Django 6.2 release notes - UNDER DEVELOPMENTLink to this heading
Expected April 2027
Welcome to Django 6.2!
These release notes cover the new features, as well as some backwards incompatible changes you should be aware of when upgrading from Django 6.1 or earlier. We’ve begun the deprecation process for some features.
See the How to upgrade Django to a newer version guide if you’re updating an existing project.
Django 6.2 is designated as a long-term support release. It will receive security updates for at least three years after its release. Support for the previous LTS, Django 5.2, will end in April 2028.
Python compatibilityLink to this heading
Django 6.2 supports Python 3.12, 3.13 and 3.14. We highly recommend and only officially support the latest release of each series.
What’s new in Django 6.2Link to this heading
Minor featuresLink to this heading
django.contrib.adminLink to this heading
…
django.contrib.admindocsLink to this heading
…
django.contrib.authLink to this heading
The default iteration count for the PBKDF2 password hasher is increased from 1,500,000 to 1,800,000.
django.contrib.contenttypesLink to this heading
…
django.contrib.gisLink to this heading
DataSourcenow preserves millisecond precision when reading time and datetime fields.
django.contrib.messagesLink to this heading
…
django.contrib.postgresLink to this heading
…
django.contrib.redirectsLink to this heading
…
django.contrib.sessionsLink to this heading
…
django.contrib.sitemapsLink to this heading
…
django.contrib.sitesLink to this heading
…
django.contrib.staticfilesLink to this heading
…
Asynchronous viewsLink to this heading
…
CacheLink to this heading
Subclasses of
BaseDatabaseCachenow support culling on a percentage of writes as an optimization. The default is 10%, and may be configured using theCULL_PROBABILITYoption.
CSPLink to this heading
…
CSRFLink to this heading
…
Database backendsLink to this heading
…
DecoratorsLink to this heading
…
EmailLink to this heading
…
Error ReportingLink to this heading
…
File StorageLink to this heading
…
File UploadsLink to this heading
…
FormsLink to this heading
…
Generic ViewsLink to this heading
…
InternationalizationLink to this heading
…
LoggingLink to this heading
…
Management CommandsLink to this heading
The new
listurlscommand lists the URLs from the project’s root URLconf, including the view class or function (and name, if present).The
makemigrationscommand now tracks all changes to unmanaged models, including field additions, removals, alterations, constraints, and model renames. After upgrading, you will see new migrations detected for unmanaged models that have changed since their creation.Whether to suppress an
ImportErrorescaping from a settings module is configurable by the newBaseCommand.requires_settingsattribute (defaultTrue). In previous versions, such errors were always suppressed.
MigrationsLink to this heading
…
ModelsLink to this heading
…
Requests and ResponsesLink to this heading
…
SecurityLink to this heading
…
SerializationLink to this heading
…
SignalsLink to this heading
…
TasksLink to this heading
…
TemplatesLink to this heading
…
TestsLink to this heading
force_login()now skips members ofAUTHENTICATION_BACKENDSnot implementing(a)get_user(), e.g. permission-only backends.
URLsLink to this heading
…
UtilitiesLink to this heading
utils.module_loading.import_string()now supports modules. Previously, top-level modules did not work, and submodules only worked if already imported.…
ValidatorsLink to this heading
…
Backwards incompatible changes in 6.2Link to this heading
Database backend APILink to this heading
This section describes changes that may be needed in third-party database backends.
…
django.contrib.adminLink to this heading
The admin
view_on_siteURL now consistently returns an HTTP 403 response when a staff user lacks view or change permission for the target model.The admin history view now checks permissions before object existence, consistently returning an HTTP 403 response for staff users without the view or change permission regardless of whether the object exists.
django.contrib.gisLink to this heading
The seconds value returned by
as_datetime()is now ac_floatrather than ac_int.
MiscellaneousLink to this heading
To facilitate the deprecation of the
safeparameter ofJsonResponse, it now defaults toFalse, because the pollution vulnerability in theArrayprototype was fixed in ES5.DjangoJSONEncodernow omits the millisecond component of serializeddatetime.datetimeanddatetime.timeobjects if they have zero milliseconds. For example,datetime.datetime(2000, 1, 1, 0, 0, 0, 1)now serializes to"2000-01-01T00:00:00"rather than"2000-01-01T00:00:00.000".utils.module_loading.import_string()now deterministically favors submodules in ambiguous cases where depending on prior import state, a same-named attribute of the parent module might have been returned instead.The minimum supported version of
asgirefis increased from 3.9.1 to 3.12.1.In the asynchronous request path, error responses (such as those rendered by
handler404andhandler500) are now rendered on the request’s thread-sensitive thread, rather than on a shared thread pool, so that database connections used during error handling are managed byclose_old_connections().
Features deprecated in 6.2Link to this heading
MiscellaneousLink to this heading
The
MiddlewareMixinclass moved fromdjango.utils.deprecationtodjango.middleware. The old import path is deprecated.The
safeparameter is deprecated fromJsonResponse. Omitting the argument is equivalent to the priorsafe=Falseusage.Calling
QuerySet.aiterator()afterprefetch_related()without providing achunk_sizeis deprecated. It currently falls back to achunk_sizeof 2000, but aValueErrorwill be raised in Django 7.1.