Episode notes
Topics include , HTTP GET requests with the Python standard library, , and alembic-git-revisions.
Transcript
Read the transcript · about 5,730 words, follows along as you listen
Michael Kennedy:Hello and welcome to Python Bytes, where we deliver Python news and headlines directly to your earbuds. This is episode 483, recorded June 9th, 2026. I'm Michael Kennedy. I'm Calvin Hendryx-Parker. And this episode is brought to you by us, All of Our Things. We'll talk a little bit about that in the introduction bit here in just a second. If you want to follow us on social media, we're on all the socials. We'll have those in the show notes for you. Sign up for the newsletter at pythonbytes.fm/newsletter or just domain click on newsletter.
Michael Kennedy:You always get a bunch of interesting things as well as some extra announcements for fun stuff that we have going on. And with that, I actually, Calvin, have a pretty big announcement. So I want to say thank you to Brian Okken. The big news is that Brian has stepped back from the show. He's been working on it for almost 10 years, just a few months short of 10 years. That's incredible. That's a great run. That's an incredible run. That is an incredible run.
Michael Kennedy:Obviously, the world has changed a lot over the last 10 years, and Brian just needs more time to focus on some of his other projects. Not stepping away from programming. He's not going to go become like an organic farmer in Eastern Oregon. Forest ranger. Exactly. You know what? I'm retiring from tech. That's it. No, but he's moved on from the show, and I just want to take a moment and say, Brian, thank you very much. You've made the show what it is over the years, and it's been great to work with you, And it's been really, really awesome.
Michael Kennedy:And I know a lot of people in the audience are going to miss you.
Calvin Hendryx-Parker:Yeah, I agree. I've gotten to know Brian over the years as well. And I really appreciate him being on the show and just being a part of the Python community. So I've enjoyed having Brian around as well. Not that he's going to go away, but he's just not here right now.
Michael Kennedy:Yeah, maybe we'll have him back as a guest sometime. Yes, absolutely. So Brian, thank you very much. And Calvin, welcome to the show.
Calvin Hendryx-Parker:I'm glad to be here. I'm excited. This is a new, the next generation of Python Bytes. Let's do it.
Michael Kennedy:Yeah, absolutely. The next generation. So I know you have your pulse on the industry in so many ways, and you have a ton to contribute. And so we're going to work together on Python Bytes for a while. And yeah, it's awesome. So thanks for coming on the show. It's really great to have you. Thank you, Brian, for being here. Calvin, welcome. Normally, we just kick off the show. Hey, I'm Brian, I'm Michael, or whatever. But this time, at least you've been on the show on this show before, as well as Talk Python.
Michael Kennedy:But just give people a real quick introduction since you're kind of new to a lot of people.
Calvin Hendryx-Parker:Sure, sure. So I'm Calvin Hendryx-Parker. I'm co-founder and CTO of Six Feet Up. We are a Python agency that loves specializing in solving hard problems and helping impactful leaders build a better world out there and do things to benefit humankind in some way. I also am a co-founder of the IndyPy meetup here in Indianapolis. So very involved in the community. I love going to PyCon and being around all the folks. So this definitely fits well with like kind of my mission, which is to bring more to the Python community if I can.
Michael Kennedy:And you're also an AWS hero, is that right?
Calvin Hendryx-Parker:Oh yeah, I am. AWS hero since 2018 or 2019, I think. Yeah. So basically means AWS thinks I'm kind of a, I guess a big deal. I don't know. He's a big deal. Yeah, right. Yeah, there's only a few of them around the globe. And it's kind of cool because you can't be an Amazon employee or employed by a competitor. And so it allows me to maintain my independence and a little bit of cloud agnosticness.
Michael Kennedy:Yeah. Awesome. All right. Well, with that, how about you kick off our first topic?
Calvin Hendryx-Parker:Oh, sure. I'd love to. So we've got just yesterday, the fine folks at Astral have released some new features that are still in beta for checking for vulnerabilities and also some malware checks. So for example, they've added the new audit subcommand. So as you, this is not an unheard of thing in the community. There's existing tools like it, for example, safety and pip audit. What is different about uv offering this? They have basically said, we have an opinion like they've done in other ways.
Calvin Hendryx-Parker:Astral has basically said, we have opinions about how things should be done. And we're trying to optimize the developer experience workflow to make this not suffer from some of the problems you get with like, for example, npm. When you do an npm install, you get this just overload of warnings for deprecations. And so you just kind of start ignoring it and not paying attention to it. The idea is to be explicit and call it when you want to have these kind of scans run.
Calvin Hendryx-Parker:So you could put it into a pre-commit hook, for example, you can obviously run it in your CI pipeline, but it's meant for the developers to run locally as well. And the add command and sync commands have been updated. Well, optionally right now, they're not enabled, but if you enable the uv malware check, the add and sync commands will proactively tell you if you're adding a potential malware package to your project right now. I actually tried it out today.
Calvin Hendryx-Parker:I actually love that. Yeah, that's really cool. I literally did it today because I was like, oh, I should go check out my last FastAPI project to make sure I'm up to date on things. And I ran the uv audit, again, super fast, as you would expect most of the tools from Astral to be. And I had my Pi coding agent go and fix all the problems. And I released a new prod release just this morning because of the uv audit tool. It seems really, really nice.
Calvin Hendryx-Parker:I'm really excited about it.
Michael Kennedy:Awesome. I have been, I talked about it maybe six months ago or so, a couple of security things you can do for the supply chain vulnerability. And it's just super scary, right? Because you're just working normally on your projects. And if you time it wrong, well, bad things happen. And they have happened to people, right? Not in great numbers in the Python world, but still enough, you know, some of the LLM tools I can think of were pretty, that was a pretty bad one.
Calvin Hendryx-Parker:Well, we're paying attention now. I think folks are hopefully paying more attention and tools like this make it easier to pay attention and less friction to be safe. I think it's got options, for example, not to install the latest version of a package. Maybe you want to like a cool off period to say, I think that was already built in to uv, which does have a cool off period. That's a smart thing to do. You don't want the package that was released today because it might have a vulnerability from a supply chain attack in there.
Calvin Hendryx-Parker:And you want to make sure, usually in a few days, those are shook out. And so grabbing a seven day old version of it, probably the safe thing to do, for example.
Michael Kennedy:Yeah, and that's what motivated me to start down that whole path of talking about those things. I'm like, oh, they just shipped no earlier than whatever it was. And so that was really excellent. And then I started using pip Audit as well and even like share how you bring that into like a Docker world. And that's great. I'm feeling like that needs to be, for me, updated to use uv Audit instead of pip Audit, which just because like one of the things I see on the screen is four to 10 times faster.
Calvin Hendryx-Parker:Everything else I'm doing with uv,
Michael Kennedy:but I just couldn't because it didn't support this, right?
Calvin Hendryx-Parker:There's an asterisk there. PIP audit with a fully primed cache is probably about as fast. But if you're going from a CI pipeline, you're going to get the 4 to 10x speed up. So those are the, again, creature comforts that I believe the astral folks have brought to the game. They've just said, we're going to be opinionated. This is how we're going to do it. And we're going to make it better for everybody, hopefully. So if you like those opinions, it's good for you.
Calvin Hendryx-Parker:If you had other opinions, well, this is probably better. Yeah.
Michael Kennedy:Yes, exactly. So out in the audience, Mike. Hey, Mike. points out that this weekend's Miasma Hades attack is timely. I don't know about it, but okay.
Calvin Hendryx-Parker:I have to research it. If you had a CI pipeline running on the weekend and got that version over the weekend, and these things always happen on a Friday late on a weekend because no one's looking, that's exactly the timing that these kind of things happen. So make sure you've got that cool off period in there.
Michael Kennedy:Yeah, exactly. So I made the mistake of actually going on vacation for the weekend, and so I wasn't paying enough attention. So I got to research this.
Calvin Hendryx-Parker:Wait, you actually took a couple days off?
Michael Kennedy:Yeah. I sat by the ocean. It wasn't terrible.
Calvin Hendryx-Parker:Nice.
Michael Kennedy:All right. Let's talk about, I think this relates a little bit back to the supply chain, but not necessarily in a vulnerability way. You also mentioned your Pi coding agent. We need to speak about this a little bit.
Calvin Hendryx-Parker:Yeah, we should.
Michael Kennedy:Yeah, absolutely. This is going to have to be one of your whole topics sometime. But it seems to me like a lot of the projects that people depend upon have these very shallow dependencies. And by that, I mean, like, yeah, I'm sure I'm using this library that lets me give, I don't know, a zip code and it gives me the state back or something like that. Right. But I only call the one function. You know what I mean? would it be possible to just have some kind of coding agent or even you just write that into your project instead of adding maybe that dependency and three other dependencies it has, then you're worried about like cool down periods and supply chain and just like, oh, this one only works on 3.14.
Michael Kennedy:This one only works or lower and this other one only works in 3.15 and above. Like, what do I do? You know, those kinds of issues. So I want to highlight this article called HTTP GET requests with Python standard library. by Alex Chan. And so Alex basically says, there's been all this stuff going on with HTTPX. I'm going to talk about that at the end of the show a little bit more. But we've also got requests, we've got URLib, we've got NyQuest, which is a little bit like a modernized request compatible API. But, you know, built into the library, we've got URLib requests, could we just put the three or four functions that we want to write but turn that and just instead of having actually htpx or requests just have it use the built-ins right so build a little facade adapter layer on top of stuff that's
Calvin Hendryx-Parker:already there what do you think of that idea i think that's smart kind of a little bit of shift left or first principles like if you don't need to bring along those whole packages you don't bring along a lot of complexity frameworks are nice when they solve you know they usually do like an 80 kind of problem if you get a 10 kind of problem i wouldn't bring those kind of dependencies into your project because now you're on the treadmill. You've got to keep up with the release cycles and security vulnerabilities, et cetera, versus if you're controlling your own fate here for just a couple little things you need, it's probably cleaner and more explicit than implicit.
Michael Kennedy:You're just not subject to have to deal with all the stuff that goes with it, right? And put security aside, just the, they released a new version or they decided they were going to do a breaking change and that's probably worthwhile, but then you've got to deal with the breaking change. You know, like if the thing you're doing is not going to change really, and it's pretty straightforward, you could just ask Claude or Pyre or whatever, hey, see this thing, could you just give me the two functions I'm using?
Michael Kennedy:If there's enough foundational stuff in the standard library, right? So I think this is a pretty interesting thing for people to think through. I was going down this path. I'm like, this is pretty cool. What if I could just make, I think I use three functions from HTTPX. What if I could do this for HTTPX instead of the thing that they were basing theirs on? How hard would that be with a little bit of Claude help, right? And it turns out that the standard library's HTTP call stuff does not have any async support whatsoever.
Calvin Hendryx-Parker:I was going to ask if that was a thing.
Michael Kennedy:No, it's not. I'm like, wait, what are the use cases for asyncio? Database, HTTP, API. Hitting a network. Wait, it's had that since 3.4, I believe, is when async was in. And then async and await came in at 3.5.
Calvin Hendryx-Parker:Michael, you need to submit a PEP now.
Michael Kennedy:You know what? Very insightful thought. I actually wrote Brett Cannon a message about this. Said, hey, what would the steps to be actually submitting a PEP for this? And he sent me back some stuff. And Brett, I haven't had it just because I sent that message and went straight on vacation. I haven't had a chance to respond, but it looks like there's some work to be done. and research to be done. But I do think that that's a totally reasonable thing.
Michael Kennedy:And DBAPI itself also surely does not support async, but should, you know?
Calvin Hendryx-Parker:Like, I think there's a few really clear places. Yeah, there's still some hard problems left in the Python core. Yeah, we thought it was all done. It's not. Yeah, yeah. Although it is nice when you've got like HTTPX2 and you can just drop in and replace.
Michael Kennedy:Yep, exactly. Yeah.
Calvin Hendryx-Parker:Nice.
Michael Kennedy:Yeah, we talked about that from the Pydantic folks and we're going to talk about that some more.
Calvin Hendryx-Parker:Yep, yep, sounds good.
Michael Kennedy:All right, over to you, Calvin, for the next one.
Calvin Hendryx-Parker:So this one's a little bit of a double-edged mixed bag. The bad host vulnerability is a critical vulnerability in Starlet, which is an ASCII framework, underlies a lot of very popular projects right now that are, if you're doing MCP or if you're doing FastAPI, it basically is kind of a core layer for the asynchronous HTTP traffic for building an API server. So this vulnerability was reported. The community responded. there was a little bit of a back and forth but I think that the exploit is trivial for example injecting a single character into an HTTP host header can bypass path-based authentication now there's this is where this gets a little more interesting is that maybe that's not a great pattern for you to do which is path-based authentication that was kind of the pushback from the Starlette maintainers which is this is not really a intended use case for Starlet it is a vulnerability. It has been patched, has been fixed, but I believe they got a little bit of a bum deal from the journalists who are covering it. So actually, in addition to this post here, there's also the maintainer's perspective, which I thought was a very interesting view into both
Calvin Hendryx-Parker:sides of the situation. Not often do you get to see when there's a vulnerability or a CVE announced that the maintainers get to kind of post their response. And I think they post the response and it's well written, well thought out, explaining why this is probably not something that's common. Many people probably weren't as vulnerable as they thought they might be, but it would affect some really major projects. And if major projects were doing a pattern that was not originally intended by the maintainers of Starlet, then you end up in this bad spot.
Calvin Hendryx-Parker:And it could end up in remote code execution as a worst case scenario or data exfiltration that you weren't expecting because of this, but it probably wasn't the way you should be architecting your application. They also got a little bit of a complaint against the Ars Technica reporter. Basically, they asked really demanding questions and wanted an immediate response. That's back here down at the bottom, which was kind of rude. They were very demanding, and they only gave them, I don't know, hours, maybe an hour or two notice that they were going to publish this article on the website.
Calvin Hendryx-Parker:And the website went on, the Ars Technica website went on to say that they had contacted the maintainers but hadn't heard back. There was no comment from the maintainers, which people can read into that how they want. So I'm glad. Yeah, it sounds really bad.
Michael Kennedy:Like Marcello is just going to go, ah, forget you. I have no comment, right?
Calvin Hendryx-Parker:Because these are open source maintainers who are doing this for the community. They don't have a security team under the covers waiting to respond to journalists and security researchers. I mean, they did work with the security researchers. They did negotiate a shared disclosure or a mutual disclosure timeframe. This ended up for the best for everyone involved, except how he got portrayed. Now, luckily, I think folks in the comments stood up for Marcelo and the team.
Calvin Hendryx-Parker:So I think people in the community understand. But someone who's just coming to that article on Ars Technica may think differently of that project. And I think they should read this article as a response to that. Very interesting.
Michael Kennedy:I generally enjoy reading Dan Gooden's work, and I like Ars Technica. Yeah, I was surprised. I was surprised. You can just see the incentives at play here. Like, hey, you got to do an article this week, or we got to be the first to publish on this.
Calvin Hendryx-Parker:Well, and I think because MCP servers were the prime target. If you're running an MCP server, you were probably using a Starlet-based framework under the covers. And so a lot of credentials are stored in there. And if they were slop-coded, vibe-coded versions of those servers out there, they could have used a path-based protection like this.
Michael Kennedy:Sure. And probably, I don't know how it links back to FastMCP, but I think that's probably based on Starlet.
Calvin Hendryx-Parker:That's what I was thinking too. I didn't go double check that though.
Michael Kennedy:Yeah, I will leave that as a exercise to the audience.
Calvin Hendryx-Parker:But I think it is. These open source maintainers are getting near daily security reports, especially when you're seeing projects like Mythos being released. I think this volume is only going to increase. So a lot of it's AI generated noise and they have to be able to deal with it. So you're seeing a lot of pushback from the open source communities against AI pull requests and security posts.
Michael Kennedy:Absolutely. Yep. We could go down that a lot, but let's instead. Yeah, yeah, yeah, I know. Let's talk about merges. Merges. Let's talk about merging. So are you an Alembic sort of person? Do you Alembic? Do you, SQLAlchemy is really the question.
Calvin Hendryx-Parker:I do, actually. On that FastAPI project that I was mentioning from this morning, I have Alembic in there.
Michael Kennedy:Okay, very interesting. Yeah, I think FastAPI, sorry. I think SQLAlchemy is pretty neat. And this project, you know, Julian Fianjo also does this quite a bit. So he is one of the founders of Mergeify, which is all about making sure that merges, PRs emerge faster.
Calvin Hendryx-Parker:That's good advice right there. Stop breaking main.
Michael Kennedy:Exactly. Stop breaking main. It's a platform that allows you to handle merges better, right? So, but one of the problems, let me see, there we go. One of the problems they ran into is the way Alembic, so what is Alembic? Alembic is a system that allows different developers in production or Q&A or whatever to have an older version of the database, change the classes that map over to the ORM to the database, and then apply this automation to restructure or migrate the database such that it's now consistent with this new world, right?
Michael Kennedy:And the way it works is every change you make, you check in an up and a down set of changes, like add this column, delete this column, right? And so on, you know, like the up would be add a column and then the down would be delete the column. And there's this set of revisions that pile up for these projects. The problem is each revision says the one that came before me was some hash or something or another, right? And if two people create a PR off of the same base and that PR needs a migration in it, they both point back to the same one, but they really need to be done one and then the other, right?
Michael Kennedy:Like you need a linear chain of migrations, not some kind of complex hierarchy of migrations. And so that is a problem, right? And they saw that, Julian and all of them saw that a lot with their merging tools, right? So this project here called Alembic Git Revisions. So instead of using a, when you run an Alembic migrate or whatever, instead of having to just capture the back version, what it uses is Git history to figure out the orders of when those actual migrations landed in the migration series.
Michael Kennedy:And say, well, they look like they pointed the same one, but this one came in this time. And then the next one came in after that.
Calvin Hendryx-Parker:So is the blockchain craze officially over that they didn't use blockchain to solve this? Exactly.
Michael Kennedy:I think we should use BitTorrent and blockchain and all these things. So yeah, I think this is a pretty neat one. So I just want to give it a shout out. So if you use... That's smart.
Calvin Hendryx-Parker:That's totally smart.
Michael Kennedy:Why would we not do this? I know. This is quite new. You can see it's been updated seven hours ago. It's about a month old. I know four months old when the repo was created. I think probably it was released just very, very recently, right? So check it out. If this sounds like it's a problem that you have, here's a really nice fix for it.
Calvin Hendryx-Parker:Yeah. I mean, just putting in place these good guardrails makes sense across our project. So this almost should become the default behavior.
Michael Kennedy:Yeah. I mean, think of when, how old is SQLAlchemy? It's pretty old. And I don't mean that in a pejorative way. I'm just thinking.
Calvin Hendryx-Parker:No, no, no. It's mature. It's very mature.
Michael Kennedy:It's like saying, well, Jago's old. Like, Jacob's been around for a long time and is doing awesome stuff. But the reason I bring that up is it's just Alembic was created in a time before all these crazy PRs. And think of all the AI PRs going on now as well. It's got to be worse, you know? Yeah. Time for that stuff. All right. So if you Alembic, check out Alembic Get Revisions from Julian and the team. Smart. Very smart. Yeah, yeah. So I think that's it for all of our topics, right?
Michael Kennedy:Yeah, yeah.
Calvin Hendryx-Parker:I did want to add in a little bit of extra here. If you've not checked it out, Library Skills is by Sebastian from the FastAPI project. FastAPI has a great skill included with the library. So if you're using agentic tools to build on top of FastAPI, your tools will now know more about the preferred best practices in that framework because those skills exist in the agents folder. This Library Skills project is a standard and allows you to build out skills for any library you may be using.
Calvin Hendryx-Parker:if you've been using agentic AI Claude Code or others to build your software projects, sometimes they grab old dependencies because that was the popular thing at the time. They go based on what was kind of popular on the internet versus what's the best practice now. And so this helps guide your agents to those best practices. So it's a cool project. It's very, very new and also has a lot. He's already almost a 600 stars. So maybe after this episode, he'll get to pass 600 stars on the library skills repository.
Calvin Hendryx-Parker:Wow. That's pretty cool.
Michael Kennedy:This is super cool. Well done, FastAPI team.
Calvin Hendryx-Parker:Yeah, I mean, they don't stop. It's pretty cool. So there you go.
Michael Kennedy:Yeah, it's really cool. And I think this is a brilliant idea. I actually been working on doing that just for myself because this is absolutely a problem. So I'm like, all right, I work on Court and Flask and I'm working on Pyramid and I use DiskCache. And some of these are popular, like FastAPI, but others, not very popular at all. So I've actually been, every project that I adopt that I think is going to be important for something like Claude is I'll go through and I'll generate this kind of document that says, here's all the stuff you need.
Michael Kennedy:And the way that I get it is I will git cloned the documentation, the latest documentation from the project and the source code until you generate this from the documentation. Everything you see in the documentation, you need to verify with the active source code of the project, right? But that's just Michael randomly working on it. It is on GitHub. You can check it out. But it's cool that they've set up this more standard way, right? That it's just not just everybody trying to solve it for themselves.
Calvin Hendryx-Parker:Yeah. And it makes sense. You want to have good, authoritative information on the versions of the things you're currently working on in your project. Because you may have a version behind, and the AI may tell you a new thing that doesn't exist in your version, and you can't upgrade yet. So again, it helps line up all the pieces and give you the best chance of building great software with these AI agents.
Michael Kennedy:I'm going to avoid a rant. But I definitely think that people who are not having great AI experiences need to think of bringing some of these ideas in there and all of a sudden hallucinations just go away. Go away. Yeah, it's incredible.
Calvin Hendryx-Parker:It's been told.
Michael Kennedy:Yeah. Mike asks, how does Django handle migration and serialization conflicts? I don't know.
Calvin Hendryx-Parker:Do you have any idea? I don't know either off the top of my head. I have not run into it much. I'd have to ask someone on my team if they had.
Michael Kennedy:Yeah. It's probably pretty similar.
Calvin Hendryx-Parker:My guess is, yeah. So is that all?
Michael Kennedy:It's pretty mature.
Calvin Hendryx-Parker:I have one more extra. Yeah, yeah, let's do it. So this one's a bit old school. If you are a developer and you've ever used the GNU make command, did you know that it has pattern matching on the targets? So you can say train-percent colon and then have a command that runs and it will place into your command like whatever you put in that percent word. So if you said train new model and then the command, it would be like train.py. And then you put a placeholder and it would put new model right there into it for you.
Calvin Hendryx-Parker:That has been there since 1994. Now, there are fancy new tools like Just and Task out there. They don't do this. This is actually, I think, a power move that I only heard about this week. So check it out. Make still very powerful and still very relevant in this day and age for doing task running. We do use Just and Task, but those projects should add this pattern matching to the target. That's really cool.
Michael Kennedy:Yeah, how interesting. There's just a never-ending source of learning in all these things, right? You're like, oh, yeah, I'll figure this out. No, maybe not.
Calvin Hendryx-Parker:And one more thing I want to mention, because we didn't get to mention at the very beginning, or something I want to pitch for everyone to come out and hang out with me. I am going to be doing a LinkedIn Live with Whit Morris from the 6.15, June 17th at 3.30 on, oh, right, it's not a code review. I say, oh, you're right, it's not a code review. What AI proves what it checked. So basically calling the AI out. We'll be doing that on the 17th. So come hang out with me that day.
Calvin Hendryx-Parker:I mean, wit.
Michael Kennedy:You're absolutely right. That is not what it was supposed to do. Exactly. Let me try again.
Calvin Hendryx-Parker:Yeah, that's exactly it.
Michael Kennedy:All right. I got a couple of extras for us to jump on. So I had recently, I had both Michael Chow and Rich Ione on Talk Python to talk about great docs. Are you familiar with this? I'm not familiar with great docs. It's a document generator plus static site generator. That's super mature because it's based on Quarto, which itself is pretty mature, right? So I did my first project documentation on top of this, and I think it is really neat. So this is just, I'm showing you the great docs documentation, but I haven't published mine yet.
Michael Kennedy:I've got Nginx settings to set first, and then they'll be up. But this is really cool because the reason I wanted to highlight this is you're talking about the library stuff and how libraries can basically set up skills that AIs can use to work with that library, right?
Calvin Hendryx-Parker:Yeah.
Michael Kennedy:Well, one of the things that's really cool about Great Docs is it automatically generates skills for your library.
Calvin Hendryx-Parker:Very relevant.
Michael Kennedy:And you can even write extra ones. And then you can just say install through like NPX skills from wherever or run their CLI to install it for like Clot or Codex or whatever, which is already neat. It also generates an LLMs and an LLMs.txt, but also a full one that has all the API documentation in there. And when you go to one of your references or whatever, you pull it up, you can go and view every bit of documentation as a markdown file that you can get.
Michael Kennedy:And so I'm thinking that this is going to become a pretty popular way to document projects because it's without doing anything at all. It's very sort of AI coding complete, I think you would say. What do you think of that?
Calvin Hendryx-Parker:I love it. I mean, the more context we can provide to these agents and tooling, the better off we are. And actually, the nicer it is for humans, too. I love Markdown, like reading Markdown so much. I find it to be very easy, and I can then format it how I want. So it's kind of a twofer there.
Michael Kennedy:Yeah, 100%. Yeah. All right. So you mentioned HTTPX2. We talked about it previously on the show as well. And I looked at the Talk Python Courses site. And I thought, man, could I switch to HTTPX2? Like technically, yes, but what is the value of it? So I looked at my requirements file and I saw, well, there's five projects using HTTPX. So if I just switch mine to HTTPX2, like still I'm primarily using just HTTPX. So like if the libraries themselves don't swap over, no matter how much you don't, you want to use a different library, you're still using that one, right?
Michael Kennedy:Because you want to use those libraries. So I went through as well, let's walk the walk. So I went through my ListMonk one, my Umami one, a memberful one, and they all now are using HPX2. So if anybody uses those and they want to use HPX2.
Calvin Hendryx-Parker:You'll now get HPX2.
Michael Kennedy:Absolutely. Very nice. Well, how about we close this episode out with a joke?
Calvin Hendryx-Parker:All right. What do you got for me, Michael?
Michael Kennedy:So I've named this one accurate. Tell me what you think about these different classifications of types of like problem solving. You know, maybe this is a CS sort of conversation. You know, we've got algorithms. This is when programmers don't want to explain what they did.
Calvin Hendryx-Parker:You'll get me every time with these kind of jokes.
Michael Kennedy:We have a heuristic, which is very interesting. Less common and less provable, but often very interesting. The heuristic is when programmers can't explain what they did. And then machine learning, when programmers don't know what they did.
Calvin Hendryx-Parker:Very black box.
Michael Kennedy:Exactly. And it won't do it again, but maybe it'll do something else also interesting.
Calvin Hendryx-Parker:I appreciate that.
Michael Kennedy:Yeah, absolutely. And I just also, Marco out of the audience just says, much appreciation for Posit's open source contributions. Yeah, so great docs is from the folks from Posit, the Shining, or Studio, but they're also doing like Shiny for Python, lots of Python stuff these days. Yeah.
Calvin Hendryx-Parker:Very nice.
Michael Kennedy:All right, well, that is a wrap, Calvin. That was fun. Thank you for being here. Awesome show with you. We'll do it again. We will. Thanks, Michael. Yep, bye, everyone.
Transcript supplied by the publisher with the episode.
Python Bytes
by Michael Kennedy and Calvin Hendryx-Parker · English · Tech & Science
Python Bytes is a weekly podcast hosted by Michael Kennedy and Calvin Hendryx-Parker. The show is a short discussion on the headlines and noteworthy news in the Python, developer, and data science space.
More from Python Bytes
-
E486 · 30 Jun 2026 · 30 min
#486 underscore-underscore-ghost-emoji
Topics include Free-threaded Python: past, present, and future, django-admin-site-search, Qwen 3.6 27B is the sweet spot for local development, and.
-
E485 · 23 Jun 2026 · 38 min
#485 Creating memories
Topics include Backup Docker volumes locally or to any S3, Pyodide 314.0 Release, nb-cli, and Hindsight.
-
E484 · 16 Jun 2026 · 50 min
#484 All our tools
Topics include pi superpowers, Warp.dev OhMyZSH, Blink mosh tmux, Claude code, MacWhisper Handy, and Tailscale.
-
E482 · 1 Jun 2026 · 24 min
#482 Mr. Beast's episode
Topics include CVE-2026-48710: A Maintainer's Perspective, daily-stars-explorer, Markdown to pdf with pandoc and typst, and postman2pytest.
-
E481 · 25 May 2026 · 33 min
#481 Ways to die
Topics include Dumb Ways for an Open Source Project to Die, How to create a pylock.toml lockfile, , and Choosing a Python Logging Library in 2026.
-
E480 · 18 May 2026 · 33 min
#480 Proud Parents
Topics include Using Django Tasks in production, , PyPI packages are increasing rapidly, and httpx2.
-
E499 · 6 Oct 2026 · 33 minNew
#499 So many questions??
Topics include PEP 824 brings ?? and ??= to Python for None handling, Python 3.15 Python 3.10, asyncio.shield, and Pyxel: the retro game engine for Python.
-
E498 · 29 Sep 2026 · 33 min
#498 A Tiny Episode
Topics include MemTensor / MemoryOS PyPI package hijacked via a malicious build backend, TinyMongo, , and One innocent dict read makes attribute access permanently slower.
-
E497 · 23 Sep 2026 · 27 min
#497 Faster than light profiling
Topics include Tachyon: A sampling profiler ships in Python 3.15's stdlib, Python Workers are now generally available on Cloudflare, Flet 1.0 - build cross-platform apps in Python, and marimo-book: Build static books from marimo notebooks.
-
E496 · 15 Sep 2026 · 33 min
#496 A lake house in Seattle
Topics include Pandas Should Go Extinct, Pydantic-pint puts real-world units in your Pydantic models, How Libraries Run Rust Inside Python (With PyO3), and AWS acquires DuckLabs.
