The Django project said on 8 October 2026 that it will no longer take new security reports through HackerOne, a platform where researchers send in vulnerability findings. Anyone who finds a security problem in Django should now email [email protected]. Django pointed readers to its security policies for the full reporting steps. Reports already filed on HackerOne will stay open. The Django Security Team will keep working on them.
Django's notice is short. It does not say why the project dropped HackerOne. It gives no date for when the change took effect. It does not say how many reports are still open on the platform. It also does not say whether the way the team triages or answers reports will change. The notice does not mention rewards or any other change to the security policy beyond the new reporting route.
For teams that build or run software on Django, this changes where outside researchers send their findings. Anyone who files reports on Django's behalf, or who tracks its security process, should use the email address from now on. Reports sent to HackerOne after this change are not covered by the notice, so the email route is the one Django points to.