Issue 357: Malcolm Tredinnick Prize Nominations and Django 6.2 Features
Nominations open for the Malcolm Tredinnick Memorial Prize, Python 3.10 reaches end of life, and the Django on the Med recaps roll in.
News
Nominate Someone for the 2026 Malcolm Tredinnick Memorial Prize
The annual prize honors someone who welcomes newcomers, freely helps others, and grows the community, with a stipend meant to fund travel to a DjangoCon, PyCon, or sprint. Nominate someone by October 15 (Anywhere on Earth).
Python 3.10.22, 3.11.17, 3.12.15, 3.13.16 and 3.14.8 are now available!
Security releases across all five series, with fixes for tarfile extraction filters, zipfile decompression bombs, and SSL hostname validation. Python 3.10.22 is the final 3.10 release, and 3.13.16 is the last full maintenance release of 3.13, so plan your upgrades.
Python Language Summit 2026
Seth Larson's writeups from the first summit held in Europe since 2011, where 47 core developers in Kraków covered free-threading, Rust for CPython, garbage collection, type manipulation, and an AGENTS.md for CPython. The summit will now alternate between PyCon US and EuroPython each year.
Updates to Django
Today, "Updates to Django" is presented by Raffaella from Djangonaut Space! 🚀
Last week we had 6 pull requests merged into Django by 5 different contributors
News in Django 6.2:
- The new
django.utils.asyncio.maybe_aclosingreturns a context manager that callsaclose()on a caller-provided iterator only if it defines one. - Support for GDAL 3.3 and 3.4 and for GEOS 3.10 is removed.
- Most Django-provided middleware now set
async_capable = Falseto avoid repetitive context switching inMiddlewareMixin.__acall__()under ASGI. For atypical use cases, e.g. high in-process concurrency over non-ORM I/O, where no thread is otherwise held, the repetitive context switching may be preferable to pinning a thread per request (seeasync_performance). Such deployments can restore the prior behavior by settingasync_capable = True; seeMiddlewareMixin <upgrading-middleware>.~django.contrib.auth.middleware.RemoteUserMiddlewareis unaffected, because it does not useMiddlewareMixin. Neither is~django.contrib.auth.middleware.LoginRequiredMiddlewarenordjango.contrib.admindocs.middleware.XViewMiddlewareaffected, as they did not implementprocess_request()orprocess_response().
Django Fellow Reports
Django Fellow Report - Jacob
When Paolo wasn’t otherwise showing us around Abruzzo last week at Django on the Med 🏖️, I had the pleasure of supporting a number of groups there, spanning:
- frontend topics (subresource integrity and importmaps)
- backend topics (temporal constraints and
django-subatomic) - performance topics (a benchmarking group kicked off, and Carlton Gibson got me to commit to auditing our free-threading readiness)
- documentation topics, and …, and …, and …
Special thanks to Anna and Simon for taking up my suggestion to pair on some delicate issues around NULL handling in the ORM. They each have PRs I’m excited to review, and the three of us now have more context for tackling whatever comes next in this area.
Django Fellow Report - Natalia
I was mostly OoO (out-of-office) this week due to 🌸 Spring break 🌼 in Uruguay. We travelled 🚗 to visit family and had a wonderful time, including multiple rounds of ice cream eating 🍦. I still prioritized attending the Security Team meeting and doing a release notes fix.
Sponsored
Reach 4,300+ Engaged Django Developers
Sponsor this newsletter to reach an active community of Python and Django developers.

Articles
Black Python Devs has a "New" website
Black Python Devs moved its website from Render Engine to Django and opened the repo, trading a project manager that cost about $1,000 a year for automated workflows (elections and award nominations already run there). Members can now create accounts and set notification preferences, and issues and PRs are welcome.
Django, arrosticini, and the Adriatic ... Django on The Med Pescara 2026
Valentino Gagliardi's sprint recap from Pescara, where a couple of coffees on day two turned into a proposal to replace QUnit with vitest for Django's admin and GIS JavaScript tests, with browser mode, coverage reporting, and accessibility-based selectors as a complement to the Playwright end-to-end work.
Start thinking about running for the Django Steering Council
Tim Schilling, speaking for himself rather than the Council, urges people to run in the next Steering Council election, which starts when Django 6.2 ships in April. DEP 19 now values teaching and community organizing alongside code, and his advice is to start writing publicly about your ideas now, since voters pick candidates they already know and trust.
Django: serve a security.txt file
A security.txt at /.well-known/security.txt (RFC 9116) tells researchers where to report vulnerabilities instead of guessing at addresses. Adam Johnson's view serves it as UTF-8 plain text, with tests that validate the required Contact and Expires fields and a system check that warns before Expires lapses without blocking your commands.
Show and hide Wagtail admin fields without writing any JavaScript
Tim Kamanin was about to write a web component to toggle between a page chooser and a URL field, then found Wagtail's built-in w-rules Stimulus controller already does it. Pass the data-w-rules attributes through a panel's attrs argument; hiding fields needs Wagtail 7.2 or newer.
Setting Up DNS for SaaS Emails
Five years of running a SaaS taught Aidas Bendoraitis to send marketing mail from a different subdomain than transactional and direct mail, so newsletter spam complaints don't drag down password resets. The guide walks through MX, SPF, DKIM, and DMARC records for each, with working examples for FastMail, Mailjet, and Brevo.
djust 1.2: More Django-Compatible, Much Faster
djust now runs Django's own template test suite against its Rust engine and passes 98.6% of it. Render time depends only on what a template reads, so the heaviest benchmark template dropped from 215 ms to 4.7 ms (Django takes about 9 ms), and the release adds class-level components and djust init for existing projects.
Sendgrid is bad at spending their marketing money
django-anymail has dropped official SendGrid support after Twilio SendGrid disabled the project's testing account in June 2025, leaving no way to run integration tests or triage SendGrid bugs. Frank Wiles puts the savings at roughly the cost of three LinkedIn ad clicks.
Rebuilding my development setup in 2026
Six weeks of rebuilding a setup so Claude Code keeps running with the laptop lid closed and can be checked from a phone: Ghostty with the herdr multiplexer, chezmoi-managed dotfiles, a Mac mini as the agent machine (with tailnet ACLs keeping it off production), and a fresh Docker Compose stack per git worktree.
Undocumented Django: Generating a SECRET_KEY
Not everything in Django is documented. This article showcases a "hidden" way to generate a new SECRET_KEY and provides general advice around keeping them actually, well, secret.
I don't write codebase documentation anymore
Instead of keeping docs current by hand, a GitHub Actions workflow runs a headless Claude Code session on every push to main and rewrites only the wiki pages that describe the changed files. One project now has a 95-page wiki with 67 Mermaid diagrams, read mostly by coding agents, and the post includes both files (a skill and a workflow) to copy.
Events
Django Day Copenhagen 2026
It is today, October 2nd! A full day of talks for the 6th edition of this event. You can participate online and in person so it's not too late.
My Django on the Med 2026 experience 🏖️
Former Djangonaut mentee Annabelle Wiegart has a lovely write-up of the recently concluded event, highlighting the magic that comes from actually having the right people together in the room to tackle new advances for Django.
Looking back at Django on the Med 🏖️ 2026
Matthias Kestenholz took the train from Zurich to Pescara and restarted his DEP for import maps in Django core, which let ES modules import stable names even as hashed static filenames change on every deploy. Firefox still can't handle multiple import maps, which is why he argues Django should merge them itself.
Podcasts
Real Python Podcast #312: Navigating AI in Open Source: Insights From Wagtail
Wagtail's Thibaud Colas and Meagen Voss explain how the project handles the flood of AI-assisted contributions, how they compare open-weight models and inference providers, and why Wagtail 8.0 aims to be a "CMS with AI, not AI CMS."
Django Chat #206: Django on the Med
Carlton and Will are back for the fall season. This episode discusses the recent Django on the Med event as well as Django news from the summer.
Videos
Django on the Med
The video version of Django Chat's 36-minute recap of the Pescara sprints, with links to everything discussed: DEP 19, DjangoCon Europe 2027 in Innsbruck, django-bgt, django-benchmark, and the open DEP pull requests that came out of the event.
Django Job Board
Proxify AB joins the board with two senior roles, Python backend and React/Node fullstack, alongside Django work at The Developer Society and The Cruise Brothers and machine learning at Provision.
Django Developer at The Developer Society
Senior Backend Developer (Python) at Proxify AB
Senior Fullstack Developer (React.js / Node.js) at Proxify AB
Machine Learning Engineer (Hybrid) at Provision
Django Developer at The Cruise Brothers
Projects
RegioHelden/django-scrubber
django_scrubber is a django app meant to help you anonymize your project's database data. It destructively alters data directly on the DB and therefore should not be used on production.
carltongibson/django-bgt
Django-orchestrated background threads for Python, built on bgt (a great way to reliably run background threads).
Sponsor Django News
Reach 4,300+ Django developers every Friday. See sponsorship details and rates.
