Sign in

Bruno Alla

@browniebroke.com
484 followers 170 following 46 posts

Backend engineer, Pythonista, Djangonaut, OSS maintainer. French 🇫🇷 living in London 🇬🇧

PostsRepliesMedia
Reposted by Bruno Alla
Dane Hillard @dane.dev · 04/08/2026
AHHHHHH WAKE UP GRAB THE DEPS AND DO A LITTLE SHAKE UP HIDE REMOTE CODE EXECUTION’S MAKEUP WHY’D YOU LEAVE THAT VECTOR ON THE TABLE SHOULD’VE CLOSED THAT GAPING HOLE WITH FABLE YOU WANTED TO — System o̶f̶ ̵a̶ is Down
022
Reposted by Bruno Alla
Tom Mullaney @tommullaney.bsky.social · 26/07/2026
I have not seen anything from LLMs, image generators, NotebookLM, or any generative AI that justify the suffering their data centers cause. And this story isn't even Boxtown. youtu.be/9wDr2dec474?...
youtu.be
Neighbors say noise from Michigan data center is 24/7 and upending their lives
YouTube video by WXYZ-TV Detroit | Channel 7
64928
Reposted by Bruno Alla
Mike McQuaid @mikemcquaid.com · 13/05/2026
Open source maintainers at profitable companies: stop asking permission to fix what your employer already depends on. No paperwork. No programme. No manager’s blessing. Just maintain it on the clock.
ossresistance.com
Open Source Resistance
A direct-action manifesto for maintainers keeping open source alive on company time.
319344
Reposted by Bruno Alla
Anthony Shaw @anthonypjshaw.bsky.social · 24/03/2026
🚨litellm was compromised via a supply chain vulnerability. Package releases included a credential stealing script. 1.82.8 - includes a malicious .pth file (litellm_init.pth) 1.82.7 - includes a malicious payload in proxy_server.py github.com/BerriAI/lite...
github.com
[Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 — credential stealer · Issue #24512 · BerriAI/litellm
[LITELLM TEAM] - For updates from the team, please see: #24518 [Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 PyPI package — credential stealer Summary The litellm==1.82.8 wheel...
123
Bruno Alla @browniebroke.com · 18/03/2026
Django REST Framework 3.17 has just been released 🎉 Long overdue release with official support for Django 6.0 and Python 3.14 Also, new docs theme ✨ (and many others changes) pypi.org/project/djan... #python #django #drf djangorestframework
pypi.org
djangorestframework · PyPI
Web APIs for Django, made easy.
020
Reposted by Bruno Alla
Steve Klabnik @steveklabnik.com · 04/02/2026
hey can anyone tell me if this is good or not
20 different 'activate your account' emails for services i don't use
351438
Reposted by Bruno Alla
Steve Klabnik @steveklabnik.com · 15/01/2026
How to think about Gas Town: steveklabnik.com/writing/how-...
steveklabnik.com
How to think about Gas Town
Blog post: How to think about Gas Town by Steve Klabnik
2113816
Reposted by Bruno Alla
Tim A. @flipperpa.bsky.social · 20/11/2025
Give the wonderful folks on your systems and security teams lots of pats on the back. This is the hellscape they inhabit daily.
Updated XKCD "All modern digital infrastructure" looking even more perilous.
2167
Reposted by Bruno Alla
Hugo van Kemenade @hugovk.dev · 07/10/2025
Just released! 🚀 Please install and enjoy Python 3.14! 🥧 discuss.python.org/t/python-3-1... #Python #Python314 #release
Two snakes enjoying a pie with 3.14 on the top and π crimping.
14825
Bruno Alla @browniebroke.com · 06/10/2025
Current status: trying to give Django 6.0a1 a spin on one of my project. Refuses to install as some of my dependencies require Django<6.0 grrrr Forked them and removes the upper version pin, everything run smoothly grrr iscinumpy.dev/post/bound-v... #python #django #packaging
iscinumpy.dev
Should You Use Upper Bound Version Constraints? -
Bound version constraints (upper caps) are starting to show up in the Python ecosystem. This is causing real world problems with libraries following this recommendation, and is likely to continue to get worse; this practice does not scale to large numbers of libraries or large numbers of users. In this discussion I would like to explain why always providing an upper limit causes far more harm than good even for true SemVer libraries, why libraries that pin upper limits require more frequent updates rather than less, and why it is not scalable. After reading this, hopefully you will always consider every cap you add, you will know the (few) places where pinning an upper limit is reasonable, and will possibly even avoid using libraries that pin upper limits needlessly until the author updates them to remove these pins. If this 10,000 word behemoth is a bit long for you, then skip around using the table of contents, or see the TL;DR section at the end, or read version numbers by Bernát Gábor, which is shorter but is a fantastic read with good examples and cute dog pictures. Or Hynek’s Semantic Versioning Will Not Save You Be sure to check at least the JavaScript project analysis before you leave! Also be warned, I pick on Poetry quite a bit. The rising popularity of Poetry is likely due to the simplicity of having one tool vs. many for packaging, but it happens to also have a special dependency solver, a new upper bound syntax, and a strong recommendation to always limit upper versions - in direct opposition to members of the Python core developer team and PyPA developers. Not all libraries with excessive version capping are Poetry projects (like TensorFlow), but many, many of them are. To be clear, Poetry doesn’t force version pinning on you, but it does push you really, really hard to always version cap, and it’s targeting new Python users that don’t know any better yet than to accept bad recommendations. And these affect the whole ecosystem, including users who do not use poetry, but want to depend on libraries that do! I do really like other aspects of Poetry, and would like to eventually help it build binary packages with Scikit-build (CMake) via a plugin, and it has some great developers. If I don’t pick on Poetry enough for you, don’t worry, I have a follow-up post that picks on it in much more detail. Also, check out pdm, which gives many of the benefits of Poetry while following PEP standards. Also pixi, which works with the Conda ecosystem. If you come across something that can’t be solved, try using --exclude-newer <DATE> in uv and pdm. This limits the solve by ignoring packages newer than some date.
130
Reposted by Bruno Alla
Rodrigo Girão Serrão 🐍🚀 @mathspp.com · 31/08/2025
A good example of what `functools.Placeholder` from Python 3.14 allows.
Code diagram showing usage of functools.Placeholder.
Full code:

from functools import Placeholder as _P, partial
import string

remove_punctuation = partial(
    str.translate,
    _P,
    str.maketrans("", "", string.punctuation),
)

remove_punctuation("Hello, world!")
# 'Hello world'
2214
Bruno Alla @browniebroke.com · 12/08/2025
@pythonbytes.fm a small shameless plug to follow up on episode 444 on the topic of squashing Django migrations github.com/browniebroke... @mkennedy.codes @brianokken.bsky.social #django #migrations
github.com
GitHub - browniebroke/django-remake-migrations: A Django admin command to recreate all migrations in a project.
A Django admin command to recreate all migrations in a project. - browniebroke/django-remake-migrations
020
Reposted by Bruno Alla
Flagpie @finecuppacoffee.bsky.social · 19/07/2025
2118
Reposted by Bruno Alla
Hynek Schlawack @hynek.me · 11/07/2025
Since I've seen/heard it a few times now: Where the hell is the nonsense coming from that Python data classes are not allowed/supposed to have methods!? Is it their name (that I was somewhat unhappy w/ for that reason)? Did Eric or Guido say something I've missed? 1/4
4143
Reposted by Bruno Alla
Hynek Schlawack @hynek.me · 06/07/2025
Almost 4 months later, here it finally is: uv: Making Python Local Workflows Fast and Boring in 2025 youtube.com/watch?v=TiBI... 1/3
youtube.com
65518
Reposted by Bruno Alla
Charlie Marsh @crmarsh.com · 03/07/2025
The uv build backend is now stable, and considered ready for production use. An alternative to setuptools, hatchling, etc. for pure Python projects, with a focus on good defaults, user-friendly error messages, and performance. When used with uv, it's 10-35x faster.
523643
Reposted by Bruno Alla
Randall Munroe @xkcd.com · 19/06/2025
David R. Hagen just solved a small mystery that I mentioned 13 years ago in the mouseover text of a comic drhagen.com/blog/the-mis...
drhagen.com
The Missing 11th of the Month - David R Hagen
Personal website of David R Hagen, scientific software engineer
603182601
Reposted by Bruno Alla
Natalia @nessita.bsky.social · 09/06/2025
📣 The DSF is hiring a Django Fellow! A paid, full-time role to help maintain Django. All the good stuff plus you'll be joining a dedicated team of Fellows 💚 Interested or know someone great? 👉 Apply by July 1: www.djangoproject.com/weblog/2025/... #Django #Python #OpenSource
djangoproject.com
DSF calls for applicants for a Django Fellow
Posted by The Fellowship Working Group on June 9, 2025
01311
Reposted by Bruno Alla
Gergely Orosz @gergely.pragmaticengineer.com · 10/06/2025
What is happening right now? ChatGPT/OpenAI outage for 3 hours Heroku down for 4 hours (even their status page is down!) NVIDIA dev docs as well (runs on Heroku) Pipedrive (CRM) issues for 4 hours What else is down… and are these connected? Something started 4 hours ago…
1317328
Reposted by Bruno Alla
Sam Rose @samwho.dev · 06/06/2025
If you've not tried it, pressing ? on any GitHub page will bring up a selection of keyboard shortcuts. I wish the window these are in were a little bigger but it shows you what's possible. I find going through notifications much easier with a keyboard than it ever was with a mouse.
071
Reposted by Bruno Alla
Steve Klabnik @steveklabnik.com · 28/05/2025
I am disappointed in the AI discourse steveklabnik.com/writing/i-am...
steveklabnik.com
I am disappointed in the AI discourse
209911178
Reposted by Bruno Alla
Sam Rose @samwho.dev · 28/05/2025
This piece is perfect. I am prepared to link this to people dozens of times over the next few years. I am the antithesis of what’s described. If you care, follow me. I don’t care if there’s only a hundred of you, what I care about is we follow each other. dansinker.com/posts/2025-0...
dansinker.com
The Who Cares Era | dansinker.com
6455
Reposted by Bruno Alla
Gina Häußge @foosel.net · 21/05/2025
On that note, huge thanks to @daniel.haxx.se for allowing me to copy & extend curl's recent AI guidelines for my projects. I've just added a corresponding section to OctoPrint's Contribution Guidelines and Security Policy: github.com/OctoPrint/Oc... octoprint.org/security/
2122
Reposted by Bruno Alla
Brett Cannon @brettcannon.fosstodon.org.ap.brid.gy · 18/05/2025
The trailer for the Python documentary is out! youtu.be/pqBqdNIPrbo?si=9LLlghqZkJR…
124
Reposted by Bruno Alla
Tom @moll.dev · 17/05/2025
Just Write moll.dev/notes/justwr...
moll.dev
Just Write - Moll.dev
75310
Reposted by Bruno Alla
Josh W. Comeau @joshwcomeau.com · 02/05/2025
The folks behind the “State of …” surveys have a new one, and there are zero questions about coding! Instead, the focus is on us. ✨ The questions are about developer interests, health, work preferences, stuff like that. I’m *super* keen to see the results! You can take the survey here:
survey.devographics.com
State of Devs 2025
Take the State of Devs survey
110331
Reposted by Bruno Alla
Adam Johnson @adamj.eu · 02/05/2025
👏 Congrats to @browniebroke.com for this DX improvement PR finally getting merged! A nice little boost for 'startproject' and 'startapp' 🚀 #Django github.com/django/djang...
github.com
Fixed #18296 -- Create custom target directory if missing in startproject and startapp by browniebroke · Pull Request #18387 · django/django
Trac ticket number ticket-18296 Branch description Given the following project structure, where apps is a directory: . ├── apps ├── manage.py └── myproject ├── __init__.py ├── asgi.py ...
131
Reposted by Bruno Alla
Hugo van Kemenade @hugovk.dev · 26/04/2025
pip 25.1 has been released and maintainer Richard Si has a great writeup about it, including: - #PEP735 dependency groups - Package installation progress bar - Resumable downloads - #PEP751 experimental lockfile generation: pip lock ichard26.github.io/blog/2025/04... #Python #pip #packaging
ichard26.github.io
What's new in pip 25.1 - Dependency groups!
pip 25.1 introduces support for Dependency Groups (PEP 735), resumable downloads, and an installation progress bar. Dependency resolution has also received a raft of bugfixes and improvements.
0228
Bruno Alla @browniebroke.com · 24/04/2025
How to enjoy debugging in production by Karen Tracey @djangoconeurope #djangoconeurope #djangoconeurope2025
031
Bruno Alla @browniebroke.com · 24/04/2025
How to enjoy debugging in production by Karen Tracey @djangoconeurope #djangoconeurope #djangoconeurope2025
000
Bruno Alla @browniebroke.com · 24/04/2025
How we make decisions in Django by @carltongibson.bsky.social #djangoconeurope #djangoconeurope2025
010
Bruno Alla @browniebroke.com · 24/04/2025
How to get foreign key wrong by Haki Benita #djangoconeurope #djangoconeurope2025
000
Bruno Alla @browniebroke.com · 24/04/2025
And we're on for day 2 with @clytaemnestra.bsky.social #djangoconeurope #djangoconeurope2025
010
Bruno Alla @browniebroke.com · 24/04/2025
And we're on for day 2 with Mia Bajić #djangoconeurope #djangoconeurope2025
000
Bruno Alla @browniebroke.com · 23/04/2025
And now @adamj.eu presenting data-oriented django drei #djangoconeurope #djangoconeurope2025
001
Bruno Alla @browniebroke.com · 23/04/2025
@timb07.bsky.social turning back time to upgrade to bigint at scale #djangoconeurope #djangoconeurope2025
000
Reposted by Bruno Alla
Django @djangoproject.com · 23/04/2025
Celebrate Django’s 20th birthday with us at DjangoCon Europe! #DjangoConEurope
0114
Bruno Alla @browniebroke.com · 23/04/2025
Second talk of the day #djangoconeurope #djangoconeurope2025
000
Reposted by Bruno Alla
Sarah Abderemane @sabderemane.bsky.social · 23/04/2025
DjangoCon Europe starts 🫶🏽 #djangoconeurope #djangoconeurope2025
DjangoCon Europe screen with the sponsors in it. There is a green banner "happy birthday" and green balloons 20 with green stars on the top of the numbers
021
Bruno Alla @browniebroke.com · 16/04/2025
Great read from @Matthias Endler about traits of great programmers endler.dev/2025/best-pr... via @changelog.com #changelog #news #dev
endler.dev
The Best Programmers I Know | Matthias Endler
I have met a lot of developers in my life. Late…
020
Reposted by Bruno Alla
Gergely Orosz @gergely.pragmaticengineer.com · 16/04/2025
Interesting to reflect how much of an impact @xkcdComic has had on tech culture - expressing making (mostly) universal truths via simple to understand comics So many golden nuggets. Like this classic:
1815210
Reposted by Bruno Alla
Bernát Gábor @gjbernat.bsky.social · 12/04/2025
Thanks for the kind words @willingc.bsky.social 🙏 gaborbernat.github.io/new-wave-of-...
151
Reposted by Bruno Alla
Gina Häußge @foosel.net · 12/04/2025
Currently reading "Burnout" by Emily and Amelia Nagoski in preparation for a talk and am once more reminded that this quote is something we all need to hear more...
You are not here to be “productive.” You are here to be you, to engage with your Something Larger, to move through the world with confidence and joy. And to do that, you require rest.

—Burnout
Emily & Amelia Nagoski
1143
Reposted by Bruno Alla
Rodrigo Girão Serrão 🐍🚀 @mathspp.com · 11/04/2025
Use the type `Literal` in your Python function signatures for arguments that represent options. This is better than using the general type that the configurations fall into. Stricter is better since it'll catch more bugs, earlier. It also helps document the valid values.
Diagram showing an example usage of Literal.

Instead of the signature:

def get_temperature(city: str, unit: str) -> int: ...

Use the following signature:

from typing import Literal

def get_temperature(
    city: str,
    unit: Literal["celsius"] | Literal["fahrenheit"],
) -> float:
    ...

print(get_temperature("Lisbon", "celsius"))  # 18.0
print(get_temperature("Lisbon", "fahrenheit"))  # 64.4
381
Reposted by Bruno Alla
Django London @handle.invalid · 06/04/2025
We’ve "migrated" a second talk into our April 8 meetup at Kraken Tech: @adamj.eu's "Data-Oriented Django Drei" on database indexes. Alongside David Imba Zorto's “How to Use Cursor as a Professional” If you can’t make it, please free your spot 👉 bit.ly/43L35eM #DjangoLondon #Python #Meetup
A dark-themed code snippet showing a Django migration for an app named ‘meetup.’ It adds a second speaker field set to ‘Adam Johnson,’ a talk field named ‘Data-Oriented Django Drei,’ and a ‘performance’ field labeled ‘Zoom-level indexes.
033
Bruno Alla @browniebroke.com · 06/04/2025
I'm late to the party but I'm considering travelling to @djangoconeurope - where are people staying? (the hotel conference is fully booked) #django #djangoconeu
000
Reposted by Bruno Alla
Adam Johnson @adamj.eu · 18/03/2025
I just got a GitHub DX PR merged into Django 😊 Use this one weird trick to activate GitHub’s Django templates/Jinja syntax highlighting. #Django #GitHub github.com/django/djang...
github.com
Made GitHub apply Django template syntax highlighting to HTML files. by adamchainz · Pull Request #19279 · django/django
Trac ticket number n/a Branch description Added a linguist override to make our templates render with its Jinja (alias Django) language on GitHub. Before: After: Checklist This PR targets the m...
1142
Bruno Alla @browniebroke.com · 07/03/2025
How well how am I doing @profanity.accountant
100
Bruno Alla @browniebroke.com · 03/03/2025
New post: Introducing django-remake-migrations browniebroke.com/blog/2025-03... #django #python #migrations #database
browniebroke.com
Introducing django-remake-migrations
Bruno Alla's personal site and blog - about programming, and other random things that interest me.
132