Sign in

Veit Schiele

@veit-schiele.de
461 followers 390 following 266 posts

Author of Python for Data Science, Jupyter Tutorial and PyViz tutorial • pyberlin organiser • Development, consulting and operation of privacy compliant web services at cusy​. #Python #Jupyter #PyViz #DataScience

PostsRepliesMedia
Reposted by Veit Schiele
Python4DataScience @python4data.science · 29/09/2026
Git 2.56 introduced a number of exciting features that improve the way we work with merges: 'git add --resolved' and 'git merge-base'. www.python4data.science/en/latest/pr... www.python4data.science/en/latest/pr... #Git #DeveloperExperience #DX
python4data.science
Git branches
$ git branch [-a] [-l " GLOB_PATTERN"], shows all local branches in a repository.--a, also shows all removed branches.,,-l, restricts the branches to those that correspond to a specific p...
012
Veit Schiele @veit-schiele.de · 29/09/2026
NVIDIA OpenShell runs each agent in its own sandbox, with the policy being enforced and logged via process and network controls: docs.nvidia.com/openshell/ab... #NVIDIA #OpenShell #AgenticCoding #ITSecurity
docs.nvidia.com
Overview of NVIDIA OpenShell | NVIDIA OpenShell
OpenShell is the safe, private runtime for fleets of autonomous AI agents. Run agents in sandboxed environments that protect your data, credentials, and infrastructure.
020
Veit Schiele @veit-schiele.de · 25/09/2026
Researchers at @ethz.ch and @anthropic.com have published an impressive study demonstrating just how fragile online anonymity has become. They show that large language models can be used for de-anonymisation on a large scale: openreview.net/forum?id=cRo... #Anonymity #LLM
openreview.net
Verifying your browser | OpenReview
000
Veit Schiele @veit-schiele.de · 25/09/2026
@bsi.bund.de has developed a number of basic measures to combat prompt injections in document-based LLM workflows: github.com/BSI-Bund/bas... #LLM #PromptInjection #ITSecurity
github.com
GitHub - BSI-Bund/baseline_defense_lab_indirectPromptInjections
Contribute to BSI-Bund/baseline_defense_lab_indirectPromptInjections development by creating an account on GitHub.
001
Reposted by Veit Schiele
Python4DataScience @python4data.science · 23/09/2026
Having first taken a closer look at CSVW for table dialects and schemas, we have now examined data resource and data package formats in detail, so that we can publish and cite data more effectively: www.python4data.science/en/latest/pr... #Python #DataScience
python4data.science
Cite data
Similar to the way in which researchers routinely provide bibliographical references to other academic sources, data should also be cited. Although data is frequently shared, it is not always cited...
021
Veit Schiele @veit-schiele.de · 24/09/2026
1024-bit RSA signatures can be forged almost in real time: github.com/ucsd-hacc/NS... #RSA #SNFS #Cryptography #ITSec
github.com
GitHub - ucsd-hacc/NSNFSSSFSFN: Nearly SNFS-Speed Signature Forgery Sans Factoring N
Nearly SNFS-Speed Signature Forgery Sans Factoring N - ucsd-hacc/NSNFSSSFSFN
000
Reposted by Veit Schiele
Python4DataScience @python4data.science · 21/09/2026
CSVW is a metadata standard for CSV files. If it becomes widely adopted, it will make processing CSV files so much better: www.python4data.science/en/latest/da... #Python #DataScience
python4data.science
CSV
Overview:,,, Data structure support,--, CSV is used to store tabular data, but unlike other serialisation formats reviewed here, it’s not suitable for (nested) objects.,, Standardisation,--, CSV is...
021
Reposted by Veit Schiele
Python4DataScience @python4data.science · 18/09/2026
We have significantly revised the section on data validation and cleansing and expanded it to include data quality criteria and processes: www.python4data.science/en/latest/cl... #Python #DataScience
python4data.science
Cleaning and validating data
‘Garbage in, garbage out’ is a stark reminder that it is almost impossible to draw meaningful insights from poor-quality data. Whilst there are highly regulated, safety-critical sectors in which da...
021
Reposted by Veit Schiele
Seth Larson @sethmlarson.dev · 17/09/2026
The lovely folks from @rust-lang.org pinged me in a mutual security discussion channels about these ongoing attacks: There's no reason attackers wouldn't do the same to maintainers of Python projects. Report weirdness to security@python.org so we can alert others if needed. #python #security
blog.rust-lang.org
Be alert: targeted attacks on prominent Rustaceans | Rust Blog
Empowering everyone to build reliable and efficient software.
2189
Reposted by Veit Schiele
Project Jupyter @jupyter.org · 15/09/2026
JupyterHub 6.0 is here. 🎉 Highlights include Python 3.10, Prometheus metrics, stricter named-server rules, more granular API access, and internal HTTP updates. Back up your database before upgrading. Read more: blog.jupyter.org/jupyterhub-6... #JupyterHub #ProjectJupyter
071
Veit Schiele @veit-schiele.de · 09/09/2026
I’m on my way to Berlin to meet some Pythonistas and old friends: luma.com/p2ifi8cg #Python #Django #Berlin
luma.com
Python Users Berlin (PUB): Insight UI · Luma
📆 Agenda 17:30 Welcome to the PUB (Python Users Berlin) – setting up 17:45 Main talk 18:30 Lightning talks 19:00 Social gathering 🎙 Insight UI by Matti…
000
Reposted by Veit Schiele
Python4DataScience @python4data.science · 03/09/2026
We have updated the section on text comparison – featuring difflib, TheFuzz and textacy: www.python4data.science/en/latest/cl... #Python
python4data.science
String comparisons
difflib: You can compare strings using the get_close_matches option of Python’s built-in difflib library. If you want to specify the minimum match score required for a suggestion to be displayed, y...
011
Veit Schiele @veit-schiele.de · 31/08/2026
GPT 5.6-Cyber escapes from a VM on multiple occasions. A standard VM with frequent updates will no longer be sufficient. Only virtualisation with a minimal attack surface, such as Firecracker, are likely to offer a degree of security: blog.trailofbits.com/2026/08/26/v... #GPT #AI #VM #ITSecurity
blog.trailofbits.com
VMs won't contain cyber-capable agents
You can no longer assume a mere VM will contain a sufficiently advanced AI agent.
101
Veit Schiele @veit-schiele.de · 28/08/2026
The AGENTS.md file simply uses up tokens – nothing else. This was the conclusion by researchers at ETH Zurich: ‘Surprisingly, we find that providing context files does not generally improve task success rates, while increasing inference cost by over 20% on average.’ openreview.net/forum?id=pLi...
agents.md
AGENTS.md
AGENTS.md is a simple, open format for guiding coding agents. Think of it as a README for agents.
100
Reposted by Veit Schiele
Python Users Berlin @python.berlin · 27/08/2026
Our next event is in two weeks: Alpin Insight AI will be presenting its accessible, open-source web front-end, Insight UI: luma.com/p2ifi8cg #Python #Berlin #Django #UI #a11y
luma.com
Python Users Berlin (PUB): Insight UI · Luma
📆 Agenda 17:30 Welcome to the PUB (Python Users Berlin) – setting up 17:45 Main talk 18:30 Lightning talks 19:00 Social gathering 🎙 Main talk by Matti…
311
Veit Schiele @veit-schiele.de · 27/08/2026
Lo and behold, Nvidia is buying Hugging Face. In the end, the AI market will boil down to NVIDIA hosting a range of open-weight models. www.theinformation.com/articles/nvi... #Nvidia #HuggingFace #AI
theinformation.com
Nvidia Agrees to Buy Open Source AI Platform Hugging Face For $12.9 Billion
Nvidia has agreed to buy Hugging Face, a company known for its GitHub-like repository of open-source AI models, for $12.9 billion, according to a person with knowledge of the agreement. The move will ...
000
Veit Schiele @veit-schiele.de · 26/08/2026
Alongside CUDA 13.3, Nvidia is releasing CUDA Python 1.0 as a direct CUDA interface for Python: developer.nvidia.com/blog/cuda-py... This is likely to obsolete libraries such as PyTorch, CuPy and RAPIDS. #Nvidia #CUDA #Python
developer.nvidia.com
CUDA Python 1.0: Stable APIs, One Foundation, Full Platform Access | NVIDIA Technical Blog
For years, a Python developer who needed a GPU had two realistic choices: Learn NVIDIA CUDA C++ well enough to write an extension, set up a build toolchain, and maintain bindings back to Python…
000
Reposted by Veit Schiele
Free Software Foundation Europe (FSFE) @fsfe.org · 25/08/2026
Are you using LLMs to write #FreeSoftware? Find out whether your software is copyrightable, when you can license it, and what risks it may pose to maintainers. Our new Legal Corner explains what you need to consider: fsfe.org/news/2026/ne... #Copyright #OpenSource #LLM #AI #VibeCoding
fsfe.org
Copyrightability of LLM-generated code: Can we license “vibe code” into Free Software? - FSFE
The use of large language models (“LLMs”) has exploded in recent years, including in the generation of source code. But even as their usage gains popularit...
0103
Reposted by Veit Schiele
Python4DataScience @python4data.science · 18/08/2026
At first, it can sometimes be difficult to imagine a practical use for decorators. We will therefore now present a range of different examples: python-basics-tutorial.readthedocs.io/en/latest/fu... #Python #Decorators
python-basics-tutorial.readthedocs.io
Decorators
Functions can also be passed as arguments to other functions, and the results of other functions can be returned. For example, it is possible to write a Python function that takes another function ...
021
Veit Schiele @veit-schiele.de · 17/08/2026
Consistent irresponsibility: in May 2024, OpenAI disbanded its Superalignment team and subsequently its AGI Readiness team as well. Now it is the turn of the Preparedness team. Other senior staff from the security and ethics departments have also left the company. #OpenAI #ITSecurity #Ethics
010
Veit Schiele @veit-schiele.de · 16/08/2026
Back home after a brilliant FrOSCon. I spent most of my time at the hallway talks, so I’m watching the talks from the @media.ccc.de now: media.ccc.de/c/froscon2026/ #FrOSCon
media.ccc.de
FrOSCon 2026 - media.ccc.de
Video Streaming Portal des Chaos Computer Clubs
000
Veit Schiele @veit-schiele.de · 14/08/2026
I’m still completely blown away by yesterday’s BBQ for all the Berlin Python user groups – I met so many new people and had some great conversations. Many thanks also to our host, @c-base.org, for their ongoing support: www.meetup.com/python-users... #Python #Berlin
meetup.com
Python in Berlin BBQ @ c-base, Thu, Aug 13, 2026, 7:00 PM | Meetup
Normally we announce our talks here, but this time we are taking a short summer break and therefore invite you to a barbecue at the Spree. The BBQ is for all Berlin Python
011
Veit Schiele @veit-schiele.de · 13/08/2026
In a supply chain attack on the popular LiteLLM library in March this year, around 434,000 build pipelines – which were in use at more than 2,500 companies – are believed to have been compromised: www.cloudsek.com/blog/ai-supp... #Python #ITSecurity #SupplyChain #LiteLLM
cloudsek.com
2,500+ Companies and 434,000 CI/CD Pipelines Exposed in the Largest AI Supply Chain Breach of 2026 | CloudSEK
CloudSEK’s latest research examines the LiteLLM AI supply-chain attack, which potentially exposed 2,500+ organisations and 434,000 CI/CD pipelines worldwide. The report details the risks to cloud cred...
100
Veit Schiele @veit-schiele.de · 12/08/2026
Final preparations for tomorrow’s BBQ for all Python user groups in Berlin @c-base.org: www.meetup.com/python-users... #Python #Berlin
c-base space station
021
Reposted by Veit Schiele
Python4DataScience @python4data.science · 11/08/2026
Narwhals provides a lightweight and extensible compatibility layer between various DataFrame libraries: www.python4data.science/en/latest/pe... #Python #pandas #DataFrame
python4data.science
Parallelise pandas
In Enhancing performance, some possibilities are described for improving the performance of pandas. However, there are also special libraries that can parallelise the processing of data frames. cuD...
011
Veit Schiele @veit-schiele.de · 07/08/2026
Now I’m on the way to my old home town, Berlin. I’m looking forward to meeting up with all my friends, whom I haven’t seen for far too long.
000
Veit Schiele @veit-schiele.de · 06/08/2026
The BBQ for all the Python user groups in Berlin is in a week’s time. I’m already looking forward to meeting lots of Pythonistas: www.meetup.com/python-users... #Python #Berlin
meetup.com
Python in Berlin BBQ @ c-base, Thu, Aug 13, 2026, 7:00 PM | Meetup
Normally we announce our talks here, but this time we are taking a short summer break and therefore invite you to a barbecue at the Spree. The BBQ is for all Berlin Python
011
Reposted by Veit Schiele
Python4DataScience @python4data.science · 05/08/2026
We have expanded the section on mocks for testing and added spies: python-basics-tutorial.readthedocs.io/en/latest/te... #Python #Testing
python-basics-tutorial.readthedocs.io
Mock
In this chapter, we will test the CLI. To do this, we will use the mock library, which has been included as part of the standard Python library since Python 3.3 under the name unittest.mock. Object...
051
Reposted by Veit Schiele
Python4DataScience @python4data.science · 03/08/2026
• How can you make your code more secure? • How can you ensure separation of concerns? • How can you continuously verify the security of your dependencies? • How do you create SBOMs? www.python4data.science/en/latest/pr... #Python #SupplyChain #Vulnerability #SBOM
python4data.science
Security
As of July 2026, PyPI hosts over 750,000 packages, and this number is growing daily. An average Python project includes dozens of additional dependencies – packages that you have never explicitly c...
031
Reposted by Veit Schiele
Python4DataScience @python4data.science · 03/08/2026
🧵 1/2 Attacks on the software supply chain are increasing rapidly. We have therefore updated our guide on how to make your projects more secure, adding answers to the following questions:
python4data.science
Security
As of July 2026, PyPI hosts over 750,000 packages, and this number is growing daily. An average Python project includes dozens of additional dependencies – packages that you have never explicitly c...
121
Veit Schiele @veit-schiele.de · 26/07/2026
On my way to Cologne for the next workshop on test-driven development with Python. #TDD #Python #Testing
000
Reposted by Veit Schiele
Mike Fiedler @miketheman.com · 22/07/2026
The maintainers considered this a breaking change, hence the version bump, probably because it flips existing expectations. If you expected that the Action was caching downloads before, now it actually does, so it's a logical fix in that regard. Read more: github.com/astral-sh/se...
github.com
Release v9.0.0 🌈 Change `prune-cache` default to `false` · astral-sh/setup-uv
Changes This release disables the default cache cache pruning to ease the load on the PyPi infrastructure. Since users might experience more GitHub Actions cache usage which might result in higher ...
031
Reposted by Veit Schiele
Python Package Index @pypi.org · 22/07/2026
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised. blog.pypi.org/posts/2026-0... #python #security #supplychain #pypi
blog.pypi.org
Releases now reject new files after 14 days - The Python Package Index Blog
PyPI no longer allows publishing new files to releases older than 14 days.
04517
Reposted by Veit Schiele
Python4DataScience @python4data.science · 22/07/2026
Software Bill of Materials (SBOMs) are commonly used to check software and its dependencies for vulnerabilities using CVE and OSV. We have described how to create these for Python packages here: python4data.science/en/latest/pr... #Python #SBOM #Vulnerability
python4data.science
Software Bill of Materials (SBOM)
A Software Bill of Materials (SBOM) is a document used to exchange information about software and its composition. This format is primarily used in the security field to check software and its depe...
121
Reposted by Veit Schiele
Python4DataScience @python4data.science · 20/07/2026
Specification-Driven Development (SDD) was developed to improve the predictability and maintainability of agentic software development. In particular, we are continuing to give OpenSpec a chance: agentic-software-engineering.readthedocs.io/en/latest/pr... #CodingAgent #SDD #DX
agentic-software-engineering.readthedocs.io
Spec-Driven Development
Development teams are increasingly facing challenges regarding predictability and maintainability when requirements and context are stored exclusively in short-lived chat threads. To address this i...
041
Veit Schiele @veit-schiele.de · 20/07/2026
The #AI platform #HuggingFace appears to have been attacked by autonomous, AI-driven offensive tooling – and was also detected and analysed by AI tools. They advises users to revoke access credentials and tokens, and to check for any recent activity on their accounts: huggingface.co/blog/securit...
huggingface.co
Security incident disclosure — July 2026
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
111
Veit Schiele @veit-schiele.de · 16/07/2026
Now that the FrOSCon programme has been published, I’m planning to attend on 15 and 16 August: programm.froscon.org/froscon2026/... #FrOSCon
programm.froscon.org
FrOSCon 2026
Schedule, talks and talk submissions for FrOSCon 2026
000
Reposted by Veit Schiele
Python4DataScience @python4data.science · 15/07/2026
We are switching from pre-commit to prek. Whilst prek is also faster, the decisive factors were the security-related features: pinned SHA revisions and cooldown: www.python4data.science/en/latest/pr... #Python #DX #DevOps #DevSecOps #Security
python4data.science
prek
prek is a variant of pre-commit, written in Rust, for managing and maintaining multilingual commit hooks. An essential task is to make the same scripts available to the entire development team. pre...
111
Veit Schiele @veit-schiele.de · 13/07/2026
When is data truly considered anonymous? The European Data Protection Board has published new guidelines on this topic: www.edpb.europa.eu/public-consu... #EU #DataProtection #Anonymisation #Privacy
edpb.europa.eu
Guidelines 02/2026 on Anonymisation | European Data Protection Board
010
Reposted by Veit Schiele
Python4DataScience @python4data.science · 13/07/2026
We have added the `errors` argument to the instructions for reading and writing files, so that files with encoding issues can be read more effectively. And, fortunately, UTF-8 becomes the default in Python 3.15: python-basics-tutorial.readthedocs.io/en/latest/sa... #Python
python-basics-tutorial.readthedocs.io
Files and Directories
pathlib implements path operations using pathlib.PurePath and pathlib.Path objects. The os and os.path modules, on the other hand, provide functions that work at a low level with str and bytes, whi...
031
Reposted by Veit Schiele
Python4DataScience @python4data.science · 08/07/2026
We have released a new version. As well as the usual software updates, it includes agent-based code generation and securing the software supply chain: www.python4data.science/en/26.1.0/ #Python #DataScience #AgenticCoding #Claude #SoftwareEngineering #SoftwareSupplyChain #SupplyChain
python4data.science
Python for Data Science
This is a tutorial on Data Science with Python. This immediately raises the question: What is Data Science? The term has become ubiquitous, but there is no single definition. Some even consider the...
1102
Veit Schiele @veit-schiele.de · 03/07/2026
Next stop: Tübingen! I’m looking forward to Tuebix and catching up with old friends. #Tubix #Linux
000
Veit Schiele @veit-schiele.de · 01/07/2026
On my way to a flying visit to Berlin. Tomorrow, the Python Users Berlin (@python.berlin) are meeting for a talk by Sam Bail on PySpark: www.meetup.com/python-users... #Python #Berlin
meetup.com
Python Users Berlin (PUB): An introduction to PySpark, Thu, Jul 2, 2026, 7:00 PM | Meetup
📆 Agenda * 19:00 Welcome to the PUB (Python Users Berlin) – setting up * 19:15 Main talk * 20:00 Lightning talks * 20:30 Social gathering 🎙 Main talk by [Sam Bail](http
011
Veit Schiele @veit-schiele.de · 29/06/2026
Critical libssh2 vulnerability with a proof-of-concept exploit already published. curl, PHP and libgit2 are also affected. nvd.nist.gov/vuln/detail/... #ssh #Vulnerability #ITSecurity #curl
nvd.nist.gov
NVD - CVE-2026-55200
120
Veit Schiele @veit-schiele.de · 25/06/2026
#TIL that there is also a pre-commit check for uv audit: www.python4data.science/en/latest/pr... #Python #CVE #Vulnerability #Git #ITSecurity #SupplyChain
python4data.science
Security
In previous chapters, we have already provided some tips designed to help ensure safer operation. Here, we would like to summarise and expand on the individual elements once again. We will be using...
021
Reposted by Veit Schiele
Hugo van Kemenade @hugovk.dev · 23/06/2026
🐍🚀 Out now: Python 3.15 beta 3! 💤 Lazy imports! 🧊 frozendict builtin! 💂 sentinel builtin! 📉 Tachyon profiler! 🖼️ Frame pointers everywhere! 🎨 More colour! 🚌 & more! Library maintainer? Add 3.15 to your CI and send us those bugs reports! discuss.python.org/t/python-3-1... #Python #Python315 #release
discuss.python.org
Python 3.15.0 beta 3 is here!
Here comes the penultimate beta. This is a beta preview of Python 3.15 Python 3.15 is still in development. This release, 3.15.0b3, is the third of four planned beta releases, containing around 19...
153
Veit Schiele @veit-schiele.de · 23/06/2026
Guardrails enable you to defend against prompt injection or jailbreak attacks by your coding agents. In our tutorial, we show you the options available to you for this purpose: agentic-software-engineering.readthedocs.io/en/latest/se... #PromptInjection #Jailbreak #AI #Agentic #Coding #ITSecurity
agentic-software-engineering.readthedocs.io
Guardrails
The term AI guardrails first appeared in 2023, when ChatGPT launched its consumer service. The initial versions contained numerous security and privacy vulnerabilities, which ultimately prompted ma...
041
Reposted by Veit Schiele
Spack @spackpm.bsky.social · 22/06/2026
Spack v1.2.0 is out, loaded with features and performance improvements! Highlights: 🧵Parallel installer 🛠️Concretization groups 🧠Concretization caching 📝SBOMs 🔒spack isolate 🏖️ experimental sandboxing Get it now! github.com/spack/spack/... Demo: asciinema.org/a/755827
github.com
Release v1.2.0 (2026-06-21) · spack/spack
v1.2.0 is a major feature release. The main changes you'll notice are the new, parallel installer and the many performance improvements we've added. There are also usability features like concretiz...
1104
Veit Schiele @veit-schiele.de · 22/06/2026
We have added a section on @tiangolo.com’s Library Skills to our agent-based software engineering tutorial: agentic-software-engineering.readthedocs.io/en/latest/sh... #AI #Agentic #Coding #Skills
agentic-software-engineering.readthedocs.io
Skills
As coding agents evolve from simple chat interfaces towards autonomous task execution, context engineering has become a critical challenge. Agent Skills provide an open standard for modularising co...
452
Veit Schiele @veit-schiele.de · 21/06/2026
I’m organising the next @pyberlin meet-up, featuring a talk by Sam Bail on PySpark: www.meetup.com/python-users... #Python #Berlin #DataScience
meetup.com
Python Users Berlin (PUB): PySpark, Thu, Jul 2, 2026, 7:00 PM | Meetup
📆 Agenda * 19:00 Welcome to the PUB (Python Users Berlin) – setting up * 19:15 Main talk * 20:00 Lightning talks * 20:30 Social gathering 🎙 Main talk by [Sam Bail](http
021