Sign in

Anže

@anze3db.pecar.me
1.3K followers 161 following 209 posts

Writing Python and surfing waves 🏄‍♂️

PostsRepliesMedia
Anže @anze3db.pecar.me · 30/09/2026
RSVP on Meetup: www.meetup.com/python-lisb... Or RSVP on Luma: luma.com/c72p4hb0 Join us on Discord: discord.gg/ZQWZK6AXRk
meetup.com
#13 Python Lisbon Meetup at Técnico, Thu, Oct 1, 2026, 7:00 PM | Meetup
**Agenda:** * 25-minute talk by [Rodrigo Girão Serrão](https://www.linkedin.com/in/rodrigo-gir%C3%A3o-serr%C3%A3o/) * One or more lightning talks ⚡ * Socializing! 🇵🇹 Va
000
Anže @anze3db.pecar.me · 30/09/2026
🐍 Python Lisbon Meetup is tomorrow! 🎤 Talk by @mathsppblog ⚡ Lightning talks 🍻 Socializing 📍 IST, Sala Multiusos, Torre Norte (new room, not the Pavilhão de Matemática!) 🕖 Thu, 1 Oct, 19:00 RSVP links below 👇
100
Anže @anze3db.pecar.me · 23/09/2026
Fun fact, I gave a lightning talk about chess and then got caught solving a chess puzzle during one the workshops 😅
010
Anže @anze3db.pecar.me · 23/09/2026
PyCon Portugal continues to be my favorite PyCon. This year it was in Aveiro (a better Venice 😉) and we had a blast! I enjoyed giving my talk on lazy imports, but the best part was meeting new people and catching up with friends. Looking forward to it again next year!
120
Anže @anze3db.pecar.me · 27/08/2026
We opened a support ticket, and the AI immediately identified the issue as being on their end. No answer to the ticket yet, but we no longer see the 30k charge in Cost Explorer 😮‍💨 If you are using Grok 4.6 through Bedrock Mantle, double-check how much you are spending!
000
Anže @anze3db.pecar.me · 27/08/2026
I had a bit of a heart attack this morning when we noticed that my Grok 4.6 benchmark experiment using Amazon Bedrock would cost $28,044.59 instead of ~$28.00 that I was expecting 😱
100
Anže @anze3db.pecar.me · 26/08/2026
Yes, always validate everything. We’ve all learned this lesson the hard way, but frameworks still make it way too easy to skip it 🤷‍♂️
120
Anže @anze3db.pecar.me · 26/08/2026
If you want to go straight to the source and see the original research: class-pollution.github.io/ jackfromeast.github.io/assets/Pyrl...
000
Anže @anze3db.pecar.me · 26/08/2026
Because I've written a similar snippet many times in the past, the first thing I did when I got home was write an open grep rule so our existing tools could catch it. Blog post on why this can be very bad and how to protect yourself on my company blog: www.fencer.dev/blog/python...
fencer.dev
Python class pollution: a paste-in Opengrep rule
Python class pollution turns getattr and setattr into RCE and auth bypass. Here is an Opengrep rule you can paste into your own ruleset to catch it in CI.
100
Anže @anze3db.pecar.me · 26/08/2026
One of the many things that I learned at DEF CON a few weeks ago is about Python Class Pollution and how a harmless snippet like the one below can cause a huge issue if an attacker controls it!
210
Anže @anze3db.pecar.me · 31/07/2026
My dog kept me in Zone 2 for 3kms. Then I had to drop him off and immediately made bad decisions. 💛
000
Anže @anze3db.pecar.me · 31/07/2026
We benchmarked 15 models for triaging vulnerabilities. * Kimi K3 came out on top but marked a true positive as a false positive ☠️ * Opus 5 refused to give a verdict on 11 vulnerabilities * Sonnet 5 and Luna outperformed Terra and Sol Full post 👇 www.fencer.dev/blog/llm-tr...
fencer.dev
Benchmarking 15 LLMs on SAST false-positive triage
We benchmarked 15 LLMs on 142 real security findings to triage SAST false positives. Kimi K3 led on accuracy, with one caveat that matters for security.
000
Anže @anze3db.pecar.me · 27/07/2026
Quite a way to start a Monday 😅
GitHub PR stats:

+86,316 of added alines
-29 removed lines
101
Anže @anze3db.pecar.me · 21/07/2026
I do think it nailed my voice though!
Voice

First person, always. Posts are “I did X and here’s what happened”, not “one can do X”. Use “we” only for genuine team work or when walking the reader through code (“Let’s look at the view”).
Address the reader directly as “you” in tutorials: “You’ll have to add the pidfile parameter.”
Warm, enthusiastic, and self-deprecating. Admit mistakes and ugly code openly: “The one-liner has a face only a mother could love”, “which may or may not have happened in the past 🙈”.
Hedge honestly, not weaselly. Say “I haven’t tested it myself, so I’m not sure it’s foolproof” or “take the results with a grain of salt” rather than vague qualifiers.
Credit people by name with links: “Shoutout to Rémy on BlueSky”, “Thank you Hynek”. Community attribution is a core habit.
Exclamation marks are welcome when the enthusiasm is real. Emoji as sentence-final emotional beats: 🎉 for wins, 😅 for sheepishness, 🤞 for hope, 💥/☠️ for breakage, 🙈 for embarrassment. A few per post, never mid-sentence decoration.
011
Anže @anze3db.pecar.me · 21/07/2026
I asked Claude to come up with writing guidelines based on my blog posts: > A few things I deliberately did not encode as guidelines: the frequent typos (characteristic of your fast publishing cadence) 88 blog post in 14 years is not fast publishing cadence 😅
000
Anže @anze3db.pecar.me · 06/07/2026
2. Turn on the DRF-type stubs we’d already installed but never wired up. It was flagging serializer-field errors, and we never figured it out until now. Yes, mypy is slow, but I think there is value in running it on Django codebases!
110
Anže @anze3db.pecar.me · 06/07/2026
It was also very useful to look at the false positives, and we were able to make two changes that reduced them by half: 1. Stop type-checking test files. No true positives were ever caught by this, and dynamic attrs from baker/setUpTestData are a common source of false positives
100
Anže @anze3db.pecar.me · 06/07/2026
We reviewed 4,978 mypy runs in our Django app: • 4,731 green • 246 failed Of the 246 failures: • 173 false positives • 73 real issues • 39 caught only by mypy and no other check! Some noise, but it prevented real bugs from reaching production. 🎉
101
Anže @anze3db.pecar.me · 03/07/2026
Our Go wrapper rebuilt an expensive index on every call. Python version builds it at package build time. Yes, we could fix the indexing problem, and then Go would be ~16x faster than Python (0.04ms vs 0.63ms), but we’ll happily trade 0.6ms to remove the whole Go-Python bridge.
000
Anže @anze3db.pecar.me · 03/07/2026
Today I migrated some Go code to Python and made it 590x FASTER 😎
100
Anže @anze3db.pecar.me · 29/06/2026
After 9 meetups full of talks, lightning talks, and even lightning turtles, it's time for the Python Lisbon Meetup to take it easy. Join us at Linha d'Água on Thursday to relax and enjoy the summer in Lisbon with Python friends 🐢 www.meetup.com/python-lisb...
meetup.com
#10 – PyLM Meetup – Social Get-Together, Thu, Jul 2, 2026, 7:00 PM | Meetup
🇬🇧 After 9 meetups full of talks, lightning talks, and even lightning turtles, it's time to take it easy. Join us at Linha d'Água — the café by the lake in Parque Eduardo
011
Anže @anze3db.pecar.me · 08/06/2026
One of my servers lost DNS after every single reboot, and it was driving me crazy. ping 8.8.8.8 worked, ping google.com didn't, and the fix never stuck. Turned out to be a config from 2010. I finally debugged it properly with Claude. blog.pecar.me/the-15-year...
blog.pecar.me
The 15-Year-Old iptables Rule That Broke My DNS
One of my servers has a weird problem after every reboot: it can ping IP addresses just fine, but it can’t resolve any DNS names. $ ping 8.8.8.8 # works $ ping google.com # ping: google.com: Temporary failure in name resolution I’ve been working around this for a while now: after every reboot I’d SSH in and overwrite /etc/resolv.conf to point straight at 8.8.8.8 instead of the local 127.0.0.53 stub. That got DNS working again, but it was never a real fix. /etc/resolv.conf is regenerated on boot, so my edit vanished the next time the machine came up and I was back to fixing it by hand. This time I decided to attempt to properly debug it with Claude.
010
Anže @anze3db.pecar.me · 26/05/2026
Max 5x plan. I had Claude running in a loop, generating tests to reach 100% coverage over the last five days, and hit the limit yesterday. 😅 We started at 92%, and my branch now has 99% coverage with only 120 files without full coverage. One more night of running in a loop should do it! 🤞
010
Anže @anze3db.pecar.me · 26/05/2026
Speaking about reading the labels. It says that I spent the limit for this month but it's actually a weekly limit, lol.
000
Anže @anze3db.pecar.me · 26/05/2026
The Claude usage page is very confusing. Since Sonnet has a separate bar I thought I'd be able to switch to it after I max out Opus, but nope. Of course this all makes sense if you actually read the tooltip/labels but who does that today anyway? 😅
200
Anže @anze3db.pecar.me · 25/05/2026
Oh, I didn’t know GitHub doesn’t have pagination in the Commits tab of a pull request. 😅
020
Anže @anze3db.pecar.me · 22/05/2026
Make sure to always reuse your botoclients. Initializing a fresh one on each task has A LOT of overhead!
000
Anže @anze3db.pecar.me · 20/05/2026
Oh no, I wouldn't even attempt that for the actual Django source code 😂
000
Anže @anze3db.pecar.me · 20/05/2026
My work project, why?
100
Anže @anze3db.pecar.me · 20/05/2026
Running Claude in a loop to push our test coverage. After 24+ hours and 22,000 new lines of tests, coverage climbed from 92% to 95%. No clue if it’ll get merged, but it's a really fun experiment 👀
100
Anže @anze3db.pecar.me · 17/05/2026
Fun fact, I was reviewing for 3 hours straight on Saturday while the Raglan surf competition was on. There was A LOT of waiting between sets, so I could focus on proposals for most of it!
000
Anže @anze3db.pecar.me · 17/05/2026
Over the last week, I've been reviewing PyCon Portugal talk and workshop proposals, and I just finished reviewing them all! 😎 Some really good ones in the mix that got me really excited about the conference in September. Make sure to grab your ticket! 2026.pycon.pt
110
Anže @anze3db.pecar.me · 13/05/2026
Good that flexibility is back! I'm sure you'll make a full recovery soon! Btw, Ana is a physio, so let me know if you ever want to run anything by her.
010
Anže @anze3db.pecar.me · 13/05/2026
Claude wrote up a Cloudflare-style post mortem: blog.pecar.me/fedidevs-pos...
blog.pecar.me
Fedidevs Postmortem
Today I had almost 9 hours of downtime on fedidevs.com and some of my other sites that I run on a Raspberry Pi at home. The alert came in just as I was heading to bed and I didn’t see it until I woke ...
000
Anže @anze3db.pecar.me · 13/05/2026
Fedidevs had quite an outage today. It went offline just as I went to bed and I didn't see it until I woke up this morning 🫣 Still better uptime than GitHub 😅
000
Anže @anze3db.pecar.me · 12/05/2026
The first km was a bit downhill so the numbers look a bit better than they should 😅 I improved quite a lot since I started but I think it's mostly due to having a good coach from day 1. How's your knee by the way? Will be you be able to start running again soon?
110
Anže @anze3db.pecar.me · 12/05/2026
Months of training runs with my dog. Went solo today and broke almost every PR I had. He’s the real coach 🐕
130
Anže @anze3db.pecar.me · 12/05/2026
The supply chain attack has now spread to PyPI: mistralai: 2.4.6 guardrails-ai: 0.10.1 Pause your dependency updates or use package cooldowns (--uploaded-prior-to flag in latest pip) Stay safe!
023
Anže @anze3db.pecar.me · 11/05/2026
Blog post with more information on all of this. Stay safe out there! socket.dev/blog/tansta...
socket.dev
TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud...
Socket detected 84 compromised TanStack npm package artifacts modified with suspected CI credential-stealing malware.
000
Anže @anze3db.pecar.me · 11/05/2026
🚨 There was another supply chain attack, this time affecting tanstack npm packages. Make sure you haven't installed the compromised packages either in your CI or locally. I would also hold off on updating any dependency for the next week or so until the dust settles from this.
101
Anže @anze3db.pecar.me · 11/05/2026
Claude had to force-remove conflicting packages, reinstall the Trixie versions, and use dpkg -i --force-overwrite where the metadata still disagreed about file ownership. I would have given up and reinstalled. Full write-up in my latest blog post 👇 blog.pecar.me/letting-cla...
blog.pecar.me
Letting Claude Upgrade My Raspberry Pi
I have two Raspberry Pis at home. One hosts my various sites including fedidevs.com and the other supports it by storing backups of all the configs and data. This includes a streaming hot standby of the Postgres database that powers some of my sites. I am not (yet) brave enough to run Claude on my primary Pi, but I decided to let it loose on my secondary. Doing an in-place dist upgrade on a Raspberry Pi is generally not recommended. The official guidance is to do a clean install instead. Since it felt very likely that I’d be doing a clean install in any case to get from Bookworm (Debian 12) to Trixie (Debian 13), I figured this was the perfect opportunity to see if Claude could pull a miracle.
030
Anže @anze3db.pecar.me · 11/05/2026
I told Claude to upgrade my Raspberry Pi from Debian 12 to 13 and went to enjoy my Sunday. It wasn't an easy upgrade. apt kept tripping over Debian's t64 transition, but Claude managed to unstuck it. When I came back, the box rebooted cleanly into Debian 13. 😲
210
Anže @anze3db.pecar.me · 05/05/2026
I wrote a few words about the Agents Day hachaton that I attended last week on Friday. It's always fun to have an excuse to spend a day tinkering with something new. I even managed to be one of the 5 that got to demo their project on stage! 👉 blog.pecar.me/agents-day-...
021
Anže @anze3db.pecar.me · 04/05/2026
Meetup page for the event: www.meetup.com/python-lisb... More info: python-lisbon-meetup.github.io/
meetup.com
#08 - PyLM Meetup at Técnico 🎓🐍, Thu, May 7, 2026, 7:00 PM | Meetup
**Agenda:** * 25-minute talk: **Strong Ref, Weak Ref, and Garbage Collector Walk Into a Bar** by [Yulia Markelova](https://www.linkedin.com/in/yulia-markelova-a70434235/)
000
Anže @anze3db.pecar.me · 04/05/2026
We have another Python Lisbon Meetup coming up on Thursday 🐍 This time Yulia will be giving a talk on strong and weak references! See you on May 7 @ 19:00 at IST, Pavilhão de Matemática, room 3.10!
100
Anže @anze3db.pecar.me · 28/04/2026
Finally wrote up my notes from DjangoCon Europe 2026 in Athens 🇬🇷 I climbed the Acropolis, ate great food, hung out with amazing people, gave a lightning talk, and fixed one regression in Django main during the sprints. blog.pecar.me/djangocon-e...
blog.pecar.me
DjangoCon Europe 2026
Before the conference My partner and I arrived in Athens a few days before the conference. It was a convenient excuse to visit a European capital we hadn’t been to yet, and of course to eat as much delicious food as possible. Django Social One day before the conference I went to the django.social event organized by Jon Gould and Andrew Miller. The bar they initially picked got too crowded, so the group moved to the backup place. I came late to the first bar, found no one there, and was a bit lost until I made it to the right spot. Once I did, I felt immediately at home. I met old friends, made some new ones, and had a very fun evening. So fun, in fact, that I forgot to take any photos, so I have no social proof that I was there 😅
011
Anže @anze3db.pecar.me · 20/04/2026
Thanks! Fixed. It was supposed to be hours. (litellm got yanked in 40 mins)
100
Anže @anze3db.pecar.me · 20/04/2026
With all the supply chain attacks going around, we have to be very careful about how we update our dependencies. I've written a full blog post about it, but here is the TLDR: 1. Pin to hashes, not just versions 2. Automate the updates 3. Use dependency cooldowns blog.pecar.me/how-to-safe...
blog.pecar.me
How to Safely Update Your Dependencies
With all the supply chain attacks happening lately (litellm being the most recent example) keeping dependencies up to date without risk has been on my mind. Below is everything I do to keep my personal projects secure, what we do at Fencer to keep our own codebase secure, and what we recommend to the startups we work with. Be hesitant about what you add The best way to reduce the risk of installing a compromised dependency is to avoid relying on it in the first place. Before adding a new dependency, I first make sure that implementing it ourselves would be too much work (or tokens!).
111
Anže @anze3db.pecar.me · 12/04/2026
Everyone’s favorite web framework is now also in the gelato business 🤤
060
Anže @anze3db.pecar.me · 03/04/2026
Another Python Lisbon Meetup in the books! Looking forward to the next one on May 7 👀
021