Anže

@anze3db.pecar.me

Writing Python and surfing waves 🏄‍♂️

We benchmarked 15 models for triaging vulnerabilities. * Kimi K3 came out on top but marked a true positive as a false positive ☠️ * Opus 5 refused to give a verdict on 11 vulnerabilities * Sonnet 5 and Luna outperformed Terra and Sol Full post 👇 www.fencer.dev/blog/llm-tr...

Benchmarking 15 LLMs on SAST false-positive triage

We benchmarked 15 LLMs on 142 real security findings to triage SAST false positives. Kimi K3 led on accuracy, with one caveat that matters for security.

fencer.dev

I asked Claude to come up with writing guidelines based on my blog posts: > A few things I deliberately did not encode as guidelines: the frequent typos (characteristic of your fast publishing cadence) 88 blog post in 14 years is not fast publishing cadence 😅

We reviewed 4,978 mypy runs in our Django app: • 4,731 green • 246 failed Of the 246 failures: • 173 false positives • 73 real issues • 39 caught only by mypy and no other check! Some noise, but it prevented real bugs from reaching production. 🎉

After 9 meetups full of talks, lightning talks, and even lightning turtles, it's time for the Python Lisbon Meetup to take it easy. Join us at Linha d'Água on Thursday to relax and enjoy the summer in Lisbon with Python friends 🐢 www.meetup.com/python-lisb...

#10 – PyLM Meetup – Social Get-Together, Thu, Jul 2, 2026, 7:00 PM | Meetup

🇬🇧 After 9 meetups full of talks, lightning talks, and even lightning turtles, it's time to take it easy. Join us at Linha d'Água — the café by the lake in Parque Eduardo

meetup.com

The Claude usage page is very confusing. Since Sonnet has a separate bar I thought I'd be able to switch to it after I max out Opus, but nope. Of course this all makes sense if you actually read the tooltip/labels but who does that today anyway? 😅

BildBild

Running Claude in a loop to push our test coverage. After 24+ hours and 22,000 new lines of tests, coverage climbed from 92% to 95%. No clue if it’ll get merged, but it's a really fun experiment 👀

Bild

Over the last week, I've been reviewing PyCon Portugal talk and workshop proposals, and I just finished reviewing them all! 😎 Some really good ones in the mix that got me really excited about the conference in September. Make sure to grab your ticket! 2026.pycon.pt

Bild

Fedidevs had quite an outage today. It went offline just as I went to bed and I didn't see it until I woke up this morning 🫣 Still better uptime than GitHub 😅

Bild

🚨 There was another supply chain attack, this time affecting tanstack npm packages. Make sure you haven't installed the compromised packages either in your CI or locally. I would also hold off on updating any dependency for the next week or so until the dust settles from this.

I told Claude to upgrade my Raspberry Pi from Debian 12 to 13 and went to enjoy my Sunday. It wasn't an easy upgrade. apt kept tripping over Debian's t64 transition, but Claude managed to unstuck it. When I came back, the box rebooted cleanly into Debian 13. 😲

I wrote a few words about the Agents Day hachaton that I attended last week on Friday. It's always fun to have an excuse to spend a day tinkering with something new. I even managed to be one of the 5 that got to demo their project on stage! 👉 blog.pecar.me/agents-day-...

BildBild

We have another Python Lisbon Meetup coming up on Thursday 🐍 This time Yulia will be giving a talk on strong and weak references! See you on May 7 @ 19:00 at IST, Pavilhão de Matemática, room 3.10!

With recent Python supply chain attacks (Trivy/LiteLLM), it’s worth mentioning uv’s `exclude-newer = "x days"` config. It forces uv to only installs packages published more than x days ago, reducing risks since problematic packages should be yanked by then. docs.astral.sh/uv/referenc...

Can't wait for lazy imports in Python 3.15! I spent a bunch of time and tokens over the weekend inlining heavy imports so that they don't get loaded during initial start of a Django app. The `manage.py check` command is now 3.8x faster (9.45s down to 2.48s).