hello.example.com - for marketing / newsletters hello@mail.example.com - … -
djust 1.2: More Django-Compatible, Much Faster
djust 1.2 passes 98.6% of Django's own template test suite, renders loop-heavy templates up to 45x faster than earlier releases, and adds class-level components, djust init and component-level testing. -
Issue 356: New technical governance approved for Django
News PyCon US 2026 Recap and Recordings All PyCon US 2026 talks are now on YouTube, along with a highlight reel and a full recap of the first year in Long Beach, which drew 1,901 attendees from 58 countries. PyCon US 2027 returns to Long Beach, May 12-18. DSF member of the month - Ken Whitesell Forty-five years a developer, now retired and answering forum questions so the core team doesn't have to, which he counts as a contribution in itself. He builds browser-based board game engines with Channels and HTMX, and his advice fits on a sticker: don't fight the framework. Django Software Foundation New Technical Governance Approved The Steering Council and the DSF Board both approved DEP 19, which simplifies Django's technical governance and swaps narrow eligibility rules for a broad set of qualities a Steering Council member might have. Documentation updates come next. Proposed change to DSF voting membership Quorum is currently measured against every member on the rolls, which only gets harder to reach as membership grows. The proposal counts members who voted in the last two years, lets everyone else opt in, and takes nobody off the rolls. Comment by October 7. Wagtail News Experiments … -
DjangoCon Chicago 2026 Highlights
DjangoCon US returned to Chicago in 2026, bringing together members of the Django community for a week of learning, connection, and collaboration. I caught up with a few members of the Caktus team to hear about their favorite talks and takeaways from this year’s conference. -
Generalization as discipline
General code comes out better than code cut to fit one job, and its authors are the first to benefit. When we cannot afford all of it, the way down runs against instinct: work out the ideal shape first, then cut what today does not need, and keep a plan for putting it back. -
First Aid Kits: Bleeding Control & Tourniquets
Should you put a tourniquet in your first aid kit? Maybe, but you should know some things before you do: Training is more important than any piece of gear. Most bleeds can be stopped with direct pressure and/or proper wound packing — and both can be done with your hands and any old piece of fabric you have lying around. If you don’t know what “direct pressure” or “wound packing” means, or if you want to practice, take a course! A Stop The Bleed course is an excellent investment, and will go into all forms of bleeding control (including how to properly apply a tourniquet.) Most basic first aid courses will also cover bleeding control to some extent, though wilderness-oriented courses (for example, Wilderness First Aid) will typically go into more depth. (These are US-oriented suggestions; readers from other areas, I’d love for you to get in touch and let me know the equivalents in your country.) Once you do take that training, you’ll learn that the most important supplies for bleeding control are gloves, a stretchy bandage and plenty of gauze. Get those first, then think about other supplies. You probably don’t need a tourniquet in your first aid … -
Python: join my optimization workshop in Lisbon, 10th October
I’m running a workshop in Lisbon next month, and you’re invited! It’s a small, in-person, hands-on session on optimizing Python code, with a Django flavour. Here are the details: What: Python optimization workshop When: Saturday 10th October 2026, 10:00–13:00 Where: Martinhal Lisbon Oriente, Parque das Nações, Lisbon. Cost: Free, but places are limited and registration is required Size: Up to 10 people Led by: Myself, Adam Johnson Organised by: Mafalda Marques Register on Luma What we’ll do In my experience, Python projects often have some easy performance improvements waiting to be found, from client projects to large open source projects like Django itself. This workshop is designed to teach you how to find the hot spots worth optimizing, using these three tools in a loop: Capture a profile with cProfile, Python’s built-in profiler. Drill into it with profiling-explorer, to find where the time actually goes. Prove your change worked with tprof, which measures just the functions you care about and can compare before against after. I’ll teach the loop end-to-end on a real example. Then we’ll spend most of the morning using it for real, and you can pick your target: Django itself. I’ll bring a small collection of potential … -
Issue 355: DjangoCon Europe 2027 in Innsbruck and Django Probe
News Executive Director Search Extended to September 22 You don't need to be a Django or Python expert, or already part of the community, to apply for the DSF's first Executive Director role. Applications now close September 22, anywhere on Earth. DjangoCon Europe 2027 is heading to Innsbruck, Austria! 🏔️⛷️🚠🇦🇹 Tickets are on sale and the Call for Proposals is open for five days of Django, Python, and community in Innsbruck, February 17 to 21, 2027. Django Software Foundation DSF Board monthly meeting, Sept 10, 2026 The board approved DEP 0019, discussed next steps in their Executive Director search, committed to funding Djangonaut Space for the next three years, later launched a new corporate sponsorship page, and more. Python Software Foundation Announcing the 2026 PSF Board Election Results! Elaine Wong, Laís Carvalho, Ee Durbin, and Georgi Ker take the four open board seats out of 670 ballots cast, as Cheuk Ting Ho, Chris Neugebauer, and Denny Perez finish their terms. Announcing the 2026 Python Packaging Council Election Results! The first Python Packaging Council is seated: Brett Cannon and Pradyun Gedam on two-year terms, Donald Stufft, Henry Schreiner, and Ralf Gommers on one-year terms, so roughly half the council turns over …