The Django project has announced a change in its security vulnerability reporting process. As of this update, the project will no longer accept new security submissions through the HackerOne platform.
All security reports previously submitted via HackerOne will remain open. The Django Security Team will continue to manage and address these existing reports through the platform until their resolution.
Individuals who discover security issues in Django are now directed to follow the reporting process detailed in the official Django security policies. This process specifies that all new security concerns should be communicated by emailing security@djangoproject.com.
This change primarily affects security researchers and developers who identify potential vulnerabilities in the Django framework. They must now use the designated email address for initial disclosure, rather than the HackerOne platform, to ensure their reports are received and processed by the Django Security Team.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Django project has ceased accepting new security reports through the HackerOne platform. Users should now report security vulnerabilities directly via email to security@djangoproject.com, following the process outlined in Django's security policies.