#490 It’s a vibe coding party
Topics covered in this episode:
Some more things about Django I've been enjoying
Who cleans up after the vibe-coding party?
Where Did All Your AI Tokens Go? AgentsView to the rescue!
Careful with phishing all
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python
Consulting from Six Feet Up
Connect with the hosts
Michael: Mastodon / BlueSky / X / LinkedIn
Calvin: Mastodon / BlueSky / X / LinkedIn
Show: Mastodon / BlueSky / X
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Calvin #1: Some more things about Django I've been enjoying
Julia Evans is learning "2010-style" web dev (Django + SQL + server-rendered HTML) after years of Go backends and JS-heavy frontends
Query builders: likes defining custom QuerySet classes with chainable filter methods (.approved().future().with_tags()) — more readable than raw SQL
Template filters: highlights urlize, linebreaksbr, json_script, and especially querystring for building/modifying query-string links in templates
Migrations: still loves Django's auto-generated migrations — 19 and counting on her project
Skips inheritance for class-based views; prefers function-based views for sharing code, though fine using Django's own mixins/interfaces
Performance surprise: CPU profiling (via py-spy) — not slow DB queries — revealed the culprit; she'd accidentally disabled the cached template loader, and re-enabling it took throughput from ~2-3 req/s to ~12 req/s on a $10/mo VM
Michael #2: Who cleans up after the vibe-coding party?
FT Magazine piece by Sam Learner (July 11) on AI coding tools overwhelming open source maintainers - sent in by listener Dylan McConnell, whose main point was that this ran in the Financial Times, not a dev blog.
cURL as the case study - Daniel Stenberg has been the only full-time person on it for years; libcurl has been installed an estimated 20+ billion times with 3,000+ listed contributors.
Bug bounty killed - cURL ended its paid security bounty program in January, citing an "explosion of AI slop reports" that take real time to debunk and drain morale.
Extractive contributions - authoring a PR is now nearly free, reviewing one still costs a human; tldraw's Steve Ruiz closed outside contributions entirely, asking why he'd want someone else writing the easy part.
Guido weighs in - van Rossum says projects are holding emergency meetings over the slop flow, and notes LLM patches tend to touch unrelated parts of a file, making review more tedious.
"Vibe Coding Kills Open Source" - paper from Miklós Koren's group: packages frequently recommended by coding models saw big download jumps with no matching engagement, breaking the reputation loop that sustains maintainers.
Stack Overflow flatlined - over 100,000 questions a month before ChatGPT, under 1,500 last month, with the response rate cut roughly in half; the public archive is now stale training data.
The course-creator angle - Josh Comeau's newest web dev course launched at about a third of prior enrollment, and he worries about devs who never learn which questions to ask.
But the most interesting portion is what was omitted.
Focused on: The end of the curl bug-bounty
Omitted: High-Quality Chaos
Why the omission is interesting
It fits a narrative. The FT piece is a maintenance-and-decline story, and January-Stenberg is a perfect witness for it. April-Stenberg complicates it - same person, same project, better data, opposite direction on the specific claim being used.
The tell is already in the article. Learner quotes Stenberg saying AI tools are much better at finding problems than fixing them. That's the April thesis in one line, and it goes undeveloped.
Reason for the shift is process, not vibes. Killing the bounty removed the cash incentive and the venue change filtered the rest. Worth saying out loud, because "AI reports got better" isn't quite it - "no bounty plus a real triage platform" is closer.
Joke too: Sarah O’Connor wrote a related piece (is this just before skynet launches?)
Calvin #3: Where Did All Your AI Tokens Go? AgentsView to the rescue!
Local-first desktop/web app for browsing, searching, and analyzing your past AI coding agent sessions (Claude Code, Codex, Copilot, Cursor, Gemini, Aider, and dozens more)
Auto-discovers session files on your machine — no config needed; everything stored locally in SQLite, no cloud/accounts
agentsview usage is a drop-in ccusage alternative — reads from pre-indexed SQLite, reports run 80–220× faster on large histories
New Activity dashboard shows peak concurrency, active vs. idle time, agent-minutes, and cost — filterable by project/agent/machine, with a -json CLI report too
Full-text + optional semantic search across every session; also imports Claude.ai/ChatGPT chat exports
Install via pip install agentsview, uvx agentsview, brew install --cask agentsview, or download desktop binaries from GitHub Releases
Michael #4: Careful with phishing all
The situation
I pass this along because it was a pretty sneaky bit of targeted phishing, and happened to play off an old interaction in bandit's repo. As usual with phishing scams there are a bunch of tells that this isn't legitimate, but just enough plausibility that I could see falling for it in a weak moment. Relative nobodies like me haven't historically been worth the effort to hit with scams this specific. Agents change the game though :-/. Be careful out there folks!
Original message
From: "Patrick (Blacktrace)" [HTML_REMOVED]
To: LISTENER EMAIL
Subject: Your Bandit #1350 (B105 NextToken false positive) -- just fixed that exact case
Date: Wednesday, July 15, 2026 12:02 AM
Hi AJ,
Saw your Bandit issue #1350 -- the B105 hardcoded-password false positive on the string NextToken. I build a deterministic gate that filters that class of Bandit noise, and #1350 was literally the case I just fixed: NextToken / next_token / page_token / nextPageToken now stay quiet, while a genuine hardcoded token like api_token="sk-live-..." still fires. Verified against your exact case.
30-second paste: https://blacktrace.co/noise-eraser
Where it still trips, published: https://blacktrace.co/kruc
Curious whether it clears what you hit -- and if it trips on something of yours, that's the more useful reply.
Patrick, Blacktrace
I asked Claude for some analysis too. It was pretty good at finding them.
The message name-drops enough real detail to feel legit, but the structure is pure phishing - everything in it exists to get AJ onto blacktrace.co. The strongest ones:
Freemail sender, corporate signoff. Signs as "Patrick, Blacktrace" but sends from emailpjv@gmail.com. Real company outreach comes from the company domain, not a personal Gmail - and there's no last name.
Over-specific targeting. It mirrors AJ's exact public activity - issue #1350, the B105 rule, the NextToken false positive, even the token variants. That's the "just enough plausibility" AJ flagged, and it's exactly what agents make cheap: scrape a GitHub issue, auto-generate tailored bait. Legit cold outreach rarely reads your history back to you this precisely.
The entire payload is two links. Strip the technical flattery and the message is just "paste here" plus "see results here." When the whole point of an email is the click, that's the tell.
"30-second paste." Low-friction urgency, and "paste" most likely means paste your source into their tool - handing your code to a stranger's site. Exfiltration dressed as convenience.
Brand-new, no-reputation domain. blacktrace.co has no track record, and the name is doing some ominous work. The /kruc slug is random noise, not how real product pages get named.
Precise-sounding jargon that's actually vague. "Deterministic gate," "noise-eraser" - impressive, empty. Bolted onto correct real details (B105 is the Bandit hardcoded-password test, sk-live- is a Stripe live-key prefix) to borrow credibility.
The disarming close. "if it trips on something of yours, that's the more useful reply" - engineered humility that flatters your expertise and baits a response. Makes engaging feel like you're doing them a favor, which drops your guard.
Extras
Calvin:
DjangoCon US 2026 is rapidly approaching, August 24-28, Chicago
Ruff v0.16.0 massively expands its default rule set
Ruff now enables 413 rules by default, up from 59
https://astral.sh/blog/ruff-v0.16.0
Michael:
Completely redesigned the home page.
Try /insights in Claude Code (terminal)
Joke: We’re Safe
#489 Or JSON?
Topics covered in this episode:
django-orjson
Best Django Redis configuration for speed and size
Linus Torvalds puts the foot down against Anti-AI Kernel Maintainers
Django Steering Council backs the Triptych Project
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python
Consulting from Six Feet Up
Connect with the hosts
Michael: Mastodon / BlueSky / X / LinkedIn
Calvin: Mastodon / BlueSky / X / LinkedIn
Show: Mastodon / BlueSky / X
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too.
Michael #1: django-orjson
Adam Johnson dropped django-orjson - drop-in replacements for the Django and DRF pieces that touch JSON, swapping stdlib json for orjson, the Rust-based library. Headline numbers: 10x faster serialization, 2x faster deserialization.
The interesting question is why this needs to be a package at all. pip install orjson is the easy part. Adam's actual pitch: adopting it "isn't easy, especially when your framework uses json in many different parts." Django scatters JSON across JsonResponse, the test client and test case classes, the json_script template tag, and more. There's no single hook to grab, so you get a library that catches them all.
Adam is refreshingly honest about the scale of the win. His words: "While database queries tend to dominate the typical Django application's runtime, the time spent in serialization and deserialization can still be significant." He calls it "a nearly free performance win" - not "this will 10x your app." That's a claim about cost, not magnitude, and it's worth keeping those straight.
Worth flagging what the post doesn't cover: caveats. There are none in the article, but orjson has real ones. Django and Flask both render datetimes as RFC 822 HTTP-date (Wed, 15 Jul 2026 12:00:00 GMT); orjson does ISO 8601. It can't do ensure_ascii, it rejects NaN and Infinity (which stdlib happily emits), and it raises on Decimal. If you've got a JS client parsing dates, that's a wire-format change.
Who should actually take this? If you're a DRF shop shoveling JSON all day, yes - it's cheap and it's real. If your app mostly renders HTML templates, you're optimizing a slice of runtime that's already near zero.
The problem Adam's package solves doesn't exist in Flask or Quart. They already centralize every JSON operation - jsonify, request.get_json(), the test client, the |tojson filter - behind one provider object at app.json. So there's no library to install. It's about ten lines:
import orjson
from quart.json.provider import JSONProvider # or flask.json.provider
class OrjsonProvider(JSONProvider):
def dumps(self, obj, **kwargs) -> str:
return orjson.dumps(obj).decode() # provider must return str
def loads(self, s, **kwargs):
return orjson.loads(s)
app.json = OrjsonProvider(app)
The numbers on talkpython.fm
Evaluated it, measured it, and skipped it. The biggest JSON payload we serve is our MCP server returning a cached episode transcript, about 139 KB. Swapping the provider saves 0.119 milliseconds per request. That total response takes 1.1 ms
We got 4.1x, not 10x - and the reason is the good lesson. Payload shape decides your speedup. The 10x is for structure-heavy data, lots of small keys where stdlib burns time in Python-level dispatch per item. Our hot payload is one giant transcript string, so the work is escaping and memcpy
Calvin #2: Best Django Redis configuration for speed and size
Peter Bengtsson revisits a classic: his 2017 "Fastest Redis configuration for Django" benchmark now has a 2026 update posted this week.
The 2017 post pitted django-redis serializers (json, ujson, msgpack, pickle) and compressors (zlib, lzma) against each other; conclusion was msgpack + zlib as the sweet spot - avoid the json serializer, it's fat and slow.
The 2026 update narrows focus to just compressors: default (no compression), zlib, lzma, and newcomer zstd.
New results: lzma compresses best but is slowest; zstd is the fastest compressor on Ubuntu; differences between them are very small.
Big takeaway across both: compression buys you a lot of space (2–3.5x smaller) for very little speed cost - worth it for Redis where memory is the constraint.
Caveat from the author: results depend heavily on your data - his test stores short strings of numbers, so benchmark your own workload.
Michael #3: Linus Torvalds puts the foot down against Anti-AI Kernel Maintainers
Write up on Ars.
Really good coverage by Maximillian: Time to wake up (for some)
Torvalds said that “Linux is not one of those anti-AI projects, and if somebody has issues with that, they can do the open-source thing and fork it. Or just walk away.”
I agree with Max, putting your head in the sand and waiting for AI to go away will likely mean you won’t be working professionally in software development in the coming years.
The statement came amid a lengthy thread arguing about the use of Sashiko, an “agentic Linux kernel code review system” that its creators claim can, in tests, independently find 53.6 percent of the bugs that would end up being fixed by human coders in later commits.
“We’re not forcing anybody to use [LLM tools], but I will very loudly ignore people who try to argue against other people from using it,” Torvalds said.
“Anybody who points to the problems at AI had better be looking in the mirror and pointing at themselves at the same time,” Torvalds wrote.
Calvin #4: Django Steering Council backs the Triptych Project
Django Steering Council issued a Letter of Collaboration backing Carson Gross & Alex Petros's funding bid for the Triptych Project - three proposals to make HTML more expressive natively, in every browser.
The three additions: PUT/PATCH/DELETE methods for forms, button actions (buttons that fire HTTP requests without a wrapping form), and partial page replacement.
Distills the core ideas from HTMX/Unpoly/Turbo into the HTML standard itself - no JS, no library, nothing to ship or maintain.
Current focus is button actions (WHATWG #12330): <button action=/logout method=POST>Logout</button> instead of wrapping a button in a form.
Relevant to Django directly - think the admin submit row and disguised delete links; Django 6.0's template partials were already inspired by these patterns.
How to help: companies can send non-binding letters of support on letterhead; individuals can read the proposals and weigh in on the WHATWG issues.
Extras
Calvin:
DOOMQL - A playable first-person shooter whose framebuffer is a SQL query.
Michael:
Granian 2.7.9 fixes WSGI threadpool scheduler starvation/underscaling
Welcome Calvin post
Joke: Solving all bugs
#488 tau - it's 2pi and it writes code
Topics covered in this episode:
The trusted-publishing debate: how to do it right vs. why you shouldn't trust it
JupyterLab 4.6 and Notebook 7.6 are out!
Tau – new small, readable terminal coding agent
Django Tasks and Django 6.1
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python
Consulting from Six Feet Up
Connect with the hosts
Michael: Mastodon / BlueSky / X / LinkedIn
Calvin: Mastodon / BlueSky / X / LinkedIn
Show: Mastodon / BlueSky / X
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Calvin #1: The trusted-publishing debate: how to do it right vs. why you shouldn't trust it
https://snarky.ca/how-to-publish-to-pypi-using-github-actions-securely/ (Brett Cannon) and https://blog.yossarian.net/2026/07/07/You-shouldnt-trust-trusted-publishing (William Woodruff)
Trusted Publishing (PyPI's OIDC-based auth scheme, also now used by npm, RubyGems, crates.io, NuGet) replaces long-lived API tokens with short-lived, auto-scoped credentials tied to CI/CD machine identity.
Yossarian's post: it's purely an authentication mechanism between a machine identity and a package — it says nothing about package safety or quality. PyPI deliberately avoids any "verified/trusted" badge for it, unlike its verified-URL checkmarks.
Same logic applies to PyPI attestations: anyone can sign with any machine identity they control, so an attestation's presence isn't itself a trust signal.
Bottom line from that post: don't confuse "trusted" (machine-to-machine) with "trustworthy" (human judgment about the package).
Snarky.ca's companion piece is more practical: given GitHub Actions compromises in the news, the real fix is 3 concrete steps — run zizmor to lock down workflow permissions/checkout credentials and pin actions to commit hashes, adopt Trusted Publishing to eliminate stored PyPI tokens, and require manual approval via a GitHub environment before any publish job runs.
Takeaway for listeners: Trusted Publishing is good hygiene for how you authenticate to PyPI, but it's not a substitute for securing your CI pipeline itself — or for actually vetting the packages you install.
Michael #2: JupyterLab 4.6 and Notebook 7.6 are out!
Michał Krassowski's rundown - a chunky minor release: 68 features, 97 bug fixes, 95 contributors, one of the biggest ever.
Scratchpad console (Notebook 7.6 headliner) - a console next to your notebook sharing its kernel, for throwaway experiments. Ctrl+B.
Jump to last-edited cell - new commands hop through recently edited cells.
File browser glow-up - Date Created column, editable breadcrumbs with Tab-completion, and Open in Terminal.
Debugger - sources open in the main area, floating step/continue overlay, live kernel-sources filter.
Custom layouts (Lab) - activity bar top/bottom, draggable panels, four-way tab splits, per-panel Ctrl+scroll zoom.
~5x faster extension builds - webpack → Rspack, and jupyter-builder means no full Lab install needed to build extensions.
Keyboard/a11y - add shortcuts from the UI (no JSON), Find & Replace in Edit menu (Ctrl+H).
Calvin #3: Tau – new small, readable terminal coding agent
Tau – new small, readable terminal coding agent (Python 3.12+), built as both a working tool and a teaching project for how coding agents work under the hood
Install via uv tool install tau-ai, pipx, or pip; ships a tau CLI
Three-layer architecture: tau_ai (provider-neutral model layer) → tau_agent (reusable "brain": messages, tools, events, loop) → tau_coding (CLI/TUI, file & shell tools, sessions)
Supports OpenAI, Anthropic, OpenAI Codex, OpenRouter, Hugging Face, and custom/local OpenAI-compatible endpoints
Built-in tools (read/write/edit/bash), durable JSONL sessions with resume/branching, project instructions via AGENTS.md, and context compaction
Core harness is UI-agnostic — same brain can power the TUI, print mode, or a custom frontend — usable as a standalone library too
Michael #4: Django Tasks and Django 6.1
Django 6.0 finally ships first-party background tasks (django.tasks) - out of Jake Howard's DEP 14, accepted May 2024, after two decades of everyone bolting on Celery/RQ/Huey.
It's an API, not a worker. Django handles task definition, validation, queuing, and result storage - it does not execute them. You bring the backend.
The default backend traps people. ImmediateBackend runs tasks inline on the request thread and blocks until done - so out of the box .enqueue() backgrounds nothing (a 5-second task means a 5-second response). The other built-in, DummyBackend, runs nothing at all. Both are dev/test only.
Nice API otherwise: slap @task on a function, call .enqueue(), get back a TaskResult you look up later by id - with async twins like aenqueue(). Gotcha: args and return values must survive a JSON round-trip, so a tuple sneakily comes back as a list.
The community local backend to know: django-tasks-local by Chris Beaven (SmileyChris). A ThreadPoolExecutor backend that gives real background threads with zero infrastructure - no Redis, no Celery, no database - plus a ProcessPoolBackend for CPU-bound work → github.com/lincolnloop/django-tasks-local
Its catch: results live in memory, so pending tasks vanish on restart or deploy. Great for dev and low-traffic production; for persistence, drop to Jake Howard's django-tasks (DatabaseBackend + worker command).
Extras
Calvin:
Fixing the dictionary with Python 3.14 — Hugo van Kemenade stumbled on - and got fixed - a markup bug in the OED's own citation of a 1706 use of the pi symbol.
Michael:
Bunny DNS is now free
Jokes:
What's the object-oriented way to become wealthy? Inheritance
To understand what recursion is... You must first understand what recursion is
3 SQL statements walk into a NoSQL bar. Soon, they walk out They couldn't find a table.
#487 Minimum requirements
Topics covered in this episode:
dust - a better du
Hermes Agent: The AI agent that grows with you
llm-coding-agent 0.1a0
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python
Consulting from Six Feet Up
Connect with the hosts
Michael: Mastodon / BlueSky / X / LinkedIn
Calvin: Mastodon / BlueSky / X / LinkedIn
Show: Mastodon / BlueSky / X
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Michael #1: dust - a better du
du + Rust = dust - a fast, visual, intuitive disk-usage CLI
Run dust and immediately see the biggest directories and files without piping through sort, head, or awk
Smart recursive output focuses on what matters instead of dumping every folder
Colored bars show relative size and parent/child hierarchy, making “where did the space go?” obvious
Perfect for Python projects bloated by .venv, caches, Docker volumes, downloaded datasets, and local AI models
Install via brew, cargo install du-dust, conda-forge, Scoop, Snap, deb-get, or GitHub releases
Calvin #2: A Way better ARchive format for Python packaging
war - new archive format spec from Astral (same team as uv/ruff), v0.0.2, still no binary encoding defined yet
Header-Index-Store layout: header IDs the file, index maps names to store offsets, store holds compressed data
Index uses a finite-state transducer (FST) to dedupe common path prefixes across entry names
Supports three entry types (file, directory, link) and three compression modes (store/DEFLATE/zstd), plus an "executable" metadata flag
Unpacking is atomic - writes to a temp dir, then renames into place, so a failed extract never leaves a half-unpacked directory
Strict name-segment rules (no NUL/control chars, no leading/trailing whitespace, blocks Windows-reserved names like CON/PRN) to avoid path traversal and cross-platform footguns
Michael #3: Hermes Agent: The AI agent that grows with you
Hermes Agent is an open-source, Python-built AI agent framework from Nous Research - think ChatGPT-style assistant, but connected to your tools, files, shell, browser, calendar, memory, and messaging apps
I’m using it in Discord as a long-running agent conversation, not just a one-off chatbot session
Hermes can connect through a gateway to platforms like Discord, Telegram, Slack, WhatsApp, email, webhooks, and more - so the same assistant can follow you across surfaces
In my setup, I can send Hermes voice/text from Discord, keep project context across turns as threads, and ask it to actually do things: read GitHub repos, run commands, edit files, schedule calendar events, generate drafts, and verify results
A fun workflow: I can trigger one-shot actions from an Apple Watch shortcut - dictate a request, send it to Hermes, and have the agent execute it asynchronously
Hermes has persistent memory, so it can remember durable preferences and facts - for example, how I like my research formatted
It also has “skills,” which are reusable procedures the agent can load later, so Hermes can self-improve over time instead of rediscovering the same workflow repeatedly
It supports scheduled jobs / cron-style automations, so it can proactively watch for releases, send summaries, run checks, or remind you about things
It’s provider-agnostic: OpenRouter, Anthropic, Google, xAI, local models, Nous Portal, and others
The big idea: Hermes turns an LLM from “a chat box I visit” into “an agent I can reach from anywhere that knows my workflows and can take real actions and learns over time.”
Calvin #4: llm-coding-agent 0.1a0
Simon Willison built a Claude/Codex-style coding agent on top of his llm library, using an alpha of the llm package plus his python-lib-template-repo
Built almost entirely via prompted TDD - asked an agent to write a spec.md, then commit + implement with red/green tests, occasionally hitting a real OpenAI key to sanity-check
Shipped to PyPI as an alpha: uvx --prerelease=allow --with llm-coding-agent llm code
Tool set mirrors familiar coding-agent primitives: read_file, edit_file (exact string replace + diff), write_file, list_files, search_files, execute_command
Also exposes a Python API - CodingAgent(model="gpt-5.5", root=..., approve=True).run(...) - which Simon didn't ask for but got anyway
Demo: llm code --yolo told GPT-5.5 to build a SwiftUI CLI clock; model correctly noted SwiftUI isn't really CLI-friendly and still produced an ASCII-art time display
Extras
Calvin:
Slides, but for developers https://sli.dev/
Wanna reduce your token usage…. only issue is that its lossy https://github.com/teamchong/pxpipe
PEP 772 - Python Packaging Council inaugural election dates set, nominations open July 28, voting September 1-15
Michael:
What the pls? revisited!
Joke: Min requirements for Linux
#486 underscore-underscore-ghost-emoji
Topics covered in this episode:
Free-threaded Python: past, present, and future
django-admin-site-search
Qwen 3.6 27B is the sweet spot for local development
A large batch of PEPs are finalized
Extras
Joke
Watch on YouTube
Show Intro
Sponsored by us! Support our work through:
Our courses at Talk Python
Consulting from Six Feet Up
Connect with the hosts
Michael: Mastodon / BlueSky / X / LinkedIn
Calvin: Mastodon / BlueSky / X / LinkedIn
Show: Mastodon / BlueSky / X
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Calvin #1: Free-threaded Python: past, present, and future
The GIL has prevented true multi-threaded parallelism in CPython since the beginning — multiple past attempts to remove it failed on performance grounds
Sam Gross at Meta finally solved it; his work became PEP 703 and ships as free-threaded CPython today
Python 3.13 was experimental with 20–40% single-threaded slowdown; 3.14 brought that to 0–10%
Python 3.15 (October 2026) delivers a unified ABI — one extension binary works on both GIL and free-threaded builds
Already >50% of the top PyPI binary wheels support free threading
Wouters predicts free-threaded becomes the default between 3.16–3.20 (2027–2031), with the GIL eventually disappearing next decade
Michael #2: django-admin-site-search
via Adam Parkin
A global/site search modal for the Django admin, by Ahmed Aljawahiry. Hit cmd+k anywhere in the admin and you get a command-palette-style search window, kind of like the one in VS Code.
It doesn't just search one model's list page. It searches your entire site in one box:
App labels
Model labels and field attributes
Actual model instances (your data)
Two ways to search the instances:
model_char_fields (the default): runs an __icontains across every CharField (and subclasses) on the model. Zero config, works out of the box.
admin_search_fields: defers to each ModelAdmin's existing get_search_results(), so it respects the search_fields you've already set up.
The part I like: it's permission-aware out of the box. Users only see results for the apps and models they actually have view permission on, so you're not leaking anything through search.
Results appear as you type, with throttling/debouncing so you're not hammering the server on every keystroke, and it's full keyboard nav: cmd+k to open, up/down to move, enter to go.
It's responsive, does dark and light mode, and it pulls Django's built-in admin CSS variables so it just matches whatever admin theme you're running.
Under the hood it's Alpine.js, but bundled into static so there's no external CDN dependency.
Setup is about what you'd expect: pip install django-admin-site-search, add it to INSTALLED_APPS, mix the AdminSiteSearchView into your AdminSite, and drop a few template includes into base_site.html.
Supports Python 3.8 through 3.14 and Django 3.2 through 6.0, MIT licensed, and everything is overridable if you want to skip certain models, add TextField matching, etc.
Calvin #3: Qwen 3.6 27B is the sweet spot for local development
Qwen 3.6 27B is being called the first local model that genuinely competes as a general-purpose intelligence — benchmarks put it at roughly mid-2025 frontier level (comparable to GPT-5 / Claude Sonnet 4.5)
Runs locally via llama.cpp; on an M5 MacBook Max with 8-bit quantization + multi-token prediction, it hits ~32 tokens/sec using ~42GB RAM
4-bit quantization gets it under 18GB, runnable on 32GB devices; Nvidia RTX cards run it even faster
The dense 27B is recommended over the faster MoE 35B A3B — author prefers higher quality output over raw speed
Privacy and reliability are the pitch: fine-tunable, can't be taken down, suitable for sensitive/proprietary data
Author sees this as a stepping stone — frontier open-weight models like GLM 5.2 are now locally runnable with company-grade hardware, and smarter-still local models are coming
Michael #4: A large batch of PEPs are finalized
A bunch of PEPs went from accepted to final.
668, 687, 691, 699, 701, 703, 728, 770, 773, 829
But this wasn’t them making their way into CPython. It’s an admin sorta thing. (Thanks PyCoders)
See the commit.
Extras
Calvin:
More fun bling for your terminal this time - https://charm.land/
Michael:
Follow up from pls, What the pls? Thanks Pito.
Joke: BEMoji
A production-grade utility and component framework built entirely on emoji class names
via Jeff Triplett
#485 Creating memories
Topics covered in this episode:
Backup Docker volumes locally or to any S3
Pyodide 314.0 Release
nb-cli: A Command-Line Interface for AI Agents and Notebook Automation
Hindsight Agent Memory That Learns
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python
AWS Community Day Midwest tomorrow Wednesday the 24th in downtown Indianapolis, Six Feet Up is sponsoring and there are 2 Sixies presenting
Connect with the hosts
Michael: Mastodon / BlueSky / X / LinkedIn
Calvin: Mastodon / BlueSky / X / LinkedIn
Show: Mastodon / BlueSky / X
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too.
Finally, if you want an bonus digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Michael #1: Backup Docker volumes locally or to any S3
Via Bryan Weber (thanks Bryan!), who spotted it over on Virtualization HowTo. Find Bryan at bryanwweber.com.
offen/docker-volume-backup is a lightweight companion container that backs up the volumes your apps actually depend on, then ships them somewhere safe.
It's tiny: written in Go and about 25MB compressed, roughly 1/20th the size of the shell-based image (jareware/docker-volume-backup) that inspired it.
Drop it into your docker compose file as a backup service, mount the volumes you care about as read-only, and you're off.
Push backups to a pile of destinations: a local directory, plus any S3, WebDAV, Azure Blob Storage, Dropbox, Google Drive, or SSH-compatible target. Mix and match as many as you want in one run.
Recurring cron-style backups in a Compose setup, or one-off backups straight from the Docker CLI.
Production-friendly touches worth calling out:
Rotates away old backups so you don't quietly fill the disk.
GPG encryption for your archives.
Notifications on finished and failed runs (so you find out about failures before you need the backup).
Stop a container during backup for a consistent snapshot using a simple docker-volume-backup.stop-during-backup=true label, then auto-restart it.
Run custom commands during the backup lifecycle (great for a database dump before the file copy).
Docker Swarm support, plus arm64 and arm/v7 builds. Hello, Raspberry Pi homelab.
Fun aside from Bryan: he searched our back catalog for this tool and the search came back so fast he thought it hadn't run. Love to hear it.
Calvin #2: Pyodide 314.0 Release
PEP 783 is the real news — Pyodide maintainers used to hand-build 300+ packages. Now anyone can publish Pyodide wheels to PyPI with cibuildwheel.
The version jump from 0.29 to 314.0 is intentional — it now tracks the Python version, so 314.x = Python 3.14. Binary compatibility is locked per Python cycle, meaning packages you build today won't break on the next Pyodide release.
sqlite3, ssl, and lzma are back in the default stdlib — no more await pyodide.loadPackage("sqlite3"). Bigger download, but a much smoother experience for newcomers.
bigint precision bug is fixed — values above 2^53 were silently losing precision when crossing the Python/JS boundary. The new JsBigInt type makes the roundtrip correct. Worth flagging if anyone is doing numeric work in a browser app.
Experimental TCP sockets in Node.js — you can now connect Pyodide to a real database (MySQL, PostgreSQL, Redis tested) when running server-side. Blurs the line between "Python in the browser" and "Python runtime anywhere Wasm runs."
Michael #3: nb-cli: A Command-Line Interface for AI Agents and Notebook Automation
From Piyush Jain (Jupyter and LangChain maintainer) on the Jupyter blog: nb-cli: A Command-Line Interface for AI Agents and Notebook Automation.
nb-cli is an experimental, Rust-based CLI to read, write, execute, and search Jupyter notebooks. The premise: agents are great at CLIs but terrible at hand-editing the nested JSON in an .ipynb, so let them operate on the notebook from the outside instead of running inside it.
Works with or without a Jupyter server. No server? It reads/writes .ipynb files directly and talks to kernels over ZeroMQ. Connected to a live JupyterLab, your edits show up instantly via Y.js (the same CRDT Jupyter uses).
Smart output format: instead of token-heavy JSON or ambiguous plain markdown, it uses @@cell / @@output sentinels with inline metadata. Less wasted context, unambiguous structure, and it degrades gracefully on truncation.
The payoff is composability. "Add a summary section and run it" becomes one shell pipeline instead of six agent tool calls. And nb search notebook.ipynb --with-errors returns only the failing cells, so the agent skips the cells that worked.
Claude Code tie-in: it ships as an agent skill. npx skills install jupyter-ai-contrib/nb-cli and your agent can drive notebooks via nb.
Out of jupyter-ai-contrib, which aims to become an official Jupyter AI subproject. Still early (crates.io is at v0.0.5), so kick the tires before anything load-bearing.
See also marimo-pair.
Calvin #4: Hindsight Agent Memory That Learns
AI agents forget everything between sessions — Hindsight gives them persistent memory that learns over time
Simple three-method API: retain(), recall(), reflect() — store, retrieve, and reason over memories
TEMPR retrieval runs semantic, keyword, graph, and temporal search in parallel for accurate results
Automatically consolidates related facts into durable observations instead of piling up duplicates
pip install hindsight-all runs the entire server in-process; integrates with LangChain, LlamaIndex, Pydantic AI, CrewAI, and more
Extras
Calvin:
Clanker: A Word For The Machine
**Ponytail — You know him. Long ponytail. Oval glasses. Has been at the company longer than the version control**
**Klangk: Multi-User AI Sandboxing, Collaboration and Coding Platform**
Cursor announces Origin
performative-ui to quick start your new idea
Michael:
Astral Joins OpenAI: The Interview
SpaceX to acquire Cursor
And OpenAI renews Open Source support
Portuguese subtitles are now available for Talk Python courses
DSF is hiring including Six Feet Up support
Joke: Oh Babe…
#484 All our tools
Topics covered in this episode:
pi + superpowers
Terminal: Warp.dev + OhMyZSH
{Blink,kitty} + mosh + tmux
Claude code
MacWhisper or Handy
Tailscale
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python Training
Six Feet Up is hosting a LinkedIn Live
Connect with the hosts
Michael: @mkennedy@fosstodon.org / @mkennedy.codes (bsky)
Calvin: @calvinhp@sixfeetup.social / @calvinhp.com (bsky)
Show: @pythonbytes@fosstodon.org / @pythonbytes.fm (bsky)
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Calvin #1: pi + superpowers
terminal-first, open-source coding agent
Session management is a first-class citizen
Extension model is what makes pi special — it's aggressively composable
Superpowers brings a structured software development methodology as loadable skills
Steps back and asks you what you're really trying to do
“hand you the keys to the car” mode vs guardrails might not be for everyone
Michael #2: Terminal: Warp.dev + OhMyZSH
If you’re using the base terminal with default settings, you have so much head-room for improvement.
I’ve been using Warp.dev since Elvis talked me into it. ;)
Remarkable terminal but the AI side of things is a bit junky, can be turned off
OhMyZSH gives better autocomplete
e.g. git branch [HTML_REMOVED] lists all branches in the local repo!
Commandbookapp.com is excellent to keep the terminal focused on terminal things and more server commands and other automation in Command Book.
Calvin #3: {Blink,kitty} + mosh + tmux
Kitty Terminal — GPU-accelerated terminal emulator for macOS, Linux, and Windows with support for graphics, ligatures, and a powerful tiling layout system built right in.
Blink Shell — The go-to terminal for iPad/iPhone power users; full SSH and Mosh client with a gorgeous interface built specifically for mobile professional workflows.
Mosh — Mobile Shell replaces SSH for remote connections, surviving network switches, sleep cycles, and flaky Wi-Fi with zero dropped sessions — essential for staying connected to long-running agentic jobs.
tmux — Terminal multiplexer that keeps sessions alive on your Linux server indefinitely; detach from a Mosh session on your Mac, reconnect from your iPad, and your agent is right where you left it.
The combo — Kitty or Blink + Mosh + tmux creates a "persistent remote brain" pattern: your beefy Linux homelab runs the compute-heavy agent sessions 24/7, and any device becomes a thin client to drop in and out at will.
Michael #4: Claude code
I prefer the IDE experience, the new PyCharm + Claude integration is really good. VS Code too. Why IDE? Because we should still be present with our code and managing context is much easier.
Use the best/latest models on high thinking. “Speed” is not your friend, it’s just shortcuts.
Create skills and agents and use them.
Curate your own rules (e.g. Talk Python’s Claude.md)
Works well on non-coding things. Just create a folder, put a ton of files in there and it’s like NotebookLM + Chat + more.
Calvin #5: MacWhisper or Handy
Transcribes your speech using your choice of Whisper or Parakeet models.
All transcription is done on your device, no data leaves your machine.
Automatic Speaker Recognition with local models.
Handy is more basic, but open source and runs on all platforms.
Michael #6: Tailscale
No need to open ports at all, Tailscale makes machines inside the same network accessible to each other
Works great for laptops, desktops, etc. But also available for servers.
Though I still use cloud firewalls for servers.
How I use it:
My dev database server, preloaded with QA data, is always running on my home mac mini m4 pro. All my apps look for that server before looking locally and tailscale makes them always accessible to each other
My local LLMs expose OpenAI API compatible APIs. Tailscale makes these accessible even while traveling or at a coffee shop.
Use my mini as an exit node. All traffic is routed outbound from my local fiber network. Great to restricted IPs like accessing my servers without caring about the local IP.
Screen share back to my home machines even while traveling.
Listen to the Talk Python episode with Alex for a deeper conversation.
Extras
Calvin:
Telescopo great Mac Markdown viewer/editor.
Michael:
One more: Typora markdown editor.
Created formal documentation for many of my open source packages using Great Docs.
Via Mark Little: Statement on the US government directive to suspend access to Fable 5 and Mythos 5
Joke: No second date
#483 Thanks Brian
Topics covered in this episode:
Vulnerability and malware checks in uv
HTTP GET requests with the Python standard library
Millions of AI agents imperiled by critical vulnerability in open source package
alembic-git-revisions
Extras
Joke
Watch on YouTube
About the show
Goodbye and Thanks Brian
Thanks Calvin for being part of this and future episodes! Also new time for the live show. Thanks Brian for all the hard work over the years.
Calvin #1: Vulnerability and malware checks in uv
release just yesterday by Astral https://astral.sh/blog/uv-audit
uv audit scans dependencies for known vulnerabilities and abandoned packages via the OSV database — runs 4–10x faster than pip-audit
Malware check runs on every install/sync, catching actively malicious packages (credential stealers, etc.) before they execute — including ones PyPI quarantined but lockfiles can still reference
Enable malware scanning with UV_MALWARE_CHECK=1 — it's opt-in and in preview
Future roadmap includes a resolver that steers toward vulnerability-free versions and install-time warnings scoped to newly added deps only
Michael #2: HTTP GET requests with the Python standard library
If you’re doing HTTP in Python, you’re probably using one of three popular libraries: requests, httpx, or urllib3.
There have been issues with httpx lately.
Niquest is another option: Drop-in replacement for Requests. Automatic HTTP/1.1, HTTP/2, and HTTP/3. WebSocket, and SSE included.
But maybe less is more, especially in the age of agentic AI
A good candidate needs two things to be true at once, not one: the used surface is small, and the behavior behind that surface is shallow.
Calvin #3: Millions of AI agents imperiled by critical vulnerability in open source package
"BadHost" (CVE-2026-48710) is a critical vulnerability in Starlette — the ASGI framework underlying FastAPI — with 325 million weekly downloads; also affects vLLM, LiteLLM, and most MCP server tooling
The exploit is trivial: injecting a single character into an HTTP Host header bypasses path-based authentication, and can lead to credential theft, SSRF, and in some cases remote code execution
MCP servers are a prime target since they store credentials for external services (email, databases, cloud accounts) — exposed data in the wild includes biopharma clinical trial DBs, full mailboxes, HR/PII pipelines, and AWS topology
Fix is available — patch to Starlette 1.0.1 immediately; use the free scanner at mcp-scan.nemesis.services to check if your servers are still running a vulnerable version
Open source sustainability footnote: the maintainer triages near-daily security reports solo, in his free time — most are AI-generated noise, and real ones like this still compete for the same evenings and weekends
Michael #4: alembic-git-revisions
By Julien Danjou from Mergify
Automatic Alembic migration chaining based on git commit history. No more Multiple head revisions are present for given argument 'head'.
See the introductory article
Caused by two migrations landed with the same down_revision, and Alembic doesn’t know which one comes first. The fix is always the same: someone manually edits the migration file to re-chain the revisions.
The insight: git already knows the order
Extras
Calvin:
GNU make can do pattern matching in the target. Not new at all, mentioned in the 1994-era docs. just and task don’t have this super power on the target name yet.
train-%:
uv run ./train.py $* --save-hyper-params --overwrite $(TRAIN_ARGS)
Michael:
Updated my HTTP client using packages from httpx to httpx2: listmonk, umami, and memberful. For motivation, see this reddit thread.
Joke: Accurate
#482 Mr. Beast's episode
Topics covered in this episode:
CVE-2026-48710: A Maintainer's Perspective
daily-stars-explorer
Markdown to pdf with pandoc and typst
postman2pytest
Extras
Joke
Watch on YouTube
About the show
Brian #1: CVE-2026-48710: A Maintainer's Perspective
Marcelo Trylesinski
suggested by Lee Luocks
Short version:
users of Starlette: upgrade to Starlette 1.0.1
security professionals: we can’t treat open source projects like corporations
This top link is a Starlette security advisory with the title
Missing Host header validation poisons request.url.path, bypassing path-based security checks
The CVE apparently caused some negative press targeting starlette.
However, “the vulnerability came from the application pattern and the deployment, never from something Starlette intended.”
A quote from an OSTIF article: “This bug is a classic “responsibility gap” where if this maintainer didn’t patch, thousands of exposed projects would have to individually secure their projects. In doing this work, they’ve voluntarily taken on the responsibility to protect the ecosystem from long-term systemic harm. As with all open source projects, they owed us nothing and could have left this to be everyone else’s problem and took the extraordinary steps of helping the ecosystem.”
Both X40 D-Sec and Ars Technica expected immediate fixes and responses from Starlette.
That’s not good. We can do better.
Michael #2: daily-stars-explorer
Explore the full history of any GitHub repository.
📈 Full Star History - Complete daily star counts for any repo
⏰ Hourly Stars - Hour-by-hour activity with timezone support
🔀 Compare Repos - Side-by-side comparison of any two repositories
📊 Activity Timelines - Commits, PRs, Issues, Forks, Contributors over time
📌 Pin Favorites - Bookmark repos for quick access without retyping
📰 Feed Mentions - See when repos were mentioned on HN, Reddit, YouTube, GitHub
💾 Export Data - Download as CSV or JSON
🌙 Dark Mode - Easy on the eyes
Try/use it online at emanuelef.github.io/daily-stars-explorer or install it for yourself.
Brian #3: Markdown to pdf with pandoc and typst
typst suggestion from Matt Harrison
Markdown is awesome
Pandoc is great for converting markdown to tons of stuff
but for pdf, it goes through LaTeX, which is … yuk (my opinion)
Pandoc also can convert to typst
And typst creates beautiful pdfs and is way easier (my opinion) to deal with than LaTeX.
New tools
brew upgrade pandoc
brew install typst
Now convert
pandoc something.md --to typst -o something.typ
typst compile something.typ something.pdf
Michael #4: postman2pytest
via Mikhail
Based on postman app
Convert Postman Collection v2.1 JSON into executable pytest test suites
Postman collections document your API. postman2pytest turns that documentation into executable regression tests that run in CI. No manual rewriting, no drift.
Extras:
New blog, who dis? - testandcode.org is now on .org and a blog and soon to be a “publisher”.
Joke: Centering a div
#481 Ways to die
Topics covered in this episode:
Dumb Ways for an Open Source Project to Die
How to create a pylock.toml lockfile
https://github.com/facebook/Lifeguard
Choosing a Python Logging Library in 2026
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python Training
The Complete pytest Course
Patreon Supporters
Connect with the hosts
Michael: @mkennedy@fosstodon.org / @mkennedy.codes (bsky)
Brian: @brianokken@fosstodon.org / @brianokken.bsky.social
Show: @pythonbytes@fosstodon.org / @pythonbytes.fm (bsky)
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Monday at 11am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Michael #1: Dumb Ways for an Open Source Project to Die
Core categories
The maintainer left
The maintainer is still there
Sabotage and capture
The release pipeline broke
Force majeure
The world moved on
The project split
-
Examples
Bulma PRs still from 2023, issues and PRs with no maintainer response for years, last release 1.5 years ago
diskcache Similar, got hired by OpenAI, crickets after that
Brian #2: How to create a pylock.toml lockfile
Tim Hopper
Tim walks through using uv, pip and pdm to create pylock.toml files.
Recommendation: use uv export --format pylock.toml -o pylock.toml
He also has How to install from a pylock.toml lockfile with pip but the short version is:
use -r because tools treat it like a requirements file
Michael #3: https://github.com/facebook/Lifeguard
Lifeguard is a static analyzer to detect Lazy Imports incompatibilities and ease the adoption overhead for Lazy Imports in Python.
I’m more excited about lazy imports after my Cutting Python Web App Memory Over 31% experience
Some Python patterns depend on imports executing immediately. For example:
Module-level side effects — a module that registers a handler or modifies global state at import time will behave differently if that import is deferred.
The registry pattern — a module that registers itself (e.g., adding to a global dict) when imported will silently fail to register under Lazy Imports.
sys.modules manipulation — code that reads or writes sys.modules assumes prior imports have already executed.
Metaclasses and __init_subclass__ — class creation side effects may depend on imports being resolved.
Project Stage: Beta Lifeguard is in active development. We are aiming to be ready for general use by the Python 3.15 final release.
Brian #4: Choosing a Python Logging Library in 2026
Ayooluwa Isaiah
" which libraries matter, how they compare, where they overlap with the standard module, and when each one makes sense.”
The slant with this article is the need to log json output, which seems reasonable as things like API entry and exit point logging will include json.
Covered libraries
standard library logging with a hat tip to python-json-logger
Same site has a guide to setting up python-json-logger
structlog
Loguru
Logbook
picologging
Some benchmarks with structlog, stdlib+json, and Loguru, with structlog coming out faster
I liked the Loguru example
I’m going to have to try @logger.catch and logger.exception() for easily logging exceptions and serialize=True to enable JSON output.
Extras
Brian:
When Women Stopped Coding - Planet Money segment , spotted on BlueSky from Savannah Ostrowski
Lean TDD is now leaner
Still working on audio version, but some great changes in 0.7.1 version
Ch 6, TDD Interpretations, move ATDD and some of BDD to chapter
Ch 7, Change name to TDD with Teams: BDD and ATDD
Ch 9, Lean TDD, streamline steps and chapter
Ch 10, Change name to Lean TDD with Teams: Lean ATDD
Ch 11, Lean TDD with AI, Add short discussion about guardrails and security
Michael:
New course: Python Web Security: OWASP Top 10 with Agentic AI
All courses now with Spanish subtitles, see announcement
Joke: Stop texting me
#480 Proud Parents
Topics covered in this episode:
Using Django Tasks in production
Co-authored with Claude?
PyPI packages are increasing rapidly
httpx2
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python Training
The Complete pytest Course
Patreon Supporters
Connect with the hosts
Michael: @mkennedy@fosstodon.org / @mkennedy.codes (bsky)
Brian: @brianokken@fosstodon.org / @brianokken.bsky.social
Show: @pythonbytes@fosstodon.org / @pythonbytes.fm (bsky)
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Monday at 11am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Brian #1: Using Django Tasks in production
Tim Schilling shares how the Djangonaut Space website has been using Django’s new tasks framework and some of the info missing from the official Django docs.
Tasks require a third party package, django-tasks-db to actually run the tasks.
Article walks through all changes necessary to get an email process running to notify admins of new testimonials. Cool simple example.
With the db backend, you can monitor progress of tasks in the admin, to see which tasks are scheduled, completed, or have errors.
Some wishes for the community to implement
new tutorial in the Django docs
Django Debug toolbar panel for tasks
test/mock backend
Great title for wish list: Thinks I’d like to see, but I’m too lazy to implement myself.
Michael #2: Co-authored with Claude?
Via Nik T.
We don’t put “executed on macOS”, “edited with PyCharm”, etc. in our commits. Why Claude?
Seems like a growth hack to me, that I don’t really care to participate in.
Some projects that have formalized their thoughts on this: The Generative AI Policy Landscape in Open Source
Adjust to turn off in ~/.claude/settings.json see the docs.
{
"attribution": {
"commit": "",
"pr": ""
}
}
Brian #3: PyPI packages are increasing rapidly
Artem Golubin
There’s been an increase of published packages per week on PyPI
A pretty big increase in the last handful of months.
30% increase since 2025, clearly due to AI
Artem is building hexora, a malicious Python code detector.
Cool package too, it can:
Audit project dependencies to catch potential supply-chain attacks
Detect malicious scripts found on platforms like Pastebin, GitHub, or open directories
Analyze IoC files from past security incidents
Audit new packages uploaded to PyPi.
Artem is using hexora to analyze recently published pypi packages and many are obviously vibecoded and trigger false positives for abuses of eval, exec, and subprocess
Side note: I don’t think that’s necessarily a false positive. Not malicious, but maybe a stupid-code-detector?
Lots are LLM related, Lots have bots contributing code
Publishing rate is crazy, dozens to hundreds of published versions in a day is a bug, not a feature
Brian’s proposal, PyPI should limit releases per day for any package to something a sane human would do, even if they make a mistake on a release, to maybe like 2-3, definitely under 10, in a day. And if the repo has obvious agent contributors listed, maybe lower to the limit to 1-2 a day? Honestly, “move fast and break things” doesn’t apply to breaking the commons.
Michael #4: httpx2
More on the httpx, httpxyz, etc changes: Pydantic people started their own fork, httpx2.
Michiel says “while we think httpxyz was definitely needed, we welcome httpx2 and think it should be the ‘blessed’ fork.”
Kludex, who is among other things maintainer of Starlette, was considering a fork
As it stands, httpx2 is lacking the performance improvements they added to httpxyz. But it will not be long before they will add those, too.
Also they already made some smart decisions:
they are switching from certifi to truststore
they are switching to compression.zstd on Python 3.14+, enabling zstd compression by default
they merged httpcore and vendored it in their repository
Discussion on Hacker News
Extras
Brian:
The Four Horsemen of the LLM Apocalypse - Anarcat
Django/JetBrains 2026 developer survey is open
Pyrefly 1.0 : “meaning we are confident that Pyrefly is ready for production use.”
Michael:
Just about ready to release Python Web Security: OWASP Top 10 with Agentic AI course. Be sure to be on the courses newsletter to get notified.
Joke: Proud Parents
#479 Talking About Types
Topics covered in this episode:
httpxyz one month in
Learn concurrency - a deep dive into multithreading with Python
pip 26.1 - lockfiles and dependency cooldowns
Python 3.15 sentinal values from PEP 661
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python Training
The Complete pytest Course
Patreon Supporters
Connect with the hosts
Michael: @mkennedy@fosstodon.org / @mkennedy.codes (bsky)
Brian: @brianokken@fosstodon.org / @brianokken.bsky.social
Show: @pythonbytes@fosstodon.org / @pythonbytes.fm (bsky)
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Monday at 11am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Michael #1: httpxyz one month in
First version of httpxyz contained just the fixes to get zstd working, and the fixes to get the test suite running on python 3.14, some ‘housekeeping’ changes related to the renaming
End of March: a compatibility shim that allows you to use httpxyz even with third-party packages that import httpx themselves, as long as you import httpxyz first.
Importing httpxyz automatically registers it under the httpx name in sys.modules , see https://httpxyz.org/httpx-compatibility/
Fixed a WHOLE bunch of performance related issues by forking httpcore
Brian #2: Learn concurrency - a deep dive into multithreading with Python
Nikos Vaggalis
“Whenever you are trying to speed up code using multiple cores, always ask yourself: “Do these threads need to talk to each other right now?” If the answer is yes, it will be slow. The best parallel code splits a big job into completely isolated chunks, processes them separately, and merges the results at the finish line.”
Good overview of thread concurrency with Python and how that’s been improved dramatically with free-threaded Python
Defines lots of terms you come across, including “embarrassingly parallel multithreading”
There’s a counter example that’s nice
Start with a shared resource, a counter, and multiple threads updating it
Attempt to fix with threading.Lock(), which fixes it, but slows things down
Good explanation of why
Proper fix with concurrent.futures and separating the work of different threads so that they can be independent and their results can be combined when they’re all finished.
Michael #3: pip 26.1 - lockfiles and dependency cooldowns
Python 3.9 is no longer supported
Experimental: installing from pylock files
Dependency cooldowns (see my post about this)
Lifting several 2020 resolver limitations
Brian #4: Python 3.15 sentinal values from PEP 661
MISSING = sentinel("MISSING")
def next_value(default: int | MISSING = MISSING):
...
if default is MISSING:
...
Take a name str as a constructor parameter
Intended to be compared with is operator, similar to None
Sentinal objects can be used as a type, also similar to None
and can be combined with other types with |.
Unlike None, sentinal values are truthy. (Elipses ... are also truthy)
This seems like a strange choice. but I guess it must have made sense to someone.
It does force you to use is instead of depending on False-ness, so I guess it’ll make code using sentinels more readable.
Interesting that the PEP was started in 2021, and we’re finally getting it this year.
Extras
Brian:
Before GitHub - Armin Ronacher
tenacity - cross-platform multi-track audio editor/recorder
learned about it from Armin’s article
Joke:
Joke option Make it myself
Seems similar to what people think about software now
Links
httpxyz one month in
httpxyz.org/httpx-compatibility
Learn concurrency - a deep dive into multithreading with Python
pip 26.1 - lockfiles and dependency cooldowns
my post about this
Python 3.15 sentinal values from PEP 661
Before GitHub
tenacity
Make it myself
#478 Iodine tablets and potable water
Topics covered in this episode:
profiling-explorer
Reverting the incremental GC in Python 3.14 and 3.15
VSCode AI Co-author defaults to on, then off
django freeze
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python Training
The Complete pytest Course
Patreon Supporters
Connect with the hosts
Michael: @mkennedy@fosstodon.org / @mkennedy.codes (bsky)
Brian: @brianokken@fosstodon.org / @brianokken.bsky.social
Show: @pythonbytes@fosstodon.org / @pythonbytes.fm (bsky)
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Monday at 11am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Brian #1: profiling-explorer
Adam Johnson
And intro post Python: introducing profiling-explorer
“profiling-explorer is a tool for exploring profiling data from Python’s built-in profilers, which are stored in pstats files. ”
Features
Dark mode
Click the calls, internal ms, or cumulative ms column headers to sort by that column.
Use the search box to filter by filename or function name.
Hover by a filename + line number pair to reveal the copy button, which copies the location to your clipboard for faster opening.
Click the callers or callees links on the right of a row (not pictured above) to see the callers or callees of that function.
Michael #2: Reverting the incremental GC in Python 3.14 and 3.15
Python 3.14 shipped with a new incremental garbage collector, but production reports of severe memory pressure (Neil Schemenauer measured up to 5× peak RSS on pathological cyclic workloads) have pushed the core team and Steering Council to revert it in both 3.14 and 3.15 - returning to the 3.13-era generational GC.
This is the second time the inc GC has been pulled back: it was also reverted right before 3.13.0 final, and it shipped in 3.14 without going through the PEP process.
The tradeoff is real: Neil's benchmarks showed max GC pause times of 1.3ms with inc GC versus 26ms with the generational one - great for latency-sensitive apps, terrible for memory-constrained ones.
Release manager Hugo van Kemenade will ship 3.14.5 early with the revert, and Gregory Smith floated the idea of a 3.14.5rc1 - the first patch-release RC since 3.9.2 back in 2021.
Tim Peters spent the thread doing live forensics on Windows, running a toy deque program that should cap at 1GB and watching it balloon to 15.6GB on a 16GB machine - and discovered the gen0 collector effectively never fires under the new scheme.
Tim's bigger meta-point: CPython has a chronic shortage of real-world GC benchmarks, pyperformance has "basically no interesting" cyclic workloads, and users almost never share real data - so core devs keep flying blind on changes like this.
Django maintainer Adam Johnson published a blog post mid-thread documenting a real memory "leak" in Django's migration system caused by inc GC, with a manual gc.collect() workaround - the listener-facing receipt that this wasn't just theoretical.
If the inc GC comes back for 3.16, it'll go through a proper PEP, and the discussion is already shifting toward keeping both collectors available via a startup flag - which Neil and Sergey Miryanov have both prototyped.
Brian #3: VSCode AI Co-author defaults to on, then off
VSCode merges Enabling ai co author by default - 3 week ago
Ton’s of “why would you do this” and related comments
VSCode merges Change default for git.addAICoAuthor to off - yesterday
Take-away, don’t rely on default, set addAICoAuthor to off yourself
Michael #4: django freeze
Convert your dynamic django site to a static one with one line of code.
Just run python manage.py generate_static_site :)
Features
Generate the static version of your Django site, optionally compressed .zip file
Generate/download the static site using urls (only superuser and staff)
Follow sitemap.xml urls
Follow internal links founded in each page
Follow redirects
Report invalid/broken urls
Selectively include/exclude media and static files
Custom base url (very useful if the static site will run in a specific folder different by the document-root)
Convert urls to relative urls (very useful if the static site will run offline or in an unknown folder different by the document-root)
Prevent local directory index
Extras
Brian:
Thinking Less, Trusting More: GenAI’s Impacts on Students’ Cognitive Habits
Michael:
Vercel breached, employee to blame
Introducing the new Talk Python web player
GitHub uptime (a couple of views 1, 2)
Joke: Friends in tech
#477 Lazy, Frozen, and 31% Lighter
Topics covered in this episode:
Django Modern Rest
Already playing with Python 3.15
Cutting Python Web App Memory Over 31%
tryke - A Rust-based Ptyhon test runner with a Jest-style API
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python Training
The Complete pytest Course
Patreon Supporters
Connect with the hosts
Michael: @mkennedy@fosstodon.org / @mkennedy.codes (bsky)
Brian: @brianokken@fosstodon.org / @brianokken.bsky.social
Show: @pythonbytes@fosstodon.org / @pythonbytes.fm (bsky)
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Monday at 11am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Michael #1: Django Modern Rest
Modern REST framework for Django with types and async support
Supports Pydantic, Attrs, and msgspec
Has ai coding support with llms.txt
See an example at the “showcase” section
Brian #2: Already playing with Python 3.15
3.15.0a8, 2.14.4 and 3.13.13 are out
Hugo von Kemenade
beta comes in May, CRs in Sept, and Final planned for October
But still, there’s awesome stuff here already, here’s what I’m looking forward to:
PEP 810: Explicit lazy imports
PEP 814: frozendict built-in type
PEP 798: Unpacking in comprehensions with * and **
PEP 686: Python now uses UTF-8 as the default encoding
Michael #3: Cutting Python Web App Memory Over 31%
I cut 3.2 GB of memory usage from our Python web apps using five techniques:
async workers
import isolation
the Raw+DC database pattern
local imports for heavy libraries
disk-based caching
See the full article for details.
Brian #4: tryke - A Rust-based Ptyhon test runner with a Jest-style API
Justin Chapman
Watch mode, Native async support, Fast test discovery, In-source testing, Support for doctests, Client/server mode for fast editor integrations, Pretty, per-assertion diagnostics, Filtering and marks, Changed mode (like pytest-picked), Concurrent tests, Soft assertions,
JSON, JUnit, Dot, and LLM reporters
Honestly haven’t tried it yet, but you know, I’m kinda a fan of thinking outside the box with testing strategies so I welcome new ideas.
Extras
Brian:
Why are’t we uv yet?
Interesting take on the “agents prefer pip”
Problem with analysis.
Many projects are libraries and don’t publish uv.lock file
Even with uv, it still often seen as a developer preference for non-libarries. You can sitll use uv with requirements.txt
PyCon US 2026 talks schedule is up
Interesting that there’s an AI track now. I won’t be attending, but I might have a bot watch the videos and summarize for me. :)
What has technology done to us?
Justin Jackson
Lean TDD new cover
Also, 0.6.1 is so ready for me to start f-ing reading the audio book and get on with this shipping the actual f-ing book and yes I realize I seem like I’m old because I use “f-ing” while typing.
Michael:
Python 3.14.4 is out
Beanie 2.1 release
Joke: HumanDB - Blazingly slow. Emotionally consistent.
#476 Common themes
Topics covered in this episode:
Migrating from mypy to ty: Lessons from FastAPI
Oxyde ORM
Typeshedded CPython docs
Raw+DC Database Pattern: A Retrospective
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python Training
The Complete pytest Course
Patreon Supporters
Connect with the hosts
Michael: @mkennedy@fosstodon.org / @mkennedy.codes (bsky)
Brian: @brianokken@fosstodon.org / @brianokken.bsky.social
Show: @pythonbytes@fosstodon.org / @pythonbytes.fm (bsky)
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Monday at 11am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Brian #1: Migrating from mypy to ty: Lessons from FastAPI
Tim Hopper
I saw this post by Sebastián Ramírez about all of his projects switching to ty
FastAPI, Typer, SQLModel, Asyncer, FastAPI CLI
SqlModel is already ty only - mypy removed
This signals that ty is ready to use
Tim lists some steps to apply ty to your own projects
Add ty alongside mypy
Set error-on-warning = true
Accept the double-ignore comments
Pick a smaller project to cut over first
Drop mypy when the noise exceeds the signalAdd ty alongside mypy
Related anecdote:
I had tried out ty with pytest-check in the past with difficulty
Tried it again this morning, only a few areas where mypy was happy but ty reported issues
At least one ty warning was a potential problem for people running pre-releases of pytest,
Not really related: packaging.version.parse is awesome
Michael #2: Oxyde ORM
Oxyde ORM is a type-safe, Pydantic-centric asynchronous ORM with a high-performance Rust core.
Note: Oxyde is a young project under active development. The API may evolve between minor versions.
No sync wrappers or thread pools. Oxyde is async from the ground up
Includes oxyde-admin
Features
Django-style API - Familiar Model.objects.filter() syntax
Pydantic v2 models - Full validation, type hints, serialization
Async-first - Built for modern async Python with asyncio
Rust performance - SQL generation and execution in native Rust
Multi-database - PostgreSQL, SQLite, MySQL support
Transactions - transaction.atomic() context manager with savepoints
Migrations - Django-style makemigrations and migrate CLI
Brian #3: Typeshedded CPython docs
Thanks emmatyping for the suggestion
Documentation for Python with typeshed types
Source: typeshedding_cpython_docs
Michael #4: Raw+DC Database Pattern: A Retrospective
A new design pattern I’m seeing gain traction in the software space: Raw+DC: The ORM pattern of 2026
I’ve had a chance to migrate three of my most important web app.
Thrilled to report that yes, the web app is much faster using Raw+DC
Plus, this was part of the journey to move from 1.3 GB memory usage to 0.45 GB (more on this next week)
Extras
Brian:
Lean TDD 0.5 update
Significant rewrite and focus
Michael:
pytest-just (for just command file testing), by Michael Booth
Something going on with Encode
httpx: Anyone know what's up with HTTPX? And forked
starlette and uvicorn: Transfer of Uvicorn & Starlette
mkdocs: The Slow Collapse of MkDocs
django-rest-framework: Move to django commons?
Certificates at Talk Python Training
Joke:
Neue Rich
#475 Haunted warehouses
Topics covered in this episode:
Lock the Ghost
Fence for Sandboxing
MALUS: Liberate Open Source
Harden your GitHub Actions Workflows with zizmor, dependency pinning, and dependency cooldowns
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python Training
The Complete pytest Course
**Patreon SupportersConnect with the hosts**
Michael: @mkennedy@fosstodon.org / @mkennedy.codes (bsky)
Brian: @brianokken@fosstodon.org / @brianokken.bsky.social
Show: @pythonbytes@fosstodon.org / @pythonbytes.fm (bsky)
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Monday at 11am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Michael #1: Lock the Ghost
The five core takeaways:
PyPI "removal" doesn't delete distribution files. When a package is removed from PyPI, it disappears from the index and project page, but the actual distribution files remain accessible if you have a direct URL to them.
uv.lock uniquely preserves access to ghost packages. Because uv.lock stores direct URLs to distribution files rather than relying on the index API at install time, uv sync can successfully install packages that have already been removed, even with cache disabled. No other Python lock file implementation tested behaved this way.
This creates a supply chain attack vector. An attacker could upload a malicious package, immediately remove it to dodge automated security scanning, and still have it installable via a uv.lock file, or combine this with the xz-style strategy of hiding malicious additions in large, auto-generated lock files that nobody reviews.
Removed package names can be hijacked with version collisions. When an owner removes a package, the name can be reclaimed by someone else who can upload different distribution types under the same version number, as happened with "umap." Lock files help until you regenerate them, then you're exposed.
Your dependency scanning needs to cover lock files, not just manifest files. Scanning only pyproject.toml or requirements.txt misses threats embedded in lock files, which is where the actual resolved URLs and hashes live.
Brian #2: Fence for Sandboxing
Suggested by Martin Häcker
“Some coding platforms have since integrated built-in sandboxing (e.g., Claude Code) to restrict write access to directories and/or network connectivity. However, these safeguards are typically optional and not enabled by default.”
“JY Tan (on cc) has extracted the sandboxing logic from Claude Code and repackaged it into a standalone Go binary.”
Source code on GitHub: https://github.com/Use-Tusk/fence
Related:
Simon Willison lethal trifecta for AI agents article from June 2025
Claude Code Sandboxing
Michael #3: MALUS: Liberate Open Source
via Paul Bauer
The service will generate the specs of a library with one AI and build the newly licensed library using the specs with another AI circumventing the licensing and copyright rules.
AI that has not been trained on open source reads the docs and API signature, creates a spec. Another AI processes that spec into working software.
Is it a real site? Are they accepting real money, or are they just trying to cause a stir around copyright?
Brian #4: Harden your GitHub Actions Workflows with zizmor, dependency pinning, and dependency cooldowns
Matthias Schoettle
Avoid things like this: hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far
Extras
Brian:
GitHub is asking to spy on us, that’s nice
Michael:
Michael’s new SaaS for podcasters: InterviewCue
DigitalOcean’s Spaces cold storage for infrequently accessed data
Minor issue about my fire and forget post, was a latent bug?
Fire and Forget at Textual follow up article
Joke: Can you?
#474 Astral to join OpenAI
Topics covered in this episode:
Starlette 1.0.0
Astral to join OpenAI
uv audit
Fire and forget (or never) with Python’s asyncio
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python Training
The Complete pytest Course
Patreon Supporters
Connect with the hosts
Michael: @mkennedy@fosstodon.org / @mkennedy.codes (bsky)
Brian: @brianokken@fosstodon.org / @brianokken.bsky.social
Show: @pythonbytes@fosstodon.org / @pythonbytes.fm (bsky)
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Monday at 11am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Brian #1: Starlette 1.0.0
As a reminder, Starlette is the foundation for FastAPI
Starlette 1.0 is here! - fun blog post from Marcello Trylesinski
“The changes in 1.0 were limited to removing old deprecated code that had been on the way out for years, along with a few bug fixes. From now on we'll follow SemVer strictly.”
Fun comment in the “What’s next?” section:
“Oh, and Sebastián, Starlette is now out of your way to release FastAPI 1.0. 😉”
Related: Experimenting with Starlette 1.0 with Claude skills
Simon Willison
example of the new lifespan mechanism, very pytest fixture-like
@contextlib.asynccontextmanager
async def lifespan(app):
async with some_async_resource():
print("Run at startup!")
yield
print("Run on shutdown!")
app = Starlette(
routes=routes,
lifespan=lifespan
)
Michael #2: Astral to join OpenAI
via John Hagen, thanks
Astral has agreed to join OpenAI as part of the Codex team
Congrats Charlie and team
Seems like **Ruff** and uv play an important roll.
Perhaps ty holds the most value to directly boost Codex (understanding codebases for the AI)
All that said, these were open source so there is way more to the motivations than just using the tools.
After joining the Codex team, we'll continue building our open source tools.
Simon Willison has thoughts
discuss.python.org also has thoughts
The Ars Technica article has interesting comments too
It’s probably the death pyx
Simon points out “pyx is notably absent from both the Astral and OpenAI announcement posts.”
Brian #3: uv audit
Submitted by Owen Lemont
Pieces of uv audit have been trickling in. uv 0.10.12 exposes it to the cli help
Here’s the roadmap for uv audit
I tried it out on a package and found a security issue with a dependency
not of the project, but of the testing dependencies
but only if using Python < 3.10, even though I’m using 3.14
Kinda cool
Looks like it generates a uv.lock file, which includes dependencies for all project supported versions of Python and systems, which is a very thorough way to check for vulnerabilities.
But also, maybe some pointers on how to fix the problem would be good. No --fix yet.
Michael #4: Fire and forget (or never) with Python’s asyncio
Python’s asyncio.create_task() can silently garbage collect your fire-and-forget tasks starting in Python 3.12
Formerly fine async code can now stop working, so heads up
The fix? Use a set to upgrade to a strong ref and a callback to remove it
Is there a chance of task-based memory leaks? Yeah, maybe.
Extras
Brian:
Nobody Gets Promoted for Simplicity - interesting read and unfortunate truth in too many places.
pytest-check - All built-in check helper functions in this list also accept an optional xfail reason.
example: check.equal(actual, expected, xfail="known issue #123")
Allows some checks to still cause a failure to happen because you no longer have to mark the whole test as xfail
Michael:
TurboAPI - FastAPI + Pydantic compatible framework in Zig (see follow up)
Pyramid 2.1 is out (yes really! :) first release in 3 years)
Vivaldi 7.9 adds minimalist hide mode.
Migrated pythonbytes.fm and talkpython.fm to Raw+DC design pattern
Robyn + Chameleon package
Joke: We now have translation services
#473 A clean room rewrite?
Topics covered in this episode:
chardet ,AI, and licensing
refined-github
pgdog: PostgreSQL connection pooler, load balancer and database sharder
Agentic Engineering Patterns
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python Training
The Complete pytest Course
Patreon Supporters
Connect with the hosts
Michael: @mkennedy@fosstodon.org / @mkennedy.codes (bsky)
Brian: @brianokken@fosstodon.org / @brianokken.bsky.social
Show: @pythonbytes@fosstodon.org / @pythonbytes.fm (bsky)
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Monday at 10am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Michael #1: chardet ,AI, and licensing
Thanks Ian Lessing
Wow, where to start?
A bit of legal precedence research.
Chardet dispute shows how AI will kill software licensing, argues Bruce Perens on the Register
Also see this GitHub issue.
Dan Blanchard, maintainer of a Python character encoding detection library called chardet, released a new version of the library under a new software license. (LGPL → MIT)
Dan is allowed to make this change because v7 is a complete “clean room” rewrite using AI
BTW, v7 is WAY better:
The result is a 48x increase in detection speed for a project that lives in the hot loops of many projects. That will lead to noticeable performance increases for literally millions of users (the package gets ~130M downloads per month).
It paves a path towards inclusion in the standard library (assuming they don’t institute policies against using AI tools).
Thread-safe detect() and detect_all() with no measurable overhead; scales on free-threaded Python 3.13t+
An individual claiming to be Mark Pilgrim, the original creator of the library, opened an issue in the project's GitHub repo arguing that Blanchard had no right to change the software license, citing the LPGL requirement that the license remain unchanged.
A 'complete rewrite' is irrelevant, since they had ample exposure to the originally licensed code (i.e. this is not a 'clean room' implementation).
Blanchard disagreed, citing how version 7.0.0 and 6.0.0 compare when subjected to JPlag, a library for detecting plagiarism.
Blanchard told The Register he had wanted to get chardet added to the Python standard library for more than a decade since it’s a core dependency to most Python projects.
Brian #2: refined-github
Suggested by Matthias Schöttle
A browser plugin that improves the GitHub experience
A sampling
Adds a build/CI status icon next to the repo’s name.
Adds a link back to the PR that ran the workflow.
Enables tab and shift tab for indentation in comment fields.
Auto-resizes comment fields to fit their content and no longer show scroll bars.
Highlights the most useful comment in issues.
Changes the default sort order of issues/PRs to Recently updated.
But really, it’s a huge list of improvements
Michael #3: pgdog: PostgreSQL connection pooler, load balancer and database sharder
PgDog is a proxy for scaling PostgreSQL.
It supports connection pooling, load balancing queries and sharding entire databases.
Written in Rust, PgDog is fast, secure and can manage thousands of connections on commodity hardware.
Features
PgDog is an application layer load balancer for PostgreSQL
Health Checks: PgDog maintains a real-time list of healthy hosts. When a database fails a health check, it's removed from the active rotation and queries are re-routed to other replicas
Single Endpoint: PgDog can detect writes (e.g. INSERT, UPDATE, CREATE TABLE, etc.) and send them to the primary, leaving the replicas to serve reads
Failover: PgDog monitors Postgres replication state and can automatically redirect writes to a different database if a replica is promoted
Sharding: PgDog is able to manage databases with multiple shards
Brian #4: Agentic Engineering Patterns
Simon Willison
So much great stuff here, especially
Anti-patterns: things to avoid
And 3 sections on testing
Red/green TDD
First run the test
Agentic manual testing
Extras
Brian:
uv python upgrade will upgrade all versions of Python installed with uv to latest patch release
suggested by John Hagen
Coding After Coders: The End of Computer Programming as We Know It
NY Times Article
Suggested by Christopher
Best quote: “Pushing code that fails pytest is unacceptable and embarrassing.”
Michael:
Talk Python Training users get a better account dashboard
Package Managers Need to Cool Down
Will AI Kill Open Source, article + video
My Always activate the venv is now a zsh-plugin, sorta.
Joke: Ergonomic keyboard
Also pretty good and related:
Claude Code Mandated
Links
legal precedence research
Chardet dispute shows how AI will kill software licensing, argues Bruce Perens
this GitHub issue
citing
JPlag
refined-github
Agentic Engineering Patterns
Anti-patterns: things to avoid
Red/green TDD
First run the test
Agentic manual testing
uv python upgrade
Coding After Coders: The End of Computer Programming as We Know It
Suggested by Christopher
a better account dashboard
Package Managers Need to Cool Down
Will AI Kill Open Source
Always activate the venv
now a zsh-plugin
Ergonomic keyboard
Claude Code Mandated
claude-mandated.png
blobs.pythonbytes.fm/keyboard-joke.jpeg?cache_id=a6026b
#472 Monorepos
Topics covered in this episode:
Setting up a Python monorepo with uv workspaces
cattrs: Flexible Object Serialization and Validation
Learning to program in the AI age
VS Code extension for FastAPI and friends
Extras
Joke
Watch on YouTube
About the show
Sponsored by us! Support our work through:
Our courses at Talk Python Training
The Complete pytest Course
Patreon Supporters
Connect with the hosts
Michael: @mkennedy@fosstodon.org / @mkennedy.codes (bsky)
Brian: @brianokken@fosstodon.org / @brianokken.bsky.social
Show: @pythonbytes@fosstodon.org / @pythonbytes.fm (bsky)
Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Monday at 11am PT. Older video versions available there too.
Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.
Brian #1: Setting up a Python monorepo with uv workspaces
Dennis Traub
The 3 things
Give the Root a Distinct Name
Use workspace = true for Inter-Package Deps
Use importlib Mode for pytest
Michael #2: cattrs: Flexible Object Serialization and Validation
cattrs is a Swiss Army knife for (un)structuring and validating data in Python.
A natural alternative/follow on from DataClass Wizard
Converts to ←→ from dictionaries
cattrs also focuses on functional composition and not coupling your data model to its serialization and validation rules.
When you’re handed unstructured data (by your network, file system, database, …), cattrs helps to convert this data into trustworthy structured data.
Batteries Included: cattrs comes with pre-configured converters for a number of serialization libraries, including JSON (standard library, orjson, UltraJSON), msgpack, cbor2, bson, PyYAML, tomlkit and msgspec (supports only JSON at this time).
Brian #3: Learning to program in the AI age
Jose Blanca
“I teach a couple of introductory Python courses and I've been thinking about which advice to give to my students, that are studying how to program for the first time. I have collected my ideas in these blog posts”
Why learning to program is as useful as ever, even with powerful AI tools available.
How to use AI as a tutor rather than a shortcut, and why practice remains the key to real understanding.
What the real learning objectives are: mental models, managing complexity, and thinking like a software developer.
Michael #4: VS Code extension for FastAPI and friends
Enhances the FastAPI development experience in Visual Studio Code
Path Operation Explorer: Provides a hierarchical tree view of all FastAPI routes in your application.
Search for routes: Use the Command Palette and quickly search for routes by path, method, or name.
CodeLens links appear above HTTP client calls like client.get('/items'), letting you jump directly to the matching route definition.
Deploy your application directly to FastAPI Cloud from the status bar with zero config.
View real-time logs from your FastAPI Cloud deployed applications directly within VS Code.
Install from Marketplace.
Extras
Brian:
Guido van Rossum interviews key Python developers from the first 25 years
Interview with Brett Cannon
Interview with Thomas Wouters
Michael:
IntelliJ IDEA: The Documentary | An origin story video
Cursor Joined the ACP Registry and Is Now Live in Your JetBrains IDE
What hyper-personal software looks like
I’m doing in-person training again (limited scope):
On-site, hands-on AI engineering enablement for software teams with Michael
Joke: Saas is dead
#471 The ORM pattern of 2026?
Topics covered in this episode:
Raw+DC: The ORM pattern of 2026?
pytest-check releases
Dataclass Wizard
SQLiteo - “native macOS SQLite browser built for normal people”
Extras
Joke
See the full show notes for this episode on the website at pythonbytes.fm/471
#470 A Jolting Episode
Topics covered in this episode:
Better Python tests with inline-snapshot
jolt Battery intelligence for your laptop
Markdown code formatting with ruff
act - run your GitHub actions locally
Extras
Joke
See the full show notes for this episode on the website at pythonbytes.fm/470
#469 Commands, out of the terminal
Topics covered in this episode:
Command Book App
uvx.sh: Install Python tools without uv or Python
Ending 15 years of subprocess polling
monty: A minimal, secure Python interpreter written in Rust for use by AI
Extras
Joke
See the full show notes for this episode on the website at pythonbytes.fm/469
#468 A bolt of Django
Topics covered in this episode:
django-bolt: Faster than FastAPI, but with Django ORM, Django Admin, and Django packages
pyleak
More Django (three articles)
Datastar
Extras
Joke
See the full show notes for this episode on the website at pythonbytes.fm/468
#467 Toads in my AI
Topics covered in this episode:
GreyNoise IP Check
tprof: a targeting profiler
TOAD is out
Extras
Joke
See the full show notes for this episode on the website at pythonbytes.fm/467
#466 PSF Lands $1.5 million
Topics covered in this episode:
Better Django management commands with django-click and django-typer
PSF Lands a $1.5 million sponsorship from Anthropic
How uv got so fast
PyView Web Framework
Extras
Joke
See the full show notes for this episode on the website at pythonbytes.fm/466
#465 Stack Overflow is Cooked
Topics covered in this episode:
port-killer
How we made Python's packaging library 3x faster
CodSpeed
Extras
Joke
See the full show notes for this episode on the website at pythonbytes.fm/465
#464 Malicious Package? No Build For You!
Topics covered in this episode:
ty: An extremely fast Python type checker and LSP
Python Supply Chain Security Made Easy
typing_extensions
MI6 chief: We'll be as fluent in Python as we are in Russian
Extras
Joke
See the full show notes for this episode on the website at pythonbytes.fm/464
#463 2025 is @wrapped
Topics covered in this episode:
Has the cost of building software just dropped 90%?
More on Deprecation Warnings
How FOSS Won and Why It Matters
Should I be looking for a GitHub alternative?
Extras
Joke
See the full show notes for this episode on the website at pythonbytes.fm/463
#462 LinkedIn Cringe
Topics covered in this episode:
Deprecations via warnings
docs
PyAtlas: interactive map of the top 10,000 Python packages on PyPI.
Buckaroo
Extras
Joke
See the full show notes for this episode on the website at pythonbytes.fm/462
#461 This episdoe has a typo
Topics covered in this episode:
PEP 798: Unpacking in Comprehensions
Pandas 3.0.0rc0
typos
A couple testing topics
Extras
Joke
See the full show notes for this episode on the website at pythonbytes.fm/461