Saltar al contenido
PodcastsNoticiasPython Bytes

Python Bytes

Michael Kennedy and Calvin Hendryx-Parker
Python Bytes
Último episodio

491 episodios

  • Python Bytes

    #490 It’s a vibe coding party

    28/07/2026 | 37 min
    Topics covered in this episode:

    Some more things about Django I've been enjoying

    Who cleans up after the vibe-coding party?

    Where Did All Your AI Tokens Go? AgentsView to the rescue!

    Careful with phishing all

    Extras

    Joke

    Watch on YouTube

    About the show

    Sponsored by us! Support our work through:

    Our courses at Talk Python

    Consulting from Six Feet Up

    Connect with the hosts

    Michael: Mastodon / BlueSky / X / LinkedIn

    Calvin: Mastodon / BlueSky / X / LinkedIn

    Show: Mastodon / BlueSky / X

    Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too.

    Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.

    Calvin #1: Some more things about Django I've been enjoying

    Julia Evans is learning "2010-style" web dev (Django + SQL + server-rendered HTML) after years of Go backends and JS-heavy frontends

    Query builders: likes defining custom QuerySet classes with chainable filter methods (.approved().future().with_tags()) — more readable than raw SQL

    Template filters: highlights urlize, linebreaksbr, json_script, and especially querystring for building/modifying query-string links in templates

    Migrations: still loves Django's auto-generated migrations — 19 and counting on her project

    Skips inheritance for class-based views; prefers function-based views for sharing code, though fine using Django's own mixins/interfaces

    Performance surprise: CPU profiling (via py-spy) — not slow DB queries — revealed the culprit; she'd accidentally disabled the cached template loader, and re-enabling it took throughput from ~2-3 req/s to ~12 req/s on a $10/mo VM

    Michael #2: Who cleans up after the vibe-coding party?

    FT Magazine piece by Sam Learner (July 11) on AI coding tools overwhelming open source maintainers - sent in by listener Dylan McConnell, whose main point was that this ran in the Financial Times, not a dev blog.

    cURL as the case study - Daniel Stenberg has been the only full-time person on it for years; libcurl has been installed an estimated 20+ billion times with 3,000+ listed contributors.

    Bug bounty killed - cURL ended its paid security bounty program in January, citing an "explosion of AI slop reports" that take real time to debunk and drain morale.

    Extractive contributions - authoring a PR is now nearly free, reviewing one still costs a human; tldraw's Steve Ruiz closed outside contributions entirely, asking why he'd want someone else writing the easy part.

    Guido weighs in - van Rossum says projects are holding emergency meetings over the slop flow, and notes LLM patches tend to touch unrelated parts of a file, making review more tedious.

    "Vibe Coding Kills Open Source" - paper from Miklós Koren's group: packages frequently recommended by coding models saw big download jumps with no matching engagement, breaking the reputation loop that sustains maintainers.

    Stack Overflow flatlined - over 100,000 questions a month before ChatGPT, under 1,500 last month, with the response rate cut roughly in half; the public archive is now stale training data.

    The course-creator angle - Josh Comeau's newest web dev course launched at about a third of prior enrollment, and he worries about devs who never learn which questions to ask.

    But the most interesting portion is what was omitted.

    Focused on: The end of the curl bug-bounty

    Omitted: High-Quality Chaos

    Why the omission is interesting

    It fits a narrative. The FT piece is a maintenance-and-decline story, and January-Stenberg is a perfect witness for it. April-Stenberg complicates it - same person, same project, better data, opposite direction on the specific claim being used.

    The tell is already in the article. Learner quotes Stenberg saying AI tools are much better at finding problems than fixing them. That's the April thesis in one line, and it goes undeveloped.

    Reason for the shift is process, not vibes. Killing the bounty removed the cash incentive and the venue change filtered the rest. Worth saying out loud, because "AI reports got better" isn't quite it - "no bounty plus a real triage platform" is closer.

    Joke too: Sarah O’Connor wrote a related piece (is this just before skynet launches?)

    Calvin #3: Where Did All Your AI Tokens Go? AgentsView to the rescue!

    Local-first desktop/web app for browsing, searching, and analyzing your past AI coding agent sessions (Claude Code, Codex, Copilot, Cursor, Gemini, Aider, and dozens more)

    Auto-discovers session files on your machine — no config needed; everything stored locally in SQLite, no cloud/accounts

    agentsview usage is a drop-in ccusage alternative — reads from pre-indexed SQLite, reports run 80–220× faster on large histories

    New Activity dashboard shows peak concurrency, active vs. idle time, agent-minutes, and cost — filterable by project/agent/machine, with a -json CLI report too

    Full-text + optional semantic search across every session; also imports Claude.ai/ChatGPT chat exports

    Install via pip install agentsview, uvx agentsview, brew install --cask agentsview, or download desktop binaries from GitHub Releases

    Michael #4: Careful with phishing all

    The situation

    I pass this along because it was a pretty sneaky bit of targeted phishing, and happened to play off an old interaction in bandit's repo. As usual with phishing scams there are a bunch of tells that this isn't legitimate, but just enough plausibility that I could see falling for it in a weak moment. Relative nobodies like me haven't historically been worth the effort to hit with scams this specific. Agents change the game though :-/. Be careful out there folks!

    Original message

    From: "Patrick (Blacktrace)" [HTML_REMOVED]
    To: LISTENER EMAIL
    Subject: Your Bandit #1350 (B105 NextToken false positive) -- just fixed that exact case

    Date: Wednesday, July 15, 2026 12:02 AM

    Hi AJ,

    Saw your Bandit issue #1350 -- the B105 hardcoded-password false positive on the string NextToken. I build a deterministic gate that filters that class of Bandit noise, and #1350 was literally the case I just fixed: NextToken / next_token / page_token / nextPageToken now stay quiet, while a genuine hardcoded token like api_token="sk-live-..." still fires. Verified against your exact case.

    30-second paste: https://blacktrace.co/noise-eraser

    Where it still trips, published: https://blacktrace.co/kruc

    Curious whether it clears what you hit -- and if it trips on something of yours, that's the more useful reply.

    Patrick, Blacktrace

    I asked Claude for some analysis too. It was pretty good at finding them.

    The message name-drops enough real detail to feel legit, but the structure is pure phishing - everything in it exists to get AJ onto blacktrace.co. The strongest ones:

    Freemail sender, corporate signoff. Signs as "Patrick, Blacktrace" but sends from emailpjv@gmail.com. Real company outreach comes from the company domain, not a personal Gmail - and there's no last name.

    Over-specific targeting. It mirrors AJ's exact public activity - issue #1350, the B105 rule, the NextToken false positive, even the token variants. That's the "just enough plausibility" AJ flagged, and it's exactly what agents make cheap: scrape a GitHub issue, auto-generate tailored bait. Legit cold outreach rarely reads your history back to you this precisely.

    The entire payload is two links. Strip the technical flattery and the message is just "paste here" plus "see results here." When the whole point of an email is the click, that's the tell.

    "30-second paste." Low-friction urgency, and "paste" most likely means paste your source into their tool - handing your code to a stranger's site. Exfiltration dressed as convenience.

    Brand-new, no-reputation domain. blacktrace.co has no track record, and the name is doing some ominous work. The /kruc slug is random noise, not how real product pages get named.

    Precise-sounding jargon that's actually vague. "Deterministic gate," "noise-eraser" - impressive, empty. Bolted onto correct real details (B105 is the Bandit hardcoded-password test, sk-live- is a Stripe live-key prefix) to borrow credibility.

    The disarming close. "if it trips on something of yours, that's the more useful reply" - engineered humility that flatters your expertise and baits a response. Makes engaging feel like you're doing them a favor, which drops your guard.

    Extras

    Calvin:

    DjangoCon US 2026 is rapidly approaching, August 24-28, Chicago

    Ruff v0.16.0 massively expands its default rule set

    Ruff now enables 413 rules by default, up from 59

    https://astral.sh/blog/ruff-v0.16.0

    Michael:

    Completely redesigned the home page.

    Try /insights in Claude Code (terminal)

    Joke: We’re Safe
  • Python Bytes

    #489 Or JSON?

    21/07/2026 | 30 min
    Topics covered in this episode:

    django-orjson

    Best Django Redis configuration for speed and size

    Linus Torvalds puts the foot down against Anti-AI Kernel Maintainers

    Django Steering Council backs the Triptych Project

    Extras

    Joke

    Watch on YouTube

    About the show

    Sponsored by us! Support our work through:

    Our courses at Talk Python

    Consulting from Six Feet Up

    Connect with the hosts

    Michael: Mastodon / BlueSky / X / LinkedIn

    Calvin: Mastodon / BlueSky / X / LinkedIn

    Show: Mastodon / BlueSky / X

    Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too.

    Michael #1: django-orjson

    Adam Johnson dropped django-orjson - drop-in replacements for the Django and DRF pieces that touch JSON, swapping stdlib json for orjson, the Rust-based library. Headline numbers: 10x faster serialization, 2x faster deserialization.

    The interesting question is why this needs to be a package at all. pip install orjson is the easy part. Adam's actual pitch: adopting it "isn't easy, especially when your framework uses json in many different parts." Django scatters JSON across JsonResponse, the test client and test case classes, the json_script template tag, and more. There's no single hook to grab, so you get a library that catches them all.

    Adam is refreshingly honest about the scale of the win. His words: "While database queries tend to dominate the typical Django application's runtime, the time spent in serialization and deserialization can still be significant." He calls it "a nearly free performance win" - not "this will 10x your app." That's a claim about cost, not magnitude, and it's worth keeping those straight.

    Worth flagging what the post doesn't cover: caveats. There are none in the article, but orjson has real ones. Django and Flask both render datetimes as RFC 822 HTTP-date (Wed, 15 Jul 2026 12:00:00 GMT); orjson does ISO 8601. It can't do ensure_ascii, it rejects NaN and Infinity (which stdlib happily emits), and it raises on Decimal. If you've got a JS client parsing dates, that's a wire-format change.

    Who should actually take this? If you're a DRF shop shoveling JSON all day, yes - it's cheap and it's real. If your app mostly renders HTML templates, you're optimizing a slice of runtime that's already near zero.

    The problem Adam's package solves doesn't exist in Flask or Quart. They already centralize every JSON operation - jsonify, request.get_json(), the test client, the |tojson filter - behind one provider object at app.json. So there's no library to install. It's about ten lines:

    import orjson
    from quart.json.provider import JSONProvider # or flask.json.provider
    class OrjsonProvider(JSONProvider):
    def dumps(self, obj, **kwargs) -> str:
    return orjson.dumps(obj).decode() # provider must return str
    def loads(self, s, **kwargs):
    return orjson.loads(s)
    app.json = OrjsonProvider(app)

    The numbers on talkpython.fm

    Evaluated it, measured it, and skipped it. The biggest JSON payload we serve is our MCP server returning a cached episode transcript, about 139 KB. Swapping the provider saves 0.119 milliseconds per request. That total response takes 1.1 ms

    We got 4.1x, not 10x - and the reason is the good lesson. Payload shape decides your speedup. The 10x is for structure-heavy data, lots of small keys where stdlib burns time in Python-level dispatch per item. Our hot payload is one giant transcript string, so the work is escaping and memcpy

    Calvin #2: Best Django Redis configuration for speed and size

    Peter Bengtsson revisits a classic: his 2017 "Fastest Redis configuration for Django" benchmark now has a 2026 update posted this week.

    The 2017 post pitted django-redis serializers (json, ujson, msgpack, pickle) and compressors (zlib, lzma) against each other; conclusion was msgpack + zlib as the sweet spot - avoid the json serializer, it's fat and slow.

    The 2026 update narrows focus to just compressors: default (no compression), zlib, lzma, and newcomer zstd.

    New results: lzma compresses best but is slowest; zstd is the fastest compressor on Ubuntu; differences between them are very small.

    Big takeaway across both: compression buys you a lot of space (2–3.5x smaller) for very little speed cost - worth it for Redis where memory is the constraint.

    Caveat from the author: results depend heavily on your data - his test stores short strings of numbers, so benchmark your own workload.

    Michael #3: Linus Torvalds puts the foot down against Anti-AI Kernel Maintainers

    Write up on Ars.

    Really good coverage by Maximillian: Time to wake up (for some)

    Torvalds said that “Linux is not one of those anti-AI projects, and if somebody has issues with that, they can do the open-source thing and fork it. Or just walk away.”

    I agree with Max, putting your head in the sand and waiting for AI to go away will likely mean you won’t be working professionally in software development in the coming years.

    The statement came amid a lengthy thread arguing about the use of Sashiko, an “agentic Linux kernel code review system” that its creators claim can, in tests, independently find 53.6 percent of the bugs that would end up being fixed by human coders in later commits.

    “We’re not forcing anybody to use [LLM tools], but I will very loudly ignore people who try to argue against other people from using it,” Torvalds said.

    “Anybody who points to the problems at AI had better be looking in the mirror and pointing at themselves at the same time,” Torvalds wrote.

    Calvin #4: Django Steering Council backs the Triptych Project

    Django Steering Council issued a Letter of Collaboration backing Carson Gross & Alex Petros's funding bid for the Triptych Project - three proposals to make HTML more expressive natively, in every browser.

    The three additions: PUT/PATCH/DELETE methods for forms, button actions (buttons that fire HTTP requests without a wrapping form), and partial page replacement.

    Distills the core ideas from HTMX/Unpoly/Turbo into the HTML standard itself - no JS, no library, nothing to ship or maintain.

    Current focus is button actions (WHATWG #12330): <button action=/logout method=POST>Logout</button> instead of wrapping a button in a form.

    Relevant to Django directly - think the admin submit row and disguised delete links; Django 6.0's template partials were already inspired by these patterns.

    How to help: companies can send non-binding letters of support on letterhead; individuals can read the proposals and weigh in on the WHATWG issues.

    Extras

    Calvin:

    DOOMQL - A playable first-person shooter whose framebuffer is a SQL query.

    Michael:

    Granian 2.7.9 fixes WSGI threadpool scheduler starvation/underscaling

    Welcome Calvin post

    Joke: Solving all bugs
  • Python Bytes

    #488 tau - it's 2pi and it writes code

    14/07/2026 | 32 min
    Topics covered in this episode:

    The trusted-publishing debate: how to do it right vs. why you shouldn't trust it

    JupyterLab 4.6 and Notebook 7.6 are out!

    Tau – new small, readable terminal coding agent

    Django Tasks and Django 6.1

    Extras

    Joke

    Watch on YouTube

    About the show

    Sponsored by us! Support our work through:

    Our courses at Talk Python

    Consulting from Six Feet Up

    Connect with the hosts

    Michael: Mastodon / BlueSky / X / LinkedIn

    Calvin: Mastodon / BlueSky / X / LinkedIn

    Show: Mastodon / BlueSky / X

    Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too.

    Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.

    Calvin #1: The trusted-publishing debate: how to do it right vs. why you shouldn't trust it

    https://snarky.ca/how-to-publish-to-pypi-using-github-actions-securely/ (Brett Cannon) and https://blog.yossarian.net/2026/07/07/You-shouldnt-trust-trusted-publishing (William Woodruff)

    Trusted Publishing (PyPI's OIDC-based auth scheme, also now used by npm, RubyGems, crates.io, NuGet) replaces long-lived API tokens with short-lived, auto-scoped credentials tied to CI/CD machine identity.

    Yossarian's post: it's purely an authentication mechanism between a machine identity and a package — it says nothing about package safety or quality. PyPI deliberately avoids any "verified/trusted" badge for it, unlike its verified-URL checkmarks.

    Same logic applies to PyPI attestations: anyone can sign with any machine identity they control, so an attestation's presence isn't itself a trust signal.

    Bottom line from that post: don't confuse "trusted" (machine-to-machine) with "trustworthy" (human judgment about the package).

    Snarky.ca's companion piece is more practical: given GitHub Actions compromises in the news, the real fix is 3 concrete steps — run zizmor to lock down workflow permissions/checkout credentials and pin actions to commit hashes, adopt Trusted Publishing to eliminate stored PyPI tokens, and require manual approval via a GitHub environment before any publish job runs.

    Takeaway for listeners: Trusted Publishing is good hygiene for how you authenticate to PyPI, but it's not a substitute for securing your CI pipeline itself — or for actually vetting the packages you install.

    Michael #2: JupyterLab 4.6 and Notebook 7.6 are out!

    Michał Krassowski's rundown - a chunky minor release: 68 features, 97 bug fixes, 95 contributors, one of the biggest ever.

    Scratchpad console (Notebook 7.6 headliner) - a console next to your notebook sharing its kernel, for throwaway experiments. Ctrl+B.

    Jump to last-edited cell - new commands hop through recently edited cells.

    File browser glow-up - Date Created column, editable breadcrumbs with Tab-completion, and Open in Terminal.

    Debugger - sources open in the main area, floating step/continue overlay, live kernel-sources filter.

    Custom layouts (Lab) - activity bar top/bottom, draggable panels, four-way tab splits, per-panel Ctrl+scroll zoom.

    ~5x faster extension builds - webpack → Rspack, and jupyter-builder means no full Lab install needed to build extensions.

    Keyboard/a11y - add shortcuts from the UI (no JSON), Find & Replace in Edit menu (Ctrl+H).

    Calvin #3: Tau – new small, readable terminal coding agent

    Tau – new small, readable terminal coding agent (Python 3.12+), built as both a working tool and a teaching project for how coding agents work under the hood

    Install via uv tool install tau-ai, pipx, or pip; ships a tau CLI

    Three-layer architecture: tau_ai (provider-neutral model layer) → tau_agent (reusable "brain": messages, tools, events, loop) → tau_coding (CLI/TUI, file & shell tools, sessions)

    Supports OpenAI, Anthropic, OpenAI Codex, OpenRouter, Hugging Face, and custom/local OpenAI-compatible endpoints

    Built-in tools (read/write/edit/bash), durable JSONL sessions with resume/branching, project instructions via AGENTS.md, and context compaction

    Core harness is UI-agnostic — same brain can power the TUI, print mode, or a custom frontend — usable as a standalone library too

    Michael #4: Django Tasks and Django 6.1

    Django 6.0 finally ships first-party background tasks (django.tasks) - out of Jake Howard's DEP 14, accepted May 2024, after two decades of everyone bolting on Celery/RQ/Huey.

    It's an API, not a worker. Django handles task definition, validation, queuing, and result storage - it does not execute them. You bring the backend.

    The default backend traps people. ImmediateBackend runs tasks inline on the request thread and blocks until done - so out of the box .enqueue() backgrounds nothing (a 5-second task means a 5-second response). The other built-in, DummyBackend, runs nothing at all. Both are dev/test only.

    Nice API otherwise: slap @task on a function, call .enqueue(), get back a TaskResult you look up later by id - with async twins like aenqueue(). Gotcha: args and return values must survive a JSON round-trip, so a tuple sneakily comes back as a list.

    The community local backend to know: django-tasks-local by Chris Beaven (SmileyChris). A ThreadPoolExecutor backend that gives real background threads with zero infrastructure - no Redis, no Celery, no database - plus a ProcessPoolBackend for CPU-bound work → github.com/lincolnloop/django-tasks-local

    Its catch: results live in memory, so pending tasks vanish on restart or deploy. Great for dev and low-traffic production; for persistence, drop to Jake Howard's django-tasks (DatabaseBackend + worker command).

    Extras

    Calvin:

    Fixing the dictionary with Python 3.14 — Hugo van Kemenade stumbled on - and got fixed - a markup bug in the OED's own citation of a 1706 use of the pi symbol.

    Michael:

    Bunny DNS is now free

    Jokes:

    What's the object-oriented way to become wealthy? Inheritance

    To understand what recursion is... You must first understand what recursion is

    3 SQL statements walk into a NoSQL bar. Soon, they walk out They couldn't find a table.
  • Python Bytes

    #487 Minimum requirements

    07/07/2026 | 27 min
    Topics covered in this episode:

    dust - a better du

    Hermes Agent: The AI agent that grows with you

    llm-coding-agent 0.1a0

    Extras

    Joke

    Watch on YouTube

    About the show

    Sponsored by us! Support our work through:

    Our courses at Talk Python

    Consulting from Six Feet Up

    Connect with the hosts

    Michael: Mastodon / BlueSky / X / LinkedIn

    Calvin: Mastodon / BlueSky / X / LinkedIn

    Show: Mastodon / BlueSky / X

    Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too.

    Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.

    Michael #1: dust - a better du

    du + Rust = dust - a fast, visual, intuitive disk-usage CLI

    Run dust and immediately see the biggest directories and files without piping through sort, head, or awk

    Smart recursive output focuses on what matters instead of dumping every folder

    Colored bars show relative size and parent/child hierarchy, making “where did the space go?” obvious

    Perfect for Python projects bloated by .venv, caches, Docker volumes, downloaded datasets, and local AI models

    Install via brew, cargo install du-dust, conda-forge, Scoop, Snap, deb-get, or GitHub releases

    Calvin #2: A Way better ARchive format for Python packaging

    war - new archive format spec from Astral (same team as uv/ruff), v0.0.2, still no binary encoding defined yet

    Header-Index-Store layout: header IDs the file, index maps names to store offsets, store holds compressed data

    Index uses a finite-state transducer (FST) to dedupe common path prefixes across entry names

    Supports three entry types (file, directory, link) and three compression modes (store/DEFLATE/zstd), plus an "executable" metadata flag

    Unpacking is atomic - writes to a temp dir, then renames into place, so a failed extract never leaves a half-unpacked directory

    Strict name-segment rules (no NUL/control chars, no leading/trailing whitespace, blocks Windows-reserved names like CON/PRN) to avoid path traversal and cross-platform footguns

    Michael #3: Hermes Agent: The AI agent that grows with you

    Hermes Agent is an open-source, Python-built AI agent framework from Nous Research - think ChatGPT-style assistant, but connected to your tools, files, shell, browser, calendar, memory, and messaging apps

    I’m using it in Discord as a long-running agent conversation, not just a one-off chatbot session

    Hermes can connect through a gateway to platforms like Discord, Telegram, Slack, WhatsApp, email, webhooks, and more - so the same assistant can follow you across surfaces

    In my setup, I can send Hermes voice/text from Discord, keep project context across turns as threads, and ask it to actually do things: read GitHub repos, run commands, edit files, schedule calendar events, generate drafts, and verify results

    A fun workflow: I can trigger one-shot actions from an Apple Watch shortcut - dictate a request, send it to Hermes, and have the agent execute it asynchronously

    Hermes has persistent memory, so it can remember durable preferences and facts - for example, how I like my research formatted

    It also has “skills,” which are reusable procedures the agent can load later, so Hermes can self-improve over time instead of rediscovering the same workflow repeatedly

    It supports scheduled jobs / cron-style automations, so it can proactively watch for releases, send summaries, run checks, or remind you about things

    It’s provider-agnostic: OpenRouter, Anthropic, Google, xAI, local models, Nous Portal, and others

    The big idea: Hermes turns an LLM from “a chat box I visit” into “an agent I can reach from anywhere that knows my workflows and can take real actions and learns over time.”

    Calvin #4: llm-coding-agent 0.1a0

    Simon Willison built a Claude/Codex-style coding agent on top of his llm library, using an alpha of the llm package plus his python-lib-template-repo

    Built almost entirely via prompted TDD - asked an agent to write a spec.md, then commit + implement with red/green tests, occasionally hitting a real OpenAI key to sanity-check

    Shipped to PyPI as an alpha: uvx --prerelease=allow --with llm-coding-agent llm code

    Tool set mirrors familiar coding-agent primitives: read_file, edit_file (exact string replace + diff), write_file, list_files, search_files, execute_command

    Also exposes a Python API - CodingAgent(model="gpt-5.5", root=..., approve=True).run(...) - which Simon didn't ask for but got anyway

    Demo: llm code --yolo told GPT-5.5 to build a SwiftUI CLI clock; model correctly noted SwiftUI isn't really CLI-friendly and still produced an ASCII-art time display

    Extras

    Calvin:

    Slides, but for developers https://sli.dev/

    Wanna reduce your token usage…. only issue is that its lossy https://github.com/teamchong/pxpipe

    PEP 772 - Python Packaging Council inaugural election dates set, nominations open July 28, voting September 1-15

    Michael:

    What the pls? revisited!

    Joke: Min requirements for Linux
  • Python Bytes

    #486 underscore-underscore-ghost-emoji

    30/06/2026 | 29 min
    Topics covered in this episode:

    Free-threaded Python: past, present, and future

    django-admin-site-search

    Qwen 3.6 27B is the sweet spot for local development

    A large batch of PEPs are finalized

    Extras

    Joke

    Watch on YouTube

    Show Intro

    Sponsored by us! Support our work through:

    Our courses at Talk Python

    Consulting from Six Feet Up

    Connect with the hosts

    Michael: Mastodon / BlueSky / X / LinkedIn

    Calvin: Mastodon / BlueSky / X / LinkedIn

    Show: Mastodon / BlueSky / X

    Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too.
    Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.

    Calvin #1: Free-threaded Python: past, present, and future

    The GIL has prevented true multi-threaded parallelism in CPython since the beginning — multiple past attempts to remove it failed on performance grounds

    Sam Gross at Meta finally solved it; his work became PEP 703 and ships as free-threaded CPython today

    Python 3.13 was experimental with 20–40% single-threaded slowdown; 3.14 brought that to 0–10%

    Python 3.15 (October 2026) delivers a unified ABI — one extension binary works on both GIL and free-threaded builds

    Already >50% of the top PyPI binary wheels support free threading

    Wouters predicts free-threaded becomes the default between 3.16–3.20 (2027–2031), with the GIL eventually disappearing next decade

    Michael #2: django-admin-site-search

    via Adam Parkin

    A global/site search modal for the Django admin, by Ahmed Aljawahiry. Hit cmd+k anywhere in the admin and you get a command-palette-style search window, kind of like the one in VS Code.

    It doesn't just search one model's list page. It searches your entire site in one box:

    App labels

    Model labels and field attributes

    Actual model instances (your data)

    Two ways to search the instances:

    model_char_fields (the default): runs an __icontains across every CharField (and subclasses) on the model. Zero config, works out of the box.

    admin_search_fields: defers to each ModelAdmin's existing get_search_results(), so it respects the search_fields you've already set up.

    The part I like: it's permission-aware out of the box. Users only see results for the apps and models they actually have view permission on, so you're not leaking anything through search.

    Results appear as you type, with throttling/debouncing so you're not hammering the server on every keystroke, and it's full keyboard nav: cmd+k to open, up/down to move, enter to go.

    It's responsive, does dark and light mode, and it pulls Django's built-in admin CSS variables so it just matches whatever admin theme you're running.

    Under the hood it's Alpine.js, but bundled into static so there's no external CDN dependency.

    Setup is about what you'd expect: pip install django-admin-site-search, add it to INSTALLED_APPS, mix the AdminSiteSearchView into your AdminSite, and drop a few template includes into base_site.html.

    Supports Python 3.8 through 3.14 and Django 3.2 through 6.0, MIT licensed, and everything is overridable if you want to skip certain models, add TextField matching, etc.

    Calvin #3: Qwen 3.6 27B is the sweet spot for local development

    Qwen 3.6 27B is being called the first local model that genuinely competes as a general-purpose intelligence — benchmarks put it at roughly mid-2025 frontier level (comparable to GPT-5 / Claude Sonnet 4.5)

    Runs locally via llama.cpp; on an M5 MacBook Max with 8-bit quantization + multi-token prediction, it hits ~32 tokens/sec using ~42GB RAM

    4-bit quantization gets it under 18GB, runnable on 32GB devices; Nvidia RTX cards run it even faster

    The dense 27B is recommended over the faster MoE 35B A3B — author prefers higher quality output over raw speed

    Privacy and reliability are the pitch: fine-tunable, can't be taken down, suitable for sensitive/proprietary data

    Author sees this as a stepping stone — frontier open-weight models like GLM 5.2 are now locally runnable with company-grade hardware, and smarter-still local models are coming

    Michael #4: A large batch of PEPs are finalized

    A bunch of PEPs went from accepted to final.

    668, 687, 691, 699, 701, 703, 728, 770, 773, 829

    But this wasn’t them making their way into CPython. It’s an admin sorta thing. (Thanks PyCoders)

    See the commit.

    Extras

    Calvin:

    More fun bling for your terminal this time - https://charm.land/

    Michael:

    Follow up from pls, What the pls? Thanks Pito.

    Joke: BEMoji

    A production-grade utility and component framework built entirely on emoji class names

    via Jeff Triplett
Más podcasts de Noticias
Acerca de Python Bytes
Python Bytes is a weekly podcast hosted by Michael Kennedy and Calvin Hendryx-Parker. The show is a short discussion on the headlines and noteworthy news in the Python, developer, and data science space.
Sitio web del podcast

Escucha Python Bytes, Es la Mañana de Federico y muchos más podcasts de todo el mundo con la aplicación de radio.es

Descarga la app gratuita: radio.es

  • Añadir radios y podcasts a favoritos
  • Transmisión por Wi-Fi y Bluetooth
  • Carplay & Android Auto compatible
  • Muchas otras funciones de la app