← All stories
● Covered by 1 source · 1 reportLow impact1 neutral

Django Project Stops Accepting Security Reports via HackerOne

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Django no longer accepts new security reports on HackerOne.
  • Existing HackerOne reports will still be managed.
  • New security issues must be reported via email.
  • Email address for reports is security@djangoproject.com.

Change in Reporting Mechanism

The Django project has announced a change in its security vulnerability reporting process. As of this update, the project will no longer accept new security submissions through the HackerOne platform.

Handling Existing Reports

All security reports previously submitted via HackerOne will remain open. The Django Security Team will continue to manage and address these existing reports through the platform until their resolution.

New Reporting Procedure

Individuals who discover security issues in Django are now directed to follow the reporting process detailed in the official Django security policies. This process specifies that all new security concerns should be communicated by emailing security@djangoproject.com.

Impact on Researchers

This change primarily affects security researchers and developers who identify potential vulnerabilities in the Django framework. They must now use the designated email address for initial disclosure, rather than the HackerOne platform, to ensure their reports are received and processed by the Django Security Team.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 08

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Primary sources

GitHub django/django

Reporting from

The Django project has ceased accepting new security reports through the HackerOne platform. Users should now report security vulnerabilities directly via email to security@djangoproject.com, following the process outlined in Django's security policies.