My dog kept me in Zone 2 for 3kms. Then I had to drop him off and immediately made bad decisions. 💛
We benchmarked 15 models for triaging vulnerabilities. * Kimi K3 came out on top but marked a true positive as a false positive ☠️ * Opus 5 refused to give a verdict on 11 vulnerabilities * Sonnet 5 and Luna outperformed Terra and Sol Full post 👇 www.fencer.dev/blog/llm-tr...
Benchmarking 15 LLMs on SAST false-positive triage
We benchmarked 15 LLMs on 142 real security findings to triage SAST false positives. Kimi K3 led on accuracy, with one caveat that matters for security.
fencer.dev
I do think it nailed my voice though!
I asked Claude to come up with writing guidelines based on my blog posts: > A few things I deliberately did not encode as guidelines: the frequent typos (characteristic of your fast publishing cadence) 88 blog post in 14 years is not fast publishing cadence 😅
I asked Claude to come up with writing guidelines based on my blog posts: > A few things I deliberately did not encode as guidelines: the frequent typos (characteristic of your fast publishing cadence) 88 blog post in 14 years is not fast publishing cadence 😅
We reviewed 4,978 mypy runs in our Django app: • 4,731 green • 246 failed Of the 246 failures: • 173 false positives • 73 real issues • 39 caught only by mypy and no other check! Some noise, but it prevented real bugs from reaching production. 🎉
After 9 meetups full of talks, lightning talks, and even lightning turtles, it's time for the Python Lisbon Meetup to take it easy. Join us at Linha d'Água on Thursday to relax and enjoy the summer in Lisbon with Python friends 🐢 www.meetup.com/python-lisb...
#10 – PyLM Meetup – Social Get-Together, Thu, Jul 2, 2026, 7:00 PM | Meetup
🇬🇧 After 9 meetups full of talks, lightning talks, and even lightning turtles, it's time to take it easy. Join us at Linha d'Água — the café by the lake in Parque Eduardo
meetup.com
One of my servers lost DNS after every single reboot, and it was driving me crazy. ping 8.8.8.8 worked, ping google.com didn't, and the fix never stuck. Turned out to be a config from 2010. I finally debugged it properly with Claude. blog.pecar.me/the-15-year...
The 15-Year-Old iptables Rule That Broke My DNS
One of my servers has a weird problem after every reboot: it can ping IP addresses just fine, but it can’t resolve any DNS names. $ ping 8.8.8.8 # works $ ping google.com # ping: google.com: Temporary failure in name resolution I’ve been working around this for a while now: after every reboot I’d SSH in and overwrite /etc/resolv.conf to point straight at 8.8.8.8 instead of the local 127.0.0.53 stub. That got DNS working again, but it was never a real fix. /etc/resolv.conf is regenerated on boot, so my edit vanished the next time the machine came up and I was back to fixing it by hand. This time I decided to attempt to properly debug it with Claude.
blog.pecar.me
The Claude usage page is very confusing. Since Sonnet has a separate bar I thought I'd be able to switch to it after I max out Opus, but nope. Of course this all makes sense if you actually read the tooltip/labels but who does that today anyway? 😅
Oh, I didn’t know GitHub doesn’t have pagination in the Commits tab of a pull request. 😅
Make sure to always reuse your botoclients. Initializing a fresh one on each task has A LOT of overhead!
Running Claude in a loop to push our test coverage. After 24+ hours and 22,000 new lines of tests, coverage climbed from 92% to 95%. No clue if it’ll get merged, but it's a really fun experiment 👀
Over the last week, I've been reviewing PyCon Portugal talk and workshop proposals, and I just finished reviewing them all! 😎 Some really good ones in the mix that got me really excited about the conference in September. Make sure to grab your ticket! 2026.pycon.pt
Claude wrote up a Cloudflare-style post mortem: blog.pecar.me/fedidevs-pos...
Fedidevs Postmortem
Today I had almost 9 hours of downtime on fedidevs.com and some of my other sites that I run on a Raspberry Pi at home. The alert came in just as I was heading to bed and I didn’t see it until I woke ...
blog.pecar.me
Fedidevs had quite an outage today. It went offline just as I went to bed and I didn't see it until I woke up this morning 🫣 Still better uptime than GitHub 😅
Fedidevs had quite an outage today. It went offline just as I went to bed and I didn't see it until I woke up this morning 🫣 Still better uptime than GitHub 😅
Months of training runs with my dog. Went solo today and broke almost every PR I had. He’s the real coach 🐕
The supply chain attack has now spread to PyPI: mistralai: 2.4.6 guardrails-ai: 0.10.1 Pause your dependency updates or use package cooldowns (--uploaded-prior-to flag in latest pip) Stay safe!
🚨 There was another supply chain attack, this time affecting tanstack npm packages. Make sure you haven't installed the compromised packages either in your CI or locally. I would also hold off on updating any dependency for the next week or so until the dust settles from this.
🚨 There was another supply chain attack, this time affecting tanstack npm packages. Make sure you haven't installed the compromised packages either in your CI or locally. I would also hold off on updating any dependency for the next week or so until the dust settles from this.
I told Claude to upgrade my Raspberry Pi from Debian 12 to 13 and went to enjoy my Sunday. It wasn't an easy upgrade. apt kept tripping over Debian's t64 transition, but Claude managed to unstuck it. When I came back, the box rebooted cleanly into Debian 13. 😲
I wrote a few words about the Agents Day hachaton that I attended last week on Friday. It's always fun to have an excuse to spend a day tinkering with something new. I even managed to be one of the 5 that got to demo their project on stage! 👉 blog.pecar.me/agents-day-...
We have another Python Lisbon Meetup coming up on Thursday 🐍 This time Yulia will be giving a talk on strong and weak references! See you on May 7 @ 19:00 at IST, Pavilhão de Matemática, room 3.10!
Finally wrote up my notes from DjangoCon Europe 2026 in Athens 🇬🇷 I climbed the Acropolis, ate great food, hung out with amazing people, gave a lightning talk, and fixed one regression in Django main during the sprints. blog.pecar.me/djangocon-e...
DjangoCon Europe 2026
Before the conference My partner and I arrived in Athens a few days before the conference. It was a convenient excuse to visit a European capital we hadn’t been to yet, and of course to eat as much delicious food as possible. Django Social One day before the conference I went to the django.social event organized by Jon Gould and Andrew Miller. The bar they initially picked got too crowded, so the group moved to the backup place. I came late to the first bar, found no one there, and was a bit lost until I made it to the right spot. Once I did, I felt immediately at home. I met old friends, made some new ones, and had a very fun evening. So fun, in fact, that I forgot to take any photos, so I have no social proof that I was there 😅
blog.pecar.me
With all the supply chain attacks going around, we have to be very careful about how we update our dependencies. I've written a full blog post about it, but here is the TLDR: 1. Pin to hashes, not just versions 2. Automate the updates 3. Use dependency cooldowns blog.pecar.me/how-to-safe...
How to Safely Update Your Dependencies
With all the supply chain attacks happening lately (litellm being the most recent example) keeping dependencies up to date without risk has been on my mind. Below is everything I do to keep my personal projects secure, what we do at Fencer to keep our own codebase secure, and what we recommend to the startups we work with. Be hesitant about what you add The best way to reduce the risk of installing a compromised dependency is to avoid relying on it in the first place. Before adding a new dependency, I first make sure that implementing it ourselves would be too much work (or tokens!).
blog.pecar.me
Everyone’s favorite web framework is now also in the gelato business 🤤
Another Python Lisbon Meetup in the books! Looking forward to the next one on May 7 👀
I'll be giving a talk about lazy imports at the next Python Lisbon Meetup! See you there? 😀 www.meetup.com/python-lisb...
I'll be giving a talk about lazy imports at the next Python Lisbon Meetup! See you there? 😀 www.meetup.com/python-lisb...
#07 - PyLM Meetup at Técnico 🎓🐍, Thu, Apr 2, 2026, 7:00 PM | Meetup
**Agenda:** * 25-minute talk: **Speed Up Your Startup Times with Lazy Imports** by [Anže Pečar](https://pecar.me/) * One or more lightning talks ⚡ * Socializing! **Join t
meetup.com
With recent Python supply chain attacks (Trivy/LiteLLM), it’s worth mentioning uv’s `exclude-newer = "x days"` config. It forces uv to only installs packages published more than x days ago, reducing risks since problematic packages should be yanked by then. docs.astral.sh/uv/referenc...
I wrote a post on how we tracked down slow imports in our Django app, fixed them by making imports lazy, and added a lint check to prevent regressions. Now I’m waiting for Python 3.15 to make all of this easier! 🚀 blog.pecar.me/speeding-up...
Speeding Up Django Startup Times with Lazy Imports
At Fancer we are building the security suite for startups. Startups use a lot of SaaS tools and services which means we are building a lot of integrations. Most of these go through API calls but we also try to leverage SDKs to make our lives a little bit easier. The problem we started noticing was that loading all these 3rd party integrations has made our Django app feel very sluggish. While this was noticeable around deployments and starting scans, it hurt the most during local development. It was taking around 10s to run ./manage.py check which meant that any Django command ended up being slow. Devs felt this the most with development server restarts and when running tests.
blog.pecar.me
Can't wait for lazy imports in Python 3.15! I spent a bunch of time and tokens over the weekend inlining heavy imports so that they don't get loaded during initial start of a Django app. The `manage.py check` command is now 3.8x faster (9.45s down to 2.48s).