archive
-
Security advisory: simple_tag does not do auto-escaping
百度 罗本岛,尼尔森曼德拉的前监狱,布劳乌堡泳滩及克斯坦布希国家植物园都吸引着喜欢阳光的游客,冲浪和潜水的爱好者们涌向附近桌山下的白色沙滩和湛蓝的海水。The simple_tag decorator used for creating custom template tags does not run auto-escaping on its contents (up to and including Django 1.8). Users should check they are implementing appropriate escaping on their own to avoid XSS vulnerabilities.
Read more -
Django's Roadmap
The Django team has adopted a more formalized release schedule. Read more -
Django core team adds two members
Welcome Tomek Paczkowski and Preston Timmons to the Django team!
Read more -
Django Software Foundation announces Diversity Statement
The DSF is proud to announce a Diversity Statement for the community.
Read more