POPULARITY
Categories
a16z General Partners Martin Casado, Sarah Wang, and Matt Bornstein unpack the story of Cursor: how a small, product-obsessed team entered one of the most competitive markets in technology, took on incumbents with seemingly unbeatable advantages, and repeatedly made decisions that ran against conventional startup wisdom. They revisit the early bet that the interface between humans and AI would matter more than building a coding-specific foundation model, why Cursor built its own product rather than a VS Code plugin, and how the founders' ability to say "no" became one of the company's defining strengths. They also discuss Cursor's rapid evolution from IDE to agent and model platform, and why the team was willing to cannibalize its own products as AI capabilities improved. The conversation gets into what founders can learn from Cursor's approach to competition, hiring, enterprise sales, M&A, and company culture, including why the team remained unfazed by competitors from Microsoft to Anthropic and how its obsessive focus on product ultimately extended into every part of building the company. Resources: Explore Cursor Compile: https://cursor.com/compile Follow Martin Casado on X: https://x.com/martin_casado Follow Matt Bornstein on X: https://x.com/BornsteinMatt Follow Sarah Wang on X: https://x.com/sarahdingwang Stay Updated:Find a16z on YouTube: YouTubeFind a16z on XFind a16z on LinkedInListen to the a16z Show on SpotifyListen to the a16z Show on Apple PodcastsFollow our host: https://twitter.com/eriktorenberg Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Talk Python To Me - Python conversations for passionate developers
In 2020, a gastroenterologist in Glasgow did the math on his new research study and came up with 30,000 samples, arriving over two years from three cities and a dozen hospitals. He asked around about how researchers keep track of that. The answer was Microsoft Excel. Shaun Chuah had written some HTML by hand in Notepad back in high school and that was about the whole of his programming experience, so he opened the Django tutorial and started reading. Six years later that app is Foundry120, holding 10 terabytes of clinical and genomics data with an agentic AI running on top of it. Episode sponsors Sentry Error Monitoring, Code talkpython26 Talk Python Courses Talk Python Courses Links from the show Guest Shaun Chuah: github.com Up and Running with Rust Course: talkpython.fm Foundry120: www.foundry120.com Designing Data Intensive Applications: www.oreilly.com Microsoft Foundry: ai.azure.com ChatIBD: www.chatibd.com Blog: shaunchuah.github.io @drshaunchuah: x.com github.com/shaunchuah: github.com Watch this episode on YouTube: youtube.com Episode #560 deep-dive: talkpython.fm/560 Episode transcripts: talkpython.fm Theme Song: Developer Rap
Topics covered in this episode: Web UIs for your reverse proxy Wagtail 8.0 is hot off the presses RISC-V is now officially supported by CPython Django's annual releases make every version an LTS Extras Joke Watch on YouTube About the show Sponsored by Logfire from Pydantic: pythonbytes.fm/logfire Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Michael #1: Web UIs for your reverse proxy Traefik, nginx, and Caddy all sit in front of a lot of self-hosted infrastructure, and all three are configured by hand-editing files. Three active projects put a control plane on top: Traefik Manager (Python + Flask), Nginx UI (Go + Vue), and caddy/ui (React + Node). All three are additive rather than replacements - none of them take ownership of your config away from you - which is the part that matters when the thing has write access to production routing. Traefik Manager is the Python one: Flask 3.1 and Gunicorn for the control plane, a lightweight Go agent for remote instances, currently v1.10.0 with an Android companion app. Nginx UI is a single Go binary at 11.3k stars, with a block-style config editor, an Ace editor doing LLM completion on nginx syntax, and an MCP server so agents can drive it. caddy/ui runs as two containers next to your existing Caddy, reads and writes your Caddyfile directly, and uses Caddy's /adapt API to validate before reload - no Docker socket required. Each one edits the config the underlying server already reads, so your files stay the source of truth and you can drop the UI without unwinding anything. Undo is a first-class feature across all three - timestamped backups with optional Git history, config version compare and restore, Caddyfile snapshots with one-click rollback. Observability is where they diverge: Traefik Manager does CrowdSec and a visual route map, Nginx UI does server metrics, caddy/ui streams access logs over SSE and pulls p50/p95/p99 off Caddy's Prometheus endpoint. Maturity spread is wide - Nginx UI has 11.3k stars, caddy/ui has 4 and was built in a single Claude session - and caddy/ui ships with auth off by default, so set CADDY_UI_USER and JWT_SECRET before it goes anywhere near a public interface. Calvin #2: Wagtail 8.0 is hot off the presses Link: https://github.com/wagtail/wagtail/releases/tag/v8.0 Custom base page models are now supported, so projects aren't locked into subclassing Wagtail's Page as shipped (Matt Westcott). New v3 REST API handles both read and write CMS operations, a first for Wagtail's API. A global registry for permission policies, plus full customizability for the remaining page views via PageViewSet. AVIF and WebP images are no longer auto-converted to PNG by default, a real behavior change to watch on upgrade. Five security fixes: page admin API restrictions, document identification by SHA1 hash, descendant collections in the Documents/Images API, snippet copy permissions, and the page translation endpoint. Formalized Django 6.1 support, and CI now runs on uv with a lockfile. Sponsor: Logfire from Pydantic Your AI agent failed at 2am. Was it the model? A tool call? The database? Most observability tools can't tell you, because they only see part of your stack. Pydantic Logfire sees all of it. One trace across your agents, LLMs, APIs, and database. Down to the infrastructure: services, Kubernetes, and hosts. It's built on OpenTelemetry, with SDKs for Python, TypeScript, and Rust, and it works with any OTel-compatible language. Every prompt, token count, and cost, right next to your vector searches and API calls. You query everything with Postgres-compatible SQL. And so can your coding agent, through the Logfire MCP server. Stop guessing. Read the trace. Pydantic Logfire. AI, it's still just engineering. Visit pythonbytes.fm/logfire today and sign up today. Get 10M records free every month, no card required. You can even click “Onboard with your coding agent” to copy a prompt to have claude or codex integrate Logfire into your app. Thanks to Pydantic for supporting the show. Calvin #3: RISC-V is now officially supported by CPython Link: https://blog.python.org/2026/08/riscv-now-officially-supported/ CPython added RISC-V as a tier 3 platform under PEP 11, specifically the 64-bit Linux target riscv64-unknown-linux-gnu. RISC-V is an open ISA anyone can implement, unlike x86 and ARM, and its market is projected to quadruple by 2032. The RISE Project donated real RISC-V machines for buildbots; the author's work was funded by a Sovereign Tech Agency fellowship. What changes: the port is now a maintained compatibility target, so CPython changes are less likely to quietly break it. What doesn't: no python.org installers, no binary wheel parity for native extensions. Next up: RISC-V runners in CPython CI for pre-merge feedback, then a push toward tier 2, plus architecture-specific optimizations. The ask is testing. If you have RISC-V hardware, build CPython, run your test suite, file what breaks. Tier 3 is the weakest support tier. PEP 11 tier 3 requires a core developer contact and a buildbot, but failures on tier 3 platforms explicitly do not block a release. Saying "ongoing CI/testing expectations" oversells it. The honest bit is "someone is now on the hook for it, and breakage gets noticed," not "it's guaranteed working." Worth the caveat that this is Linux SBCs, not microcontrollers. A VisionFive 2 counts, an ESP32-C6 or Pico 2 does not. Those are 32-bit non-Linux parts where MicroPython is still the answer. Michael #4: Django's annual releases make every version an LTS Starting with Django 2028, Django will move to one January feature release per year, adopt calendar-based version numbers, and support every release for three years. The old distinction between standard and LTS releases disappears, giving teams a predictable annual upgrade path that aligns more closely with Python's own release and support cadence. Every Django release becomes the safe, long-supported choice, so teams no longer need to wait for a specially designated LTS version or absorb two years of changes at once. Each release gets one year of mainstream bug fixes followed by two years of security and data-loss fixes. New releases support the three latest Python versions and add the next Python release during their first year. Calendar versioning begins with Django 2028, followed by Django 2029 and so on. Three Django versions will be supported at any time, giving third-party packages a clearer rolling target. Nothing changes before 2028, and existing commitments for Django 5.2 LTS and 6.2 LTS remain in place. Extras Calvin: The Python docs now document the time complexity of built-in types https://docs.python.org/3.16/library/time-complexity.html Thinking in Python - Bruce Eckel's free book https://thinkinginpython.com/ Michael: prune_uv_pythons.py - Prune uv-managed Python installs, keeping only the newest patch per minor version Runs automatically in my system “upgrade” script: upgrade-output-2026.png Started using Ollama cloud models for my Hermes assistant. Thanks to Jeff Triplett I learned they are not just local models. Joke: The Tao of Programming - Book Seven: Corporate Wisdom
Talk Python To Me - Python conversations for passionate developers
Your site is down. It's 3am. Is it a bug, a bill, or a breach? You can't tell yet, and everyone is watching you find out. Matt Lea has spent fifteen years being the person companies call when an outage is costing them real money per hour, and his whole argument is that everything you'd want in that moment gets decided months earlier, on ordinary afternoons, when someone chose the convenient thing. We walk his top twelve dos and don'ts in AWS - infrastructure as code, IAM roles instead of access keys, private subnets, no wildcards, no public buckets - and I push on which of them actually matter if you're one person on a small VPS. Then we get to Cloud War Games, where Matt breaks things on purpose so your team's first real incident isn't their first incident. Let's get into it. Episode sponsors Sentry Error Monitoring, Code talkpython26 Talk Python Courses Talk Python Courses Links from the show Guest Matt Lea: linkedin.com Talk Python Certificates: training.talkpython.fm/certificates Schematical: schematical.com CloudWarGames.com: cloudwargames.com Zero to Hero on AWS Security: www.oreilly.com Repo: github.com Custom Wheel Offset: customwheeloffset.com 2012 TechCrunch Disrupt Hackathon: techcrunch.com tech comics: schematical.com shhgit: github.com Zero Trust in 200ms: Implementing Identity-Per-Transaction: us.pycon.org Coolify: coolify.io returned to full GA Nov 2025: aws.amazon.com Signed URLs/cookies: docs.aws.amazon.com Cloudflare: www.cloudflare.com Bunny Shield: bunny.net Cloud War Games One: www.youtube.com Cloud War Games Two: www.youtube.com LinkedIn: linkedin.com YouTube: youtube.com KnocKnoc: knocknoc.io Watch this episode on YouTube: youtube.com Episode #559 deep-dive: talkpython.fm/559 Episode transcripts: talkpython.fm Theme Song: Developer Rap
Topics covered in this episode: Python 3.12.14, 3.11.16, 3.10.21 - security releases Codeberg's AI-code ban tests its role as a GitHub alternative Brett Cannon: what's missing for reproducible builds on PyPI nothing records the source code a distribution came from. direct_url.json captures it when you install from a repo or archive, so the fix is putting the same info in sdist/wheel metadata. recording the build tools. Wheels can already do this via PEP 770 SBOMs in .dist-info/sboms/ - sdists can't, since they're a tarball plus a precalculated PKG-INFO with nowhere to hang extra metadata. Either "don't use sdists" or an sdist v2. Extra extra extra, hear all about it Extras Joke Watch on YouTube Sponsored by Logfire from Pydantic pythonbytes.fm/logfire This episode is brought to you by Pydantic Logfire. It's observability for AI apps from the team behind Pydantic - agents, LLMs, APIs, database, and infrastructure in a single trace, queried with Postgres-compatible SQL. Your coding agent can query it too, through their MCP server. I'll tell you more later. Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Calvin #1: Python 3.12.14, 3.11.16, 3.10.21 - security releases https://blog.python.org/2026/08/python-31214-31116-31021/ Source-only security releases for the three branches now in security-fix-only mode; release team blamed the European solar eclipse for the timing. tarfile hardening. Multiple path-traversal bypasses of the data filter closed, including a symlink escape that bypassed the CVE-2025-4330 fix; extract() now applies the filter to link targets too. Four fresh CVEs: CVE-2026-2297 (SourcelessFileLoader not using io.open_code() for .pyc), CVE-2026-4224 (expat crash on deeply nested content models), CVE-2026-3644 (control chars in http.cookies.Morsel), plus the completed CVE-2021-4189 fix in ftplib.ftpcp. Quadratic-complexity DoS cleanup across the stdlib: HTMLParser, configparser regexes, unicodedata.normalize(), csv.Sniffer.sniff(), and ElementTree XPath index predicates. Header/injection fixes: CR/LF rejected in HTTPConnection.set_tunnel(), control chars blocked in wsgiref.handlers status, and webbrowser now rejects leading dashes (plus a %action prefix bypass). http.client now caps chunked trailer lines and 1xx interim responses at 100 each - a hostile server could previously hang the client forever despite a socket timeout. Memory-safety odds and ends: stale pointers in lzma/bz2/zlib decompressors after MemoryError, a bz2 stack overflow on reuse-after-error, and bundled libexpat bumped to 2.8.3. If you're still on 3.10, 3.11, or 3.12 - and you extract tarballs from anywhere you don't fully control - this one's not optional. Michael #2: Codeberg's AI-code ban tests its role as a GitHub alternative Armin's article “Codeberg Divides” Armin Ronacher argues that Codeberg's new terms, which prohibit projects mostly written with generative AI, create a vague and difficult-to-enforce boundary. His larger concern is that a democratically governed host can still be unpredictable or ideologically narrow, weakening Codeberg's potential as a broad European alternative to GitHub. The strongest question for Python developers is whether repository hosting should judge legal open source by how code was produced, or focus on behavior and resource abuse. “Mostly generated” is hard to measure in modern codebases where developers mix handwritten code, completions, agents, and generated refactors. Ronacher suggests clearer alternatives: ban all LLM involvement, or target autonomous repository spam, abusive resource use, and low-quality generated contributions directly. Codeberg is free to choose a values-driven community, but that may conflict with being predictable, neutral infrastructure and a serious GitHub competitor. Worth discussing: can open-source communities set meaningful AI boundaries without driving maintainers and projects into opposing camps? Very first search for these terms lands on this page. Codeberg looked like a viable alternative. … Unfortunately, the latest update to its terms of service seems to mark a first step in changing one part I moved there for, namely the “freedom” part. Sponsor: Logfire from Pydantic Your AI agent failed at 2am. Was it the model? A tool call? The database? Most observability tools can't tell you, because they only see part of your stack. Pydantic Logfire sees all of it. One trace across your agents, LLMs, APIs, and database. Down to the infrastructure: services, Kubernetes, and hosts. It's built on OpenTelemetry, with SDKs for Python, TypeScript, and Rust, and it works with any OTel-compatible language. Every prompt, token count, and cost, right next to your vector searches and API calls. You query everything with Postgres-compatible SQL. And so can your coding agent, through the Logfire MCP server. Stop guessing. Read the trace. Pydantic Logfire. AI, it's still just engineering. Visit pythonbytes.fm/logfire today and sign up today. Get 10M records free every month, no card required. You can even click “Onboard with your coding agent” to copy a prompt to have claude or codex integrate Logfire into your app. Thanks to Pydantic for supporting the show. Calvin #3: Brett Cannon: what's missing for reproducible builds on PyPI Framing came out of his 2026 Python Packaging Council nomination - the secure-supply-chain gap he found is that Python has no defined way to do reproducible builds at all. Design goal is zero friction: producers uploading to PyPI shouldn't have to do anything. The work lands on build backends and installers. Gap #1: nothing records the source code a distribution came from. direct_url.json captures it when you install from a repo or archive, so the fix is putting the same info in sdist/wheel metadata. Gap #2: recording the build tools. Wheels can already do this via PEP 770 SBOMs in .dist-info/sboms/ - sdists can't, since they're a tarball plus a precalculated PKG-INFO with nowhere to hang extra metadata. Either "don't use sdists" or an sdist v2. The replay mechanism already exists: [build-system] in pyproject.toml is a defined entry point, so if backends recorded their own environment, you could reinstall and re-run the build. Payoff idea: trusted third parties report successful reproductions back to PyPI, which displays "independently reproduced by X" - surfaced in the index API so installers could prefer reproduced files. Explicitly framed as a perk, not a requirement - roughly SLSA build level 1, no shaming projects that don't opt in. Verbal kicker option: "And don't think pure-Python wheels are off the hook. Something built that wheel, and if that something was compromised, so is your wheel. SolarWinds was a build-process attack." Michael #4: Extra extra extra, hear all about it Python 3.14.7 Upgraded the MCP servers to 2026-07-28 v2 protocols (talk python, python bytes) Got agentsview running synced via postgres Talk Python courses, teams trial offering Talk Python courses, government procurement offering Lean TDD audio book is out Extras Calvin: uv now prefers post-quantum key exchange - https://github.com/astral-sh/uv/releases/tag/0.12.4 Joke: Beware of dog
Topics covered in this episode: Claude Code /insights Post-quantum crypto lands in Python MCP goes stateless — and FastMCP gets renamed inshellisense - IDE style command line auto complete Extras Joke Watch on YouTube About the show Sponsored by Xweather Xweather combines enterprise-grade weather intelligence with agent-ready APIs, natural language capabilities, and an MCP server so your agents can adapt workflows, automate responses, and make better decisions based on real-world conditions. Michael will tell you more about them later in the show. Get started for free at pythonbytes.fm/xweather Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Michael #1: Claude Code /insights Michael's Insights: michael-kennedy-claude-code-insights-2026-08-09.html Be careful sharing these outputs, they include details references to your projects, errors, security findings, etc. ;) /insights reads your last 30 days of local session transcripts and hands back an interactive HTML report on how you actually work. One command, zero setup: type /insights in a session, or run claude -p "/insights" from the shell for a non-interactive version that just prints the path Reads what's already on disk: pulls session logs from ~/.claude/projects/, skipping agent sub-sessions and anything under 2 messages or 1 minute Project areas: clusters your sessions into themes like "CLI Tooling" or "Documentation" with session counts Friction analysis: categorizes where things went wrong by root cause - and quotes your own prompts back at you Interaction style: tells you whether you're a delegator or a micromanager, plus which workflows are worth doubling down on Actually actionable: suggests concrete CLAUDE.md additions and Claude Code features you're not using The catch: Haiku does the per-session classification, so the first run takes several minutes; results cache to ~/.claude/usage-data/facets/ and the report lands at ~/.claude/usage-data/report.html Calvin #2: Post-quantum crypto lands in Python pyca/cryptography 48 ships ML-KEM (key establishment) and ML-DSA (signatures) — NIST's post-quantum standards, now one pip install away. Big deal because it's the 11th most-downloaded package on PyPI (~1.2B downloads/month) and sits under Ansible, Certbot, Airflow, and paramiko. No PQ there, no PQ anywhere in Python. Trail of Bits did the work (Rust bindings, cross-backend API, tests, AWS-LC backend support), funded by the Sovereign Tech Agency. Timing tracks a June 22 White House order setting federal deadlines: PQ key establishment by end of 2030, PQ signatures by end of 2031. Not a drop-in swap — the wire sizes explode. ML-DSA-65 signatures are 3,309 bytes vs Ed25519's 64; ML-KEM-768 public keys are 1,184 bytes vs X25519's 32. Hardcoded field sizes and length prefixes will bite. API looks like the existing asymmetric primitives, except ML-KEM is encapsulate/decapsulate rather than a Diffie-Hellman exchange. SLH-DSA (the hash-based conservative backstop) is still in progress. The primitives are here, but protocols haven't caught up — so you won't be running post-quantum Certbot this week. Sponsor: Xweather You're using agents that can write code, summarize documents, and automate workflows. But they're missing one thing: awareness of the world around them. This is where today's sponsor, Xweather comes in. Xweather combines enterprise-grade weather intelligence with agent-ready APIs, natural language capabilities, and an MCP server built for tools like Claude, Codex, Copilot, and modern IDEs – so your agents can adapt workflows, automate responses, and make better decisions based on real-world conditions. Backed by Vaisala, whose instruments fly on NASA missions to Mars, Xweather delivers trusted data and unique insights that go beyond conditions to actual impact – from real-time lightning strikes to road surface forecasts. Start with 15,000 free API calls each month and pay only for what you use as you grow. Xweather is your full weather stack, for developers by developers. Start building for free today at pythonbytes.fm/xweather. The link is in your podcast player's show notes and on the episode page. Thanks so much to Xweather for supporting Python Bytes. Calvin #3: MCP goes stateless — and FastMCP gets renamed From Philipp Acsany over at Real Python The 2026-07-28 spec landed July 28 and the Python SDK shipped 2.0.0 the same day. Biggest rewrite since MCP launched, and it's breaking on purpose. Context for scale: the Tier 1 SDKs are pulling close to half a billion downloads a month, with TypeScript and Python each past a billion total. The headline is the stateless core. The initialize/initialized handshake and the Mcp-Session-Id header are both retired — protocol version, client identity, and capabilities now ride in _meta on every request, with an optional server/discover RPC if a client wants capabilities up front. Any request can land on any instance behind plain round-robin, no shared storage. Server-initiated calls are the hard part of the migration. Sampling, elicitation, and roots/list no longer call back to the client; instead the server returns resultType: "input_required" and the client retries with inputResponses attached. Multi Round-Trip Requests, MRTR. Also: Mcp-Method and Mcp-Name are now required headers so gateways route on headers instead of cracking JSON bodies, and missing-resource errors move to standard 32602. Deprecation sweep with an actual policy behind it — Roots, Sampling, Logging, and the legacy HTTP+SSE transport all deprecated with a twelve-month minimum offramp. Tasks graduated out of the experimental core into a real extension, which is what the formalized extensions framework was for. MCP Apps is now an official extension too, so a tool call can return sandboxed interactive HTML. Auth picked up RFC 9207 issuer validation, issuer-bound credentials, and a shift from DCR toward CIMD. Python SDK 2.0 is where it gets personal: FastMCP is now MCPServer, no alias, no shim. McpError → MCPError. Wire types went snake_case (is_error, input_schema) and moved to a standalone mcp_types package, with mcp.types kept as a permanent alias. One Client object replaces the old transport + ClientSession + initialize() stack. httpx became httpx2. Sync handlers run on worker threads now, so asyncio.get_running_loop() raises inside them. The good news: one MCPServer serves both protocol eras, so 2025-era clients keep working with nothing to configure, and a Resolve(fn) parameter lets one tool body cover MRTR and the old path. 1.x is maintenance-and-security-fixes only — pin mcp>=1.28,
Malebná dedinka na Záhorí s takmer 1100 obyvateľmi. Aj tak by sa dala opísať Petrova Ves. Obec, v ktorej by mali v blízkej budúcnosti vyrásť veterné elektrárne. Samozrejme, ak projekt prejde posúdením vplyvov na životné prostredie a získa súhlasné stanovisko. Časť miestnych však s niečím podobným vehementne nesúhlasí. V lokálnom podniku či v obchode sa hovorí najmä o tom, ako turbíny ublížia vtáctvu, vode, pôde a ako ľudia nebudú môcť pre infrazvuk spávať. Čo za projekt sa to v Petrovej Vsi vlastne chystá, v akom je štádiu, a kde vznikajú všetky tieto obavy Petrovčanov a kto komunikuje celú vec chabo? Štát či samotná obec? Eva Frantová sa v podcaste Dobré ráno pýta Mareka Moravčíka z domácej redakcie denníka SME, ktorý Petrovu Ves spolu s kolegom Martinom Mlynárom navštívil osobne. Zdroje zvukov: SME Odporúčanie Ak ešte nemáte dosť mojich knižných odporúčaní, skúste si prečítať London Falling od Patricka Keefeho. Ide o investigatívu záhadnej smrti britského tínedžera, ktorý bezdôvodne vyskočí z balkóna a utopí sa v Temži. Jeho rodičia nechápu, čo sa stalo, a až postupne zisťujú, že ich 19-ročný syn sa vydával za ruského oligarchu a zaplietol sa s ľuďmi z londýnskeho podsvetia. Keefe je môj obľúbený autor. Má za sebou aj knihy ako Impérium bolesti alebo Nič nehovor, ktoré som tu už odporúčala a ani tentoraz nesklamal! – Všetky podcasty denníka SME nájdete na sme.sk/podcasty – Odoberajte aj audio verziu denného newslettra SME.sk s najdôležitejšími správami na sme.sk/brifingSee omnystudio.com/listener for privacy information.
"On utilise la bêtise des autres pour annuler sa bêtise à soi" Série spéciale Intelligence(s)Cet été, IFTTD part en exploration. Sur les 52 derniers épisodes, on a parlé d'intelligence artificielle 38 fois. On maîtrise plutôt bien la partie artificielle &mdash mais l'intelligence, la vraie, l'originale, on n'en a presque jamais parlé. Alors le temps d'un été, on remonte à la source : 6 épisodes, 6 chercheurs, pour comprendre ce qu'est vraiment l'intelligence.Le D.E.V. de la semaine est Emile Servan-Schreiber, entrepreneur et chercheur, fondateur de Hypermind (intelligence collective) et The Forecasting Machine (intelligence artificielle). Dans cet épisode, Emile nous explique comment l'intelligence collective permet d'améliorer les décisions, à condition de structurer le processus par des règles et de valoriser la diversité d'opinions. À travers l'exemple célèbre de la devinette du poids du b&oeliguf de Galton, il montre que la performance d'un groupe n'est pas seulement une question d'expertise mais aussi de divergence d'opinions. Il partage les limites du collectif, les conditions pour le faire fonctionner, et fait le parallèle fascinant entre nos cerveaux, les IA et les colonies de termites. Un échange pour comprendre pourquoi, parfois, il vaut mieux 100 opinions différentes qu'une seule certitude.Chapitrages00:01:00 : La foule intelligente00:05:10 : Naissance des marchés prédictifs00:08:23 : Règles du collectif00:14:08 : Le théorème de diversité00:19:28 : Expertise contre diversité00:29:21 : Le jury et la conformité00:31:38 : La force de l'hétérogénéité00:39:33 : Réunions et décisions00:46:48 : Le collectif des LLM00:56:43 : Livres et inné-acquis Liens évoqués pendant l'émission Livre: "Supercollectif" de Emile Servan-SchreiberLivre: "Brief history of intelligence" de Max BennettJeu: Marché prédictif HypermindFilm: 12 hommes en colère
Talk Python To Me - Python conversations for passionate developers
Every company has one. The little internal tool that Jane built back in 2021, and then Jane left. Nobody understands it, nobody will touch it. There are two unwritten rules around it: don't change it, it's working. And if you break it, you bought it. That's dark-matter enterprise software. For every app you can actually see, there are ten of these sitting in the shadows, frozen. Michael Booth thinks that just changed. He read my article on hyper-personal software and ran with it, writing about hyper-team software: small teams inside big companies finally building the tools that were never going to get built. We cover where this works, where it quietly goes wrong, and the guardrails that keep it from turning into a mess. Let's get into it. Episode sponsors Sentry Error Monitoring, Code talkpython26 Python in Production Talk Python Courses Links from the show Guest Michael Booth: github.com Talk Python AI Integrations: talkpython.fm/blog From Hyper-Personal to Hyper-Team Software: Small Team-Built, AI-Assisted Tools Inside the Enterprise: www.databooth.com.au What hyper-personal software looks like (MK's article): mkennedy.codes Databooth Site: www.databooth.com.au Wall Street just lost $285 billion because of 13 markdown files: martinalderson.com SaaSpocalypse is real but everyone is panicking about the wrong thing: www.reddit.com Warp Terminal: www.warp.dev Watch this episode on YouTube: youtube.com Episode #558 deep-dive: talkpython.fm/558 Episode transcripts: talkpython.fm Theme Song: Developer Rap
Imensurável Bondade - Julia Peres by IDE
The terminal has been a constant in software development for decades. It has remained largely unchanged while everything around it transformed. However, as AI agents have become central to the developer workflow, the terminal is emerging as a natural home for agentic development, and a new category of tooling is forming around it. Warp is a popular Rust-based terminal and agentic development environment. The company recently open-sourced its codebase and launched Oz, its cloud agent infrastructure product aimed at helping enterprises automate software development at scale. Zach Lloyd is the co-founder and CEO of Warp, and a former principal engineer at Google where he led engineering on the Google Docs suite. In this episode, Zach joins Gregor Vand to discuss how Warp has evolved over the years, why the terminal is better suited than the IDE for agentic development, how Oz approaches the governance and auditability challenges enterprises face with AI agents, and more.Sponsorship inquiries:sponsor@softwareengineeringdaily.com The post The Terminal as an Agentic Interface appeared first on Software Engineering Daily.
The terminal has been a constant in software development for decades. It has remained largely unchanged while everything around it transformed. However, as AI agents have become central to the developer workflow, the terminal is emerging as a natural home for agentic development, and a new category of tooling is forming around it. Warp is a popular Rust-based terminal and agentic development environment. The company recently open-sourced its codebase and launched Oz, its cloud agent infrastructure product aimed at helping enterprises automate software development at scale. Zach Lloyd is the co-founder and CEO of Warp, and a former principal engineer at Google where he led engineering on the Google Docs suite. In this episode, Zach joins Gregor Vand to discuss how Warp has evolved over the years, why the terminal is better suited than the IDE for agentic development, how Oz approaches the governance and auditability challenges enterprises face with AI agents, and more.Sponsorship inquiries:sponsor@softwareengineeringdaily.com The post The Terminal as an Agentic Interface appeared first on Software Engineering Daily.
The terminal has been a constant in software development for decades. It has remained largely unchanged while everything around it transformed. However, as AI agents have become central to the developer workflow, the terminal is emerging as a natural home for agentic development, and a new category of tooling is forming around it. Warp is a popular Rust-based terminal and agentic development environment. The company recently open-sourced its codebase and launched Oz, its cloud agent infrastructure product aimed at helping enterprises automate software development at scale. Zach Lloyd is the co-founder and CEO of Warp, and a former principal engineer at Google where he led engineering on the Google Docs suite. In this episode, Zach joins Gregor Vand to discuss how Warp has evolved over the years, why the terminal is better suited than the IDE for agentic development, how Oz approaches the governance and auditability challenges enterprises face with AI agents, and more.Sponsorship inquiries:sponsor@softwareengineeringdaily.com The post The Terminal as an Agentic Interface appeared first on Software Engineering Daily.
The terminal has been a constant in software development for decades. It has remained largely unchanged while everything around it transformed. However, as AI agents have become central to the developer workflow, the terminal is emerging as a natural home for agentic development, and a new category of tooling is forming around it. Warp is a popular Rust-based terminal and agentic development environment. The company recently open-sourced its codebase and launched Oz, its cloud agent infrastructure product aimed at helping enterprises automate software development at scale. Zach Lloyd is the co-founder and CEO of Warp, and a former principal engineer at Google where he led engineering on the Google Docs suite. In this episode, Zach joins Gregor Vand to discuss how Warp has evolved over the years, why the terminal is better suited than the IDE for agentic development, how Oz approaches the governance and auditability challenges enterprises face with AI agents, and more.Sponsorship inquiries:sponsor@softwareengineeringdaily.com The post The Terminal as an Agentic Interface appeared first on Software Engineering Daily.
The terminal has been a constant in software development for decades. It has remained largely unchanged while everything around it transformed. However, as AI agents have become central to the developer workflow, the terminal is emerging as a natural home for agentic development, and a new category of tooling is forming around it. Warp is a popular Rust-based terminal and agentic development environment. The company recently open-sourced its codebase and launched Oz, its cloud agent infrastructure product aimed at helping enterprises automate software development at scale. Zach Lloyd is the co-founder and CEO of Warp, and a former principal engineer at Google where he led engineering on the Google Docs suite. In this episode, Zach joins Gregor Vand to discuss how Warp has evolved over the years, why the terminal is better suited than the IDE for agentic development, how Oz approaches the governance and auditability challenges enterprises face with AI agents, and more.Sponsorship inquiries:sponsor@softwareengineeringdaily.com The post The Terminal as an Agentic Interface appeared first on Software Engineering Daily.
"Pour beaucoup de personnes, l'intérêt d'une conversation, c'est de découvrir des choses qu'on ne savait pas" Série spéciale Intelligence(s)Cet été, IFTTD part en exploration. Sur les 52 derniers épisodes, on a parlé d'intelligence artificielle 38 fois. On maîtrise plutôt bien la partie artificielle &mdash mais l'intelligence, la vraie, l'originale, on n'en a presque jamais parlé. Alors le temps d'un été, on remonte à la source : 6 épisodes, 6 chercheurs, pour comprendre ce qu'est vraiment l'intelligence.La D.E.V. de la semaine est Dana Samson, professeure en neuropsychologie, spécialisée en neurosciences sociales à l'Université catholique de Louvain. Dana nous plonge dans la richesse et la complexité de l'intelligence sociale, loin d'un unique facteur mesurable. Elle explique pourquoi nos interactions reposent sur une multitude de processus, parfois intuitifs, parfois réfléchis, tous influencés par l'expérience et le contexte. On y découvre les mécanismes de la perception des émotions, l'impact des normes sociales et la singularité de chaque parcours humain. Cet épisode nous incite à valoriser la diversité et à accepter que nos faiblesses sociales sont tout aussi structurantes que nos forces.Chapitrages00:01:01 : Intelligence sociale00:08:33 : Intuition et réflexion00:13:57 : Biologie du social00:15:55 : Normes et moralité00:23:52 : Cartographie des compétences00:34:40 : Progresser avec l'expérience00:39:43 : Diversité et autisme00:44:20 : Lien avec les autres intelligences00:49:24 : IA et interactions humaines00:52:55 : Diversité et conclusion
PHP Alive and Kicking – August 4, 2026 Hosts: Chris Miller (standing in solo while Mike is on holiday) Mike escaped to a beach so Chris hosts alone with special guest Derick Rethans. Expect date-time philosophy, PHP 8.6 goodies, Xdebug secrets, deprecation drama, and a heated debate about how to queue at a pub. From University Websites to Committing to PHP Derick traces his PHP origins back to his university days, building websites that needed database connectivity. ASP.NET was an option, but nobody wanted to pay for it — Linux was cool, and PHP was easy to start using. That combination hooked him early. His very first accepted contribution came from a practical need: everyone wanted centered Shockwave Flash films on their pages, back before CSS even existed. Centering meant knowing the width of a file, and while getimagesize() already existed (and still works today), it didn’t understand Flash. Derick added that support. From there he fell into bug triage, spending several years working through the issue tracker alongside Jani Taskinen (whose “Sniper” name still shows up in commit logs). For a long time it was just the two of them reproducing and fixing bugs — an important task that gets neglected easily, which is exactly how backlogs of a thousand issues and pull requests build up. The Eternal Problem of Date and Time Chris and Derick dig into why date-time bugs are so hard to triage: date algorithms are genuinely complicated, and it takes real time to figure out whether a report is a user’s mistake or an actual PHP bug. Crashes are easy to reproduce; subtle date arithmetic is not. The core philosophical question is “what does adding a month even mean?” If it’s January 31st and you add a month, PHP historically just bumps the month number, producing February 31st, which overflows to March 2nd or 3rd. But most people who add a month really just want the next month and don’t care about day counts — so “next month” is conceptually distinct from “add a month.” Derick has been brainstorming better interfaces so people can’t make these mistakes, though it’s a lot of work. They touch on Carbon as a unified interface people understand, but agree that making Carbon the language standard isn’t the right move. At the language level you need something that works for everybody and ideally doesn’t break existing code. What’s Coming in PHP 8.6 The first new time class is landing: a Duration object representing seconds and nanoseconds within a specific range, living in the Time namespace. It’s a trial run for new APIs and immediately useful — for example, passing a duration to sleep or to timeouts in the new polling API, rather than juggling raw integers. Another highlight is partial function application. With the pipe operator from 8.5, piping into anything that takes more than one argument meant wrapping it in a closure (and extra parentheses because of how the parser works). Partials let you pre-fill some arguments so the resulting callable accepts just one — perfect for pipelines. There’s also TLS session resumption support for streams, which lets OpenSSL shortcut the expensive session setup on repeated TLS connections. Bigger stream-layer work by Jakub Zelenka of the PHP Foundation is underway too, but that’s a huge job on old code and won’t make 8.6 — Chris and Derick both note the pain of keeping a year-and-a-half-long project in sync with the master branch. Xdebug in 8.6 and the Xdebug Cloud Xdebug’s recent headline feature (shipped with 8.5) is native path mapping, which lets you configure remote-to-local path mappings inside Xdebug itself instead of your IDE — handy when your code runs in Docker or on a dev machine. Feedback since release is driving quality-of-life improvements. For 8.6, relatively little is broken, though a change to how PHP reports line numbers needs untangling so debugging stops on the correct lines. Derick also has a new code-coverage implementation that gives better, more correct results at roughly a 10% speed cost. He’d rather ship correct output than fast output — and points out that PHPCov may be quicker but skips path and branch coverage entirely. The pair discuss how branch coverage doubles your test count at every branching point, and how Xdebug has a hard limit (around 64K) to avoid running out of memory on pathological code. Finally, Chris asks about Xdebug Cloud — a paid service that enables debugging where networking otherwise wouldn’t, such as remote teams sharing a single development machine (an SSH tunnel only lets one person listen on the debug port). It’s £15/month or £150/year for an individual, priced similarly to Packagist’s private packages, and helps fund Derick’s ongoing Xdebug work. He plans to do more marketing about it this year. Deprecations, Consensus, and Two-Thirds Votes Every year PHP collects a big list of deprecations — around 20 to 25 this cycle — voted on separately. Derick is more reluctant than most to approve them, arguing many offer no clear user benefit. His examples: deprecating metaphone() (whose suggested Composer replacement ironically relies on the internal function) and the dechunk filter (which can’t really be removed because HTTP streams use it internally). The list() deprecation is another sore point — Chris uses it, and the vote is tied 21–21 with one abstention, so it won’t pass under the two-thirds rule. Derick reminds everyone that “yes” needs to be twice “no.” Returning from a finally block is another candidate that makes little sense to use but hurts nothing to keep. Chris and Derick reflect on how voting was originally meant to confirm consensus reached on the mailing list, not to be the decision itself. A 50%+1 result isn’t consensus; two-thirds is the compromise, even if true 75–80% agreement would be ideal. Joe notes many deprecations are groundwork to reserve keywords for future RFCs — which raises the perennial question of how you measure real-world usage across Composer’s dependency chains. Infrastructure, the Website, and the Next Generation The PHP infrastructure has been converted to an Ansible-based repository over the last year and a half (largely by Derick, with help from Joe), replacing a wild mix of individually maintained servers — one was still running FreeBSD 4.3. They’ve also migrated to a new CDN, which brought surprises: a default one-month cache, ignoring the query string in cache keys, and even dark/light mode being an organization-wide setting rather than per-user. On the website side, everything currently lives in a single root directory of 1999-vintage code, and there’s a long-pending patch to restructure it. The PHP Foundation’s ambassadors program — with speaking, marketing, and research streams — aims to make the very techy php.net homepage speak to CTOs and newcomers about who uses PHP and why it’s a thriving project (only 31-ish years old, versus C’s 60). The conversation closes on caretakers and the next generation of contributors. Triage, they stress, doesn’t require deep internals knowledge — just reading reports to see if they still make sense is hugely valuable. Security and infrastructure access necessarily stay gatekept for trust reasons, and both agree a bus factor of one (or even two) isn’t good enough. Chris admits he’s struggling to name people who are both nice and know infra. Links from the show: Join us live in Discord — discord.phparch.com Watch live on YouTube — youtube.com/phparch PHP Tek Conference 2027 — Call for Papers now open PHP Arch Swag Store — store.phparch.com Xdebug — and Xdebug Cloud for shared debugging Magazine discount code ALIVE3 — three free months on an annual digital subscription Host: Chris Miller X: @ccmiller2018 Mastodon: @miller@phpc.social Bluesky: @ccmiller2018.bsky.social PHPArch.me: @miller Mike Page Mastodon: @MikePageDev@phpc.social PHPArch.me: @mikepagedev Streams: Youtube Channel Twitch Connect & Hire PHP Architect Website Twitter/X Mastodon Hire PHP Developers Looking to hire PHP developers? Email support@phparch.com – the team is available for consulting, infrastructure work, Ansible playbooks, and code review. Partner This podcast is made a little better thanks to our partners Displace Infrastructure Management, Simplified Automate Kubernetes deployments across any cloud provider or bare metal with a single command. Deploy, manage, and scale your infrastructure with ease. https://displace.tech/ OurCVEs Your security posture, on autopilot with OurCVEs CodeRabbit Cut code review time & bugs in half instantly with CodeRabbit. PHP Architect Consulting Your PHP codebase deserves a partner, not a contractor PHP Architect provides long-term technical partnerships for organizations that need senior-level PHP expertise that you can depend on. https://www.phparch.com/consulting/ Music Provided by Epidemic Sound https://www.epidemicsound.com/ Join Us Live Next Week Youtube Channel Got feedback? Join us on Discord at discord.phparch.com The post PHP Alive and Kicking 2026.08.04 appeared first on PHP Architect.
Après quatre années florissantes, où ils ont atteint en moyenne trois milliards de dollars par an, les investissements étrangers au Sénégal (IDE) ont chuté à 37 millions de dollars en 2025, comme le pointe le rapport annuel de la Conférence des Nations unies sur le commerce et le développement (Cnuced). S'agit-il de la fin d'un cycle massif d'investissements, ou d'une frilosité vis-à-vis du gouvernement et de sa politique financière ? L'effondrement des investissements est avant tout conjoncturel : les grands projets pétroliers et gaziers de Sangomar et de Grand Tortue ont entraîné un afflux de financements ces dernières années, mais le gros de ces investissements est terminé. L'heure est maintenant à la production. Le Sénégal aurait pu cependant recevoir beaucoup plus que les 37 millions de dollars comptabilisés en 2025, estime Moubarak Lo, ancien conseiller économique de la primature, aujourd'hui consultant : « Le Sénégal peut, de manière structurelle, maintenir trois à cinq milliards de dollars par an [d'investissements], mais cela suppose une promotion active de l'économie. Or, le pays n'a pas de réseau de promotion des investissements à l'étranger, contrairement à d'autres pays. On fait des roadshows mais ça ne suffit pas. On ne peut pas se limiter à attendre, il faut être proactif, on sait le faire pour l'investissement en portefeuille dans les titres d'État ou les bons du Trésor ou les obligations, mais on ne sait pas le faire pour les investissements directs et c'est cet aggiornamento qu'il faut faire. » Manque de visibilité L'endettement colossal du Sénégal – dette évaluée à 132% du PIB fin 2024 par le FMI – pourrait, sur le papier, agir comme un repoussoir. Mais dans les faits, il n'y a pas de raison qu'elle pèse sur les investisseurs privés, selon l'expert sénégalais. Justin Maria, directeur France d'Access Bank, confirme que la dette n'est pas un argument. Il cite à titre d'exemple la France, qui attire des investisseurs privés malgré sa dette publique de 3 500 milliards d'euros. Pour lui, c'est l'absence de visibilité qui peut inquiéter : « Le Sénégal est devenu un pays à risque. Pas tant sur les fondamentaux à long terme, car personne n'a de boule de cristal ; par contre, à court terme, on n'a pas de vision sur l'état des finances publiques, l'état des liquidités, c'est ce qui bloque les investisseurs. » « On peut redresser la barre l'année prochaine » Moubarak Lo réfute le qualificatif de pays à risque et pense que le Sénégal a les moyens de retrouver très vite son attractivité, même si le Fonds monétaire international, qui a suspendu son programme fin 2024, est toujours en discussion avec Dakar. « Aujourd'hui, le pays a une vingtaine ou une trentaine de projets d'envergure. Il faut prendre chaque projet, aller voir les cinq ou six entreprises clés au niveau mondial et convaincre l'une d'elles d'investir dans le pays. On peut redresser la barre dès cette année, ou plus certainement en 2027, le Sénégal », assure l'économiste. Contrairement au Sénégal, d'autres pays ont vu leurs investissements directs augmenter l'année dernière. La Guinée arrive en tête, avec plus de 7 700 millions de dollars reçus en 2025, selon le rapport de la Cnuced. À lire aussiSénégal: pourquoi les investissements directs étrangers s'effondrent-ils?
Slovenská politika už akoby celkom rezignovala na spravovanie štátu. Namiesto riešenia bazálneho metabolizmu krajiny – teda rozpadávajúceho sa zdravotníctva, nefunkčného školstva či chýbajúcej a hlboko podfinancovanej infraštruktúry, vláda ponúka občanom iba donekonečna sa opakujúci kolovrátok zástupných tém, lacné cirkusové vystúpenia do seba zahľadených politikov a permanentné živenie strachu a neustále hrotenie okamžitých emócií.Štát sa tak zmenil na fabriku na nepriateľov, kde sa namiesto reálnych výsledkov predávajú emócia, viralita a politika „na prvú signálnu“. No a azda jedným z najväčších terčov politickej nomenklatúry sa stávajú tí, ktorí celý tento aparát držia nad vodou – ľudia, ktorí poctivo pracujú a tvoria hodnoty. „Sme v studenej vojne s vlastnou krajinou – a ona s nami. Tí, čo skutočne tvoria a makajú, to robia nie vďaka, ale napriek vlastnému štátu.“ hovorí Imrich Kovaľ.Podnikanie na Slovensku sa podľa neho zmenilo na festival ľudí tancujúcich na samej hrane prežitia alebo tých, ktorí zo štátu luxusne žijú. Na jednej strane vidíme absurdné likvidačné pokuty za chýbajúce mäkčene na pokladničných blokoch či chýbajúce klimatizácie v rozhorúčených nemocniciach, na strane druhej nemožno nevidieť až cynicko-bezohľadný papalášizmus, luxus a aroganciu moci.Štát nevníma podnikateľov ako partnerov a živiteľov, ale ako podozrivých, ktorých treba neustále kontrolovať, šikanovať a žmýkať. Pokiaľ sa vládne prostredníctvom biznis modelu poháňaného nenávisťou, niet sa čo diviť, že najschopnejší ľudia balia firmy, odchádzajú za hranice a rezignujú na veci verejné, myslí si šéf firmy Merineo.Keď viete, že zajtrajšok bude ťažký tak si dnešok chcete užiť. Politika sa tak stala únikom pred realitou a formou zábavy. Žijeme dobu "hrotu," teda hrotíme to, emócie, prežívanie. A rezignovali sme na riešenie bazálneho metabolizmu krajiny.Vraciame sa k mentalite pánov a poddaných, ku generačne overeným modelom ešte z komunizmu, ale komunisti - na rozdiel od týchto tu, aspoň mali rozum a vedeli, že nemôžu naštvať. svojich poddaných, z ktorých žili, dodáva Kovaľ.Podľa neho to však nie je primárne iba o samotnej politike, ale predovšetkým je to o našej neochote chcieť od štátu viac a verejne sa preto i angažovať. Preto je potrebná zmena objednávky, teda toho, čo od politiky my - ako občania, vlastne očakávame.„Všetci riešia veľkú politiku, ale nikto neotvára novú objednávku od voličov. Vo svete nekonečných možností si generačne opakovane vyberáme vodcov so silnou rukou. Našou achilovkou je poddanská mentalita a potreba silnej ruky.“Slovensko však nie je stratená krajina a nie je ani krajinou “beyond repair,” teda neopraviteľnou krajinou. Našou obrovskou devízou je naša až neuveriteľná schopnosť adaptability. Ide teraz o to, ako ju využijeme, prízvukuje Kovaľ a odkazuje, že práve teraz žijeme osudový zápas o budúcnosť tejto krajiny.Počúvate Aktuality Nahlas, pekný deň a pokoj v duši praje Braňo Dobšinský.
Chain Reactions is the live marketing talk show from Myosin — built by operators, for operators — breaking down the marketing happening all around you with people who actually run growth.Today, Arnav is joined by the two OGs of the show, Blake and Polina, for a 90-minute run-through of the stories the Silicon Valley echo chamber is losing its mind over, a live tool teardown, a debate, and a game that exposes how many ads you consume without realizing it.What we get into:- Kunal Shah taking the WhatsApp global CEO seat — CRED, UPI, and whether messaging apps actually become the payment layer in markets like India, China, and parts of Europe- SpaceX's IPO, the 5% float, and xAI/Grok acquiring Cursor for $60B in stock — a customer-and-talent grab more than an IDE play- Why local models became the whole conversation overnight: token economics, Anthropic's pricing shift, and what the Fable/Mythos restrictions mean for anyone building on frontier models- Google's $75M move into A24, AI in filmmaking, and the creative-tooling debate (Tron, Toy Story, and the "press a button to make AI disappear" crowd)- Markdown — Polina walks through the content automation system behind her UFC prediction tool: trusted-source scraping, virality scoring, Telegram alerts, and Fal.ai image generation with a human always in the loop- Hot Button — should performance marketing report to the CFO or the CMO? A "cordial" debate that turns into a real argument about attribution, LTV, and who owns the risk- Adaholic — guess the brand and category from the ad clip. Polina runs away with it, seven wins deep.CHAPTERS00:00 Intro — welcome back, Blake & Polina01:16 Watercooler: Kunal Shah → WhatsApp global CEO (CRED, UPI, WeChat-ification)09:32 SpaceX IPO + xAI/Grok acquires Cursor for $60B20:07 The local models moment, token economics & Anthropic pricing30:19 Google's $75M into A24 + AI in film and creative38:08 Markdown: Polina's UFC content automation teardown54:32 Hot Button: should performance marketing report to CFO or CMO?1:11:16 Adaholic: name that ad#ChainReactions #GrowthMarketing #AIMarketing #GTM #PerformanceMarketing #MarketingPodcast #Myosin #MarketingStrategy #LocalModels #VibeMarketing #CMO #SpaceX #Grok #B2BMarketing #MarketingNews #GrowthMarketing #AIMarketing
Slovenská politika už akoby celkom rezignovala na spravovanie štátu. Namiesto riešenia bazálneho metabolizmu krajiny – teda rozpadávajúceho sa zdravotníctva, nefunkčného školstva či chýbajúcej a hlboko podfinancovanej infraštruktúry, vláda ponúka občanom iba donekonečna sa opakujúci kolovrátok zástupných tém, lacné cirkusové vystúpenia do seba zahľadených politikov a permanentné živenie strachu a neustále hrotenie okamžitých emócií.Štát sa tak zmenil na fabriku na nepriateľov, kde sa namiesto reálnych výsledkov predávajú emócia, viralita a politika „na prvú signálnu“. No a azda jedným z najväčších terčov politickej nomenklatúry sa stávajú tí, ktorí celý tento aparát držia nad vodou – ľudia, ktorí poctivo pracujú a tvoria hodnoty. „Sme v studenej vojne s vlastnou krajinou – a ona s nami. Tí, čo skutočne tvoria a makajú, to robia nie vďaka, ale napriek vlastnému štátu.“ hovorí Imrich Kovaľ.Podnikanie na Slovensku sa podľa neho zmenilo na festival ľudí tancujúcich na samej hrane prežitia alebo tých, ktorí zo štátu luxusne žijú. Na jednej strane vidíme absurdné likvidačné pokuty za chýbajúce mäkčene na pokladničných blokoch či chýbajúce klimatizácie v rozhorúčených nemocniciach, na strane druhej nemožno nevidieť až cynicko-bezohľadný papalášizmus, luxus a aroganciu moci.Štát nevníma podnikateľov ako partnerov a živiteľov, ale ako podozrivých, ktorých treba neustále kontrolovať, šikanovať a žmýkať. Pokiaľ sa vládne prostredníctvom biznis modelu poháňaného nenávisťou, niet sa čo diviť, že najschopnejší ľudia balia firmy, odchádzajú za hranice a rezignujú na veci verejné, myslí si šéf firmy Merineo.Keď viete, že zajtrajšok bude ťažký tak si dnešok chcete užiť. Politika sa tak stala únikom pred realitou a formou zábavy. Žijeme dobu "hrotu," teda hrotíme to, emócie, prežívanie. A rezignovali sme na riešenie bazálneho metabolizmu krajiny.Vraciame sa k mentalite pánov a poddaných, ku generačne overeným modelom ešte z komunizmu, ale komunisti - na rozdiel od týchto tu, aspoň mali rozum a vedeli, že nemôžu naštvať. svojich poddaných, z ktorých žili, dodáva Kovaľ.Podľa neho to však nie je primárne iba o samotnej politike, ale predovšetkým je to o našej neochote chcieť od štátu viac a verejne sa preto i angažovať. Preto je potrebná zmena objednávky, teda toho, čo od politiky my - ako občania, vlastne očakávame.„Všetci riešia veľkú politiku, ale nikto neotvára novú objednávku od voličov. Vo svete nekonečných možností si generačne opakovane vyberáme vodcov so silnou rukou. Našou achilovkou je poddanská mentalita a potreba silnej ruky.“Slovensko však nie je stratená krajina a nie je ani krajinou “beyond repair,” teda neopraviteľnou krajinou. Našou obrovskou devízou je naša až neuveriteľná schopnosť adaptability. Ide teraz o to, ako ju využijeme, prízvukuje Kovaľ a odkazuje, že práve teraz žijeme osudový zápas o budúcnosť tejto krajiny.Počúvate Aktuality Nahlas, pekný deň a pokoj v duši praje Braňo Dobšinský.
Talk Python To Me - Python conversations for passionate developers
Security has always been the vegetables of software. Everyone agrees it matters, and somehow it never quite makes it onto the plate. At PyCon US this year, that changed. For the first time ever, security got its own dedicated, day-long track, one of just two at the whole conference, sitting right next to AI. And the room was packed to the back wall. On this episode, I'm joined by the three people at the center of it. Seth Larson, Security Developer in Residence at the Python Software Foundation and, very recently, a CPython core developer. Juanita Gomez, a PhD researcher at UC Santa Cruz in open source security, who co-chaired the track. And Mike Fiedler, PyPI's Safety and Security Engineer, one of the very few people paid full-time to keep the packages you install safe. We use the arc of the track's talks to take the temperature of Python security right now: supply chain attacks, dependency cooldowns, zero trust, SBOMs, and the push to bring Rust into CPython. And why not one of us thinks security is anywhere close to solved. Turns out that's the good news. It's why the room was full. Episode sponsors Sentry Error Monitoring, Code talkpython26 Talk Python Courses Links from the show Guests Juanita Gomez: linkedin.com Mike Fiedler: miketheman.dev Seth Michael Larson: sethmlarson.dev Trailblazing Python Security: us.pycon.org Everything Security at PyCon US 2026 (PSF blog): pyfound.blogspot.com Dependency Cooldowns: cooldowns.dev Anatomy of a Phishing Campaign (Mike Fiedler) Recording: www.youtube.com FedRAMP: www.gsa.gov Zero Trust in 200ms: Implementing Identity-Per-Transaction with Python & Serverless-Tristan McKinnon: www.youtube.com Rust for CPython project: blog.python.org pre-PEP: discuss.python.org Rust for CPython: Making Python Safer and More Robust for Everyone - Emma Smith: www.youtube.com SBOMit: github.com Asleep at the Wheel: Getting your SBOMs to pay attention... - Sanchit Sahay, Abhishek Reddypalle: www.youtube.com Volatility: volatilityfoundation.org Post Incident Runtime SBOM Generation from Python Memory - Hala Ali: www.youtube.com zizmor: docs.zizmor.sh GitHub Actions security in Python packages (Andrew Nesbitt write-up): nesbitt.io andrew/pycon: data & analysis for the GitHub Actions security talk: github.com GitHub Actions Security in Python Packages - Andrew Nesbitt: www.youtube.com gh-profiler: examine a GitHub user's profile to gauge their contributions: github.com PyCon US YouTube channel: www.youtube.com SBOMit: adding verification to SBOMs (OpenSSF): openssf.org Ecosystems: ecosyste.ms Watch this episode on YouTube: youtube.com Episode #557 deep-dive: talkpython.fm/557 Episode transcripts: talkpython.fm Theme Song: Developer Rap
Deus é bom (parte 3) - André Manzoni by IDE
Welcome to the final episode of this season of Rust in Production. My guest is Orhun Parmaksız from JetBrains, and we talk about building developer tools with Rust.JetBrains is best known for IntelliJ IDEA, Kotlin, and a long line of IDEs for professional software teams. In the Rust world, that now includes RustRover: a commercial IDE built on the IntelliJ platform, with deep Rust support for navigation, refactoring, debugging, testing, and large codebases.This episode is about where Rust fits into that world. We talk about why JetBrains does not plan to rewrite the IntelliJ platform in Rust, why Fleet used Rust for its File System Daemon, how Air builds on parts of Fleet's architecture, and why JetBrains prefers out-of-process Rust helpers over JNI inside the JVM. We also get into RustRover's internals: PSI, THIR, MIR-based expression evaluation in the debugger, procedural macro sandboxing, library stubs, parser regression testing, cargo-nextest support, and the practical trade-offs between JetBrains' indexing model and rust-analyzer's Salsa-based approach.
"Si on ne sait pas ressentir de la colère, on ne sait pas mettre ses limites. Si on ne sait pas ressentir de la peur, on ne sait pas se protéger" Série spéciale Intelligence(s)Cet été, IFTTD part en exploration. Sur les 52 derniers épisodes, on a parlé d'intelligence artificielle 38 fois. On maîtrise plutôt bien la partie artificielle &mdash mais l'intelligence, la vraie, l'originale, on n'en a presque jamais parlé. Alors le temps d'un été, on remonte à la source : 6 épisodes, 6 chercheurs, pour comprendre ce qu'est vraiment l'intelligence.Le D.E.V. de la semaine est Moïra Mikolajczak, Professeure à l'Université catholique de Louvain. Durant cet épisode, elle explore avec nous les cinq grandes compétences qui composent l'intelligence émotionnelle, expliquant pourquoi l'identification et la régulation de nos émotions sont des enjeux aussi cruciaux au travail qu'à la maison. Moïra revient aussi sur la progression possible de ces compétences à tout âge, balayant l'idée qu'on serait figé par l'inné. Elle partage des pistes concrètes pour mieux comprendre, exprimer et utiliser ses émotions &ndash et ainsi améliorer sa vie et celle de ses proches. Un épisode riche de pistes pour tous ceux qui veulent muscler leur intelligence émotionnelle, au-delà des clichés.Chapitrages00:01:00 : L'intelligence émotionnelle expliquée00:06:19 : Comprendre ses émotions00:08:15 : Dire ses ressentis00:09:01 : Apprendre à réguler00:10:04 : Tirer parti des émotions00:22:30 : Émotions et enfance00:27:54 : Animaux et émotions00:33:22 : Granularité émotionnelle00:41:30 : Exprimer sans déborder00:47:29 : Écouter le message00:51:25 : La roue des émotions00:55:54 : Former les adultes Liens évoqués pendant l'émission Formation en ligne à l'intelligence émotionnelle pour le grand publicFormation en ligne à l'intelligence émotionnelle à destination des entreprises (avec évaluation et certification)
Topics covered in this episode: Some more things about Django I've been enjoying Who cleans up after the vibe-coding party? Where Did All Your AI Tokens Go? AgentsView to the rescue! Careful with phishing all Extras Joke Watch on YouTube About the show Sponsored by us! Support our work through: Our courses at Talk Python Consulting from Six Feet Up Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Calvin #1: Some more things about Django I've been enjoying Julia Evans is learning "2010-style" web dev (Django + SQL + server-rendered HTML) after years of Go backends and JS-heavy frontends Query builders: likes defining custom QuerySet classes with chainable filter methods (.approved().future().with_tags()) — more readable than raw SQL Template filters: highlights urlize, linebreaksbr, json_script, and especially querystring for building/modifying query-string links in templates Migrations: still loves Django's auto-generated migrations — 19 and counting on her project Skips inheritance for class-based views; prefers function-based views for sharing code, though fine using Django's own mixins/interfaces Performance surprise: CPU profiling (via py-spy) — not slow DB queries — revealed the culprit; she'd accidentally disabled the cached template loader, and re-enabling it took throughput from ~2-3 req/s to ~12 req/s on a $10/mo VM Michael #2: Who cleans up after the vibe-coding party? FT Magazine piece by Sam Learner (July 11) on AI coding tools overwhelming open source maintainers - sent in by listener Dylan McConnell, whose main point was that this ran in the Financial Times, not a dev blog. cURL as the case study - Daniel Stenberg has been the only full-time person on it for years; libcurl has been installed an estimated 20+ billion times with 3,000+ listed contributors. Bug bounty killed - cURL ended its paid security bounty program in January, citing an "explosion of AI slop reports" that take real time to debunk and drain morale. Extractive contributions - authoring a PR is now nearly free, reviewing one still costs a human; tldraw's Steve Ruiz closed outside contributions entirely, asking why he'd want someone else writing the easy part. Guido weighs in - van Rossum says projects are holding emergency meetings over the slop flow, and notes LLM patches tend to touch unrelated parts of a file, making review more tedious. "Vibe Coding Kills Open Source" - paper from Miklós Koren's group: packages frequently recommended by coding models saw big download jumps with no matching engagement, breaking the reputation loop that sustains maintainers. Stack Overflow flatlined - over 100,000 questions a month before ChatGPT, under 1,500 last month, with the response rate cut roughly in half; the public archive is now stale training data. The course-creator angle - Josh Comeau's newest web dev course launched at about a third of prior enrollment, and he worries about devs who never learn which questions to ask. But the most interesting portion is what was omitted. Focused on: The end of the curl bug-bounty Omitted: High-Quality Chaos Why the omission is interesting It fits a narrative. The FT piece is a maintenance-and-decline story, and January-Stenberg is a perfect witness for it. April-Stenberg complicates it - same person, same project, better data, opposite direction on the specific claim being used. The tell is already in the article. Learner quotes Stenberg saying AI tools are much better at finding problems than fixing them. That's the April thesis in one line, and it goes undeveloped. Reason for the shift is process, not vibes. Killing the bounty removed the cash incentive and the venue change filtered the rest. Worth saying out loud, because "AI reports got better" isn't quite it - "no bounty plus a real triage platform" is closer. Joke too: Sarah O'Connor wrote a related piece (is this just before skynet launches?) Calvin #3: Where Did All Your AI Tokens Go? AgentsView to the rescue! Local-first desktop/web app for browsing, searching, and analyzing your past AI coding agent sessions (Claude Code, Codex, Copilot, Cursor, Gemini, Aider, and dozens more) Auto-discovers session files on your machine — no config needed; everything stored locally in SQLite, no cloud/accounts agentsview usage is a drop-in ccusage alternative — reads from pre-indexed SQLite, reports run 80–220× faster on large histories New Activity dashboard shows peak concurrency, active vs. idle time, agent-minutes, and cost — filterable by project/agent/machine, with a -json CLI report too Full-text + optional semantic search across every session; also imports Claude.ai/ChatGPT chat exports Install via pip install agentsview, uvx agentsview, brew install --cask agentsview, or download desktop binaries from GitHub Releases Michael #4: Careful with phishing all The situation I pass this along because it was a pretty sneaky bit of targeted phishing, and happened to play off an old interaction in bandit's repo. As usual with phishing scams there are a bunch of tells that this isn't legitimate, but just enough plausibility that I could see falling for it in a weak moment. Relative nobodies like me haven't historically been worth the effort to hit with scams this specific. Agents change the game though :-/. Be careful out there folks! Original message From: "Patrick (Blacktrace)" [HTML_REMOVED] To: LISTENER EMAIL Subject: Your Bandit #1350 (B105 NextToken false positive) -- just fixed that exact case Date: Wednesday, July 15, 2026 12:02 AM Hi AJ, Saw your Bandit issue #1350 -- the B105 hardcoded-password false positive on the string NextToken. I build a deterministic gate that filters that class of Bandit noise, and #1350 was literally the case I just fixed: NextToken / next_token / page_token / nextPageToken now stay quiet, while a genuine hardcoded token like api_token="sk-live-..." still fires. Verified against your exact case. 30-second paste: https://blacktrace.co/noise-eraser Where it still trips, published: https://blacktrace.co/kruc Curious whether it clears what you hit -- and if it trips on something of yours, that's the more useful reply. Patrick, Blacktrace I asked Claude for some analysis too. It was pretty good at finding them. The message name-drops enough real detail to feel legit, but the structure is pure phishing - everything in it exists to get AJ onto blacktrace.co. The strongest ones: Freemail sender, corporate signoff. Signs as "Patrick, Blacktrace" but sends from emailpjv@gmail.com. Real company outreach comes from the company domain, not a personal Gmail - and there's no last name. Over-specific targeting. It mirrors AJ's exact public activity - issue #1350, the B105 rule, the NextToken false positive, even the token variants. That's the "just enough plausibility" AJ flagged, and it's exactly what agents make cheap: scrape a GitHub issue, auto-generate tailored bait. Legit cold outreach rarely reads your history back to you this precisely. The entire payload is two links. Strip the technical flattery and the message is just "paste here" plus "see results here." When the whole point of an email is the click, that's the tell. "30-second paste." Low-friction urgency, and "paste" most likely means paste your source into their tool - handing your code to a stranger's site. Exfiltration dressed as convenience. Brand-new, no-reputation domain. blacktrace.co has no track record, and the name is doing some ominous work. The /kruc slug is random noise, not how real product pages get named. Precise-sounding jargon that's actually vague. "Deterministic gate," "noise-eraser" - impressive, empty. Bolted onto correct real details (B105 is the Bandit hardcoded-password test, sk-live- is a Stripe live-key prefix) to borrow credibility. The disarming close. "if it trips on something of yours, that's the more useful reply" - engineered humility that flatters your expertise and baits a response. Makes engaging feel like you're doing them a favor, which drops your guard. Extras Calvin: DjangoCon US 2026 is rapidly approaching, August 24-28, Chicago Ruff v0.16.0 massively expands its default rule set Ruff now enables 413 rules by default, up from 59 https://astral.sh/blog/ruff-v0.16.0 Michael: Completely redesigned the home page. Try /insights in Claude Code (terminal) Joke: We're Safe
Talk Python To Me - Python conversations for passionate developers
For years, "Django and async" came with an asterisk. The docs themselves warned you off it. Scary performance notes, a story that felt half-finished. Well, that story just got rewritten, literally, and the person who rewrote it is here to tell you why the old framing was wrong. Carlton Gibson is a former Django Fellow, sat on the security team for eight years, and he's on the steering council. On this episode we get into the async topic doc rewrite, what actually remains versus what was just fear, the new Tasks framework in 6.0, DB-level cascades and fetch modes landing in 6.1, and why free-threading is the bet that's about to pay off big for Django. If you've been told Django's async story isn't ready, this is the episode that puts that myth to bed. Episode sponsors Sentry Error Monitoring, Code talkpython26 Python in Production Talk Python Courses Links from the show DjangoCon Europe: djangocon.eu PyCon Italia: pycon.it Django on the Med: djangomed.eu Django Mantle: noumenal.es PyPI: pypi.org release notes: docs.djangoproject.com on_delete: docs.djangoproject.com Fetch modes: docs.djangoproject.com HttpRequest.multipart_parser_class: docs.djangoproject.com async topic doc: docs.djangoproject.com docs: docs.djangoproject.com DEP 14: github.com django-tasks: github.com django-tasks-local: github.com Celery: docs.celeryq.dev PEP 703: peps.python.org free-threading HOWTO: docs.python.org PEP 779: peps.python.org ASGI: docs.djangoproject.com PGBouncer: www.pgbouncer.org Channels: channels.readthedocs.io sync_to_async / async_to_sync: docs.djangoproject.com noumenal.es: noumenal.es Django Chat: djangochat.com @carlton@fosstodon.org: fosstodon.org Article: Cutting Python Web App Memory Over 31%: mkennedy.codes Watch this episode on YouTube: youtube.com Episode #556 deep-dive: talkpython.fm/556 Episode transcripts: talkpython.fm Theme Song: Developer Rap
Nikola Trebulová je projektová manažérka a analytička spoločnosti, ktorá niekedy vzbudzuje kontroverziu pre „štátom posvätené podnikanie s kontrolami originality“. V rozhovore objasňuje význam týchto kontrol, prípady z praxe aj prečo je slovenský ODO-Pass lepší ako riešenia zo zahraničia.Hoci sa spoločnosť Iris Ident často spája s rôznymi názormi, jej reálnym a dokázateľným výsledkom sú tisíce odhalených podvodov a kultivácia trhu s jazdenými vozidlami. Iris Ident pôsobí pod dohľadom Ministerstva dopravy SR ako technická služba kontroly originality, pričom vyvíja softvér a spravuje Register prevádzkových záznamov vozidiel (RPZV).Podľa projektovej manažérky a analytičky spoločnosti Nikoly Trebulovej siaha história spoločnosti do hlbokej minulosti – už v roku 1995 napríklad vytvorila automatizovaný systém na kontrolu pohybu vozidiel na hraničných priechodoch.Kontrola originality nie je len byrokraciaNa Slovensku sa ročne vykoná zhruba 90- až 100-tisíc kontrol originality (KO), a to prevažne pri dovezených vozidlách, no nevyhnutná je napríklad aj pri zmene farby auta Mnohí motoristi vnímajú túto povinnosť ako dodatočnú byrokraciu a poplatok, avšak Trebulová upozorňuje na jej opodstatnenosť: „Existujú vozidlá, ktoré sú vyhodnotené stupňom 3 (nevyhovel) a odsúvajú sa na skúmanie políciou. Tento systém preukázateľne znižuje cieľovú destináciu podvodníkov na Slovensko.“ Kontrola samotná je nedeštruktívna, overujú sa pri nej nielen doklady, ale aj neoprávnené zásahy do konštrukcie. Ak sa zistí podozrenie, auto sa zadrží a detailné skúmanie preberá polícia.Unikátne prepojenia a dáta, ktoré tvoria ODO-PassNajznámejším výstupom pre bežného kupujúceho je ODO-Pass. Ide o výpis z registra RPZV, ktorý má referenčný charakter, právnu váhu a je použiteľný aj v súdnych sporoch. Tento register čerpá dáta od širokej škály subjektov – od staníc technickej a emisnej kontroly, cez poisťovne, leasingové spoločnosti až po inzertné portály. Slovensko je navyše napojené na medzinárodné informačné systémy ako Eucaris (moduly Mileage a AVIS) a získava dáta z oficiálnych autorít z USA. Prednedávnom sa podarilo získať aj dlho očakávané prístupy k dôležitej histórii nemeckých vozidiel.Kuriózne podvody z praxe: Ako oklamať STK čiernou páskou?Podvody sú s príchodom moderných technológií síce zložitejšie a drahšie, no stále existujú. Nikola Trebulová v podcaste spomenula pobavujúci, no zároveň odstrašujúci prípad z Bratislavy. Išlo o Škodu Octavia využívanú ako taxík, ktorá mala graf vývoja kilometrov veľmi "zubatý". Analytici detailným skúmaním zistili extrémne primitívny, no účinný podvod: „Pán iba prelepil posledné číslo na odometri čiernou páskou. To auto nemalo najazdené 50 000, ale 500 000 kilometrov,“ uviedla Trebulová, pričom toto vozidlo vďaka páske opakovane prechádzalo kontrolami bez toho, aby si to niekto na prvý pohľad všimol.Budúcnosť patrí elektromobilom a tvrdšej ochrane spotrebiteľaS narastajúcim podielom elektromobilov vzniká nová výzva – zistenie degradácie batérie. „Elektromobily nebudú predajné bez toho, aby tam bolo vlastne to zdravie baterky uvedené,“ hovorí Trebulová. Iris Ident sa preto spojil s lídrami v oblasti diagnostiky a plánuje certifikáty o zdraví batérie integrovať priamo do svojich systémov a reportov pre širšie komerčné využitie.Výrazný krok vpred by mala čoskoro priniesť aj nová slovenská legislatíva. Pripravuje sa zákon, ktorý stanoví, že ak kupujúci odhalí manipuláciu s odometrom a súčasťou predaja nebol výpis z registra prevádzkových záznamov (ODO-Pass), bude môcť úplne odstúpiť od kúpnej zmluvy. Stočené kilometre sú totiž na vozidle považované za neodstrániteľnú vadu.Vypočujte si celý rozhovor, dozviete sa viac o zákulí spoločnosti IRIS IDENT, o prípadoch z praxe aj o tom, aké nové taktiky používajú moderní podvodníci pri dovoze áut.
Deus é bom - Thiago Manzoni by IDE
"Des contraintes, sont bienvenues pour la créativité. Quand on dit aux gens, faites tout ce que vous voulez, c'est la catastrophe." Série spéciale Intelligence(s)Cet été, IFTTD part en exploration. Sur les 52 derniers épisodes, on a parlé d'intelligence artificielle 38 fois. On maîtrise plutôt bien la partie artificielle &mdash mais l'intelligence, la vraie, l'originale, on n'en a presque jamais parlé. Alors le temps d'un été, on remonte à la source : 6 épisodes, 6 chercheurs, pour comprendre ce qu'est vraiment l'intelligence.Le D.E.V. de la semaine est Todd Lubart, professeur de psychologie à l'Université Paris-Cité. Avec lui, on plonge dans la créativité comme moteur fondamental de l'intelligence, et on découvre pourquoi les contraintes sont un terreau fertile pour innover. Todd évoque comment la créativité s'exprime dans tous les métiers, au-delà des artistes, et pourquoi elle se travaille tout au long de la vie. On parle aussi du rôle grandissant de l'IA, qui transforme le travail créatif sans pour autant remplacer l'apport humain, singulier et idiosyncrasique. Enfin, Todd partage comment chacun peut développer son processus créatif par la pratique, la curiosité et les expériences hors du cadre.Chapitrages00:00:59 : Créativité et intelligence00:04:27 : Mesurer la créativité00:08:14 : Créativité chez les animaux00:09:47 : Créativité et QI00:12:24 : Inspiration au travail00:22:27 : Expertise et créativité00:25:55 : Âge et créativité00:28:30 : Paresse et idées00:33:13 : Contraintes créatives00:37:03 : La créativité se développe00:41:24 : Trop tôt, pas assez créatif00:44:01 : IA et créativité humaine00:46:28 : Ressources sur la créativité Liens évoqués pendant l'émission Psychologie de la créativitéThe Seven C's of creativity, 7 ouvrages qui déblayent les 7 thèmes qu'on retrouve dans la créativité
Topics covered in this episode: django-orjson Best Django Redis configuration for speed and size Linus Torvalds puts the foot down against Anti-AI Kernel Maintainers Django Steering Council backs the Triptych Project Extras Joke Watch on YouTube About the show Sponsored by us! Support our work through: Our courses at Talk Python Consulting from Six Feet Up Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Michael #1: django-orjson Adam Johnson dropped django-orjson - drop-in replacements for the Django and DRF pieces that touch JSON, swapping stdlib json for orjson, the Rust-based library. Headline numbers: 10x faster serialization, 2x faster deserialization. The interesting question is why this needs to be a package at all. pip install orjson is the easy part. Adam's actual pitch: adopting it "isn't easy, especially when your framework uses json in many different parts." Django scatters JSON across JsonResponse, the test client and test case classes, the json_script template tag, and more. There's no single hook to grab, so you get a library that catches them all. Adam is refreshingly honest about the scale of the win. His words: "While database queries tend to dominate the typical Django application's runtime, the time spent in serialization and deserialization can still be significant." He calls it "a nearly free performance win" - not "this will 10x your app." That's a claim about cost, not magnitude, and it's worth keeping those straight. Worth flagging what the post doesn't cover: caveats. There are none in the article, but orjson has real ones. Django and Flask both render datetimes as RFC 822 HTTP-date (Wed, 15 Jul 2026 12:00:00 GMT); orjson does ISO 8601. It can't do ensure_ascii, it rejects NaN and Infinity (which stdlib happily emits), and it raises on Decimal. If you've got a JS client parsing dates, that's a wire-format change. Who should actually take this? If you're a DRF shop shoveling JSON all day, yes - it's cheap and it's real. If your app mostly renders HTML templates, you're optimizing a slice of runtime that's already near zero. The problem Adam's package solves doesn't exist in Flask or Quart. They already centralize every JSON operation - jsonify, request.get_json(), the test client, the |tojson filter - behind one provider object at app.json. So there's no library to install. It's about ten lines: import orjson from quart.json.provider import JSONProvider # or flask.json.provider class OrjsonProvider(JSONProvider): def dumps(self, obj, **kwargs) -> str: return orjson.dumps(obj).decode() # provider must return str def loads(self, s, **kwargs): return orjson.loads(s) app.json = OrjsonProvider(app) The numbers on talkpython.fm Evaluated it, measured it, and skipped it. The biggest JSON payload we serve is our MCP server returning a cached episode transcript, about 139 KB. Swapping the provider saves 0.119 milliseconds per request. That total response takes 1.1 ms We got 4.1x, not 10x - and the reason is the good lesson. Payload shape decides your speedup. The 10x is for structure-heavy data, lots of small keys where stdlib burns time in Python-level dispatch per item. Our hot payload is one giant transcript string, so the work is escaping and memcpy Calvin #2: Best Django Redis configuration for speed and size Peter Bengtsson revisits a classic: his 2017 "Fastest Redis configuration for Django" benchmark now has a 2026 update posted this week. The 2017 post pitted django-redis serializers (json, ujson, msgpack, pickle) and compressors (zlib, lzma) against each other; conclusion was msgpack + zlib as the sweet spot - avoid the json serializer, it's fat and slow. The 2026 update narrows focus to just compressors: default (no compression), zlib, lzma, and newcomer zstd. New results: lzma compresses best but is slowest; zstd is the fastest compressor on Ubuntu; differences between them are very small. Big takeaway across both: compression buys you a lot of space (2–3.5x smaller) for very little speed cost - worth it for Redis where memory is the constraint. Caveat from the author: results depend heavily on your data - his test stores short strings of numbers, so benchmark your own workload. Michael #3: Linus Torvalds puts the foot down against Anti-AI Kernel Maintainers Write up on Ars. Really good coverage by Maximillian: Time to wake up (for some) Torvalds said that “Linux is not one of those anti-AI projects, and if somebody has issues with that, they can do the open-source thing and fork it. Or just walk away.” I agree with Max, putting your head in the sand and waiting for AI to go away will likely mean you won't be working professionally in software development in the coming years. The statement came amid a lengthy thread arguing about the use of Sashiko, an “agentic Linux kernel code review system” that its creators claim can, in tests, independently find 53.6 percent of the bugs that would end up being fixed by human coders in later commits. “We're not forcing anybody to use [LLM tools], but I will very loudly ignore people who try to argue against other people from using it,” Torvalds said. “Anybody who points to the problems at AI had better be looking in the mirror and pointing at themselves at the same time,” Torvalds wrote. Calvin #4: Django Steering Council backs the Triptych Project Django Steering Council issued a Letter of Collaboration backing Carson Gross & Alex Petros's funding bid for the Triptych Project - three proposals to make HTML more expressive natively, in every browser. The three additions: PUT/PATCH/DELETE methods for forms, button actions (buttons that fire HTTP requests without a wrapping form), and partial page replacement. Distills the core ideas from HTMX/Unpoly/Turbo into the HTML standard itself - no JS, no library, nothing to ship or maintain. Current focus is button actions (WHATWG #12330): Logout instead of wrapping a button in a form. Relevant to Django directly - think the admin submit row and disguised delete links; Django 6.0's template partials were already inspired by these patterns. How to help: companies can send non-binding letters of support on letterhead; individuals can read the proposals and weigh in on the WHATWG issues. Extras Calvin: DOOMQL - A playable first-person shooter whose framebuffer is a SQL query. Michael: Granian 2.7.9 fixes WSGI threadpool scheduler starvation/underscaling Welcome Calvin post Joke: Solving all bugs
Fredrik och Kristoffer sågs på stan för ett snack om Gram, teoribyggande, och ganska mycket mer. Kristoffer jobbar på ett jätteprojekt när han inte har något annat för sig. Kommunikation är ett problem - när det tar massor av tid att förklara varför och hur någonting behöver göras, tid man också skulle kunna lägga på att få en del av dem gjorda. Problemen kanske också behöver mogna och utforskas innan det går att låta någon annan göra något åt dem på ett effektivt sätt. Spelar det någon roll hur mycket ett gränssnitt sticker ut eller passar in i nuvarande trender? Vad får uppmärksamhet och varför? Och varför får det inte fler konsekvenser att påstå saker vitt och brett? Man borde inte bygga verktyg som stödjer dåliga sätt att jobba på. Man borde hitta bättre sätt att jobba istället för att bygga bättre verktyg för att stödja dåliga arbetssätt. Eller? Branschen har fastnat i icke-optimala sätt att jobba. Vad vill Kristoffer göra med Gram och varför? Och vad vill han inte göra? Hur borde flikar fungera? Och hur borde bra git-stöd i en textredigerare se ut? Varför är långa listor i gränssnitt alltid svårt? Det och andra problem man borde lösa på ett bra sätt en gång, inte halvbra många gånger. Programmering som teoribyggande. Varför kan vi inte rita i våra IDE:er, eller på andra sätt fånga allt teoribyggande och alla antaganden som inte går att utläsa av koden? Gränsen mellan språkmodeller och deterministiska verktyg. AI-sök saboterar möjligheter att hitta vissa sorters nålar i höstacken. Kodgranskning och teoribyggande - borde man fokusera mer på teorin i sitt granskande? All teori som inte finns med i koden. Rust är lite för bra för Kristoffer. Men det finnas massor som skulle kunna bli bättre också. Ett stort tack till Cloudnet som sponsrar vår VPS! Har du kommentarer, frågor eller tips? Vi är @kodsnack, @thieta, @krig, och @bjoreman på Mastodon, har en sida på Facebook och epostas på info@kodsnack.se om du vill skriva längre. Vi läser allt som skickas. Gillar du Kodsnack får du hemskt gärna recensera oss i iTunes! Du kan också stödja podden genom att ge oss en kaffe (eller två!) på Ko-fi, eller handla något i vår butik. Länkar Sommar-låten Hajk jj - git-ersättare Zed Patrik - vän av och gäst i podden Bug refinement - man vet att det är viktigt när förklaringen är femton sidor om man skulle skriva ut den! Mörk - Kristoffers markdownparser i Gleam Om jag haft mer tid hade jag skrivit ett kortare brev Gram Neovim Kai's power tools Bryce Kai's power goo - video Kai själv Jupyter notebook Magit Versionskontrollsystem där man skapade motsvarigheten till en commit först - innan man börjar göra ändringar - var nog just jj i ett avsnitt av Developer voices RAD debugger RAD game tools REPL - read-evaluate-print-loop Tailwind Immediate-mode GUI CSS GPUI - hårdvaruaccelererat UI-ramverk som driver Zed och Gram Gleam Commonmark Servo Nlnet - ger stöd till personer och organisationer som bidrar till ett öppet informationssamhälle Henna Virkkunen Computer science off course Programming as theory building Peter Naur BNF - Backus-Naur-form, eller Backusnormalform MS paint Stöd oss på Ko-fi! objc2 - Rust-låda med Objective-c-bindningar Newspeak Deltadb - Zeds nya lösning för versionskontroll Zig Tokio Garry Tan - VD för Y combinator och glad vibekodare Token ring Titlar Ett nytt utvecklingspass Den tekniska personen När vi har mer än tre användare Ticket-fokuserat sätt att arbeta Lär er använda git Jag borde bli bättre på git Alla borde bli bättre på git Atomerna för att bygga saker Ett sämre git Sortera sin kompost Välja precis rätt ord Gram power tools Metaboll Experimentgram Det är ju bara en texteditor En ny padda Immediate-mode CSS Tre tentakler Ni ser inte bra ut utifrån I ord förklara vad jag vill ha När man kan sin modell Vem är du att vara upprörd? Par-promptande Glorifierat undo En teori om hur man vill jobba Framtiden för programmering Min startup i Gleam Rust är för bra Nu sker det magi i bakgrunden Värdelös kunskap Professionell Rust Ett skal som ser ut att funka Mesh och b-post
Na slovenskom online autobazáre Autobazar.EU sa aktuálne nachádza 250 inzerátov osobných vozidiel s nájazdom nad 400-tisíc kilometrov – teda áut, ktoré prešli vzdialenosť rovnajúcu sa viac než desiatim cestám okolo Zeme. Analýza tejto ponuky ukazuje jasný vzorec: v lukratívnom klube suverénne dominuje diesel a spomedzi značiek najčastejšie Škoda, konkrétne model Octavia. Analýzu vypracoval motoristický novinár Erik Stríž.Diesel má drvivú prevahuZo skúmaných 250 inzerátov má až 227 vozidiel, teda 90,8 %, naftový motor. Benzínových áut je len 18 (7,2 %) a zvyšných päť jazdí na LPG v kombinácii s benzínom.Tento pomer len potvrdzuje dlhodobo známy fakt, že naftové motory – najmä osvedčené jednotky typu 1.9 TDI, 2.0 TDI, TDCi či CDI – boli po desaťročia konštruované s dôrazom na vysoké ročné nájazdy a dlhú životnosť motora, čo z nich robilo prirodzenú voľbu pre firemné vozové parky, taxislužby aj vodičov s dennou dochádzkou na veľké vzdialenosti.Benzínové motory sa medzi autami s vysokým nájazdom objavujú výrazne zriedkavejšie, hoci analýza ukazuje, že pokiaľ sa už na takom vysokom kilometrovníku objavia, ich priemerný nájazd v tejto skupine nie je nižší než pri dieseloch.Škoda a Volkswagen spolu tvoria tretinu ponukyZastúpenie značiek jednoznačne kopíruje ich dlhodobú obľubu na slovenskom trhu. Najviac inzerátov patrí Volkswagenu (42) a Škode (41), spolu teda takmer tretina (33 %) všetkých vozidiel s nájazdom nad 400-tisíc km. Nasleduje Mercedes-Benz (32 áut, 12,8 %), Audi (22), BMW (18), Ford a Volvo (po 12) a Renault (10). Zvyšok ponuky je rozdelený medzi desiatky ďalších značiek.Pri pohľade na konkrétne modely jednoznačne vyniká Škoda Octavia – tvorí až 68 % všetkých inzerátov tejto značky (28 zo 41) a s veľkým náskokom je najčastejším modelom na trhu vysokých nájazdov vôbec.Druhá je Škoda Superb (11 kusov). Medzi ďalšie najfrekventovanejšie modelové rady patria Volkswagen Passat, Mercedes-Benz Triedy E, Audi A6, BMW radu 5, Volkswagen Golf a Volkswagen Sharan.Ide prevažne o modely strednej a vyššej strednej triedy, ktoré boli po dlhé roky obľúbenou voľbou firemných flotíl a nemeckého aj domáceho dovozu.Priemerný vek 15 rokov, no výnimky idú aj proti prúduPriemerný rok výroby skúmaných vozidiel je 2011, čo zodpovedá priemernému veku približne 15 rokov. Najstarším zastúpeným vozidlom je BMW radu 3 z roku 1987, no zaujímavosťou je, že hranicu 400-tisíc kilometrov v ponuke prekonalo aj niekoľko výrazne mladších vozidiel z rokov 2020 až 2023 – typicky ide o bývalé firemné, lízingové alebo dovozové vozidlá s intenzívnym ročným nájazdom.Priemerný nájazd v celej skupine dosahuje 456-tisíc kilometrov, medián je 437-tisíc km. Podľa značiek dosahuje najvyšší priemerný nájazd Mercedes-Benz (takmer 500-tisíc km), nasledovaný Volvom a Škodou. Tento údaj je však potrebné čítať opatrne – nejde o dôkaz vyššej technickej odolnosti konkrétnej značky, keďže vzorka odráža len aktuálnu ponuku inzerátov, nie štatistiku skutočnej životnosti vozového parku.Kombi je kráľom vysokých nájazdovZ hľadiska karosérie jednoznačne prevažujú kombi vozidlá (31 % ponuky) – logicky, keďže ide o karosériu tradične spájanú s vyšším ročným nájazdom, firemným využitím aj rodinami s deťmi. Nasledujú sedan (19 %) a SUV (15 %), pričom zvyšok ponuky tvoria dodávky, MPV, hatchbacky a iné typy karosérií.Manuálna prevodovka mierne prevažuje nad automatickou (57 % oproti 41 %), pričom zvyšné 2 % tvoria iné alebo neuvedené typy, čo opäť súvisí s vekom vozidiel – automatické prevodovky sa v nižších a stredných triedach masovo presadili až v poslednej dekáde.Čo z toho vyplýva pre kupujúcichAnalýza potvrdzuje, že diesel spojený s osvedčenými modelmi ako Škoda Octavia, Volkswagen Passat či Mercedes Triedy E si dodnes drží povesť „nezničiteľného" auta schopného zvládnuť aj státisíce kilometrov.Zároveň treba pripomenúť, že vysoký nájazd sám osebe nehovorí nič o technickom stave konkrétneho kusu – rozhodujúca je história servisu, kvalita údržby a doklady o priebehu najazdených kilometrov. Pri kúpe vozidla s nájazdom nad 400-tisíc kilometrov preto odborníci odporúčajú dôkladnú kontrolu histórie vozidla a vykonanie komplexného preverenia vozidla nezávislým technikom.K metodike analýzyAnalýza vychádza z ponuky portálu Autobazar.EU k 8. júlu 2026 – z filtra osobných vozidiel s nájazdom od 400 000 km (250 inzerátov). Zastúpenie značiek, paliva, karosérie a prevodovky vychádza z celej množiny 250 inzerátov, podrobnejšie štatistiky nájazdu podľa modelov zo vzorky 236 z nich. Zvyšné inzeráty boli z hodnotenia vylúčené, keďže išlo o evidentné chybne uvedené údaje alebo mali iné vážne dôvody na nezaradenie do výberu.
Deus é bom - Gabriel Manzoni by IDE
"L'intelligence humaine, ce n'est pas aussi compliqué et profond que ce qu'on imagine" Série spéciale Intelligence(s)Cet été, IFTTD part en exploration. Sur les 52 derniers épisodes, on a parlé d'intelligence artificielle 38 fois. On maîtrise plutôt bien la partie artificielle &mdash mais l'intelligence, la vraie, l'originale, on n'en a presque jamais parlé. Alors le temps d'un été, on remonte à la source : 6 épisodes, 6 chercheurs, pour comprendre ce qu'est vraiment l'intelligence.Le D.E.V. de la semaine est Nicolas Gauvrit, enseignant-chercheur en sciences cognitives à l'Université de Lille. Spécialiste du raisonnement humain et du QI, il démonte les mythes qui entourent cette mesure controversée. À travers l'histoire et la technique du QI, il partage comment cette note globale donne une évaluation fiable du fonctionnement cognitif, mais échoue à saisir la créativité et d'autres formes d'intelligence. Nicolas insiste sur l'importance de distinguer la compétence réelle de la performance au test. Un épisode qui questionne franchement ce que le QI capture, ce qu'il ignore, et les limites de la notion d'intelligence elle-même.Chapitrages00:00:59 : Intelligence et QI00:06:30 : Ce que mesure le QI00:18:31 : Limites et types d'intelligence00:28:05 : Peut-on améliorer son QI ?00:34:21 : À quoi sert le test de QI ?00:36:44 : LLM et intelligence00:53:08 : Système 1, système 200:57:53 : Définir l'intelligence autrement Liens évoqués pendant l'émission Livre "Qi intelligence humaine" par NJ Mackintosh
Topics covered in this episode: The trusted-publishing debate: how to do it right vs. why you shouldn't trust it JupyterLab 4.6 and Notebook 7.6 are out! Tau – new small, readable terminal coding agent Django Tasks and Django 6.1 Extras Joke Watch on YouTube About the show Sponsored by us! Support our work through: Our courses at Talk Python Consulting from Six Feet Up Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Calvin #1: The trusted-publishing debate: how to do it right vs. why you shouldn't trust it https://snarky.ca/how-to-publish-to-pypi-using-github-actions-securely/ (Brett Cannon) and https://blog.yossarian.net/2026/07/07/You-shouldnt-trust-trusted-publishing (William Woodruff) Trusted Publishing (PyPI's OIDC-based auth scheme, also now used by npm, RubyGems, crates.io, NuGet) replaces long-lived API tokens with short-lived, auto-scoped credentials tied to CI/CD machine identity. Yossarian's post: it's purely an authentication mechanism between a machine identity and a package — it says nothing about package safety or quality. PyPI deliberately avoids any "verified/trusted" badge for it, unlike its verified-URL checkmarks. Same logic applies to PyPI attestations: anyone can sign with any machine identity they control, so an attestation's presence isn't itself a trust signal. Bottom line from that post: don't confuse "trusted" (machine-to-machine) with "trustworthy" (human judgment about the package). Snarky.ca's companion piece is more practical: given GitHub Actions compromises in the news, the real fix is 3 concrete steps — run zizmor to lock down workflow permissions/checkout credentials and pin actions to commit hashes, adopt Trusted Publishing to eliminate stored PyPI tokens, and require manual approval via a GitHub environment before any publish job runs. Takeaway for listeners: Trusted Publishing is good hygiene for how you authenticate to PyPI, but it's not a substitute for securing your CI pipeline itself — or for actually vetting the packages you install. Michael #2: JupyterLab 4.6 and Notebook 7.6 are out! Michał Krassowski's rundown - a chunky minor release: 68 features, 97 bug fixes, 95 contributors, one of the biggest ever. Scratchpad console (Notebook 7.6 headliner) - a console next to your notebook sharing its kernel, for throwaway experiments. Ctrl+B. Jump to last-edited cell - new commands hop through recently edited cells. File browser glow-up - Date Created column, editable breadcrumbs with Tab-completion, and Open in Terminal. Debugger - sources open in the main area, floating step/continue overlay, live kernel-sources filter. Custom layouts (Lab) - activity bar top/bottom, draggable panels, four-way tab splits, per-panel Ctrl+scroll zoom. ~5x faster extension builds - webpack → Rspack, and jupyter-builder means no full Lab install needed to build extensions. Keyboard/a11y - add shortcuts from the UI (no JSON), Find & Replace in Edit menu (Ctrl+H). Calvin #3: Tau – new small, readable terminal coding agent Tau – new small, readable terminal coding agent (Python 3.12+), built as both a working tool and a teaching project for how coding agents work under the hood Install via uv tool install tau-ai, pipx, or pip; ships a tau CLI Three-layer architecture: tau_ai (provider-neutral model layer) → tau_agent (reusable "brain": messages, tools, events, loop) → tau_coding (CLI/TUI, file & shell tools, sessions) Supports OpenAI, Anthropic, OpenAI Codex, OpenRouter, Hugging Face, and custom/local OpenAI-compatible endpoints Built-in tools (read/write/edit/bash), durable JSONL sessions with resume/branching, project instructions via AGENTS.md, and context compaction Core harness is UI-agnostic — same brain can power the TUI, print mode, or a custom frontend — usable as a standalone library too Michael #4: Django Tasks and Django 6.1 Django 6.0 finally ships first-party background tasks (django.tasks) - out of Jake Howard's DEP 14, accepted May 2024, after two decades of everyone bolting on Celery/RQ/Huey. It's an API, not a worker. Django handles task definition, validation, queuing, and result storage - it does not execute them. You bring the backend. The default backend traps people. ImmediateBackend runs tasks inline on the request thread and blocks until done - so out of the box .enqueue() backgrounds nothing (a 5-second task means a 5-second response). The other built-in, DummyBackend, runs nothing at all. Both are dev/test only. Nice API otherwise: slap @task on a function, call .enqueue(), get back a TaskResult you look up later by id - with async twins like aenqueue(). Gotcha: args and return values must survive a JSON round-trip, so a tuple sneakily comes back as a list. The community local backend to know: django-tasks-local by Chris Beaven (SmileyChris). A ThreadPoolExecutor backend that gives real background threads with zero infrastructure - no Redis, no Celery, no database - plus a ProcessPoolBackend for CPU-bound work → github.com/lincolnloop/django-tasks-local Its catch: results live in memory, so pending tasks vanish on restart or deploy. Great for dev and low-traffic production; for persistence, drop to Jake Howard's django-tasks (DatabaseBackend + worker command). Extras Calvin: Fixing the dictionary with Python 3.14 — Hugo van Kemenade stumbled on - and got fixed - a markup bug in the OED's own citation of a 1706 use of the pi symbol. Michael: Bunny DNS is now free Jokes: What's the object-oriented way to become wealthy? Inheritance To understand what recursion is... You must first understand what recursion is 3 SQL statements walk into a NoSQL bar. Soon, they walk out They couldn't find a table.
Talk Python To Me - Python conversations for passionate developers
Coding agents have gotten really good at one kind of work. You scope a feature, edit some files, run the tests, ship it. It all happens on disk. But that is not how data work feels. You load something, you look at it, you run a cell, you watch how it responds, and you decide the next move from whatever is sitting in memory. And until now, your agent couldn't see any of that. It only saw the files. Never the live state. This episode, that wall comes down. marimo pair drops a coding agent right inside a running notebook, with full access to every variable Python is holding in memory. The notebook becomes a shared canvas. You point, it runs the code. You tell it to zoom in on the Picasso paintings, and the chart just updates. No MCP tools to wire up, no schema to describe. Just Python, and an agent that can finally see what you see. Trevor Manz is back to walk us through it. Episode sponsors Sentry Error Monitoring, Code talkpython26 Talk Python Courses Links from the show marimo pair: marimo.io/pair Course transcripts announcement: talkpython.fm/blog anywidget: Jupyter Widgets made easy: talkpython.fm marimo: marimo.io blog: marimo.io GitHub: github.com given this: martinalderson.com llms.txt: talkpython.fm mcp: talkpython.fm cli: talkpython.fm open issues: github.com Discord: marimo.io Marimo Pair: marimo.io OpenCode: opencode.ai AI Tooling for Software Engineers in 2026: newsletter.pragmaticengineer.com Watch this episode on YouTube: youtube.com Episode #555 deep-dive: talkpython.fm/555 Episode transcripts: talkpython.fm Theme Song: Developer Rap
Talk Python To Me - Python conversations for passionate developers
You ask an AI a question and it answers with total confidence. Most of the time, a confidently wrong answer is just an annoyance. But what if the question is medical, and there's a real patient on the other end? In that world, a hallucination isn't a bug, it's a patient-safety event. Sumit Gundawar is a London-based software engineer who builds the clinical platform for a UK longevity and aesthetic-medicine clinic, and his whole argument is that in high-stakes AI, the model is the easy part. Earning trust is the real engineering. We dig into grounding, refusal logic, human-in-the-loop design, and the messy frontier of longevity and biohacking, plus a live demo of an assistant that refuses to answer when it can't back up the claim. Let's get into it. Episode sponsors Six Feet Up Talk Python Courses Links from the show Guest Sumit Gundawar: linkedin.com Course transcripts announcement: talkpython.fm/blog Sumit Gundawar - JAX London Speaker: jaxlondon.com Anthropic: anthropic.com OpenAI Platform: platform.openai.com Anthropic: anthropic.com LangChain: langchain.com OWASP: owasp.org Pydantic: pydantic.dev EU AI Act - Regulatory Framework: digital-strategy.ec.europa.eu HIPAA - HHS: www.hhs.gov NHS: www.nhs.uk Llama: llama.com Qwen - QwenLM on GitHub: github.com OpenAI Platform: platform.openai.com Hugging Face: huggingface.co Llama: llama.com Granola: www.granola.ai HIPAA - HHS: www.hhs.gov CodeRabbit: www.coderabbit.ai Cursor Origin: cursor.com GitHub Status: www.githubstatus.com Midjourney Medical: www.midjourney.com Neko Health: www.nekohealth.com CERN: home.cern ATLAS Experiment: atlas.cern Watch this episode on YouTube: youtube.com Episode #554 deep-dive: talkpython.fm/554 Episode transcripts: talkpython.fm Theme Song: Developer Rap
Pour l'épisode #335 je recevais Marcel Weekes. On en débrief avec Jeremy.
Ide o to získať vplyv v meste, obci či v kraji alebo sa zviditeľniť v politike do budúcna? Koalícia aj opozícia už nasadzuje svojich favoritov v boji o miesta županov, starostov či primátorov a prebiehajú aj prvé spájania či trieštenia. Ako to vyzerá v jednotlivých mestách či krajoch, ktoré súboje sa oplatí sledovať a ako čítať rozhodnutia Smeru či Hlasu pokiaľ ide o kandidátov do komunálnych volieb a vzťahy v koalícii? Eva Frantová sa v podcaste Dobré ráno pýta zástupcu šéfredaktora Denníka SME Jakuba Fila. Zdroje zvukov: STVR, Markíza, Facebook_/Marián Porvažník, Martin Winkler, Jozef Ráž Odporúčanie Dnes je mojím odporúčaním kniha There is No Place for Us od Briana Goldstona, ktorá sa venuje fenoménu takzvaných pracujúcich bezdomovcov v USA. Ide o ľudí, ktorí majú prácu, často aj na plný úväzok, no pre vysoké nájmy, nízke mzdy a slabú ochranu nájomníkov si nedokážu udržať bývanie. Kniha ukazuje, ako sa ľudia napriek práci a ambíciám prepadávajú do bezdomovectva — spia v autách alebo v lacných hotelových izbách. Je obrazom toho, že bezdomovectvo v súčasnej Amerike nie je len o ľuďoch na ulici, mnohí ostávajú skrytí a často sa neobjavujú ani v oficiálnych štatistikách. – Všetky podcasty denníka SME nájdete na sme.sk/podcasty – Odoberajte aj audio verziu denného newslettra SME.sk s najdôležitejšími správami na sme.sk/brifingSee omnystudio.com/listener for privacy information.
Topics covered in this episode: dust - a better du Hermes Agent: The AI agent that grows with you llm-coding-agent 0.1a0 Extras Joke Watch on YouTube About the show Sponsored by us! Support our work through: Our courses at Talk Python Consulting from Six Feet Up Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Michael #1: dust - a better du du + Rust = dust - a fast, visual, intuitive disk-usage CLI Run dust and immediately see the biggest directories and files without piping through sort, head, or awk Smart recursive output focuses on what matters instead of dumping every folder Colored bars show relative size and parent/child hierarchy, making “where did the space go?” obvious Perfect for Python projects bloated by .venv, caches, Docker volumes, downloaded datasets, and local AI models Install via brew, cargo install du-dust, conda-forge, Scoop, Snap, deb-get, or GitHub releases Calvin #2: A Way better ARchive format for Python packaging war - new archive format spec from Astral (same team as uv/ruff), v0.0.2, still no binary encoding defined yet Header-Index-Store layout: header IDs the file, index maps names to store offsets, store holds compressed data Index uses a finite-state transducer (FST) to dedupe common path prefixes across entry names Supports three entry types (file, directory, link) and three compression modes (store/DEFLATE/zstd), plus an "executable" metadata flag Unpacking is atomic - writes to a temp dir, then renames into place, so a failed extract never leaves a half-unpacked directory Strict name-segment rules (no NUL/control chars, no leading/trailing whitespace, blocks Windows-reserved names like CON/PRN) to avoid path traversal and cross-platform footguns Michael #3: Hermes Agent: The AI agent that grows with you Hermes Agent is an open-source, Python-built AI agent framework from Nous Research - think ChatGPT-style assistant, but connected to your tools, files, shell, browser, calendar, memory, and messaging apps I'm using it in Discord as a long-running agent conversation, not just a one-off chatbot session Hermes can connect through a gateway to platforms like Discord, Telegram, Slack, WhatsApp, email, webhooks, and more - so the same assistant can follow you across surfaces In my setup, I can send Hermes voice/text from Discord, keep project context across turns as threads, and ask it to actually do things: read GitHub repos, run commands, edit files, schedule calendar events, generate drafts, and verify results A fun workflow: I can trigger one-shot actions from an Apple Watch shortcut - dictate a request, send it to Hermes, and have the agent execute it asynchronously Hermes has persistent memory, so it can remember durable preferences and facts - for example, how I like my research formatted It also has “skills,” which are reusable procedures the agent can load later, so Hermes can self-improve over time instead of rediscovering the same workflow repeatedly It supports scheduled jobs / cron-style automations, so it can proactively watch for releases, send summaries, run checks, or remind you about things It's provider-agnostic: OpenRouter, Anthropic, Google, xAI, local models, Nous Portal, and others The big idea: Hermes turns an LLM from “a chat box I visit” into “an agent I can reach from anywhere that knows my workflows and can take real actions and learns over time.” Calvin #4: llm-coding-agent 0.1a0 Simon Willison built a Claude/Codex-style coding agent on top of his llm library, using an alpha of the llm package plus his python-lib-template-repo Built almost entirely via prompted TDD - asked an agent to write a spec.md, then commit + implement with red/green tests, occasionally hitting a real OpenAI key to sanity-check Shipped to PyPI as an alpha: uvx --prerelease=allow --with llm-coding-agent llm code Tool set mirrors familiar coding-agent primitives: read_file, edit_file (exact string replace + diff), write_file, list_files, search_files, execute_command Also exposes a Python API - CodingAgent(model="gpt-5.5", root=..., approve=True).run(...) - which Simon didn't ask for but got anyway Demo: llm code --yolo told GPT-5.5 to build a SwiftUI CLI clock; model correctly noted SwiftUI isn't really CLI-friendly and still produced an ASCII-art time display Extras Calvin: Slides, but for developers https://sli.dev/ Wanna reduce your token usage…. only issue is that its lossy https://github.com/teamchong/pxpipe PEP 772 - Python Packaging Council inaugural election dates set, nominations open July 28, voting September 1-15 Michael: What the pls? revisited! Joke: Min requirements for Linux
SED News is a monthly podcast from Software Engineering Daily where hosts Gregor Vand and Sean Falconer break down the biggest stories shaping software engineering, Silicon Valley, and the broader tech industry. In this episode, Gregor and Sean dig into the growing tension around restricted AI models, including Anthropic‘s Fable being pulled from the Claude platform days after launch. They explore what Sean calls “vibe regulations” and the risk foreign governments and enterprises face when a model they depend on can be cut off. They also cover the FT’s reporting on London’s “DeepMind mafia,” a vibe-coding clone controversy involving YC-backed Corgi and Papermark, SpaceX‘s acquisitions of Cursor and Mesh, and Anthropic’s launch of Claude Science. They also take on the latest round of the IDE wars, and explore who owns your dev toolchain, the vendor lock-in that now comes from context and memory rather than the model itself, and the widening cost gap between frontier tools and open weight models. As always, the episode wraps up with a few standout Hacker News threads. The post SED News: Restricted Models, IDE Wars, and the DeepMind Mafia appeared first on Software Engineering Daily.
Nick Olsen is the Head of AI Innovation at Mainsail Partners, where he works hands-on with 25 scaling vertical SaaS companies helping them adopt AI in engineering and product. Before joining Mainsail, Nick spent 20 years helping build ResMan from a 3-person startup into a scaled software company serving the multifamily property management market. Today, Nick leads a team of engineers who embed directly inside portfolio companies to build AI systems alongside their teams. They don't just advise from the sidelines—they commit code, ship features, and help technical leaders redesign how modern software organizations operate. Nick explains why AI-first engineering is no longer a competitive advantage for SaaS companies—it's becoming the minimum requirement to stay competitive. The winners won't just write code faster. They'll build better products, make better decisions, and deliver dramatically more customer value with AI-native teams. Key Takeaways Table Stakes — AI-first engineering is no longer optional for serious SaaS companies. It's becoming the minimum operating standard. Roles Are Collapsing — Product, design, and engineering are moving closer together as AI removes slow handoffs and bottlenecks. Velocity Misleads — Shipping 3x more features doesn't matter if customers don't want them. Outcome beats output. Judgment Wins — AI makes building cheaper and faster. Strategic product judgment becomes more valuable, not less. Agents Matter — The best teams increasingly treat AI agents like teammates with jobs, accountability, and measurable performance. UX Is Changing — Customers may increasingly stop logging into SaaS apps and interact through agents instead. Quote from Nick Olsen, Head of AI Innovation at Mainsail Partners "We are well past any point of skepticism or any engineer that says, Hey, this isn't gonna be here forever, or this isn't my thing. Engineers no longer should be starting in the traditional code editor, the IDE. Engineering has moved to much more of an agentic approach where you're starting in the terminal or or some sort of Claude Code or Codex app. "How we're building software has completely and radically shifted. Companies are starting to move past treating AI as a tool. They're starting to treat AI as the way that they actually operate. It's not a tool like Excel is for a financial analyst, but that's actually where I start. "We're trying to see people transition to treat AI as an actual teammate and actually affecting change within their organization.. And that's from the product and management side as well as to the engineering side." Links Nick Olsen on LinkedIn Mainsail Partners on LinkedIn Mainsail Partners website Podcast Sponsor – Full Scale This podcast is sponsored by Full Scale, one of the fastest-growing software development companies in any region. Full Scale vets, employs, and supports over 300 professional developers, designers, and testers in the Philippines who can augment and extend your core dev team. Learn more at fullscale.io. The Practical Founders Podcast Tune into the Practical Founders Podcast for weekly in-depth interviews with founders who have built valuable software companies without big funding. Subscribe to the Practical Founders Podcast using your favorite podcast app or view on our YouTube channel. Get the weekly Practical Founders newsletter and podcast updates at practicalfounders.com. Practical Founders CEO Peer Groups Be part of a committed and confidential group of practical founders creating valuable software companies without big VC funding. A Practical Founders Peer Group is a committed and confidential group of founders/CEOs who want to help you succeed on your terms. Each Practical Founders Peer Group is personally curated and moderated by Greg Head.
Topics covered in this episode: Free-threaded Python: past, present, and future django-admin-site-search Qwen 3.6 27B is the sweet spot for local development A large batch of PEPs are finalized Extras Joke Watch on YouTube Show Intro Sponsored by us! Support our work through: Our courses at Talk Python Consulting from Six Feet Up Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Calvin #1: Free-threaded Python: past, present, and future The GIL has prevented true multi-threaded parallelism in CPython since the beginning — multiple past attempts to remove it failed on performance grounds Sam Gross at Meta finally solved it; his work became PEP 703 and ships as free-threaded CPython today Python 3.13 was experimental with 20–40% single-threaded slowdown; 3.14 brought that to 0–10% Python 3.15 (October 2026) delivers a unified ABI — one extension binary works on both GIL and free-threaded builds Already >50% of the top PyPI binary wheels support free threading Wouters predicts free-threaded becomes the default between 3.16–3.20 (2027–2031), with the GIL eventually disappearing next decade Michael #2: django-admin-site-search via Adam Parkin A global/site search modal for the Django admin, by Ahmed Aljawahiry. Hit cmd+k anywhere in the admin and you get a command-palette-style search window, kind of like the one in VS Code. It doesn't just search one model's list page. It searches your entire site in one box: App labels Model labels and field attributes Actual model instances (your data) Two ways to search the instances: model_char_fields (the default): runs an __icontains across every CharField (and subclasses) on the model. Zero config, works out of the box. admin_search_fields: defers to each ModelAdmin's existing get_search_results(), so it respects the search_fields you've already set up. The part I like: it's permission-aware out of the box. Users only see results for the apps and models they actually have view permission on, so you're not leaking anything through search. Results appear as you type, with throttling/debouncing so you're not hammering the server on every keystroke, and it's full keyboard nav: cmd+k to open, up/down to move, enter to go. It's responsive, does dark and light mode, and it pulls Django's built-in admin CSS variables so it just matches whatever admin theme you're running. Under the hood it's Alpine.js, but bundled into static so there's no external CDN dependency. Setup is about what you'd expect: pip install django-admin-site-search, add it to INSTALLED_APPS, mix the AdminSiteSearchView into your AdminSite, and drop a few template includes into base_site.html. Supports Python 3.8 through 3.14 and Django 3.2 through 6.0, MIT licensed, and everything is overridable if you want to skip certain models, add TextField matching, etc. Calvin #3: Qwen 3.6 27B is the sweet spot for local development Qwen 3.6 27B is being called the first local model that genuinely competes as a general-purpose intelligence — benchmarks put it at roughly mid-2025 frontier level (comparable to GPT-5 / Claude Sonnet 4.5) Runs locally via llama.cpp; on an M5 MacBook Max with 8-bit quantization + multi-token prediction, it hits ~32 tokens/sec using ~42GB RAM 4-bit quantization gets it under 18GB, runnable on 32GB devices; Nvidia RTX cards run it even faster The dense 27B is recommended over the faster MoE 35B A3B — author prefers higher quality output over raw speed Privacy and reliability are the pitch: fine-tunable, can't be taken down, suitable for sensitive/proprietary data Author sees this as a stepping stone — frontier open-weight models like GLM 5.2 are now locally runnable with company-grade hardware, and smarter-still local models are coming Michael #4: A large batch of PEPs are finalized A bunch of PEPs went from accepted to final. 668, 687, 691, 699, 701, 703, 728, 770, 773, 829 But this wasn't them making their way into CPython. It's an admin sorta thing. (Thanks PyCoders) See the commit. Extras Calvin: More fun bling for your terminal this time - https://charm.land/ Michael: Follow up from pls, What the pls? Thanks Pito. Joke: BEMoji A production-grade utility and component framework built entirely on emoji class names via Jeff Triplett
Talk Python To Me - Python conversations for passionate developers
This episode is a fun crossover from our Python news and tips podcast, Python Bytes. We have had some big changes over there. Brian Okken has moved on and Calvin Hendryx-Parker has joined the show as the new co-host. To kick off this new era, we decided to do a longer and more personal episode called "All Our Tools". The idea is both of us talk about some of our most useful day-to-day developer and business owner tools that we think you all would find useful. It was so well received, that I'm bringing it to you all as a crossover episode. Enjoy and we hope you find something new and awesome to help you with your software and data science day to day. Episode sponsors Sentry Error Monitoring, Code talkpython26 Python in Production Talk Python Courses Links from the show @calvinhp@sixfeetup.social: sixfeetup.social @calvinhp.com: bsky.app calvinhp.com: calvinhp.com Original airing on Python Bytes: pythonbytes.fm pi: pi.dev superpowers: github.com Warp.dev: Warp.dev OhMyZSH: ohmyz.sh Commandbookapp.com: Commandbookapp.com Blink: blink.sh kitty: sw.kovidgoyal.net mosh: mosh.org tmux: github.com Claude code: www.anthropic.com Claude.md: Claude.md MacWhisper: goodsnooze.gumroad.com Handy: handy.computer Tailscale: tailscale.com Talk Python episode with Alex: talkpython.fm Telescopo: www.telescopo.app Typora markdown: typora.io formal documentation for many of my open source packages: mkennedy.codes Great Docs: posit-dev.github.io Statement on the US government directive to suspend access to Fable 5 and Mythos 5: www.anthropic.com No second date: x.com Watch this episode on YouTube: youtube.com Episode #553 deep-dive: talkpython.fm/553 Episode transcripts: talkpython.fm Theme Song: Developer Rap
Topics covered in this episode: Backup Docker volumes locally or to any S3 Pyodide 314.0 Release nb-cli: A Command-Line Interface for AI Agents and Notebook Automation Hindsight Agent Memory That Learns Extras Joke Watch on YouTube About the show Sponsored by us! Support our work through: Our courses at Talk Python AWS Community Day Midwest tomorrow Wednesday the 24th in downtown Indianapolis, Six Feet Up is sponsoring and there are 2 Sixies presenting Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an bonus digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Michael #1: Backup Docker volumes locally or to any S3 Via Bryan Weber (thanks Bryan!), who spotted it over on Virtualization HowTo. Find Bryan at bryanwweber.com. offen/docker-volume-backup is a lightweight companion container that backs up the volumes your apps actually depend on, then ships them somewhere safe. It's tiny: written in Go and about 25MB compressed, roughly 1/20th the size of the shell-based image (jareware/docker-volume-backup) that inspired it. Drop it into your docker compose file as a backup service, mount the volumes you care about as read-only, and you're off. Push backups to a pile of destinations: a local directory, plus any S3, WebDAV, Azure Blob Storage, Dropbox, Google Drive, or SSH-compatible target. Mix and match as many as you want in one run. Recurring cron-style backups in a Compose setup, or one-off backups straight from the Docker CLI. Production-friendly touches worth calling out: Rotates away old backups so you don't quietly fill the disk. GPG encryption for your archives. Notifications on finished and failed runs (so you find out about failures before you need the backup). Stop a container during backup for a consistent snapshot using a simple docker-volume-backup.stop-during-backup=true label, then auto-restart it. Run custom commands during the backup lifecycle (great for a database dump before the file copy). Docker Swarm support, plus arm64 and arm/v7 builds. Hello, Raspberry Pi homelab. Fun aside from Bryan: he searched our back catalog for this tool and the search came back so fast he thought it hadn't run. Love to hear it. Calvin #2: Pyodide 314.0 Release PEP 783 is the real news — Pyodide maintainers used to hand-build 300+ packages. Now anyone can publish Pyodide wheels to PyPI with cibuildwheel. The version jump from 0.29 to 314.0 is intentional — it now tracks the Python version, so 314.x = Python 3.14. Binary compatibility is locked per Python cycle, meaning packages you build today won't break on the next Pyodide release. sqlite3, ssl, and lzma are back in the default stdlib — no more await pyodide.loadPackage("sqlite3"). Bigger download, but a much smoother experience for newcomers. bigint precision bug is fixed — values above 2^53 were silently losing precision when crossing the Python/JS boundary. The new JsBigInt type makes the roundtrip correct. Worth flagging if anyone is doing numeric work in a browser app. Experimental TCP sockets in Node.js — you can now connect Pyodide to a real database (MySQL, PostgreSQL, Redis tested) when running server-side. Blurs the line between "Python in the browser" and "Python runtime anywhere Wasm runs." Michael #3: nb-cli: A Command-Line Interface for AI Agents and Notebook Automation From Piyush Jain (Jupyter and LangChain maintainer) on the Jupyter blog: nb-cli: A Command-Line Interface for AI Agents and Notebook Automation. nb-cli is an experimental, Rust-based CLI to read, write, execute, and search Jupyter notebooks. The premise: agents are great at CLIs but terrible at hand-editing the nested JSON in an .ipynb, so let them operate on the notebook from the outside instead of running inside it. Works with or without a Jupyter server. No server? It reads/writes .ipynb files directly and talks to kernels over ZeroMQ. Connected to a live JupyterLab, your edits show up instantly via Y.js (the same CRDT Jupyter uses). Smart output format: instead of token-heavy JSON or ambiguous plain markdown, it uses @@cell / @@output sentinels with inline metadata. Less wasted context, unambiguous structure, and it degrades gracefully on truncation. The payoff is composability. "Add a summary section and run it" becomes one shell pipeline instead of six agent tool calls. And nb search notebook.ipynb --with-errors returns only the failing cells, so the agent skips the cells that worked. Claude Code tie-in: it ships as an agent skill. npx skills install jupyter-ai-contrib/nb-cli and your agent can drive notebooks via nb. Out of jupyter-ai-contrib, which aims to become an official Jupyter AI subproject. Still early (crates.io is at v0.0.5), so kick the tires before anything load-bearing. See also marimo-pair. Calvin #4: Hindsight Agent Memory That Learns AI agents forget everything between sessions — Hindsight gives them persistent memory that learns over time Simple three-method API: retain(), recall(), reflect() — store, retrieve, and reason over memories TEMPR retrieval runs semantic, keyword, graph, and temporal search in parallel for accurate results Automatically consolidates related facts into durable observations instead of piling up duplicates pip install hindsight-all runs the entire server in-process; integrates with LangChain, LlamaIndex, Pydantic AI, CrewAI, and more Extras Calvin: Clanker: A Word For The Machine **Ponytail — You know him. Long ponytail. Oval glasses. Has been at the company longer than the version control** **Klangk: Multi-User AI Sandboxing, Collaboration and Coding Platform** Cursor announces Origin performative-ui to quick start your new idea Michael: Astral Joins OpenAI: The Interview SpaceX to acquire Cursor And OpenAI renews Open Source support Portuguese subtitles are now available for Talk Python courses DSF is hiring including Six Feet Up support Joke: Oh Babe…
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
The browser blind spot: Why your security tool may not be blocking what you think it is [Guest Diary] https://isc.sans.edu/diary/The%20browser%20blind%20spot%3A%20Why%20your%20security%20tool%20may%20not%20be%20blocking%20what%20you%20think%20it%20is%20%5BGuest%20Diary%5D/33084 Android 17 Security Patches https://source.android.com/docs/security/bulletin/android-17 Oracle Critical Security Patch Update Advisory - June 2026 https://www.oracle.com/security-alerts/cspujun2026.html Multiple JetBrains IDE plugins caught stealing AI keys https://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Talk Python To Me - Python conversations for passionate developers
OpenAI just acquired Astral, the company behind uv, Ruff, and ty. And if your first thought was "wait, is uv toast?", you are not alone. But here's the twist Charlie Marsh shared with me: he thinks they may ship more open source at OpenAI than they ever did at Astral. On this episode, we get into the acquisition, the mixed feelings, the future of your favorite Python tools, and what it's like to build right at the center of the AI universe. Episode sponsors Sentry Error Monitoring, Code talkpython26 Talk Python Courses Links from the show Guest Charlie Marsh: github.com The announcement: astral.sh OpenAI: openai.com uv: github.com ty: github.com Ruff: github.com pyx: astral.sh Codex team: openai.com Anthropic did something similar by acquiring Bun: www.anthropic.com Daily Stars Explorer: emanuelef.github.io Agentic AI Programming for Python: training.talkpython.fm Python Web Security: OWASP Top 10 with Agentic AI: training.talkpython.fm Episode #552 deep-dive: talkpython.fm/552 Episode transcripts: talkpython.fm Theme Song: Developer Rap
Topics covered in this episode: pi + superpowers Terminal: Warp.dev + OhMyZSH {Blink,kitty} + mosh + tmux Claude code MacWhisper or Handy Tailscale Extras Joke Watch on YouTube About the show Sponsored by us! Support our work through: Our courses at Talk Python Training Six Feet Up is hosting a LinkedIn Live Connect with the hosts Michael: @mkennedy@fosstodon.org / @mkennedy.codes (bsky) Calvin: @calvinhp@sixfeetup.social / @calvinhp.com (bsky) Show: @pythonbytes@fosstodon.org / @pythonbytes.fm (bsky) Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Calvin #1: pi + superpowers terminal-first, open-source coding agent Session management is a first-class citizen Extension model is what makes pi special — it's aggressively composable Superpowers brings a structured software development methodology as loadable skills Steps back and asks you what you're really trying to do “hand you the keys to the car” mode vs guardrails might not be for everyone Michael #2: Terminal: Warp.dev + OhMyZSH If you're using the base terminal with default settings, you have so much head-room for improvement. I've been using Warp.dev since Elvis talked me into it. ;) Remarkable terminal but the AI side of things is a bit junky, can be turned off OhMyZSH gives better autocomplete e.g. git branch [HTML_REMOVED] lists all branches in the local repo! Commandbookapp.com is excellent to keep the terminal focused on terminal things and more server commands and other automation in Command Book. Calvin #3: {Blink,kitty} + mosh + tmux Kitty Terminal — GPU-accelerated terminal emulator for macOS, Linux, and Windows with support for graphics, ligatures, and a powerful tiling layout system built right in. Blink Shell — The go-to terminal for iPad/iPhone power users; full SSH and Mosh client with a gorgeous interface built specifically for mobile professional workflows. Mosh — Mobile Shell replaces SSH for remote connections, surviving network switches, sleep cycles, and flaky Wi-Fi with zero dropped sessions — essential for staying connected to long-running agentic jobs. tmux — Terminal multiplexer that keeps sessions alive on your Linux server indefinitely; detach from a Mosh session on your Mac, reconnect from your iPad, and your agent is right where you left it. The combo — Kitty or Blink + Mosh + tmux creates a "persistent remote brain" pattern: your beefy Linux homelab runs the compute-heavy agent sessions 24/7, and any device becomes a thin client to drop in and out at will. Michael #4: Claude code I prefer the IDE experience, the new PyCharm + Claude integration is really good. VS Code too. Why IDE? Because we should still be present with our code and managing context is much easier. Use the best/latest models on high thinking. “Speed” is not your friend, it's just shortcuts. Create skills and agents and use them. Curate your own rules (e.g. Talk Python's Claude.md) Works well on non-coding things. Just create a folder, put a ton of files in there and it's like NotebookLM + Chat + more. Calvin #5: MacWhisper or Handy Transcribes your speech using your choice of Whisper or Parakeet models. All transcription is done on your device, no data leaves your machine. Automatic Speaker Recognition with local models. Handy is more basic, but open source and runs on all platforms. Michael #6: Tailscale No need to open ports at all, Tailscale makes machines inside the same network accessible to each other Works great for laptops, desktops, etc. But also available for servers. Though I still use cloud firewalls for servers. How I use it: My dev database server, preloaded with QA data, is always running on my home mac mini m4 pro. All my apps look for that server before looking locally and tailscale makes them always accessible to each other My local LLMs expose OpenAI API compatible APIs. Tailscale makes these accessible even while traveling or at a coffee shop. Use my mini as an exit node. All traffic is routed outbound from my local fiber network. Great to restricted IPs like accessing my servers without caring about the local IP. Screen share back to my home machines even while traveling. Listen to the Talk Python episode with Alex for a deeper conversation. Extras Calvin: Telescopo great Mac Markdown viewer/editor. Michael: One more: Typora markdown editor. Created formal documentation for many of my open source packages using Great Docs. Via Mark Little: Statement on the US government directive to suspend access to Fable 5 and Mythos 5 Joke: No second date
Talk Python To Me - Python conversations for passionate developers
If you've ever been to PyCon, you know one of the best parts of the expo hall is Startup Row, a stretch of booths where early-stage companies built on Python show off what they're creating. But only attendees get to walk that lane, so let's bring it to everyone. In this episode, we stroll down Startup Row together. We kick things off with the organizers, Jason and Shay, who share the program's origin story going back to Paul Graham and the PSF, plus some surprising stats, including two unicorns among the alumni. Then we meet five startups: Tetrix, bringing AI to institutional investing in private markets. Arcjet, security that lives inside your app as an SDK. Phemeral.dev, serverless hosting built for Python web apps. CapiscIO, an identity and authority layer for AI agents. And Pixeltable, a multimodal database from Marcel Kornacker, co-creator of Apache Parquet. See if you can spot the theme running through them all. Let's go for a walk. Episode sponsors AgentField AI Talk Python Courses Links from the show Guests Naunidh Bhalla: linkedin.com Grant Gittes: linkedin.com Marcel Kornacker: linkedin.com Beon de Nood: linkedin.com Chinmaya Joshi: linkedin.com David Mytton: linkedin.com Shea Tate-Di Donna: linkedin.com Jason Rowley: linkedin.com Azul Garza: github.com Renée Rosillo: linkedin.com Tetrix: tetrix.co Tetrix Jobs: tetrix.co Arcjet: arcjet.com Pixeltable: pixeltable.com Phemeral.dev: phemeral.dev CapiscIO: capisc.io Episode #551 deep-dive: talkpython.fm/551 Episode transcripts: talkpython.fm Theme Song: Developer Rap