{"title":"How is Django Formed?","version":"5.0","locale":"el","docname":"internals/howto-release-django","url":"/el/5.0/internals/howto-release-django/","canonical":"https://djangodocs.dev/el/5.0/internals/howto-release-django/","summary":"This document explains how to release Django. Please, keep these instructions up-to-date if you make changes! The point here is to be descriptive, not prescriptive,…","html":"<h1>How is Django Formed?<a class=\"heading-anchor\" href=\"#how-is-django-formed\"><span class=\"visually-hidden\">Link to this heading</span><span aria-hidden=\"true\">#</span></a></h1>\n<p>This document explains how to release Django.</p>\n<p><strong>Please, keep these instructions up-to-date if you make changes!</strong> The point\nhere is to be descriptive, not prescriptive, so feel free to streamline or\notherwise make changes, but <strong>update this document accordingly!</strong></p>\n<section id=\"overview\">\n<h2>Overview<a class=\"heading-anchor\" href=\"#overview\"><span class=\"visually-hidden\">Link to this heading</span><span aria-hidden=\"true\">#</span></a></h2>\n<p>There are three types of releases that you might need to make:</p>\n<ul class=\"simple\">\n<li><p>Security releases: disclosing and fixing a vulnerability. This’ll\ngenerally involve two or three simultaneous releases – e.g.\n3.2.x, 4.0.x, and, depending on timing, perhaps a 4.1.x.</p></li>\n<li><p>Regular version releases: either a final release (e.g. 4.1) or a\nbugfix update (e.g. 4.1.1).</p></li>\n<li><p>Pre-releases: e.g. 4.2 alpha, beta, or rc.</p></li>\n</ul>\n<p>The short version of the steps involved is:</p>\n<ol class=\"arabic simple\">\n<li><p>If this is a security release, pre-notify the security distribution list\none week before the actual release.</p></li>\n<li><p>Proofread the release notes, looking for organization and writing errors.\nDraft a blog post and email announcement.</p></li>\n<li><p>Update version numbers and create the release package(s).</p></li>\n<li><p>Upload the package(s) to the <code class=\"docutils literal notranslate\">djangoproject.com</code> server.</p></li>\n<li><p>Verify package(s) signatures, check if they can be installed, and ensure\nminimal functionality.</p></li>\n<li><p>Upload the new version(s) to PyPI.</p></li>\n<li><p>Declare the new version in the admin on <code class=\"docutils literal notranslate\">djangoproject.com</code>.</p></li>\n<li><p>Post the blog entry and send out the email announcements.</p></li>\n<li><p>Update version numbers post-release.</p></li>\n</ol>\n<p>There are a lot of details, so please read on.</p>\n</section>\n<section id=\"prerequisites\">\n<h2>Prerequisites<a class=\"heading-anchor\" href=\"#prerequisites\"><span class=\"visually-hidden\">Link to this heading</span><span aria-hidden=\"true\">#</span></a></h2>\n<p>You’ll need a few things before getting started:</p>\n<ul>\n<li><p>A GPG key. If the key you want to use is not your default signing key, you’ll\nneed to add <code class=\"docutils literal notranslate\">-u you&#64;example.com</code> to every GPG signing command below, where\n<code class=\"docutils literal notranslate\">you&#64;example.com</code> is the email address associated with the key you want to\nuse. You will also need to add <code class=\"docutils literal notranslate\">-i you&#64;example.com</code> to the <code class=\"docutils literal notranslate\">twine</code> call.</p></li>\n<li><p>An install of some required Python packages:</p>\n<div class=\"code-block\" data-language=\"shell\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Shell</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Shell code\"><code>$ python -m pip install wheel twine\n</code></pre></div>\n</li>\n<li><p>Access to Django’s project on PyPI. Create a project-scoped token following\nthe <a class=\"reference external\" href=\"https://pypi.org/help/#apitoken\">official documentation</a> and set up\nyour <code class=\"docutils literal notranslate\">$HOME/.pypirc</code> file like this:</p>\n<figure class=\"code-block code-block-captioned\" data-language=\"ini\"><figcaption class=\"code-block-caption\"><code class=\"docutils literal notranslate\">~/.pypirc</code></figcaption>\n<div class=\"code-block-toolbar\"><span class=\"code-block-language\">Ini</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Ini code\"><code><span class=\"k\">[distutils]</span>\n  <span class=\"na\">index-servers</span> <span class=\"o\">=</span>\n    <span class=\"na\">pypi</span>\n    <span class=\"na\">django</span>\n\n<span class=\"k\">[pypi]</span>\n  <span class=\"na\">username</span> <span class=\"o\">=</span> <span class=\"s\">__token__</span>\n  <span class=\"na\">password</span> <span class=\"o\">=</span> <span class=\"c1\"># User-scoped or project-scoped token, to set as the default.</span>\n\n<span class=\"k\">[django]</span>\n  <span class=\"na\">repository</span> <span class=\"o\">=</span> <span class=\"s\">https://upload.pypi.org/legacy/</span>\n  <span class=\"na\">username</span> <span class=\"o\">=</span> <span class=\"s\">__token__</span>\n  <span class=\"na\">password</span> <span class=\"o\">=</span> <span class=\"c1\"># A project token.</span>\n</code></pre></figure>\n</li>\n<li><p>Access to the <code class=\"docutils literal notranslate\">djangoproject.com</code> server to upload files.</p></li>\n<li><p>Access to the admin on <code class=\"docutils literal notranslate\">djangoproject.com</code> as a «Site maintainer».</p></li>\n<li><p>Access to post to <code class=\"docutils literal notranslate\">django-announce</code>.</p></li>\n<li><p>If this is a security release, access to the pre-notification distribution\nlist.</p></li>\n</ul>\n<p>If this is your first release, you’ll need to coordinate with another releaser\nto get all these things lined up.</p>\n</section>\n<section id=\"pre-release-tasks\">\n<h2>Pre-release tasks<a class=\"heading-anchor\" href=\"#pre-release-tasks\"><span class=\"visually-hidden\">Link to this heading</span><span aria-hidden=\"true\">#</span></a></h2>\n<p>A few items need to be taken care of before even beginning the release process.\nThis stuff starts about a week before the release; most of it can be done\nany time leading up to the actual release:</p>\n<ol class=\"arabic\">\n<li><p>If this is a security release, send out pre-notification <strong>one week</strong> before\nthe release. The template for that email and a list of the recipients are in\nthe private <code class=\"docutils literal notranslate\">django-security</code> GitHub wiki. BCC the pre-notification\nrecipients. Sign the email with the key you’ll use for the release and\ninclude <a class=\"reference external\" href=\"https://cveform.mitre.org/\">CVE IDs</a> (requested with Vendor:\ndjangoproject, Product: django) and patches for each issue being fixed.\nAlso, <a class=\"reference internal\" href=\"/el/5.0/internals/security/#security-disclosure\"><span class=\"std std-ref\">notify django-announce</span></a> of the upcoming\nsecurity release.</p></li>\n<li><p>As the release approaches, watch Trac to make sure no release blockers\nare left for the upcoming release.</p></li>\n<li><p>Check with the other mergers to make sure they don’t have any uncommitted\nchanges for the release.</p></li>\n<li><p>Proofread the release notes, including looking at the online version to\n<a class=\"reference internal\" href=\"/el/5.0/internals/contributing/writing-documentation/#documentation-link-check\"><span class=\"std std-ref\">catch any broken links</span></a> or reST errors, and\nmake sure the release notes contain the correct date.</p></li>\n<li><p>Double-check that the release notes mention deprecation timelines\nfor any APIs noted as deprecated, and that they mention any changes\nin Python version support.</p></li>\n<li><p>Double-check that the release notes index has a link to the notes\nfor the new release; this will be in <code class=\"docutils literal notranslate\">docs/releases/index.txt</code>.</p></li>\n<li><p>If this is a feature release, ensure translations from Transifex have been\nintegrated. This is typically done by a separate translation’s manager\nrather than the releaser, but here are the steps. Provided you have an\naccount on Transifex:</p>\n<div class=\"code-block\" data-language=\"shell\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Shell</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Shell code\"><code>$ python scripts/manage_translations.py fetch\n</code></pre></div>\n<p>and then commit the changed/added files (both <code class=\"docutils literal notranslate\">.po</code> and <code class=\"docutils literal notranslate\">.mo</code>).\nSometimes there are validation errors which need to be debugged, so avoid\ndoing this task immediately before a release is needed.</p>\n</li>\n<li><p><a class=\"reference internal\" href=\"/el/5.0/internals/contributing/writing-documentation/#django-admin-manpage\"><span class=\"std std-ref\">Update the django-admin manual page</span></a>:</p>\n<div class=\"code-block\" data-language=\"shell\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Shell</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Shell code\"><code>$ <span class=\"nb\">cd</span> docs\n$ make man\n$ man _build/man/django-admin.1  <span class=\"c1\"># do a quick sanity check</span>\n$ cp _build/man/django-admin.1 man/django-admin.1\n</code></pre></div>\n<p>and then commit the changed man page.</p>\n</li>\n<li><p>If this is the alpha release of a new series, create a new stable branch\nfrom main. For example, when releasing Django 4.2:</p>\n<div class=\"code-block\" data-language=\"shell\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Shell</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Shell code\"><code>$ git checkout -b stable/4.2.x origin/main\n$ git push origin -u stable/4.2.x:stable/4.2.x\n</code></pre></div>\n<p>At the same time, update the <code class=\"docutils literal notranslate\">django_next_version</code> variable in\n<code class=\"docutils literal notranslate\">docs/conf.py</code> on the stable release branch to point to the new\ndevelopment version. For example, when creating <code class=\"docutils literal notranslate\">stable/4.2.x</code>, set\n<code class=\"docutils literal notranslate\">django_next_version</code> to <code class=\"docutils literal notranslate\">'5.0'</code> on the new branch.</p>\n</li>\n<li><p>If this is the «dot zero» release of a new series, create a new branch from\nthe current stable branch in the <a class=\"reference external\" href=\"https://github.com/django/django-docs-translations\">django-docs-translations</a> repository. For\nexample, when releasing Django 4.2:</p>\n<div class=\"code-block\" data-language=\"shell\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Shell</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Shell code\"><code>$ git checkout -b stable/4.2.x origin/stable/4.1.x\n$ git push origin stable/4.2.x:stable/4.2.x\n</code></pre></div>\n</li>\n</ol>\n</section>\n<section id=\"preparing-for-release\">\n<h2>Preparing for release<a class=\"heading-anchor\" href=\"#preparing-for-release\"><span class=\"visually-hidden\">Link to this heading</span><span aria-hidden=\"true\">#</span></a></h2>\n<p>Write the announcement blog post for the release. You can enter it into the\nadmin at any time and mark it as inactive. Here are a few examples: <a class=\"reference external\" href=\"https://www.djangoproject.com/weblog/2013/feb/19/security/\">example\nsecurity release announcement</a>, <a class=\"reference external\" href=\"https://www.djangoproject.com/weblog/2012/mar/23/14/\">example regular release announcement</a>,\n<a class=\"reference external\" href=\"https://www.djangoproject.com/weblog/2012/nov/27/15-beta-1/\">example pre-release announcement</a>.</p>\n</section>\n<section id=\"actually-rolling-the-release\">\n<h2>Actually rolling the release<a class=\"heading-anchor\" href=\"#actually-rolling-the-release\"><span class=\"visually-hidden\">Link to this heading</span><span aria-hidden=\"true\">#</span></a></h2>\n<p>OK, this is the fun part, where we actually push out a release!</p>\n<ol class=\"arabic\">\n<li><p>Check <a class=\"reference external\" href=\"https://djangoci.com\">Jenkins</a> is green for the version(s) you’re putting out. You\nprobably shouldn’t issue a release until it’s green.</p>\n</li>\n<li><p>A release always begins from a release branch, so you should make sure\nyou’re on a stable branch and up-to-date. For example:</p>\n<div class=\"code-block\" data-language=\"shell\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Shell</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Shell code\"><code>$ git checkout stable/4.1.x\n$ git pull\n</code></pre></div>\n</li>\n<li><p>If this is a security release, merge the appropriate patches from\n<code class=\"docutils literal notranslate\">django-security</code>. Rebase these patches as necessary to make each one a\nplain commit on the release branch rather than a merge commit. To ensure\nthis, merge them with the <code class=\"docutils literal notranslate\">--ff-only</code> flag; for example:</p>\n<div class=\"code-block\" data-language=\"shell\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Shell</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Shell code\"><code>$ git checkout stable/4.1.x\n$ git merge --ff-only security/4.1.x\n</code></pre></div>\n<p>(This assumes <code class=\"docutils literal notranslate\">security/4.1.x</code> is a branch in the <code class=\"docutils literal notranslate\">django-security</code> repo\ncontaining the necessary security patches for the next release in the 4.1\nseries.)</p>\n<p>If git refuses to merge with <code class=\"docutils literal notranslate\">--ff-only</code>, switch to the security-patch\nbranch and rebase it on the branch you are about to merge it into (<code class=\"docutils literal notranslate\">git\ncheckout security/4.1.x; git rebase stable/4.1.x</code>) and then switch back and\ndo the merge. Make sure the commit message for each security fix explains\nthat the commit is a security fix and that an announcement will follow\n(<a class=\"extlink-commit reference external\" href=\"https://github.com/django/django/commit/bf39978a53f117ca02e9a0c78b76664a41a54745\">example security commit</a>).</p>\n</li>\n<li><p>For a feature release, remove the <code class=\"docutils literal notranslate\">UNDER DEVELOPMENT</code> header at the\ntop of the release notes and add the release date on the next line. For a\npatch release, remove the <code class=\"docutils literal notranslate\">Expected</code> prefix and update the release date,\nif necessary. Make this change on all branches where the release notes for a\nparticular version are located.</p></li>\n<li><p>Update the version number in <code class=\"docutils literal notranslate\">django/__init__.py</code> for the release.\nPlease see <a class=\"reference internal\" href=\"#notes-on-setting-the-version-tuple\">notes on setting the VERSION tuple</a> below for details\non <code class=\"docutils literal notranslate\">VERSION</code>.</p></li>\n<li><p>If this is a pre-release package, update the «Development Status» trove\nclassifier in <code class=\"docutils literal notranslate\">setup.cfg</code> to reflect this. Otherwise, make sure the\nclassifier is set to <code class=\"docutils literal notranslate\">Development Status :: 5 - Production/Stable</code>.</p></li>\n<li><p>Tag the release using <code class=\"docutils literal notranslate\">git tag</code>. For example:</p>\n<div class=\"code-block\" data-language=\"shell\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Shell</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Shell code\"><code>$ git tag --sign --message<span class=\"o\">=</span><span class=\"s2\">&quot;Tag 4.1.1&quot;</span> <span class=\"m\">4</span>.1.1\n</code></pre></div>\n<p>You can check your work by running <code class=\"docutils literal notranslate\">git tag --verify &lt;tag&gt;</code>.</p>\n</li>\n<li><p>Push your work, including the tag: <code class=\"docutils literal notranslate\">git push --tags</code>.</p></li>\n<li><p>Make sure you have an absolutely clean tree by running <code class=\"docutils literal notranslate\">git clean -dfx</code>.</p></li>\n<li><p>Run <code class=\"docutils literal notranslate\">make -f extras/Makefile</code> to generate the release packages. This will\ncreate the release packages in a <code class=\"docutils literal notranslate\">dist/</code> directory.</p></li>\n<li><p>Generate the hashes of the release packages:</p>\n<div class=\"code-block\" data-language=\"shell\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Shell</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Shell code\"><code>$ <span class=\"nb\">cd</span> dist\n$ md5sum *\n$ sha1sum *\n$ sha256sum *\n</code></pre></div>\n</li>\n<li><p>Create a «checksums» file, <code class=\"docutils literal notranslate\">Django-&lt;&lt;VERSION&gt;&gt;.checksum.txt</code> containing\nthe hashes and release information. Start with this template and insert the\ncorrect version, date, GPG key ID (from\n<code class=\"docutils literal notranslate\">gpg --list-keys --keyid-format LONG</code>), release manager’s GitHub username,\nrelease URL, and checksums:</p>\n<div class=\"code-block\" data-language=\"text\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Text</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Text code\"><code>This file contains MD5, SHA1, and SHA256 checksums for the source-code\ntarball and wheel files of Django &lt;&lt;VERSION&gt;&gt;, released &lt;&lt;DATE&gt;&gt;.\n\nTo use this file, you will need a working install of PGP or other\ncompatible public-key encryption software. You will also need to have\nthe Django release manager&#39;s public key in your keyring. This key has\nthe ID ``XXXXXXXXXXXXXXXX`` and can be imported from the MIT\nkeyserver, for example, if using the open-source GNU Privacy Guard\nimplementation of PGP:\n\n    gpg --keyserver pgp.mit.edu --recv-key XXXXXXXXXXXXXXXX\n\nor via the GitHub API:\n\n    curl https://github.com/&lt;&lt;RELEASE MANAGER GITHUB USERNAME&gt;&gt;.gpg | gpg --import -\n\nOnce the key is imported, verify this file:\n\n    gpg --verify &lt;&lt;THIS FILENAME&gt;&gt;\n\nOnce you have verified this file, you can use normal MD5, SHA1, or SHA256\nchecksumming applications to generate the checksums of the Django\npackage and compare them to the checksums listed below.\n\nRelease packages\n================\n\nhttps://www.djangoproject.com/m/releases/&lt;&lt;MAJOR VERSION&gt;&gt;/&lt;&lt;RELEASE TAR.GZ FILENAME&gt;&gt;\nhttps://www.djangoproject.com/m/releases/&lt;&lt;MAJOR VERSION&gt;&gt;/&lt;&lt;RELEASE WHL FILENAME&gt;&gt;\n\nMD5 checksums\n=============\n\n&lt;&lt;MD5SUM&gt;&gt;  &lt;&lt;RELEASE TAR.GZ FILENAME&gt;&gt;\n&lt;&lt;MD5SUM&gt;&gt;  &lt;&lt;RELEASE WHL FILENAME&gt;&gt;\n\nSHA1 checksums\n==============\n\n&lt;&lt;SHA1SUM&gt;&gt;  &lt;&lt;RELEASE TAR.GZ FILENAME&gt;&gt;\n&lt;&lt;SHA1SUM&gt;&gt;  &lt;&lt;RELEASE WHL FILENAME&gt;&gt;\n\nSHA256 checksums\n================\n\n&lt;&lt;SHA256SUM&gt;&gt;  &lt;&lt;RELEASE TAR.GZ FILENAME&gt;&gt;\n&lt;&lt;SHA256SUM&gt;&gt;  &lt;&lt;RELEASE WHL FILENAME&gt;&gt;\n</code></pre></div>\n</li>\n<li><p>Sign the checksum file (<code class=\"docutils literal notranslate\">gpg --clearsign --digest-algo SHA256\nDjango-&lt;version&gt;.checksum.txt</code>). This generates a signed document,\n<code class=\"docutils literal notranslate\">Django-&lt;version&gt;.checksum.txt.asc</code> which you can then verify using <code class=\"docutils literal notranslate\">gpg\n--verify Django-&lt;version&gt;.checksum.txt.asc</code>.</p></li>\n</ol>\n<p>If you’re issuing multiple releases, repeat these steps for each release.</p>\n</section>\n<section id=\"making-the-release-s-available-to-the-public\">\n<h2>Making the release(s) available to the public<a class=\"heading-anchor\" href=\"#making-the-release-s-available-to-the-public\"><span class=\"visually-hidden\">Link to this heading</span><span aria-hidden=\"true\">#</span></a></h2>\n<p>Now you’re ready to actually put the release out there. To do this:</p>\n<ol class=\"arabic\">\n<li><p>Upload the release package(s) to the djangoproject server, replacing\nA.B. with the appropriate version number, e.g. 4.1 for a 4.1.x release:</p>\n<div class=\"code-block\" data-language=\"shell\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Shell</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Shell code\"><code>$ scp Django-* djangoproject.com:/home/www/www/media/releases/A.B\n</code></pre></div>\n<p>If this is the alpha release of a new series, you will need to create the\ndirectory A.B.</p>\n</li>\n<li><p>Upload the checksum file(s):</p>\n<div class=\"code-block\" data-language=\"shell\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Shell</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Shell code\"><code>$ scp Django-A.B.C.checksum.txt.asc djangoproject.com:/home/www/www/media/pgp/Django-A.B.C.checksum.txt\n</code></pre></div>\n</li>\n<li><p>Test that the release packages install correctly using <code class=\"docutils literal notranslate\">pip</code>. Here’s one\nmethod:</p>\n<div class=\"code-block\" data-language=\"shell\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Shell</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Shell code\"><code>$ <span class=\"nv\">RELEASE_VERSION</span><span class=\"o\">=</span><span class=\"s1\">&#39;4.1.1&#39;</span>\n$ <span class=\"nv\">MAJOR_VERSION</span><span class=\"o\">=</span><span class=\"sb\">`</span><span class=\"nb\">echo</span> <span class=\"nv\">$RELEASE_VERSION</span><span class=\"p\">|</span> cut -c <span class=\"m\">1</span>-3<span class=\"sb\">`</span>\n\n$ python -m venv django-pip\n$ . django-pip/bin/activate\n$ python -m pip install https://www.djangoproject.com/m/releases/<span class=\"nv\">$MAJOR_VERSION</span>/Django-<span class=\"nv\">$RELEASE_VERSION</span>.tar.gz\n$ deactivate\n$ python -m venv django-pip-wheel\n$ . django-pip-wheel/bin/activate\n$ python -m pip install https://www.djangoproject.com/m/releases/<span class=\"nv\">$MAJOR_VERSION</span>/Django-<span class=\"nv\">$RELEASE_VERSION</span>-py3-none-any.whl\n$ deactivate\n</code></pre></div>\n<p>This just tests that the tarballs are available (i.e. redirects are up) and\nthat they install correctly, but it’ll catch silly mistakes.</p>\n</li>\n<li><p>Run the <a class=\"reference external\" href=\"https://djangoci.com/job/confirm-release/\">confirm-release</a> build on Jenkins to verify the checksum file(s)\n(e.g. use <code class=\"docutils literal notranslate\">4.2rc1</code> for\n<a class=\"reference external\" href=\"https://media.djangoproject.com/pgp/Django-4.2rc1.checksum.txt\">https://media.djangoproject.com/pgp/Django-4.2rc1.checksum.txt</a>).</p>\n</li>\n<li><p>Upload the release packages to PyPI (for pre-releases, only upload the wheel\nfile):</p>\n<div class=\"code-block\" data-language=\"shell\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Shell</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Shell code\"><code>$ twine upload -s dist/*\n</code></pre></div>\n</li>\n<li><p>Go to the <a class=\"reference external\" href=\"https://www.djangoproject.com/admin/releases/release/add/\">Add release page in the admin</a>, enter the new release number\nexactly as it appears in the name of the tarball\n(<code class=\"docutils literal notranslate\">Django-&lt;version&gt;.tar.gz</code>). So for example enter «4.1.1» or «4.2rc1»,\netc. If the release is part of an LTS branch, mark it so.</p>\n<p>If this is the alpha release of a new series, also create a Release object\nfor the <em>final</em> release, ensuring that the <em>Release date</em> field is blank,\nthus marking it as <em>unreleased</em>. For example, when creating the Release\nobject for <code class=\"docutils literal notranslate\">4.2a1</code>, also create <code class=\"docutils literal notranslate\">4.2</code> with the Release date field blank.</p>\n</li>\n<li><p>Make the blog post announcing the release live.</p></li>\n<li><p>For a new version release (e.g. 4.1, 4.2), update the default stable version\nof the docs by flipping the <code class=\"docutils literal notranslate\">is_default</code> flag to <code class=\"docutils literal notranslate\">True</code> on the\nappropriate <code class=\"docutils literal notranslate\">DocumentRelease</code> object in the <code class=\"docutils literal notranslate\">docs.djangoproject.com</code>\ndatabase (this will automatically flip it to <code class=\"docutils literal notranslate\">False</code> for all\nothers); you can do this using the site’s admin.</p>\n<p>Create new <code class=\"docutils literal notranslate\">DocumentRelease</code> objects for each language that has an entry\nfor the previous release. Update djangoproject.com’s <a class=\"reference external\" href=\"https://github.com/django/djangoproject.com/blob/main/djangoproject/static/robots.docs.txt\">robots.docs.txt</a>\nfile by copying entries from <code class=\"docutils literal notranslate\">manage_translations.py robots_txt</code> from the\ncurrent stable branch in the <code class=\"docutils literal notranslate\">django-docs-translations</code> repository. For\nexample, when releasing Django 4.2:</p>\n<div class=\"code-block\" data-language=\"shell\"><div class=\"code-block-toolbar\"><span class=\"code-block-language\">Shell</span><button type=\"button\" class=\"copy-button\" data-copy hidden><span class=\"copy-button-label\">Copy</span></button></div><pre role=\"group\" tabindex=\"0\" aria-label=\"Shell code\"><code>$ git checkout stable/4.2.x\n$ git pull\n$ python manage_translations.py robots_txt\n</code></pre></div>\n</li>\n<li><p>Post the release announcement to the <a class=\"reference internal\" href=\"/el/5.0/internals/mailing-lists/#django-announce-mailing-list\"><span class=\"std std-ref\">django-announce</span></a>, <a class=\"reference internal\" href=\"/el/5.0/internals/mailing-lists/#django-developers-mailing-list\"><span class=\"std std-ref\">django-developers</span></a>,\n<a class=\"reference internal\" href=\"/el/5.0/internals/mailing-lists/#django-users-mailing-list\"><span class=\"std std-ref\">django-users</span></a> mailing lists, and the Django Forum. This should include a\nlink to the announcement blog post.</p></li>\n<li><p>If this is a security release, send a separate email to\n<a class=\"reference external\" href=\"mailto:oss-security&#37;&#52;&#48;lists&#46;openwall&#46;com\">oss-security<span>&#64;</span>lists<span>&#46;</span>openwall<span>&#46;</span>com</a>. Provide a descriptive subject, for example,\n«Django» plus the issue title from the release notes (including CVE ID). The\nmessage body should include the vulnerability details, for example, the\nannouncement blog post text. Include a link to the announcement blog post.</p></li>\n<li><p>Add a link to the blog post in the topic of the <code class=\"docutils literal notranslate\">#django</code> IRC channel:\n<code class=\"docutils literal notranslate\">/msg chanserv TOPIC #django new topic goes here</code>.</p></li>\n</ol>\n</section>\n<section id=\"post-release\">\n<h2>Post-release<a class=\"heading-anchor\" href=\"#post-release\"><span class=\"visually-hidden\">Link to this heading</span><span aria-hidden=\"true\">#</span></a></h2>\n<p>You’re almost done! All that’s left to do now is:</p>\n<ol class=\"arabic simple\">\n<li><p>Update the <code class=\"docutils literal notranslate\">VERSION</code> tuple in <code class=\"docutils literal notranslate\">django/__init__.py</code> again,\nincrementing to whatever the next expected release will be. For\nexample, after releasing 4.1.1, update <code class=\"docutils literal notranslate\">VERSION</code> to\n<code class=\"docutils literal notranslate\">VERSION = (4, 1, 2, 'alpha', 0)</code>.</p></li>\n<li><p>Add the release in <a class=\"reference external\" href=\"https://code.djangoproject.com/admin/ticket/versions\">Trac’s versions list</a> if necessary (and make it the\ndefault by changing the <code class=\"docutils literal notranslate\">default_version</code> setting in the\ncode.djangoproject.com’s <a class=\"reference external\" href=\"https://github.com/django/code.djangoproject.com/blob/main/trac-env/conf/trac.ini\">trac.ini</a>, if it’s a final release). The new X.Y\nversion should be added after the alpha release and the default version\nshould be updated after «dot zero» release.</p>\n</li>\n<li><p>If it’s a final release, update the current stable branch and remove the\npre-release branch in the <a class=\"reference external\" href=\"https://code.djangoproject.com/#Djangoreleaseprocess\">Django release process</a> on Trac.</p></li>\n<li><p>If this was a security release, update <a class=\"reference internal\" href=\"/el/5.0/releases/security/\"><span class=\"doc\">Archive of security issues</span></a> with\ndetails of the issues addressed.</p></li>\n</ol>\n</section>\n<section id=\"new-stable-branch-tasks\">\n<h2>New stable branch tasks<a class=\"heading-anchor\" href=\"#new-stable-branch-tasks\"><span class=\"visually-hidden\">Link to this heading</span><span aria-hidden=\"true\">#</span></a></h2>\n<p>There are several items to do in the time following the creation of a new\nstable branch (often following an alpha release). Some of these tasks don’t\nneed to be done by the releaser.</p>\n<ol class=\"arabic simple\">\n<li><p>Create a new <code class=\"docutils literal notranslate\">DocumentRelease</code> object in the <code class=\"docutils literal notranslate\">docs.djangoproject.com</code>\ndatabase for the new version’s docs, and update the\n<code class=\"docutils literal notranslate\">docs/fixtures/doc_releases.json</code> JSON fixture, so people without access\nto the production DB can still run an up-to-date copy of the docs site.</p></li>\n<li><p>Create a stub release note for the new feature version. Use the stub from\nthe previous feature release version or copy the contents from the previous\nfeature version and delete most of the contents leaving only the headings.</p></li>\n<li><p>Increase the default PBKDF2 iterations in\n<code class=\"docutils literal notranslate\">django.contrib.auth.hashers.PBKDF2PasswordHasher</code> by about 20%\n(pick a round number). Run the tests, and update the 3 failing\nhasher tests with the new values. Make sure this gets noted in the\nrelease notes (see the 4.1 release notes for an example).</p></li>\n<li><p>Remove features that have reached the end of their deprecation cycle. Each\nremoval should be done in a separate commit for clarity. In the commit\nmessage, add a «refs #XXXX» to the original ticket where the deprecation\nbegan if possible.</p></li>\n<li><p>Remove <code class=\"docutils literal notranslate\">.. versionadded::</code>, <code class=\"docutils literal notranslate\">.. versionadded::</code>, and <code class=\"docutils literal notranslate\">.. deprecated::</code>\nannotations in the documentation from two releases ago. For example, in\nDjango 4.2, notes for 4.0 will be removed.</p></li>\n<li><p>Add the new branch to <a class=\"reference external\" href=\"https://readthedocs.org/projects/django/\">Read the Docs</a>. Since the automatically\ngenerated version names («stable-A.B.x») differ from the version names\nused in Read the Docs («A.B.x»), <a class=\"reference external\" href=\"https://github.com/readthedocs/readthedocs.org/issues/5537\">create a ticket</a> requesting\nthe new version.</p></li>\n<li><p><a class=\"reference external\" href=\"https://github.com/pypa/trove-classifiers/issues/29\">Request the new classifier on PyPI</a>. For example\n<code class=\"docutils literal notranslate\">Framework :: Django :: 3.1</code>.</p></li>\n<li><p>Update the current branch under active development and add pre-release\nbranch in the <a class=\"reference external\" href=\"https://code.djangoproject.com/#Djangoreleaseprocess\">Django release process</a> on Trac.</p></li>\n</ol>\n</section>\n<section id=\"notes-on-setting-the-version-tuple\">\n<h2>Notes on setting the VERSION tuple<a class=\"heading-anchor\" href=\"#notes-on-setting-the-version-tuple\"><span class=\"visually-hidden\">Link to this heading</span><span aria-hidden=\"true\">#</span></a></h2>\n<p>Django’s version reporting is controlled by the <code class=\"docutils literal notranslate\">VERSION</code> tuple in\n<code class=\"docutils literal notranslate\">django/__init__.py</code>. This is a five-element tuple, whose elements\nare:</p>\n<ol class=\"arabic simple\">\n<li><p>Major version.</p></li>\n<li><p>Minor version.</p></li>\n<li><p>Micro version.</p></li>\n<li><p>Status – can be one of «alpha», «beta», «rc» or «final».</p></li>\n<li><p>Series number, for alpha/beta/RC packages which run in sequence\n(allowing, for example, «beta 1», «beta 2», etc.).</p></li>\n</ol>\n<p>For a final release, the status is always «final» and the series\nnumber is always 0. A series number of 0 with an «alpha» status will\nbe reported as «pre-alpha».</p>\n<p>Some examples:</p>\n<ul class=\"simple\">\n<li><p><code class=\"docutils literal notranslate\">(4, 1, 1, &quot;final&quot;, 0)</code> → «4.1.1»</p></li>\n<li><p><code class=\"docutils literal notranslate\">(4, 2, 0, &quot;alpha&quot;, 0)</code> → «4.2 pre-alpha»</p></li>\n<li><p><code class=\"docutils literal notranslate\">(4, 2, 0, &quot;beta&quot;, 1)</code> → «4.2 beta 1»</p></li>\n</ul>\n</section>","rootId":"how-is-django-formed","toc":[{"title":"Overview","anchor":"overview","children":[]},{"title":"Prerequisites","anchor":"prerequisites","children":[]},{"title":"Pre-release tasks","anchor":"pre-release-tasks","children":[]},{"title":"Preparing for release","anchor":"preparing-for-release","children":[]},{"title":"Actually rolling the release","anchor":"actually-rolling-the-release","children":[]},{"title":"Making the release(s) available to the public","anchor":"making-the-release-s-available-to-the-public","children":[]},{"title":"Post-release","anchor":"post-release","children":[]},{"title":"New stable branch tasks","anchor":"new-stable-branch-tasks","children":[]},{"title":"Notes on setting the VERSION tuple","anchor":"notes-on-setting-the-version-tuple","children":[]}],"breadcrumbs":[{"docname":"internals/index","title":"Django internals","url":"/el/5.0/internals/"}],"prev":{"docname":"internals/git","title":"The Django source code repository","url":"/el/5.0/internals/git/"},"next":null,"formats":{"html":"/el/5.0/internals/howto-release-django/","markdown":"/el/5.0/internals/howto-release-django.md","json":"/el/5.0/internals/howto-release-django.json"},"source":"https://github.com/django/django/blob/stable/5.0.x/docs/internals/howto-release-django.txt","official":"https://docs.djangoproject.com/el/5.0/internals/howto-release-django/","inVersions":["6.1","6.0","5.2","5.1","5.0","4.2","4.1","4.0","3.2","3.1","3.0","2.2","2.1","2.0","1.11","1.10"],"inLocales":["en","zh-hans","fr","ja","id","it","pt-br","ko","es","el","pl"]}