* Post security release announcements to our blog.
* Post announcements to django-announce, a very low-traffic mailing list specifically for security announcements.
* Post announcements to django-users, a mailing list with over 20,000 subscribers from all over the Django community.
* Post announcements to django-developers, where most of the people who hack on Django hang out.
* Publicize these releases on Twitter, Reddit, HN, etc.
Further, we work with people who re-distribute Django (e.g. as part of RHEL/Fedora/Ubuntu/etc.) and people who use Django in high-risk areas to get them early access to security notifications [1].
So yeah, we make a lot of noise about security issues.
BundleScout looks nice, but it kinda sucks that you'd make people pay to hear about security issues. We're going to continue to do our best to make sure people find out about them quickly and for free.
[1] https://docs.djangoproject.com/en/dev/internals/security/#re...