Django 6.2 release notes - UNDER DEVELOPMENTLink to this heading

Expected April 2027

Welcome to Django 6.2!

These release notes cover the new features, as well as some backwards incompatible changes you should be aware of when upgrading from Django 6.1 or earlier. We’ve begun the deprecation process for some features.

See the How to upgrade Django to a newer version guide if you’re updating an existing project.

Django 6.2 is designated as a long-term support release. It will receive security updates for at least three years after its release. Support for the previous LTS, Django 5.2, will end in April 2028.

Python compatibilityLink to this heading

Django 6.2 supports Python 3.12, 3.13 and 3.14. We highly recommend and only officially support the latest release of each series.

What’s new in Django 6.2Link to this heading

Minor featuresLink to this heading

django.contrib.adminLink to this heading

django.contrib.admindocsLink to this heading

django.contrib.authLink to this heading

  • The default iteration count for the PBKDF2 password hasher is increased from 1,500,000 to 1,800,000.

django.contrib.contenttypesLink to this heading

django.contrib.gisLink to this heading

  • DataSource now preserves millisecond precision when reading time and datetime fields.

django.contrib.messagesLink to this heading

django.contrib.postgresLink to this heading

django.contrib.redirectsLink to this heading

django.contrib.sessionsLink to this heading

django.contrib.sitemapsLink to this heading

django.contrib.sitesLink to this heading

django.contrib.staticfilesLink to this heading

django.contrib.syndicationLink to this heading

Asynchronous viewsLink to this heading

CacheLink to this heading

  • Subclasses of BaseDatabaseCache now support culling on a percentage of writes as an optimization. The default is 10%, and may be configured using the CULL_PROBABILITY option.

CSPLink to this heading

CSRFLink to this heading

Database backendsLink to this heading

DecoratorsLink to this heading

EmailLink to this heading

Error ReportingLink to this heading

File StorageLink to this heading

File UploadsLink to this heading

FormsLink to this heading

Generic ViewsLink to this heading

InternationalizationLink to this heading

LoggingLink to this heading

Management CommandsLink to this heading

  • The new listurls command lists the URLs from the project’s root URLconf, including the view class or function (and name, if present).

  • The makemigrations command now tracks all changes to unmanaged models, including field additions, removals, alterations, constraints, and model renames. After upgrading, you will see new migrations detected for unmanaged models that have changed since their creation.

  • Whether to suppress an ImportError escaping from a settings module is configurable by the new BaseCommand.requires_settings attribute (default True). In previous versions, such errors were always suppressed.

MigrationsLink to this heading

ModelsLink to this heading

Requests and ResponsesLink to this heading

SecurityLink to this heading

SerializationLink to this heading

SignalsLink to this heading

TasksLink to this heading

TemplatesLink to this heading

TestsLink to this heading

URLsLink to this heading

UtilitiesLink to this heading

ValidatorsLink to this heading

Backwards incompatible changes in 6.2Link to this heading

Database backend APILink to this heading

This section describes changes that may be needed in third-party database backends.

django.contrib.adminLink to this heading

  • The admin view_on_site URL now consistently returns an HTTP 403 response when a staff user lacks view or change permission for the target model.

  • The admin history view now checks permissions before object existence, consistently returning an HTTP 403 response for staff users without the view or change permission regardless of whether the object exists.

django.contrib.gisLink to this heading

  • The seconds value returned by as_datetime() is now a c_float rather than a c_int.

MiscellaneousLink to this heading

  • To facilitate the deprecation of the safe parameter of JsonResponse, it now defaults to False, because the pollution vulnerability in the Array prototype was fixed in ES5.

  • DjangoJSONEncoder now omits the millisecond component of serialized datetime.datetime and datetime.time objects if they have zero milliseconds. For example, datetime.datetime(2000, 1, 1, 0, 0, 0, 1) now serializes to "2000-01-01T00:00:00" rather than "2000-01-01T00:00:00.000".

  • utils.module_loading.import_string() now deterministically favors submodules in ambiguous cases where depending on prior import state, a same-named attribute of the parent module might have been returned instead.

  • The minimum supported version of asgiref is increased from 3.9.1 to 3.12.1.

  • In the asynchronous request path, error responses (such as those rendered by handler404 and handler500) are now rendered on the request’s thread-sensitive thread, rather than on a shared thread pool, so that database connections used during error handling are managed by close_old_connections().

Features deprecated in 6.2Link to this heading

MiscellaneousLink to this heading

  • The MiddlewareMixin class moved from django.utils.deprecation to django.middleware. The old import path is deprecated.

  • The safe parameter is deprecated from JsonResponse. Omitting the argument is equivalent to the prior safe=False usage.

  • Calling QuerySet.aiterator() after prefetch_related() without providing a chunk_size is deprecated. It currently falls back to a chunk_size of 2000, but a ValueError will be raised in Django 7.1.