Django 6.2 release notes - UNDER DEVELOPMENT#
Expected April 2027
Welcome to Django 6.2!
These release notes cover the new features, as well as some backwards incompatible changes you should be aware of when upgrading from Django 6.1 or earlier. We’ve begun the deprecation process for some features.
See the How to upgrade Django to a newer version guide if you’re updating an existing project.
Django 6.2 is designated as a long-term support release. It will receive security updates for at least three years after its release. Support for the previous LTS, Django 5.2, will end in April 2028.
Python compatibility#
Django 6.2 supports Python 3.12, 3.13 and 3.14. We highly recommend and only officially support the latest release of each series.
What’s new in Django 6.2#
Minor features#
django.contrib.admin#
…
django.contrib.admindocs#
…
django.contrib.auth#
The default iteration count for the PBKDF2 password hasher is increased from 1,500,000 to 1,800,000.
django.contrib.contenttypes#
…
django.contrib.gis#
…
django.contrib.messages#
…
django.contrib.postgres#
…
django.contrib.redirects#
…
django.contrib.sessions#
…
django.contrib.sitemaps#
…
django.contrib.sites#
…
django.contrib.staticfiles#
…
Asynchronous views#
…
Cache#
Subclasses of
BaseDatabaseCachenow support culling on a percentage of writes as an optimization. The default is 10%, and may be configured using theCULL_PROBABILITYoption.
CSP#
…
CSRF#
…
Database backends#
…
Decorators#
…
Email#
…
Error Reporting#
…
File Storage#
…
File Uploads#
…
Forms#
…
Generic Views#
…
Internationalization#
…
Logging#
…
Management Commands#
The new
listurlscommand lists the URLs from the project’s root URLconf, including the view class or function (and name, if present).The
makemigrationscommand now tracks all changes to unmanaged models, including field additions, removals, alterations, constraints, and model renames. After upgrading, you will see new migrations detected for unmanaged models that have changed since their creation.Whether to suppress an
ImportErrorescaping from a settings module is configurable by the newBaseCommand.requires_settingsattribute (defaultTrue). In previous versions, such errors were always suppressed.
Migrations#
…
Models#
…
Requests and Responses#
…
Security#
…
Serialization#
…
Signals#
…
Tasks#
…
Templates#
…
Tests#
force_login()now skips members ofAUTHENTICATION_BACKENDSnot implementing(a)get_user(), e.g. permission-only backends.
URLs#
…
Utilities#
utils.module_loading.import_string()now supports modules. Previously, top-level modules did not work, and submodules only worked if already imported.…
Validators#
…
Backwards incompatible changes in 6.2#
Database backend API#
This section describes changes that may be needed in third-party database backends.
…
Miscellaneous#
To facilitate the deprecation of the
safeparameter ofJsonResponse, it now defaults toFalse, because the pollution vulnerability in theArrayprototype was fixed in ES5.DjangoJSONEncodernow omits the millisecond component of serializeddatetime.datetimeanddatetime.timeobjects if they have zero milliseconds. For example,datetime.datetime(2000, 1, 1, 0, 0, 0, 1)now serializes to"2000-01-01T00:00:00"rather than"2000-01-01T00:00:00.000".utils.module_loading.import_string()now deterministically favors submodules in ambiguous cases where depending on prior import state, a same-named attribute of the parent module might have been returned instead.The minimum supported version of
asgirefis increased from 3.9.1 to 3.12.1.
Features deprecated in 6.2#
Miscellaneous#
The
MiddlewareMixinclass moved fromdjango.utils.deprecationtodjango.middleware. The old import path is deprecated.The
safeparameter is deprecated fromJsonResponse. Omitting the argument is equivalent to the priorsafe=Falseusage.Calling
QuerySet.aiterator()afterprefetch_related()without providing achunk_sizeis deprecated. It currently falls back to achunk_sizeof 2000, but aValueErrorwill be raised in Django 7.1.