James Bennett

@b-list.org

Django/Python guy. Tip your servers and normalize your Unicode. he/him Angry politics and other non-tech parts of me are at @ubernostrum.bsky.social Elsewhere: https://www.b-list.org/ https://infosec.exchange/@ubernostrum https://github.com/ubernostrum

Unfortunately I did not understand in time that the Packaging Council election requires a *separate* voter-enrolling affirmation from other PSF-run elections, so I did not receive a ballot. But if I had, I would have voted Brett at the top of it. He's done incredible work improving Python packaging.

Brett Cannon@brettcannon.mastodon.social.ap.brid.gy · 6d ago

I have to admit that having a company make a corporate blog post about endorsing PPC nominees was a bit startling for me (and not because they didn't endorse me; the people that were listed are all good candidates). I haven't decided if I don't care or if I don't like having a company making […]

Tired: “we were hacked and our password database was exfiltrated and is now being used for credential stuffing” Wired: “Our credential agent broke containment and is now autonomously attacking other services”

re: omarchy trying to create parallel infra to subvert the linux community and kick trans/female/black people out i know some people think that sounds crazy but DHH literally is doing a podcast tour saying that is exactly what he's doing lol

Based on Omarchy’s recent history, evidently trans and marginalized folks are the only ones who can configure a Docker deployment without creating a massive security hole.

That someone who was always a huge asshole in the Before Times still is apparently a huge asshole, But Now With AI, was one of the less surprising things I learned today.

Happy to announce v3.0.0 of my build-and-inspect-python-package GitHub Action that does what the name says. If u maintain a Python pkg u should really give it a look! Much, much fewer broken pkgs have been pushed to PyPI & who doesn't love automatic trove classifier → GHA test matrix conversion‽

Any news report that starts “OpenAI says…” or claims “an AI” (sic) has “broken containment” or “gone rogue” is no longer doing journalism, but PR for the #AI industry. #OpenAI used their product to hack a third-party and failed to implement adequate safeguards. That’s it. That’s the story. #AIHype

They wanted her to make a second effort with reluctant adopters, extol the virtues, etc. She was clearly uncomfortable with this and didn’t do it. But there they all are, bolted to the ceiling, and were just supposed to trust that they aren’t recording, that nothing is being “trained” 3/

A quick shadow drop of sorts: who hasn't implemented a cache on top of Postgres? I know, everyone has. And yet, here's another contender that's based on psycopg and can use existing SQLAlchemy engines (or whatever you implement): ⚡️psycache ⚡️ 1/2