Skip to content
Melo Podcasts Home
CategoriesLanguagesFollowing

Episode notes

Topics include , Codeberg’s AI-code ban tests its role as a GitHub alternative, , , , and.

Transcript

Read the transcript · about 7,310 words, follows along as you listen

Michael Kennedy:Hello and welcome to Python Bytes, where we deliver Python news and headlines directly to earbuds. This is episode 492, recorded August 18th, 2026. I'm Michael Kennedy. And I'm Calvin Hendryx-Parker. This episode is brought to you by Logfire. So thank you to Logfire from Pydantic. Check them out at pythonbytes.fm/logfire. It's about observability for your AI apps and beyond. Tell you more about them later. Connect with us on social, links on the website.

Michael Kennedy:Be part of the live show. Check it out on the website, pythonbytes.fm. It's live. And we have a really cool newsletter that we send out mostly every week with all sorts of extras. So you can sign up there as well. Just visit the website, click the newsletter, do the thing. We'll keep it private and not abuse it. Speaking of abuse.

Calvin Hendryx-Parker:We're good people. You're good people. Let's make sure we keep people safe, Michael.

Michael Kennedy:Exactly. Sometimes you can have nice things on the internet. That's true.

Calvin Hendryx-Parker:And well, the good thing is that with the solar eclipse in Europe last week, a new release came out of some security updates for Python 3.12, 3.11, and 3.10. The key bit here, well, there's a lot of key bits, which is there's lots of security updates that have happened. They're pretty important if you're doing certain kinds of activities. So for example, if you are using tar files to, if you're extracting tar files with any of these versions of Python, you are going to want to update ASAP because this basically fixed a path traversal bypass of the data filter. So a symlink escape that could bypass bits and pieces here and get people access to places they're not supposed to be.

Calvin Hendryx-Parker:Kind of important. Now the important bit here is that this is only a source release, is a source release only. If you want to upgrade to these versions of Python, the 3.12.14, 3.11.16, and 3.10.21, you are going to have to download the source tarball or patch your existing build process to get these released into your production environments. But if you are on these versions, you're going to want to get those things patched. I mean, it's nice that these are in security only

Michael Kennedy:fixed mode. There's not a binary version. I have to use this. There is not a binary version of

Calvin Hendryx-Parker:these been released. These are in security fix only mode. I mean, hopefully you're getting into Python 3.13 and 3.14 as they are the current releases. It's nice that the community supports these versions that far back. I don't know when 3.10 was released, but it was quite a while ago. And you've got to be able to stay on top of these. This is in your hands now. This is kind of more of a do-it-yourself, but at least the fixes are available. So tar file is a big one. There are four fresh CVEs that are being covered by these fixes here. One of them is for the sourceless file loader. The other one is the cookies morsel, which there's basically a couple of fixes there on that. And then the ftp lib ftp cp. So there's also a bunch of denial of service type fixes, some cleanups in HTML parser, config parser, Unicode data normalize, element tree XPath bits.

Calvin Hendryx-Parker:There's some header injection fixes. Again, just lots of cleanups around the edges. Michael, have you ever used the web browser module from the standard library?

Michael Kennedy:I'm learning now there's a web browser module.

Calvin Hendryx-Parker:There is a web browser module. It allows you to pop a web browser. That's pretty handy. I've used it for a couple like little demo-y type things, but there was a allowed control character in there that would have caused an action prefix bypass. So if folks were sneaky and knew those things existed, they could basically jump in and bypass some of these security controls. The HTTP client also now caps chunked trailer lines and the 100 responses to 100 each.

Calvin Hendryx-Parker:So a hostile server could previously hang a client, even if you had a socket timeout in place. So lots of memory safety stuff, lots of other little cleanups. Again, it's a pretty sweeping set of security fixes. And they chose to release it now because it's as good a time as any. There's no set schedule for these specific releases on these older versions of Python. Excuse me. But it's good we've got people watching our backs and making sure we stay secure out there.

Calvin Hendryx-Parker:Like I say, you can go look at the release notes. There's a ton of fixes in here. It's a really long set of releases and fixes that went into us. Thanks to all the Python core devs and volunteers and people submitting patches. I'm sure some of this stuff probably came out of the new models that are able to detect these kinds of pieces. But obviously, humans are putting the pieces into place. So go be safe out there, Michael. And upgrade your Pythons.

Calvin Hendryx-Parker:This is always something I'm worried about. Yeah, I mean. Upgrade your Python, please.

Michael Kennedy:Here's also one of those reasons why I kind of want to stay on top.

Calvin Hendryx-Parker:Yeah.

Michael Kennedy:Of having a fairly new version. And I'll be like, oh, we're not going to touch it. And hey, it's 3.8, but it works. It's like, yeah, but when this kind of jump, this stuff comes out of the blue, you're all of a sudden scrambling to get your app to run rather than just a point release.

Calvin Hendryx-Parker:Yeah. It's hard to argue for the old stance of like, well, just because it works, it should just stay in production. Or even if it's behind a firewall or behind some kind of level of protections, we've seen that these models can now chain together multiple vulnerabilities to get access to spaces they weren't supposed to get access to. All that's required at this point is setting good goals for the agentic AI tools. And they can get around a lot of things if they're given unfettered access, even not unfettered access, even if they're sandboxed in, they could still do this.

Calvin Hendryx-Parker:So keep up to date. Again, this is a reason for staying on the latest released version of Python. But the community does support back patches. You just got to go build them yourself.

Michael Kennedy:I'll have more on that later on the building. Maybe. So yes, but maybe.

Calvin Hendryx-Parker:Maybe.

Michael Kennedy:What do you got? My favorite way to install Python is uv Python. No kidding. Install, right? And a quick, I just upgraded it. You got to upgrade to get the latest. It's just kind of odd. It doesn't.

Calvin Hendryx-Parker:Oh, they've got someone's got built.

Michael Kennedy:It does. 3.11.16. And 3.12.14. That looks like they've packaged it into Python build standalone.

Calvin Hendryx-Parker:That's nice.

Michael Kennedy:Well, it's good to see the astral folks have got our back. Yes, obviously. Like that's a theme, right?

Calvin Hendryx-Parker:It's definitely a theme. Well, there you go. Go. Well, if you're on this older version of Python, you might need to just go upgrade to uv at this point and save yourself some headache.

Michael Kennedy:Yeah. Yeah, absolutely. You could technically just use uv to manage your Python and still, I don't know.

Calvin Hendryx-Parker:Yeah, you don't need it. You don't necessarily, yeah, you can do the rest of the way you're currently doing it. Right. But if you're going to jump in there, you might as well modernize and fix. You're already in there. You're already doing it.

Michael Kennedy:You're already in there. Okay. Speaking of, you gave a quick shout out to give an AI agent some kind of go find bugs. And I 100% agree. You and I both likened to this to running a lender for the first time. And you're like, there's a thousand errors. Oh my God, it's so much. Right, so stay on top of these things. But these tools are causing some places a ripple, other places a tidal wave. And Codeberg is one of those places that, I don't know, like, I'm not sure how to feel about Codeberg.

Michael Kennedy:I, in principle, like it, but I think people want Codeberg to be more than Codeberg wants to be, let's say that. What the heck is Codeberg?

Calvin Hendryx-Parker:Codeberg isn't What is Codeberg?

Michael Kennedy:It is a GitHub alternative, let's say.

Calvin Hendryx-Parker:Okay.

Michael Kennedy:Evolved out of previous attempts to create a GitHub alternative. It's a nonprofit community-led effort with a democratic process that provides services to free and open source projects, such as Git hosting using 4Gio, Pages, CI/CD, and so on. So it's already got this restriction like, hey, it's only for free and open source stuff. It's not for just general paid software, private repos, and so on, right? Fine. So that's kind of its mission, and that's what it is.

Michael Kennedy:But a lot of people are looking at GitHub going, I mean, just yesterday GitHub was down. I'm like, oh, man, I guess I'll try this PR again in a half hour because it couldn't load the PR stuff, and then I just got the unicorn, which kind of feels like it's supposed to be amazing, but it's a bad unicorn. Should have like a leather jacket and be smoking or something. I don't know.

Calvin Hendryx-Parker:I know, kind of the fail whale of GitHub.

Michael Kennedy:Yes, exactly. And there might be people out there that don't know the fail whale, but oh my gosh, that Twitter went down bad in the beginning. Yeah, so it's like the fail wheel. Early days. But right now, I just pulled this up into the top of the Codeberg page. Time recording.

Calvin Hendryx-Parker:Yeah, the number two is interesting.

Michael Kennedy:There's just like, there's stuff we don't want here. And we don't approve of it, and it needs to get the heck out. Even if it is free and open source, it still needs to get the heck out, okay? So I feel like this was just, there's stuff we don't like, let's get it out. And the number two you pointed out and laughed at is like cryptocurrency projects are no longer allowed. And like, you know, I'm fine with that. Like, whatever.

Calvin Hendryx-Parker:Okay, okay.

Michael Kennedy:If that's your mission to just not have that kind of stuff, I'm here for it. Like cryptocurrency is weird. I'm not 100% against it, but it's just

Calvin Hendryx-Parker:I'm not either. So that's why I thought it was kind of weird. There's definitely some opinions here that had a thought process going on behind them that we're not seeing the full story. I guess we can go view the full change, but

Michael Kennedy:Yeah, but this first one is quite weird. It says LLM generated content is being restricted. More specifically, if you have a project that they somehow decide they believe it is majority LLM, banned. Even if it has been here for a long time, it has gotten a lot of attention and a lot of maybe even wrote it by hand to start. But then you do some mega refactoring that touches every file. Banned. So you may like that. You may not. It's extreme. It seems a little extreme given that we just recently covered Linus Torvalds saying like, look, using AI to review our stuff is a tool.

Michael Kennedy:It feels a bit myopic to me. And fine, like I said, this is their project. They can do it, but people have thoughts. People have a lot of thoughts. Wait, Armin has a thought? Could you imagine? Armin Roniker has a thought. And he wrote, and the reason a lot of people have thoughts is they were like, I would just love a GitHub alternative, like for different reasons. Some people are just like, I don't like the way GitHub works. It's been down a lot.

Michael Kennedy:Other people are like, I want a European company, not just an American company to kind of be a first-class player in this space. Right. And whatever, like all of those people are like, but Codeberg is now broken. So that's out. And that was my hope, right? Like Obi-Wan, you're my only hope. Oh, Obi-Wan doesn't like all of them content. Well, I guess he's out. Anyway, so Armin wrote an article called Codeberg Divides. And so they changed their terms of service, as I said.

Michael Kennedy:They're entirely within the rights to do this. It's a democratic process. But democracies don't inherently make good decisions. That's what I'm saying, right? So GitHub's never been democratic, and there's plenty not to like. But as a core piece of infrastructure, it's been reliable, right? So I don't know. How do you even enforce this majority? Like I said, if I have a project, let's say a web app that uses some CSS front end, and I ask AI to change the CSS front end around, even though I wrote all the code, all the back end, in the diff perspective, chances are it's going to overwhelm the back end amount of code if I have to have it rewrite every bit of HTML because it's grid versus flex box versus whatever.

Calvin Hendryx-Parker:This is groundwork stuff that the AIs can be directed very easily to take care of for us as humans.

Michael Kennedy:Yeah, and so here's sort of the thoughts. It's a real shame that open source and free software communities are splitting this deeply over LLM and agents. We all already acknowledge copyright issues, energy use, those kinds of things. But it's also just how software is being made, right? And people need to, projects are going to need to figure out how to coexist. And yeah, if you want GitHub to face true competition, This is not it.

Calvin Hendryx-Parker:Yeah, this is not going to work. Michael, I got an idea. Okay. We're going to do a blockchain project to host a GitHub alternative that is a distributed autonomous organization. And it's going to have like smart contracts and rules. We're going completely the other direction.

Michael Kennedy:You're making my ears hurt just a little bit with that word. So what about this? What if we go back a little further and we can like do a sweet arc? Like what if we do like a BitTorrent hosted, smart contract backed?

Calvin Hendryx-Parker:Even more, like the layers go deep. So, you know, the decentralization aspect of BitTorrent totally makes sense here. I think we could make this go.

Michael Kennedy:No, we could totally make it go. All right, so that was Armand's thought. I wish this was more forward looking in a place that we could depend on rather than a place that divides and just kicks a bunch of people up. Now, one of the reasons I'm sure they did this is, well, these AI things use 20 times as much resources.

Calvin Hendryx-Parker:Yeah.

Michael Kennedy:Okay. So I just searched for the terms to see kind of Codeberg terms, and I came up with this website. The domain is amazing, but it says... Oh, wow. I asked literally just for the terms of service of Codeberg, and the first thing that comes up is, I regret migrating to Codeberg. And this is actually a really interesting and well-thought-out article. So this person just recently left GitHub and moved all their projects over here because they're like, ah, GitHub is kind of getting clunky, and I have just pure open source and so on.

Michael Kennedy:So GitHub looked like a viable alternative, which is like this is the main spine running through this conversation. So unfortunately, the latest update to its terms of service seemed to mark the first step in changing one part I moved there for, namely freedom, is now gone. I can't work on it. And one of the interesting things about this term, I'll move on from this section in just a second. But from their terms, is the content that harms the reputation of CodeBerg, which is like, we don't have a great reason for it.

Michael Kennedy:And one of the criteria they use is it has to have a community behind it in order for it to be legit. And LLMs and AI don't make community, right? It seems like from the blog post, it seems like many vibe coders don't realize that they don't actually have a community around them. And I think that that cuts at two things. One, casting all of this stuff as vibe coders and just junk users who don't really know what they're doing. That's already kind of a...

Calvin Hendryx-Parker:There's a valid practice of agentic engineering in producing software.

Michael Kennedy:Yes. And this seems to lump it all in with like, oh, it's a bunch of these idiots that don't know what they're doing and we want them off our community. Sounds like a bunch of people who were against the stuff two years ago and have never tried it. don't realize the effect it has. But so just wrapping this up, this person says, look, I have a bunch of solo developer open source projects. And my community is people who just ask for features or ask me to change something.

Michael Kennedy:They're just people who want something from the software. They're not really a community with rich discussions, right? And so

Calvin Hendryx-Parker:I agree with this person's take on, like, it's a bunch of little tools that are my tools and I need a good place to host them. And I want to share them with my little community.

Michael Kennedy:Yeah, like I've been publishing silly little tool for decades. And that was from even the SourceForge days, right?

Calvin Hendryx-Parker:This is the essence of like open source, the cathedral and the bazaar, like that whole bit. Exactly.

Michael Kennedy:And so one of the reasons CodeBurg is blocking LLMs is because they think there can't be a community and therefore it's a fake project. This guy's like, I got a bunch of projects that don't have community, but they're important to me. And I think that's actually the majority. This results in censorship for me. But the same thing is, what if you just charged for the ones or had a very high or very strong rate limit for interactions? And if your AI does too much to burden our infrastructure, well, then, you know, maybe you cover that or you move them over to a portion of infrastructure that's even slower.

Michael Kennedy:Right. I don't know. But there's a whole lot of concrete ideas from this. I regret moving to Kudberg.

Calvin Hendryx-Parker:Anyway. It's amazing that was the first post, like first result for a valid search for their terms of service. I know, that's a strong own goal right there. Speaks volumes right there. Well, the others are going to emerge. Obviously, the fact that we still live in an open world with a fairly open internet, people can build their distributed blockchain DAO version of GitHub if they want.

Michael Kennedy:Well, I'm looking forward to setting up. We should build on Codeberg. Oh my gosh. Okay. All right, sorry. That was a bit of a detour. A fun detour. But let me tell you about our sponsor, actually.

Calvin Hendryx-Parker:You should. I think this is important.

Michael Kennedy:Yeah, because there's some really cool stuff that Logfire from Pydantic is doing. And this is a bit of an alternative worldview, one that I definitely agree with. But Logfire is about monitoring and observing and understanding what your AI agents and other web apps like FastAPI and Postgres and so on are up to. So it's 2 a.m. Your AI agent has failed. Why? Was it the model, a tool called the database? Most observability tools can't tell you because they only see part of your stack, like your web stack or something.

Michael Kennedy:Pydantic Logfire sees all of it. One trace across your agents, LLMs, APIs, and database. Down to the infrastructure, services, Kubernetes, and hosts. It's built on open telemetry with SDKs for Python, TypeScript, and Rust. And it works with any OTEL-compatible language. Every prompt, token count, cost right next to your vector searches and API calls. You query everything with Postgres-compatible SQL. And you give that to your coding agent through the Logfire MCP.

Michael Kennedy:So stop guessing, read the trace, Identic Logfire. AI is still just engineering, as we said. So visit pythonbytes.fm/Logfire today and sign up. You'll get 10 million records for free every month, no credit card expired. And this is a pretty cool thing as well. I need to add Logfire to my app so that I get this cool feature. How do you do it? They have a button that'll copy some markdown text to your clipboard and you click it and it says onboard your coding agent.

Michael Kennedy:So it just gives you instructions you can hand to Claude or Codex specifically what it needs to do to integrate your app with Logfire. So I think that's super cool. So thank you to Pydantic and Logfire for supporting the show.

Calvin Hendryx-Parker:Actually, I love the idea of the observability of grabbing the prompts and the costs and the token usage. more folks are going to be heading down this route because it's been very hard to analyze the return on investment of using these tools. And as the costs potentially rise and subscriptions maybe shift and go away, you're going to want to know this kind of data to make good decisions. We're doing this right now at Six Feet Up. Are you? Awesome.

Calvin Hendryx-Parker:Yeah, we're having these kinds of discussions, I should say. And I could probably use a tool like this.

Michael Kennedy:Well, I don't buy Steadafim slash Longfire.

Calvin Hendryx-Parker:Oh, you know, there's a code there. That's a good one for us.

Michael Kennedy:Yeah, fantastic. All right. Yeah, it's a super cool platform. And like I said, right here, just onboard with your code agent, click that, and then paste it. What's really interesting is that the instructions say things like, your user may have just clicked this and not actually read it yet. So please work them through this. Those are some good people.

Calvin Hendryx-Parker:They were doing the good work right there.

Michael Kennedy:Yeah, same thing, a call in a team knows what they're doing over there. I love it. So does Brett. Brett Cannon knows a few things as well. Brett Cannon does know a few things.

Calvin Hendryx-Parker:Actually, this is important. And again, I feel like the last few episodes, I've been on a bit of a security run with things. And this is continuing it. And he's got some great ideas. When he was writing his nomination post for the 2026 Python Packaging Council nomination or elections, part of his pitch why he should be there is we need a secure supply chain for the Python ecosystems around building reproducible builds. And so right now, we don't have technically reproducible builds on PyPI, but they're not far away.

Calvin Hendryx-Parker:There's like he identified three gaps in the current process to get us to a point where we have basically the good design goal for him is zero friction. Can producers upload something to PyPI? They shouldn't have to do anything. And all the work lands on the build backends and installers to track and trace and allow you to know where your software came from that you're installing. We all are aware of the LiteLLM exploit that happened back in March. And part of that was because of a supply chain injections into the build process. The other one here is like he mentioned SolarWinds, that SolarWinds attack from a few years back. Again, a supply chain injection during the build process.

Calvin Hendryx-Parker:So gap number one is nothing right now records the source code, where the source code distribution came from so if you add in a json descriptor it can capture you know when you install it where it's from what get repo is the canonical source of truth for that code and it's something that'd be very important for you to know if you're going to go back through and do an audit of the tools

Michael Kennedy:or the code and dependencies that you have into your build process interesting so you might be able to have a another tier of trust than just it's on pypi but yeah yeah here's how it's built

Calvin Hendryx-Parker:Yeah, exactly. And if you combine those with the PyPI two-factor and security measures that they've been putting in place, this gives you a little more comfort with where something came from. Gap number two is during the build, in the build tools and during the build process, having a software bill of materials. So referred to as an SBOM. We can do this with PEP 770 has a convention for this. Software distributions can't because there are tarball plus like some package info stuff. So if you have a wheel, you can basically enable this already. So the first two things, very little friction. A file that describes where your GitHub repository is. The second one is using wheels and PEP 770 to have software build materials in there. So either don't use SDIS or move to the SDIS V2 support for this. And then basically the mechanisms already exist for tying this all together in the pyproject.toml.

Calvin Hendryx-Parker:There's a build system section. If it has a defined entry point, so then backends can record their own environment and you can reinstall and rerun the build. So the goal being, again, if I build the software today and if I build the software six months from now or 18 months from now, I should get the exact same binary each time and there should be no worry or at least a way to audit and trace back what happens. So now trusted third parties can report successful reproductions back to PyPI, which can display like an independently reproduced by some authority surfaced in the index. So installers can also prefer reproduced files.

Calvin Hendryx-Parker:So PyPI would have to have a couple of changes to support surfacing this data and making decisions based on that data. This is not a nice to have. This is definitely, it's not a requirement. This is basically like you need to have this as part of your build process or else you're not considered a top level or a first class citizen in PyPI because it shouldn't be hard to do.

Michael Kennedy:One of the things about the reproducibility that you hinched on right there at the end, I think is cool. I look at, say, the hash or whatever of the binary that I got. And then if I want to rebuild that myself, I should get the same hash if I follow the steps or something like that, right? Which is super cool. Yeah. But so many things can be very variable. I mean,

Calvin Hendryx-Parker:the GCC compiler on your system, the minor versions of Python, the architecture, whether it was ARM or x86. There's a whole bunch of variables that go on in there. It'd be nice to be able to get those from a trusted source. And PyPI is obviously doing great work at making sure we get safe wheels and distributions of software.

Michael Kennedy:Yeah, definitely some great folks, including Seth and Mike,

Calvin Hendryx-Parker:over there working on this. Well, and thanks to Seth Larson for listening to his idea and helping him check over this blog post. So the right folks are involved all around. That Python Packaging Council nomination, I think the voting is happening soon. I didn't actually note down when it is, but I can't imagine why we wouldn't want Brett to be on that panel of people. Exactly. He's got the right ideas. I'm all for this. Just because to keep the world safe, we need to have these kinds of table stick ideas built into our infrastructure of Python

Michael Kennedy:and the build systems. Yeah, and Brett's been working in packaging and package adjacent stuff for a long time recently.

Calvin Hendryx-Parker:Yeah, so go enable these features. You'll start participating in the ecosystem and then eventually PyPI will support it and you'll be able to know that the software you're getting has come from verified sources. Maybe that's an extreme, not verified sources, but at least the build can be reproduced. Yeah. Verifiable. Verifiable, not verified. Subtle difference.

Michael Kennedy:yeah okay so now moving moving on we have a extra extra extra here all about it a whole section of extras well this is when there are so many extras that i'm like this can no longer be extra it must be hoisted up into a top level topic all right and i don't know i've got a sidebar full

Calvin Hendryx-Parker:of them so let's see i got questions about one of these here for sure all right let's go well

Michael Kennedy:You talked about the security fixes of like 3.11 and so on, 3.11.6 and beyond. We also got a new...

Calvin Hendryx-Parker:They are. Some of them have landed in 3.14.

Michael Kennedy:Yeah. So 3.14.7 is out. And sometimes these are like, we've changed some minor setting or whatever. This is a proper release of Python. And I know it's mid-August and in a month and a half, we're going to have 3.15, which is very exciting. But there's a couple interesting takeaways here. Plus, you should just install this. So under security, it doesn't fit on my screen, the number of single sentence things fixed. So that alone tells you maybe we should pay attention.

Michael Kennedy:So like here, for example, the one you talked about, GitHub 15987, the tarball extract. And then there's another one somewhere in here, like this is the workaround of that fix, also fixed. But there's some denial of service-ish things like element tree find all from XML parsing or even web page parsing has quadratic behavior if you give it certain types of inputs. And that means you could create like a element tree find all bomb type of thing. So there's a bunch of this complexity stuff here.

Michael Kennedy:But this is also a proper release. So I'm going to scroll at a high rate the entire time that I'm talking. And it is way still going on. This is all core Python internals, not even the standard library. Ooh, okay. And then, now maybe that was a standard library as well, but also build and then Windows and Mac. I mean, there are pages and pages and pages of changes here. And if you go up one, like I said, there's an interesting theme. So if you look at free, free threaded.

Michael Kennedy:Yep. Oh, wow. This is one of the, I mean, it is lighting up the find section. Yeah, the little scroll bar highlight that shows where the find lands. There are so many race conditions that are getting fixed. This is just something Python has not really had to deal with. And I don't know how I feel about this, Calvin. I'm very excited about free-threaded, but there's this many fixes now.

Calvin Hendryx-Parker:They should have skipped the.7 and made it.15, like 3.14,.15. I know.

Michael Kennedy:It's the lead-in to 3.15 or whatever, right?

Calvin Hendryx-Parker:Yeah.

Michael Kennedy:Yeah, but in the core built-ins, there's just tons of, like, Fix the data race condition and free-threaded build of gc.gen count. Fix the potential deadlock on intern from string and other functions on the free-threaded build. And so if you're doing stuff with free-threaded, you definitely want to go through this.

Calvin Hendryx-Parker:I hope some folks who've been posting blog posts around free-threading go redo their benchmarks against this release to see how that has changed. Yeah, 100%.

Michael Kennedy:Okay, well, that was one of them. That's a lot. I know. That was just one of the things. Remember you gave me homework last time? I'm like, oh, I just, I literally just added the MCP server for Python bytes. And you said, oh, Michael, that'll hold that protocol is out of date. You got it. There's a new one. I'm like, no. Well, I upgraded it. So Python bytes, it's MCP server, which only existed last week. Now uses the, let me see if I get this from memory.

Michael Kennedy:2026.0728 version two protocol, which is more stateless. So it's backwards compatible with the old ones, and it now adopts the new one. So that's pretty cool. And also for Talk Python, they were basically a similar update there.

Calvin Hendryx-Parker:So how long did that take you? I mean, were you able to just point the clankers at it and say go?

Michael Kennedy:The clankers grinded for a while to probably an hour. Yeah, probably took an hour. It was a pretty significant amount of turn. But no worries, I got it done. Nice. You know, if I had run on Fast MCP, which is now just MCP server, I believe, is the name of the project now, probably would have been better, even though there were breaking changes. But this is integral. It's just a part of the Quart Flask app that are these websites. And so it had a little more low-level stuff. But at the same time, it wasn't. I mean, my active time was probably 15 minutes. But I had to verify and check. And so, oh, let me go over

Calvin Hendryx-Parker:to Claude and ask it if it still knows how to talk to it. Think of the scale you can handle now. I mean, people can just hammer your MCP service now.

Michael Kennedy:I know. It's so stateless. They can just ask it questions all day long. All day long. And in principle, I don't really mind. I mean, I'm not inviting to not to do this amount of service because I do get that sometimes and it's not fun. But it is all the database backed indexed queries. So it is like sub millisecond usually when you ask questions like this. So it's pretty cool. All right. Yeah. Remember we talked about AgentsView. I believe you brought this up.

Michael Kennedy:And I'm like, all right, so crazy that on my M5 Pro MacBook Pro, I see some portion of my work and projects reported. And then I go to my mini and I see some other portion, the complement of my work reported. And then I'm like, well, I finally set up Postgres Sync, which is really cool. So if you set up this Postgres Sync thing, you just get a web page that you can host. I'm hosting it on Tailscale, super private behind all my stuff.

Calvin Hendryx-Parker:Nice.

Michael Kennedy:And then that gives you a unified view. There's just a little daemon sort of thing that runs on each machine that just, you know, normally it's running on SQLite. It just looks at SQLite, goes, what's changed? And it just pushes those changes and merges them on a Postgres thing that's running in Docker on my mini behind Tailscale.

Calvin Hendryx-Parker:I have a question for you on that because we're using agents view a little more to help with that analysis and looking at our users and models. The Postgres sync, could you have multiple users push into it? Because that's exactly what I think I want to do.

Michael Kennedy:The one thing to be a little careful of, and I kind of would like to just say, could we just not put this data here at all, is it syncs the actual chat conversation, the chat log.

Calvin Hendryx-Parker:The sessions. Because you're getting the full fidelity of the agent's view, but in a centralized spot.

Michael Kennedy:Yeah, I mean, it is cool that you can go and do things like hit command K and then do vector and semantic search across your work. But at the same time, the more people send in stuff in, it's plausible that you could write another script that just deletes that data.

Calvin Hendryx-Parker:Yeah.

Michael Kennedy:After, right, like just goes and just zeroes it out because there's actually zero words in this, even though the token count was recorded and so on. I haven't tried that, but possible.

Calvin Hendryx-Parker:I like the fact you can do like, I guess it even mentions their team dashboard.

Michael Kennedy:Yeah, exactly. And I am a team of one for this, but I'm still working in two places and I need it because otherwise it doesn't work.

Calvin Hendryx-Parker:Yeah, yep. I've got the same. I'm going to set that up.

Michael Kennedy:All right. Let's carry on this order. Like I said, this is why this had to be promoted. Brian Okken. Hey, Brian. He had talked over last year on the show about working on Lean TDD, TDD Without the Waste, and sort of redoing that. And he has just released the Audible version. How cool is this?

Calvin Hendryx-Parker:I like that. And it's him narrating it, too. So if you missed Brian's voice from this podcast, you can go over and listen to him read the

Michael Kennedy:whole book to you. It's pretty wild. Like, this is audible. And it's Brian. Yeah, it is Brian. And he did a really good job. It sounds, you know, professional and great. And I very much like it. And I know that when he was working on this book, one of his goals was to not make it too overburdened with code samples such that it could be an audio book that is actually worth listening to. So link into that and check that out. Two more things. These have to do with Talk Python courses.

Michael Kennedy:So I talked to someone recently who wanted to take a course from Talk Python. And they said, well, this is really great. And this is exactly what I want to take. But it turns out our company, our organization, has some subscription to some other junkier Python training thing that I don't want to use. But they said if they're going to cover it, I have to use their Python thing, not some other random internet thing that who knows what it is, right?

Michael Kennedy:So I thought, well, that's not right. Shouldn't people be able to, you know, if you're a company, get a sense of this is a good thing for your company. So if you work for especially a large company, this falls into that category. I have a program that I set up for you called a free Python training evaluation for teams. So what it is, is for up to 15 people, they get complete free access to one of the, pick one, one of the Talk Python 60 courses. And then you can go through it.

Michael Kennedy:And then that team can report back like, hey, was this worth doing? We maybe bring Talk Python as a vendor into your company. You get a really nice dashboard of how all your students are doing, going through the course. And yeah, so who's redeemed the seats? Are they finished? Like all that kind of stuff. You can download updates and so on. No MCP server though. Not for this. But you could download the CSV and then go to town on it, right? So everybody gets basically free access to the course, mobile apps, all that.

Michael Kennedy:So if you work for a team, if I work for a large company and you have a team there and there's like a lot of restrictions on what training options are available, please reach out to me, Michael at talkpython.fm. Let's set one of these up. It costs you nothing to try it out.

Calvin Hendryx-Parker:Get the name brand training.

Michael Kennedy:Exactly.

Calvin Hendryx-Parker:Not the generic lookalike.

Michael Kennedy:Exactly. Not the generic where you've got to press play every single video and navigate around. Not good. And related to that, I've also set up a government procurement page that gives all... Wow, you're fancy. That's really fancy. It existed before, but it wasn't on a page where people knew that they could get it. So it lists our sam.gov unique ID. So if you work for a government entity, there's all these rules like, oh, it has to be registered with this thing.

Michael Kennedy:And it has to be active. And you have to have a 508 report on your accessibility, et cetera, et cetera. I put all that stuff up here. So if you work for a government and you would like a governmental agency, especially the U.S., please check it out. This all makes it super easy. You probably have to address this kind of stuff some of the time.

Calvin Hendryx-Parker:It looks like you put a lot of work into this, and it shows. Thank you. It's amazing.

Michael Kennedy:Thank you. All right. Well, those were many extras. Those were many, many extras. We are done with the extras.

Calvin Hendryx-Parker:I've got one extra, which is a follow-up to last week's episode around the post-quantum key exchange. And the fine folks over at Astral have made a new release of uv. That's what it was like five days ago. And it now supports and prefers post-quantum key exchange. So they've already got your back. You can opt in to TLS diagnostics, but you're going to get post-quantum key exchange out of the box when you're using uv node. So I thought that was pretty cool.

Michael Kennedy:You know what? Just bookend it with uv. Well done. Astral. Open AI team.

Calvin Hendryx-Parker:so far they're still doing again the good work i appreciate their what they're putting out there for the community and keeping the again staying on top of us like that's really cool that this has we went from one week being announced to next week it's in use and you're getting it

Michael Kennedy:yeah that's super cool and i think i do think they're doing a great job so yeah yep so grab the latest version of uv yeah i love it all right are you ready for a joke let's close it out do it This joke is called beware of dog. Oh. We've all seen the beware.

Calvin Hendryx-Parker:Yeah, Mushu made his appearance last week on the show.

Michael Kennedy:Yes, exactly. Exactly. We've all seen the signs. Do you really, is it just a, be careful, there is a dog here? Or is it like a dangerous, aggressive dog? We don't know. But this one is aggressive. Oh, let me tell you. So there's a big sign that says, warning, beware of dog. He uses Kali Linux. So you're laughing. Tell people what Kali Linux is for those who don't know.

Calvin Hendryx-Parker:For those security folks who are looking to do some pen testing, you may have installed Kali Linux in the past. So it provides some attack tools to let you go after other people's servers, or your own, hopefully.

Michael Kennedy:Yeah, yeah.

Calvin Hendryx-Parker:Not others.

Michael Kennedy:It basically is a distribution that bundles a whole host of things you would separately install if you were a pen tester, hacker sort of thing. And it comes ready to go, right?

Calvin Hendryx-Parker:That needs to be the new logo for Kali Linux, like a big junkyard dog with a big like spiked collar exactly love it terminal with the uh the name and address on it there's no place like one two seven zero zero one exactly tattooed on his arm you know i'm a sucker for dad jokes that i will laugh every time i know these are these are

Michael Kennedy:pretty solid these are pretty solid so beware the dog he's his cali Linux all right well that is it for the show, Calvin, thank you for being here with all of us. Yeah, you bet. And check out Pydantic Logfire at pythonpys.fm slash logfire. Really appreciate them supporting the show. Update your Pythons. Yes. uv, Python, even had an upgrade. So for in-place point release upgrades for uv, you can just, there's a single command now to update all of them.

Michael Kennedy:So just do that.

Calvin Hendryx-Parker:Stay safe out there.

Michael Kennedy:That's right. Bye, y'all.

Calvin Hendryx-Parker:See ya.

Transcript supplied by the publisher with the episode.

Python Bytes

by Michael Kennedy and Calvin Hendryx-Parker · English · Tech & Science

Python Bytes is a weekly podcast hosted by Michael Kennedy and Calvin Hendryx-Parker. The show is a short discussion on the headlines and noteworthy news in the Python, developer, and data science space.

More from Python Bytes

  1. E495 · 8 Sep 2026 · 28 min

    #495 Banned

    Topics include EuroPython 2026 videos are online, The State of Django 2026: Boring is so back, htmx 4.0.0 has been released, and Functionally Zen.

  2. E494 · 1 Sep 2026 · 29 min

    #494 Python Wrapture

    Topics include OpenAI's Python SDK has migrated to HTTPX2, TMOG - Native Task Manager for macOS, Windows, and Linux, wrapture - one wrapper for mocking, tracing, and observability, and linkedin2md.

  3. E493 · 26 Aug 2026 · 41 min

    #493 CalVer and LTS

    Topics include Web UIs for your reverse proxy, , , and Django’s annual releases make every version an LTS.

  4. E491 · 12 Aug 2026 · 42 min

    #491 Feeling Judged

    Topics include , Post-quantum crypto lands in Python, MCP goes stateless — and FastMCP gets renamed, and inshellisense - IDE style command line auto complete.

  5. E490 · 28 Jul 2026 · 37 min

    #490 It’s a vibe coding party

    Topics include Some more things about Django I've been enjoying, Who cleans up after the vibe-coding party, AgentsView, and.

  6. E489 · 21 Jul 2026 · 31 min

    #489 Or JSON?

    Topics include django-orjson, Best Django Redis configuration for speed and size, puts the foot down, and Django Steering Council backs the Triptych Project.

  7. E499 · 6 Oct 2026 · 33 minNew

    #499 So many questions??

    Topics include PEP 824 brings ?? and ??= to Python for None handling, Python 3.15 Python 3.10, asyncio.shield, and Pyxel: the retro game engine for Python.

  8. E498 · 29 Sep 2026 · 33 min

    #498 A Tiny Episode

    Topics include MemTensor / MemoryOS PyPI package hijacked via a malicious build backend, TinyMongo, , and One innocent dict read makes attribute access permanently slower.

  9. E497 · 23 Sep 2026 · 27 min

    #497 Faster than light profiling

    Topics include Tachyon: A sampling profiler ships in Python 3.15's stdlib, Python Workers are now generally available on Cloudflare, Flet 1.0 - build cross-platform apps in Python, and marimo-book: Build static books from marimo notebooks.

  10. E496 · 15 Sep 2026 · 33 min

    #496 A lake house in Seattle

    Topics include Pandas Should Go Extinct, Pydantic-pint puts real-world units in your Pydantic models, How Libraries Run Rust Inside Python (With PyO3), and AWS acquires DuckLabs.

Every episode of Python Bytes →

Take it with you

The Melo app keeps playing with the screen off, works in the car and on your watch, wakes you to your station, and browses the whole catalogue offline. Free, no ads, no account.

Get it on Google Play