1
0
mirror of https://github.com/django/django.git synced 2025-06-20 10:59:12 +00:00

Clarified that only latest dependency versions are valid for security reports.

This commit is contained in:
Jake Howard 2025-06-18 15:04:34 +01:00 committed by GitHub
parent 22506b2c16
commit bc1bfe12b6
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
2 changed files with 15 additions and 1 deletions

View File

@ -58,7 +58,10 @@ Django version Python versions
============== ===============
For each version of Python, only the latest micro release (A.B.C) is officially
supported. You can find the latest micro version for each series on the `Python
supported. Python versions that have reached end-of-life are no longer
maintained by the Python project and therefore should not be used with Django.
You can find the latest supported micro version for each series on the `Python
download page <https://www.python.org/downloads/>`_.
We will support a Python version up to and including the first Django LTS

View File

@ -55,6 +55,17 @@ set up, run, and reproduce the issue.
Please do not attach screenshots of code.
Use supported versions of dependencies
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Django only :ref:`officially supports <faq-python-version-support>` the latest
micro release (A.B.C) of Python. Vulnerabilities must be reproducible when all
relevant dependencies (not limited to Python) are at supported versions.
For example, vulnerabilities that only occur when Django is run on a version of
Python that is no longer receiving security updates ("end-of-life") are **not
considered valid**, even if that version is listed as supported by Django.
User input must be sanitized
~~~~~~~~~~~~~~~~~~~~~~~~~~~~