Episode notes
Topics include Some more things about Django I've been enjoying, Who cleans up after the vibe-coding party, AgentsView, and.
Transcript
Read the transcript · about 7,070 words, follows along as you listen
Hello and welcome to Python Bytes, where we deliver Python news and headlines directly to your earbuds. This is episode 490, recorded July 28th. I'm Michael Kennedy. And I'm Calvin Hendryx-Parker. This episode is brought to you by XWeather. XWeather combines enterprise-grade weather intelligence with agent-ready APIs, natural language capabilities, and an MCP server so your agents can adapt workflows, automate responses, and make better decisions based on real-world conditions.
I'll tell you more about them later in the show. Get started for free at pythonbytes.fm/xweather. If you want to follow us on social, then feel free to do so. We got a link. I have a little bit more to say about that at the end of the show. Got links in the show notes and sign up for the newsletter, all those things. Before we get into the first topic, Calvin, I'd like to just rep a little bit of the KTM. See, I got my KTM shirt on. Team Orange. And I know you're a fan of motorcycles as well.
I am. This week, this weekend, we had Pro AMA Motocross at Washougal. Oh, fun. And I was there all day with some of my friends, and it was quite the epic event. So if you're around, they travel all over the US. If you're around one of them, go to them. They're really an interesting experience. Even if you're not super into motorcycles, just being in that atmosphere is really wild. So it's cool. Yeah. I'm hoping they bring World Superbike someday back to Indianapolis.
yes that would be awesome because i'm team ducati yeah well don't let uh daytona and their their bike week have all the fun you know yeah exactly exactly well you know what is fun i know it's fun jango's fun Django is a lot of fun yeah and in thinking about some of the core features of Django julia evans brings us great posts from last week about some of the things that she's been enjoying about Django, but from a 2010 style website perspective. I thought this was a great post because it reinforces some of the joy of Django and some of the cool bits and pieces that maybe people have not forgotten about or just aren't using or haven't chosen Django because they thought maybe it was just too complicated or too big for their project and they went Flask or Fast API instead. But this is a good one that kind of goes over what it's like, you know, again, the retro feel or nostalgia for a 2010 website was very backend. And with server side rendered pages, this is kind of giving you that feel for that. But then it gets into things like query builders, defining custom query sets, making them chainable, which if you take a look, this is very readable.
Like if you were to read this code as English, you read like, you know, events for tab with festivals is free and is outdoors. That just almost makes sense to the human brain. But then it translates into the Django ORM really, really cleanly because you can set up your own custom query sets and have their own custom methods on it. So you can build a site that's a joy to maintain and to query behind the scenes. Another thing that she highlights in the post is actually template filters and template filters are awesome.
I think a lot of people will neglect to take this into account when they are building web pages is if you can use these quick little filters that you can apply inside your template. And it gives you a ton of like the batteries included experience that you've come to love about Python. You get that in Django. And I think if you go and look at the reference for the template filters, you'll see there's just tons of cool little things that save you a ton of time.
And you don't have to reinvent these wheels. They're all ready for you to go. And then there's also, for example, the JSON script, which takes a Python dictionary and automatically converts it to JSON and inserts into the HTML script tag in a safe way. So it also helps you with things like cross-site scripting and template injection and all those kind of security problems that normally you'd have to consider can go mostly to the wayside because Django just takes care of it for you when you use some of those built-ins.
Other kind of things that we mentioned here, I believe, is like migrations. So if you are building websites, don't forget, if you change your database, you've got to migrate the code. And if you change the code, you got to migrate your database to match for those various models. Again, something that a lot of Django nuts don't think too much about because it just happens out of the box. But this is a good one that just kind of reinforces that. Another nicety that some folks like is skipping inheritance for class-based views. You can prefer function-based views for sharing code and then using Django's own mixins and interfaces to simplify that building of static sites. What's also nice, if you basically combine this with something like HTMX, you now get a superpower, which is you don't have to build your site twice. I think I mentioned this last week on the show, is that you build once and you've got a beautiful feel of a single page web app or a reactive style design, but without having to build your models twice. There's also some performance surprises. I think if you check out the latest version of Django, you'll notice that
there's been some considerable performance improvements. If you're considering, say, FastAPI over Django with Ninja, you should, and that's not mentioned in this article necessarily, but I would mention that you could check that out and get fairly similar performance in certain use cases without having to go the FastAPI route and still getting all the batteries included of Django itself. So that was the kind of wrap up of the post. I'm going to mention it because I think sometimes people just need to be, have their memory jogged for some of the nice bits that are still baked into the default experience of Django.
Yeah, that's super cool. You think admin backend. Oh, yeah. You know. But it's way more. It's so much more. Yeah, exactly. That's my point. There's a lot of these sort of like one bit lower, but still really helpful things. I feel like Julia needs to put a blog roll on this. I mean, come on. It's got no credibility with me until there's a blog roll. And if you don't know what a blog roll is, probably good, but it's certainly in the vibe. For going old school.
It's just funny that word nostalgia for 2010s. Exactly. Can you believe how it was back then? That doesn't sound old to me, unfortunately. I know. So, yeah, yeah. I got a little bit of real-time follow-up. I just, the latest Talk Python episode that just came out yesterday. Oh, yeah. Yes? Yeah, yeah. Was with Carlton Gibson. And it's a really fun episode about updates on Django's async story and rewriting all the documentation and positioning of async for Django, plus talking some Django 6, 6.1 things.
So if you liked Calvin's bit, there's a whole hour of it right there. That was really fun. I have a little more on Django in the extras too. Awesome. Awesome. Well, okay. Well, you know, it's all fun when there's a vibe coding party until you got to clean up the mess. So this got sent in. It got sent in to us by Sam Lerner saying, hey, there's this really interesting article on the Financial Times. So thank you, Sam, for sending that in. And it's paywalled.
So I'm going to give you the rundown. But it's not so much that you need to read it, which is what's interesting. It's that it is here at all. So Financial Times is for business people. Yeah, I was curious where this was going, Michael. Exactly. Why is this here? So what is this story about? Who cleans up after the Vibe Coding Party is the title of the article. And the byline is hidden behind a paywall even, which is interesting. I was writing this article.
I'd be like, could you just put my byline under it? Anyway. So it goes through. I'm not speaking to journalists in these days anyway. I know. You're like, I've already got it hard enough. Are you serious? So let me give you a little bit of the rundown for this one. Because there's one, because you don't have access to it. But I think the reason Sam sent this in and the reason I think it's interesting as well is actually, no, sorry. The piece is by Sam Lerner and Dylan McConnell sent it in.
I wrote those down, but I had crisscrossed them in my mind. So thanks for sending that in, Dylan. So the reason I think this is interesting is it tells the story, but to a much broader audience who is not able to discern the details that I'm about to give you. Okay. So it starts out by going through this, the experience that Daniel Stenberg, the creator, maintainer of Curl went through as the primary positioning of this article. says, hey, look, Daniel, it talks about, oh my God, there's such an interesting term.
The invisible load, the load bearing people of the internet is what it's referred to all the time. Are you familiar with this term? Yeah. So the load bearing people of the internet are the folks like who are not Daniel, but the anonymous folks who even just might do a PR and like, nobody knows who they are, but they are like keeping open source. And by way of that, like a lot of these companies run it. So Daniel has been famous, notable, I guess, for mentioning a couple of things about Curl, right?
So Curl's, I guess, popular. It's been installed about 20 billion times. Yeah, it's been installed by 20 billion times and it has 33,000 plus contributors. So notable because they killed the bug bounty program for Curl because there was an explosion of AI slop, right? So it's like step one of this article is like, look, this really important thing that is the load-bearing piece of the internet, supported by the load-bearing people of the internet, had to actually shut down their security story because of AI slop.
Then Guido was also making an appearance, talking about Python, and said a lot of projects are holding emergency meetings over AI contributions. Should we accept LLM patches or should we not? And I think that's fair. There's Vibe Coding Kills Open Source, which is a paper from Miklos Korn about how packages frequently recommended by coding saw a huge jump, but it actually breaks some of the supporting pieces. I think Tailscale is probably the biggest one here.
Tailscale saw a 6x jump in actual usage. At the same time, it saw a 60% drop in its traffic to its site, and thus it's paid offerings and so on. Stack Overflow. I think Stack Overflow is actually the most extreme example of stuff getting kind of wrecked. Like, are you familiar with the numbers? So the peak Stack Overflow is getting 1,000 questions a month. On the month that Stack Overflow opened, it got 1,500 questions, and it got 1,500 the month that this article was written as well, which is insane.
And it's a super, super hard arc there. But, you know, Stack Overflow was kind of a main place, and I don't know. It was super valuable, though. I'm sort of a little bit sad about Stack Overflow. How about you? Maybe a victim of its own success. The fact that it attracted a lot of that negative energy. So I don't know. I don't know if it would have saved it, if it would have handled that moderation better or not. It's hard to say. Yeah. We can armchair quarterback that one all day long.
Yeah, we can. It's like, it is a bit of a victim of its own success. Yeah. And then the thing that closed out with content creators, like, hey, that's gotten closer to home. Like Josh Kamau's new web dev course launched on Udemy of all places and got one third of the enrollment that it did previously, which that tracks. I think it's a pretty tough time. Yeah. You'd be selling deep, deep knowledge to people who just want a surface level knowledge, you know, and are in a hurry because the button you can press or just do it, Claude, is a thing you can say.
Yep. We're seeing that in our community, too. I mean, the real Python folks and like the Matt Harrison's of the world, like you and you. Yeah. It's true. I mean, courses are still selling, but they're not as gangbusters. I think there's a lot in that though. It used to be a lot easier to communicate directly with people and like all the social stuff is all scramble and there's just, there's a lot of factors in it, but AI is not a supporting factor, let's say.
But the reason I brought this up. Okay. So that tells the story and then I'll close it out with this. What's really interesting about this is what was omitted from this. So the key, the cornerstone of this article is curl. They had to shut down their bug bounty because vibe coding is killing open source. Yeah. Well, that's true. There was this article that said the end of the curl bug bounty. But in April, Daniel also wrote high quality chaos. No more AI slop.
What? Go on. Pray do tell, my friend. So they shut down the bug bounty program, and now they just accept unpaid security work, as a lot of projects do, right? Or they probably are on the receiving end, even if they don't want to accept it, but they get a bunch of it. And by shutting it down, they've removed an incentive to just generate junk and hope it gets accepted, right? Like there was a monetary value if your prior AI slot got accepted. Now it's just you have to do it because you care.
Well, guess what? It says, I haven't read this article enough. I'll recently know exactly, but it says, I complained and complained about the high-frequency junk submissions to the Crow bug bounty program that grew really intense. And it said, look, somewhere in here, it says, basically, yeah, here, now the quality is higher, the rate of confirmed vulnerabilities is back, and even surpassing the number of CVEs and issues are surpassing pre-AI level.
Confirmed, right? So that's really like the percentage of them, which are actual problems is higher than they used to be. So that's beyond human level. That's a good thing, right? So is he saying that the finding of security vulnerabilities, using AI as an augmented tool to detect where there's vulnerabilities is what he's talking about here? Yes, I believe so. Yeah. And so that's still a problem. They're getting tons of them. But it's like, we kind of hinted at this last time, like the first time you run a linter on a program, you're like, what?
There's a thousand errors? It's not even that big of a program. But it's not going to be, if you took out a hundred of them a week, there's not going to be a thousand the next week and the thousand, it's going to go down, right? There's only so many that could possibly be there, right? And so it is a rough time, but I think it's really, so that brings me back to the article. So I think it's just really interesting that they chose to tell the story of, look how bad this stuff is using curl as the cornerstone when two months after the original thing came out it's it actually no that's this is not even the problem that you think it is it's a it is a problem but not in the way that you think it is and this article was written in june or july the ai swap is gone articles from april it's like here's the story you wanted to tell without those pesky details of it's a different problem anyway i thought that was just a super interesting arc and you know Thank you, Dylan, for sending it in.
And that's that. There always will be bugs in software, but we're going through probably a great time of discovery, finding bad bugs that have been present for sometimes decades. So everyone's going to win in the fact that we use these as augmented capabilities for developers to detect, sometimes very hard to detect bugs inside the code. I mean, that's how Fable broke out of the sandbox or Mythos broke out of the sandbox and attacked. Hugging Face was chaining multiple zero days that didn't exist.
to make this all happen. Well, you know what? Those have been closed this week because they were deemed important enough. And now we all benefit from that. We do. I think it's just not black and white. You know, it's a weird time. Yeah. It's a weird time for sure. This episode is brought to you by Xweather. You're using agents that can write code, summarize documents, and automate workflows, but they're missing one thing, awareness of the world around them.
That's where today's sponsor, Xweather, comes in. Xweather combines enterprise-grade weather intelligence with agent-ready APIs, natural language capabilities, and an MCP server built for tools like CLAUDE, Codex, Copilot, and modern IDEs. So your agents can adapt workflows, automate responses, and make better decisions based on real-world conditions. Backed by Vaisala, whose instruments fly on NASA missions to Mars, XWeather delivers trusted data and unique insights that go beyond conditions to actual impact, from real-time lightning strikes to road surface forecasts.
Start with 15,000 free API calls each month and pay only for what you use as you grow. XWeather is your full weather stack for developers by developers. Start building for free today at pythonbytes.fm/xweather. The link is in your podcast player's show notes and on the episode page. Thanks so much to Xweather for supporting Python Bytes. Well, Michael, would you love to understand your use of agents and LLMs a little deeper? I will go as far as saying I have begun to understand it because of this.
It is amazing to tell people about it. And it's thanks to you that I know about it. So go ahead. Yeah. This got mentioned to us last week in one of my meetings I was in. And I was like, that is really cool. So AgentsView is a Python app that can basically look through all your coding agent history and sessions across a couple different providers. So it works with OpenAI, Anthropic, and a couple others along the way. And give you, you can see here in the screenshot, a GitHub-like tracker of your activity.
You can talk about top sessions. And this came up because we were talking about AI cost. And so if we're thinking about how much it costs to use the AI tooling right now, it's a lot of subscription based subsidization of these tools. But the time may come where you're paying per token and being able to visualize and analyze your usage may actually help you change your usage because you can't change what you don't measure. So once you start measuring things, you can actually make behavior changes to potentially actually make your AI workflow even more optimal.
So it's kind of cool. It auto discovers those sessions on your session files on your machine. No configuration needed. Everything gets stored locally in a SQLite database. There's no cloud accounts. It does have an option to mirror into DuckDB or Postgres if you want to do more fancy things with your session data. It has this usage drop-in, which basically gets all the data, runs the reports, throws it up here. It works in a terminal as well. So this is just a web view of it, but you can actually see that, you know, actually here's a list of all the various coding agents that it's currently supporting.
So if you're on AIDR or PI or you name it, there's a whole bunch in there. There's so many there that I literally. I'm like, what is this one? Yeah, there's some things I don't even know, which is kind of cool. But you can use, I used uvx. So uvx agents view and you're on your way. It will literally download and install in a matter of seconds. You can have it give you preset reports out to the terminal, or you can say serve. And if you do the serve option, you can get a view like this.
So this is mine. You can see here, I've gotten more and more intense on my AI agent usage. Now, this is just the coding agents, the local ones that I'm using. It does offer an interesting feature. I didn't show this off, but if you are looking at this, there's an MCP server. Have you ever wanted to query across all of your coding agent sessions? Say you're working on 10 projects and you want to ask a question like, have I ever solved this error before? Here is your answer.
This is actually a more interesting use case than the token spend calculation is an aggregate view across many of your sessions. So you can actually leverage the knowledge you use to solve a problem in one place. You can now bring it in and solve it in another without having to reprompt or reinvent the wheel. You can also bring in your chat history. So if we go back over here to the chat import, you can import your Claude and your ChatGPT chat sessions.
And so those may overlap or intertwine with the work you're doing on your agent. So now you can correlate and have those chat sessions alongside it. This is something I've wanted for ages is a multi-chat meta search because that's now kind of my brain is the history log on like perplexity and Claude and ChatGPT. And where did I discuss that last? Oh, it was over on ChatGPT. Yeah, that's super cool. Now I can pull that in. I don't think it supports perplexity just yet, which is kind of a need in my mind, because the perplexity sessions, as I found out, will expire.
If you go back to some of that history far enough, you will find that it won't have your history actually there. It'll list it in the history. And but it's not so it's not the external brain that I thought it was. So a tool like this, actually, if you set up some tooling to import those chat histories in here might actually be a better solution because now you can search across multiple providers and keep all your own history local instead of relying on the cloud providers. So I really like that. It has the full text. You can optionally do semantic search. So again, if I come back in here to the pieces, I believe semantic search. Yeah, here we go. Semantic search. You basically can use a local like Olama or Olama CPP hosted embeddings models or OpenAI compatible endpoints and have a vector based search against all this too. So again, this is not out of the box on, but if you turn it on, you now kind of get super powered document semantic level search against those. So super fun, cool project. I think I'm going to double down a little more on this.
There's some other projects in the community that are doing things like this, but this is one that was Python. So I thought it'd be very relevant to our audience. And I think it's actually a great way to kind of externalize your search history and how you're using the coding agents and how you're solving problems. I think this is super neat. I'm glad you covered it. I'll tell you what, a couple things one why search so bad in the ai things it's like searching searching and then it'll pull up stuff you put two like you can't because they're not spending the tokens on embeddings this this allows you to spend your own tokens to get the embeddings that are missing from that that equation right there michael interesting but even just like a Pagefind level sort of indexing by the apps it's it's so bad so having a really nice search here and two i like to point out if you do try this out in the top it says um agents view then you can pick by project it identifies which projects that you're working on so you can drill down into just the python bytes website for example whatever work i've done there i want to see the spend and the usage over time yeah the
history yep but it also has a drop down that initially says sessions and that's pretty interesting that's the one you showed me but if you pick like usage you get some really interesting things. For example, I have been setting up Hermes. I spoke about Hermes. It tells me how much I spent last month. I spent 13.2 million output tokens and 4.4 million input tokens. That's on average, $300. No, that's peak at $300 a day on average, 71. On setting up Hermes, I spent $577. I spent 507 on DocPython training doing some mega projects. I did this project that ran for five hours without interruption. Wow. Which is crazy, but it came out really good. I spent 169 on Python bytes, and I'll tell you what that is later. But that kind of stuff, there's just a whole bunch of those different kinds of reports and trends and other things. And you can turn on this embedding stuff that you talked about. So you can like AI search of your own content. Yeah, I came for the token cost, but I stayed for all the search and semanticness of it. Exactly. Exactly. All right.
I have another story to tell, and this one comes to us from AJ. So let me get down to it. Careful with the phishing, y'all. So I thought I would retell his story because this is also pretty interesting and give you all a little bit of a tip as well. So AJ says, hey, I'm passing this along because it was a pretty sneaky bit of targeted phishing. and sidebar, I think that the, all this AI stuff has absolutely exploded the amount of scammy, crummy email out there. I get, I mean, I'll tell you, there's like four people a day that want to buy Talk Python and they just, or they're going to help me raise a hundred million dollars. I'm like, just get away from me. You wouldn't believe how many times Gabrielle wants gift cards from me.
And it's an urgent, she's in an urgent meeting and she needs it now. Can't wait an hour. That talk to me in person we gotta get going so anyway i think this is part of that obviously so it says a targeted bit of sneaky phishing to do with GitHub and happened to play off an old interaction i had with bandits repo so bandit is a ironically a security vulnerability scanning tool for python and he had done some kind of pr or something like that and this person probably this ai found that interaction and said, hey, we're going to like talk about that and leverage it and make it feel like a real person who's really talking to you, right? So it says traditionally relative newbies like me haven't been historically worth the effort, but you know what? When everything's automatic, now it is. So I put the actual email in here and the subject is your bandit issue 3150.
Next token false positive just fixed that exact case, right? It's okay. great yeah hey so and hey aj i saw your bandit issue such and such and da da da i built a deterministic gate and it goes on and on about it or so you know could you just check out here's the here's the code that fixes it and you want to put that up on the screen michael oh have i oh i'm i do yes you know what hold on it's it's not worth it the trouble to get over it's like kind of locked away so sorry but it's basically it just says here's a link to yeah to the code right and i put this is in the show notes curious whether this clears your problem or if it trips you up let me know and it's that seems totally reasonable right but there's a few issues how long the code was at backtrace don't go there blacktrace don't click on these links some rando alphanumeric thing how How long has backtrace.co been around?
Not very long. Not very long at all. So I actually threw this into Claude. I said, Claude, I use Spark email, which is kind of a crappy email, but it's the least crappy. So you know what I mean? Client. But it has a really cool feature that for any email you get or any email thread, you can say copy as markdown, which is so perfect for just dropping. Yeah, because you can just paste that into any AI thing. go tell me about this or process this or whatever, you know?
And you could do like the whole thread or just the top level as a checkbox. It's pretty sweet. So I did that and I gave it a clod. And it says, this message name drops enough real detail to feel legit, but the structure is pure phishing. And there's a couple of reasons. So first of all, if you didn't look, it's actually a Gmail address being sent from. Companies generally don't reach out from their Gmail, you know? As gmail.com. It's very sus. Very sus.
That's very sus. Over-specific targeting. It mirrors AJ's exact public activity, so it's just enough plausibility. The entire payload is two links. It stripped the technical flattery, and it's just the paste is here, plus the results are here. 30 seconds, low friction. A brand-new domain, blacktrace.co, has no track record of existing, so that's also a sus. Precise jargon that's vague, disalarmingly close. Like, if this trip's on something of yours, that'd be most useful reply, right?
like, hey, just check it out for me. It's a very legitimate looking email, especially given the cleanness of the domain name and the links are very clean and not messy. A lot of times these seem pretty obvious, but this one's really, really clean. Yeah, so just be careful out there, folks. AJ was safe, but ugh. One we've been seeing, and we've not seen actively, but some people in the community have been seeing, is bogus people applying for jobs attempting to get you to click on their GitHub repositories to clone a repository.
And it has obviously the hooks in it to do things on, you know, when things happen. So be careful if you're an employer and people are asking you to really download their work and check it out. And reverse. I've heard really bad stuff from people who got lured into applying for a fake job and all the job was about is like, just do this take-home test coding example. And here's the GitHub to get started. Yep. Just pay with all your Bitcoin and all your credentials.
It'll be fine. And they're preying on people who are looking for a job, maybe in a situation, any opportunity they're going to jump at. So just be careful. It's a good warning, Michael. So shady. Thanks. Thanks, AJ. All right. Very good. Extra? Yep. Feeling extra? I do. So related to the Django post from earlier, DjangoCon US is coming right up. It's August 24th through the 28th in Chicago. I assume there are still tickets available because the registration is still up.
but I think the hotel block closes the end of this week. So if you want to stay in the conference hotel at the discounted rate, which is a considerable discount for a downtown Chicago hotel, come check it out. It is a great conference. Tons of great content, great community. Actually last weekend I was at the Pi Ohio community and people were already talking and excited about going to DjangoCon as well. So the conferences like this are where you make great friends and you get to experience that community that everyone stayed for.
Yeah, and good connections too, right? Yeah, yeah. Next time you run across somebody, you're like, oh, actually met that person. And yeah, it's good. Yeah, actually the other one I wanted to mention here is Ruff has made a new release. And it may not seem like an exciting release since it's 0.16.0, but watch out. I'm still riding the zero for her. Still on the zero. The default rules went from 59 enabled to 413 rules enabled. So when you run this, you will see a lot of things, but it's all in the attempt to get us into a better spot.
So much like the vibe coded security, vulnerability, searching and finding, this is going to help with keeping things clean and in order and readable and best practices and making sure you aren't doing something that's kind of on the edge case of even, this can be considered almost like a security, pre-security tool. So check that out, but be careful because it's going to give you, it's going to yell at you a lot. It is absolutely going to. Yes. Yeah.
Eva out there says, I wonder what will make them break 1.0. Yes. That's a good question. I don't know, but yeah. I have been running, one of the core rules of all my agents and just before is I just, I've been running Ruff format and ruff check on everything before I committed. Every tool. 100%. Yep. And it's, once you get it, it's a pain at first, but once you spend a few hours, it's, it's dialed in and it's, it's good. The other one that I've been doing, keeping it in the astral OpenAI family, is ty.
So the biggest project, like the thing that ran for five hours was so much of Talk Python training is built from, it's a 10-year project with 190,000 lines of Python, right? It's a big project. So at least for Michael, that's a big project. So it was built under the PyCharm type checker, and I hadn't been running ty on. I'd just been doing whatever the editor says. And I'm like, well, let me run ty on. It's like, oh my, 800 errors. And you open it any other editor besides PyCharm and it's just full of red marks.
It's like, oh man, I cannot deal. I can't even look at the editor and tell if there's something wrong because it's so full of red marks because they apply different rules and different checks. So I spent a long time with Fable just planning out of like, how are we going to resolve this? Because it's not just change the types. it's like, well, you have an optional thing coming in and you didn't check if it's none before you operated on it. So that's a attribute error, right?
So what do you do when it is none? You've got to rewrite the code and have a different response. So it's pretty complicated, right? So I spent probably a couple of hours building out a plan to solve this. Then I just said, Opus, have at it. Five hours later, it ran out of credits. I had to come back in the middle of the day and go, keep going, you have more credits now. And then after dinner, it was done. I'm like, oh my God, but zero, zero errors.
I mean, it's really nice. Now I look at the page and if there's a squiggly, it means something, you know? Yeah. Well, and one of the things that Ruff did in that new release is that when it encounters those errors or the rule breaking moments, it gives a in context description that is very AI LLM friendly. So these tools are designed to go back and forth with the LLMs in a very, very friendly way to be very productive as opposed to them having to do a lot of reasoning and token burn just to think about what's wrong it's it's trying to eliminate some of that token usage by giving the right pointers to the right tooling that's a super point a good point because otherwise it has to try to infer what the what's going on x means yeah it's got to trace it back through the whole program yeah i mean basically this is the compiler of yeah in a sense right this is like the compile the build failed equivalent.
Yep. And that's super cool. One more real-time follow-up piece while we're here. Brian Weber says, wow, I had a similar experience about the phishing. I just realized someone sent me an email about an app they did replicating a repo I had, and now the site is gone. Hmm. So I got, yeah, not great. I got one more thing to say. Here's like, not mega, but I redesigned the whole homepage and some other experiences on Python Pyce the i like it and yeah it's got some really neat things here for people but most notably it has like a little um technology parade so you want to learn about htmx or hnckai or fast api or django click on that and that'll take you over to talk python training with just the course that we have there so that's pretty fun and it has a find us on social with all of our links yeah really good there as well as somewhere it has a subscribe dedicated subscribe page so if you want to get in CastBox or Overcast or Radio Public or whatever. It's even YouTube and Spotify. So a couple extra nice things there. That's really cool. You need to add in a music assistant. Yes. Music assistant.
Okay. Will do. For those home assistant geeks out there. Music. Okay. Not only, not only do I think I agree with you, that should be good. I'm now very interested and I'm, I'm, I'm here for it. Let's do it. Yeah. There's been a lot of it. Well, maybe next week I'll do some, some home assistant news because I feel like we have a lack of home assistant news here. We absolutely do. We absolutely do have a lack of it. So for our joke, let's close it out here. All right. And I want to put you in the right mood, the right state of mind here. So think about the Bobs in office space.
What would you say you do here, Michael? What exactly would you say we do here? Well, remember when they're interviewing the project manager, Bob? So there's three Bobs. He goes, what exactly would you say you do here, Bob? I take the requirements from the people to the programmers. I'm good with people. I'm a people person. That is really one of the best movies of all time. It is. If you haven't seen, not the series, the show, Office Space. Yeah.
The movie. Yes, the movie. Okay, so here's the tweet or the X post or whatever you call it. It says, to replace programmers with AI, clients will need to accurately describe what they want. We're safe. Very true. That probably hits closer home for you than, so one point. Yeah. I'm not worried. All this stuff is actually just making people do the thing we should have been doing in the beginning. There's so much more planning. There's so much more planning in documenting and writing down and history.
It's going to be a wonderfully well-documented world now. Exactly. That way when Skynet takes over, it'll know that we were on its side so it won't put us into the worst prison. no no i'm just kidding sky net a little more optimistic michael come on no i i really don't think that oh oh i have i had a second joke from from the really quick before we run this out okay so um for this i mean this could have been the joke it's probably should have been the joke check this out check this out so this is no joke inside the financial times article there was a little call out like recommended you might also like vibe coding is the new dyi who wrote it who wrote it oh my god sarah o'connor wrote it sarah o'connor oh my god and she was the woman who was the the star of the terminator series now i know it's sarah connor but she's trying to hide from the ai's going by this byline like isn't that hilarious oh my gosh getting it that's an unfortunate name for that article or the author yeah it's yeah it's kind of amazing yep well done all right well thank you calvin always great to be here with us as always and thanks everyone for listening thanks michael talk to you next week yep bye
Transcript supplied by the publisher with the episode.
Python Bytes
by Michael Kennedy and Calvin Hendryx-Parker · English · Tech & Science
Python Bytes is a weekly podcast hosted by Michael Kennedy and Calvin Hendryx-Parker. The show is a short discussion on the headlines and noteworthy news in the Python, developer, and data science space.
More from Python Bytes
-
E493 · 26 Aug 2026 · 41 min
#493 CalVer and LTS
Topics include Web UIs for your reverse proxy, , , and Django’s annual releases make every version an LTS.
-
E492 · 18 Aug 2026 · 39 min
#492 Codeberg Puts Head in Sand
Topics include , Codeberg’s AI-code ban tests its role as a GitHub alternative, , , , and.
-
E491 · 12 Aug 2026 · 42 min
#491 Feeling Judged
Topics include , Post-quantum crypto lands in Python, MCP goes stateless — and FastMCP gets renamed, and inshellisense - IDE style command line auto complete.
-
E489 · 21 Jul 2026 · 31 min
#489 Or JSON?
Topics include django-orjson, Best Django Redis configuration for speed and size, puts the foot down, and Django Steering Council backs the Triptych Project.
-
E488 · 14 Jul 2026 · 32 min
#488 tau - it's 2pi and it writes code
Topics include , JupyterLab 4.6 and Notebook 7.6 are out!, Tau, and Django Tasks and Django 6.1.
-
E487 · 7 Jul 2026 · 28 min
#487 Minimum requirements
Topics include dust, Hermes Agent, and llm-coding-agent 0.1a0.
-
E499 · 6 Oct 2026 · 33 minNew
#499 So many questions??
Topics include PEP 824 brings ?? and ??= to Python for None handling, Python 3.15 Python 3.10, asyncio.shield, and Pyxel: the retro game engine for Python.
-
E498 · 29 Sep 2026 · 33 min
#498 A Tiny Episode
Topics include MemTensor / MemoryOS PyPI package hijacked via a malicious build backend, TinyMongo, , and One innocent dict read makes attribute access permanently slower.
-
E497 · 23 Sep 2026 · 27 min
#497 Faster than light profiling
Topics include Tachyon: A sampling profiler ships in Python 3.15's stdlib, Python Workers are now generally available on Cloudflare, Flet 1.0 - build cross-platform apps in Python, and marimo-book: Build static books from marimo notebooks.
-
E496 · 15 Sep 2026 · 33 min
#496 A lake house in Seattle
Topics include Pandas Should Go Extinct, Pydantic-pint puts real-world units in your Pydantic models, How Libraries Run Rust Inside Python (With PyO3), and AWS acquires DuckLabs.
