Natalia Bidart and Jacob Walls

Blog Info The Django weblog
Blog website Link

How the Django Software Foundation Became a CNA

June 25, 2026 » The Django weblog » [Archived Version]

Why the DSF pursued CNA status Django has a long history of responsible security practices: a dedicated, private security mailing list, clear advisory policies, and predictable security releases. Even so, we relied on external organizations to assign CVE IDs (Common Vulnerabilities and Exposures). This sometimes introduced administrative delays and extra coordination overhead. Becoming a CNA (CVE Numbering Authority) allows the DSF to: Assign CVEs ourselves for vulnerabilities in Django and se…

Read More