buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
New.
Zscaler: Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor #infosec #cybercrime #Teams #ransomware #Python
🐸 Zwei Thementage für Kinder und Jugendliche vom Teckkids e.V. auf der FrOSCon!
15. August: alles rund um den Voxel-Spielebaukasten Luanti. Eigene Mods programmieren, eigene Mobs in 3D gestalten, Spiele ausprobieren.
16. August: Spieleprogrammierung mit Python, Pygame und Ursina.
Für alle ab der 4. Klasse bis etwa 16 Jahre. Vorkenntnisse braucht niemand. Angeleitet von jungen Tutor*innen von @Teckids Kosten frei wählbar.
Infos und Anmeldung:
https://teckids.org/blog/2026/06/froglabs-froscon/
I'm manually editing a Python file on a deployed host to fix a known problem in the library that was installed via pip.
It's fixed the problem, telemetry is reporting in. But I feel unclean.
If you use the `setup-uv` #GitHub #Action in your workflows, consider upgrading to version 9.0.0 soon.
This version changes the default behavior to store the downloaded #Python wheels from #PyPI in GHA Cache, shedding load from PyPI, especially relevant for frequent CI/CD runs.
The maintainers considered this a breaking change, hence the version bump, probably because it flips existing expectations.
If you expected that the Action was caching downloads before, now it actually does, so it's a logical fix in that regard.
Read more: https://github.com/astral-sh/setup-uv/releases/tag/v9.0.0
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
Hahaha. Funny.
#ai #llm #vibecoding #software #programming #python #opensource #dev #devops #tech #technology
Want to support the PSF and stock up on #Python books at the same time? The 'Ultimate Python Development' Humble Bundle is available now 🐍 📚 You can customize your donation split: click "Adjust Donation" → "Custom Amount" to boost the % going to the PSF!
https://www.humblebundle.com/books/ultimate-python-development-bundle-packt-books
🏗️ Ich wollte eigentlich nur ein Dokument erstellen.
Jetzt besitze ich versehentlich eine Softwarearchitektur. 😅
Wie das passieren konnte, warum plötzlich Betonmischer, Prüfsummen und Fräulein Müller – die wohl nahezu allwissendste KI aller Zeiten – eine Hauptrolle spielen und weshalb ich mir möglicherweise gerade einen unfairen Wettbewerbsvorteil gegenüber... mir selbst verschaffe, gibt's hier zu lesen:
🚫🐧 Der Raspberry Pi Workshop in der Datenburg Bonn fällt im August wegen Urlaub aus. 🌴
📅 Der nächste Termin ist **Donnerstag, 17.09. Bis dahin suchen wir spannende Projektideen für den Workshop! 💡🔧
Welche Themen oder Bastelprojekte wünscht ihr euch? Schreibt gerne hier eure Vorschläge. 😊
#RaspberryPi #Linux #Maker #DIY #Python #OpenSource #Bonn #Datenburg #Workshop #Hardware
Hey all
I've dumped the #Python course I originally started via Coursera as it was really badly planned.
Instead, I've started the #OpenLearn (Open Uni) short course "Learn to code for data analysis" which uses Pythion and looks pretty good so far.
They want me to use Anaconda with notebooks and Jupytr (sp). So i've downloaded full version of #Anaconda but there appears to be a lot of slop installed in the package, 562 apps. I'm pretty sure some of it is AI related and I dont want to use that.
I know it's a newb question but can I uninstall every app apart from notebooks and jupytr?
The state of #Python ecosystem right now: almost everything is slop. Some projects are complete vibe-coded slop (autobahn, chardet, cryptography). Some projects are disguised slop ("Coding agents shouldn't co-author themselves.")
There is only a handful of human projects left (Flask being one bright example). And they're being killed. They're being killed by the neverending slew of slop pull requests. They're being killed by all their dependencies becoming slop. They're being killed because this whole ecosystem has became such a complete cesspit that you have zero motivation to do anything.
EDIT: and honestly, this is only going to get worse. When you kill the incentive to work on projects, you only get more slop. Maintainers give in, and more projects become slop. Or they give up, and projects get forked unto slop.
I'm a software developer and sysadmin who could really use being #fedihired.
What I'd really like to do is Rust, but once you ignore the dubious scammy stuff, there seems to be nothing out there. Prove me wrong with a counterexample!
I've spent decades fixing Enterprise mudballs mostly written in #Perl. If you've got a crufty legacy system that everybody else is too scared to touch, I'm your man. I love fixing stuff like that.
I've also done commercial #Scala, #Python, #C/#C++, and although I don't usually admit it on my CV but these are now Trying Times when everything is on the table, even #PHP (the longest six months of my life).
Perl naturally leads into Unix system administration and infrastructure. I've built and maintained mail clusters, VoIP systems, network monitoring, DNS management platforms, that sort of thing. If it's non-sexy but something which needs to be done, I'm there.
Available immediately, for contract or permie, onsite in Amsterdam/Randstad or remote to anywhere.
Drop me a private mention or mail peter@mooli.net if you have or know of something.
Hey all! I've signed up for a free 2 week course, an introduction to #Python as thanks to all the wonderful suggestions last week, that is what I have chosen to learn :)
My question is, is there an alternative to Microsoft Visual Studio Code that is not connected to Microsoft, Google and doesnt push AI?? I had a look at Colab but it seems connected to google/gemini.
Thanks!
What's a good active python community that does not use discord?
Jag var idag år gammal när jag lärde mig att det finns en #openSource #Scrivener-klon till #Linux som heter #Manuskript. Fortfarande i beta men ändå. Jag blir lite sugen på att bidra till projektet, det hade gett mig möjligheten att fördjupa mig i #python
Small step for humanity, giant leap for me.
I created (I’m not a professional programmer) a python script to scrape the stock market for my favourites and mail me a technical analysis after closing every day with RSI 14, negative and positive diversity.
Nicely formatted in a table. All of this you can do manually but now I got it served.
For me this helps and makes, well I wouldn’t say life but my day a bit easier
😀
New.
Group-IB: Phishing in the Balkans: Fake Traffic Fines, Real Losses https://www.group-ib.com/blog/balkans-fake-traffic-fines-phishing/
Sekoia: Don’t Eat The ChocoPoCs! How Vulnerability Researchers Were Repeatedly Targeted By Trojanised Exploits https://www.sekoia.com/blog/dont-eat-the-chocopocs-how-vulnerability-researchers-were-repeatedly-targeted-by-trojanised-exploits
Kaspersky: The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign https://securelist.com/tr/the-soc-files-screenconnect-campaign-with-asyncrat/120472/ @Kaspersky
Picus: Amadey Malware Explained: How the Windows Botnet Loader and RAT Work madey-malware-explained-how-the-windows-botnet-loader-and-rat-work
From yesterday:
Symantec: The BYOVD Epidemic: How Attackers Are Weaponizing Trusted Windows Drivers to Kill Security https://www.security.com/threat-intelligence/byovd-vulnerable-drivers #infosec #phishing #threatresearch #Windows #botnet #malware #Python
Literally overheard in another meeting:
"I realize that I am sitting in meetings with developers who are literally prompting claude to write code, and just copypasta that code into the PRs. And I realize to myself. Am I getting more stupid for doing this? Why are we doing this? Why have we been directed to do this? Why am I not fighting this?"
#Claude #Agentic #noAI #python #golang #kotlin #developers #software #whythefuckarewehere
My wife pointed out that I tend to be REALLY LOUD when I'm on a zoom/Meet call for work.
I realized she's right, so I built a tool called "Inside Voice" that beeps at me if my microphone's audio gets louder than an adjustable threshold.
I'm pretty happy with it!
Big news for the #Python packaging world: The inaugural Python Packaging Council election is coming up soon! The council will be the technical decision-making body for Python packaging specs, coordinating across tools, teams, and the wider community. Learn more on the PSF blog:
https://pyfound.blogspot.com/2026/06/packaging-council-inaugural-election.html
An ideal is that it should not happen.
The reality might be Python-related in this case. Two days ago:
Default Python has been upgraded to 3.12 : r/freebsd
<https://www.reddit.com/r/freebsd/comments/1ugdsdk/default_python_has_been_upgraded_to_312/>
<https://www.reddit.com/r/freebsd/comments/1ugdsdk/comment/ou25r7m/> noted the removal of qutebrowser.
I'm told I need pinned posts on my profile.
I'm a #software #engineer living in #Saskatchewan, #Canada, the middle of the prairies. I've worked in countless domains, but find #python generally useful for many of them, and have been using it for nearly 30 years.
I'm a #HouseRabbit enthusiast and have had them for more than 20 years.
Other hobbies include #electronics, #rock music / playing #guitar, writing #FreeSoftware, and enjoying novelty music & #RiffTrax / #CinematicTitanic / #MST3K.
Great coverage from @lwn of the PSF PyPI Safety & Security Engineer @miketheman's talk on Trusted Publishing at Open Source Summit. 36% of @pypi uploads now use Trusted Publishing. Is yours one of them?
This is what collaborative, coordinated, responsible disclosure looks like.
It was a pleasure to work with GitGuardian on this #PyPI #security investigation to help protect the global #Python #SupplyChain
https://blog.gitguardian.com/hunting-leaked-pypi-tokens-62-live-125-packages-exposed/
Also serves as a reminder to adopt Trusted Publishing whenever possible!
https://docs.pypi.org/trusted-publishers/
I've spent years maintaining the UNICORN Binance Suite, dealing with those weird edge cases where WebSockets look alive but are actually dead to your trading strategy.
Since most tutorials completely skip these production-level failure modes, I wrote a comprehensive Python API guide for 2026. It focuses purely on data integrity, proper lifecycle handling, and local depth caches.
If you are building crypto trading tools with Python, I hope this architecture blueprint saves you some sleepless nights.
🔗 https://blog.technopathy.club/the-complete-binance-python-api-guide-2026
The Python Security Response Team patched an authentication bypass in the python.org release management API in under 48 hours. No evidence of exploitation, all artifacts verified.
Check out the full writeup 👇
https://pyfound.blogspot.com/2026/06/mitigated-api-bypass-for-download-metadata-python-dot-org.html
OpenAI is now a Platinum Sponsor of the Rust Foundation, after giving them $600,000. That allows OpenAI to place an OpenAI representative in the Board of Directors of the Rust Foundation.
OpenAI now (theoretically) has great influence over what Rust projects get funding and which don't. Of course the OpenAI representative assures us that he won't be partial to projects that benefit OpenAI and asks us to trust him in advance. He says he wants to direct funding to Rust projects where one dollar would have the highest impact, not necessarily to where it directly benefits OpenAI.
Remember that OpenAI recently bought Astral, the for-profit company that makes uv for Python. That is written in Rust.
OpenAI's agentic coding "assistant" Codex is also written in Rust. Wouldn't every AI bro argue that the highest impact per dollar is achieved by funding an "AI" agent that could then turn every junior developer into a 100x engineer?
My trust needs to be earned. A person could be my brother, and my trust in them would nonetheless vanish the moment he joins OpenAI. Trust is not something I hand out in advance, especially not to OpenAI employees.
The Rust Foundation made the same mistake of accepting dirty money as the Blender Foundation some weeks ago.
By allowing OpenAI into their Board of Directors, the Rust Foundation makes it clear that its members aren't deserving of my trust either.
Of course they also already accept other problematic corporations as sponsors.
Look! It's @sethmlarson and I at the #UNOpenSourceWeek !
We presented, facilitated, and listened to others.
#HIRING! Senior Engineer, #python based full stack but leaning to devops/infra. 70/30 would be my ideal split. Fully remote UK only, £63,000 non negotiable sadly, but ~20% pension on top. Closing date: WEDS NOON! So get in touch (thayer@team-prime.com) asap if this might be you.
Org: healthcare, data, ~30 person team. Zero AI currently in place, but some may be implemented very gently/ethically/thoughtfully over the next year, or not!
Would esp suit someone who prefers chill vs rocket ship.
Sometimes people tell us to "get a job" as if it's that simple.
There are multitudinous good reasons why we:
1. Consider our work for Vulpine Labs and the local community more important than any run of the mill "job".
2. Cannot seriously be expected to attain traditional employment.
3. Shun traditional models of pay in favour of Mutual Aid.
And we won't let capitalism grind us down.
Today, Atha:
Reset the mouse traps in the bus
Cleared snow off the bus and car (altitude does not care for your "seasons", mere mortals)
Got a new phone from a good friend
Set up an LELink LeafSpy OBD2 device to help diagnose and fix the car
Did some reading at the library to get back in the mood for learning Python
And Inara:
Did trans HRT injections
Did some cleaning and tidying
Took the car to do a slow charge session
Did some phone setup
Will likely cook food for us and a homeless friend, and do some VR.
If you want to fling us some currency to keep the mardy old system at bay and fill up the bus's thirsty diesel tank, feel free to send to
https://ko-fi.com/athakitsune or
https://PayPal.me/athamanatha or
Cashapp $athamanatha
Wise and some limited bank transfer options also available on request.
#buslife #poor #mutualaid #pleasedonate #helpfolkslive2026 #helpthehomeless #share4reach #boost4reach #queermutualaid #homeless #queer #homelessmutualaid #trans #transmutualaid #hrt #lgbtq #lgbtqia #lgbtqia2plus #electriccar #diagnostics #EV #nissanleaf #snow #library #books #python #programming #syntax #code #androidphone #unemployable #unemployed #underemployed #volunteering #community #fuelprices #communesandconvoys
I was told about this blog site, a couple of weeks ago. There are interesting pages listed here
The subjects vary in the manner as seen in the first page (check the screencaps)
## What I really like about this place, is that it loads blazingly fast
I also love the fact that you can use browsers in your,
* bash
* csh
* ksh
* zsh
* sh
* fish
* without any bloat just like browsing should be, everywhere
https://rldane.space/junited-2026.html
Thank you @rl_dane
#Blog #site #fast #HTML #great #cool #sweet #nice #programming #Python
iRODS Automated Ingest v0.7.0 is released!
https://github.com/irods/irods_capability_automated_ingest/releases/tag/v0.7.0
Da gibt es so eine LED-Badge in 🔴 oder 🟢 oder 🔵 mit einem programmierbaren LED Feld . Herkunft und Link zum ursprünglichen Bashslript gibts hier.
Das Python GUI hat Dankward, Teilnehner am Wolust gemacht. Ein Fork
https://github.com/dewomser/LED-badge-gui
I'm looking for work, please boost!
I'm a senior software engineer with 35 years of experience. I've worked across an unusually wide range of domains: mobile game backends, privacy-preserving data platforms, high-throughput COVID testing infrastructure, email and account systems, e-payment processing, job marketplace systems, and bioinformatics. I pick up new domains quickly and have a track record of doing it repeatedly. I understand how to turn business needs into engineering requirements.
I've worked remotely since the 1990s and can operate with minimal supervision. I don't need hand-holding to find the right problem to solve. Several of my most valued projects were self-directed: I identified the need, built the thing, and shipped it.
Some of the technologies I'm familiar with include: Python, Perl, TypeScript/JavaScript, Haskell, Go, C, Java. Postgres, MySQL, SQLite. Flask, SQLAlchemy. AWS (Lambda, S3, RDS, SQS, EC2). Docker, Git. Github and Gitlab.
I've also repeatedly picked up new languages and stacks as needed: Haskell for differential privacy research, TypeScript for a 24/7 AWS Lambda system, Flask for my most recent employer. I've become productive with new systems over and over, and I can do it quickly.
I'm also a published author (Higher-Order Perl, Morgan Kaufmann), longtime blogger, and conference speaker with a reputation for making complex ideas clear.
My résumé is at https://plover.com/~mjd/cv/Mark%20Jason%20Dominus.pdf
mjd@pobox.com
Thanks for your attention!
#OpenToWork #remoteWork #softwareEngineering #Python #backend #hiring
I just pushed that procrastination project into Codeberg and Brew BSDCafe. Feel free to test. I do not have intention to continue or fix it except the dynamic systray icon update.
FreeBSD Network Info
https://brew.bsd.cafe/maulanahirzan/FreeBSD-Network-Info
Weekend project that turned into infra I actually run daily: MastoSum.
The stack: RHEL host, 100% rootless Podman. Web on FastAPI, Celery worker/beat/flower, PostgreSQL 16, Valkey. All on userspace networking (pasta), images built & shipped by a self-hosted Forgejo runner. No root daemon, no privileged anything.
What it does: tracks technical hashtags all day and produces one daily briefing, every point linked to the original post + author. It reads only public hashtag timelines, credits every source, and trains on nothing.
And yes, an LLM writes the prose: a local Ministral model from French lab Mistral AI, running on my own hardware. No cloud, nothing leaving the box. Saying that plainly, not burying it. The whole design goal was to point readers *back* at the authors, not replace reading them.
Example output:
https://mastosum.linuxserver.pro/s/OGuLC5whmCS1ET9jAe9leg
Just released ansible_jailexec v1.3.0
It's an Ansible connection plugin I wrote for managing FreeBSD jails. No SSH required.
New in this version: you can now run it without a privilege escalation method (sudo/doas) if you connect Ansible directly to the host as root.
Codeberg: https://codeberg.org/Larvitz/ansible_jailexec/releases/tag/v1.3.0
PyPI: https://pypi.org/project/ansible-jailexec/1.3.0/
GitHub: https://github.com/chofstede/ansible_jailexec/releases/tag/v1.3.0
New.
Sophos: Pointing a Cursor at evading detection https://www.sophos.com/en-us/blog/pointing-a-cursor-at-evading-detection @SophosXOps
More:
Infosecurity-Magazine: https://www.infosecurity-magazine.com/news/ai-edr-evasion-tooling/ #infosec #threatresearch #Python #Telegram
TIL:
```
if not path.exists(path):
return None
with open(path) as f:
f.readline()
```
can fail if the path is deleted between the first and the second block.
Ein Bug (?) in Thonny (#python #ide für Anfänger) kostet mich hier echt Lebenszeit: Unter #linux #kde erscheint der "save as" Dialog HINTER dem Hauptfenster.
Für die Schüler heißt das: Das Programm ist abgestürzt (denn es ist ein modaler Dialog, das Hauptprogramm läuft nicht weiter, wenn dieser nicht beendet wurde).
Das habe ich natürlich schon 1000 mal gezeigt, aber die, die heute nachschreiben, haben das natürlich alle ausnahmslos nicht mitbekommen.
#fediLZ #informatik
When you have the chance do you hire the #automation driven #devops engineer, or the #code (in this case #python and #golang heavy) driven devops engineer.
Le petit plus #fediverse :
**: non, ce n'est pas vrai, mais si je ne le dis pas, ils vont me tomber dessus :-p
Thanks to @sethmlarson we have a new CPython security policy.
I like how it starts:
"Python Security Response Team (PSRT) members balance this work against many other responsibilities. Please be thoughtful about the time and attention your report requires. Repeated failure to respect the security policy will result in future reports being rejected, or the reporter being banned from the python GitHub organization, regardless of technical merit."
https://devguide.python.org/security/policy/
#Python #security
I know "AI" is a polarizing topic around here, but I wanted to share a small side-project I've been tinkering with to scratch a personal itch: MastoSum.
It’s a lightweight web app that listens to public streams, filters for the hashtags I actually care about, and uses an LLM to generate a daily digest of the last 24 hours. Basically, a personalized news feed to help cut through the noise.
It works reasonably well for what I need. Here’s an example of today's run: https://mastosum.linuxserver.pro/s/6q1ZdTOuHBfKyQ3aVU3dOw
So after 1 - 2 weeks doing a lot of #perl i don't get why people say write once language? Its not more ugly than lets say #python or #php or even #js. It's diffrent but in no means ugly or harder than other languages. What do i miss? Yeah i get people obsest with writing the smallest code can write pretty awefull onliners but on the other side its like an hiku or a small poem and by no means you should use that in production or in big applications. You dont use a poem to write a book right?
Hudson River Trading is hiring Experienced C++ Developer, Distributed Compute
🔧 #cplusplus #python #api
🌎 New York City, New York
⏰ Full-time
🏢 Hudson River Trading
Job details https://jobsfordevelopers.com/jobs/experienced-c-developer-distributed-compute-at-hudsonrivertrading-com-apr-4-2025-76a10f?utm_source=mastodon.world&utm_medium=social&utm_campaign=posting
#jobalert #jobsearch #hiring
My employer just announced a "strategic partnership" with Anthropic so I think it's time to try and get #FediHired. I'm a software engineer with 20 years of experience. I consider myself a #Python genralist and also have experience in embedded C (though I haven't done much C in the past few years).
Dear #Python experts, I want to create a graphical progress bar for a command line program that uses ffmpeg to extract audio from mp4 video files.
I suppose at some point I could develop a graphical interface to call the command line programs I use for this process, but that's way more complicated than the complicated thing I want to do now.
The video files are generally different sizes every time.
Can you recommend or point me to a good site that may be of value in this endeavor? I've not had much luck searching on my own.
Ab Juli suche ich eine Stelle als Junior Fachinformatikerin für Anwendungsentwicklung.
Meine Lieblingssprache is #Python, ich habe mehr Erfahrung im Frontend als im Backend, aber möchte mich mehr Richtung letzterem entwickeln.
Ich wohne in Wilhelmshaven, würde für einen guten Job umziehen. Am liebsten wäre mir remote oder zumindest hybrid und nicht nur arbeiten mit KI.
Mehr über mich: https://shidigital.com/
#fediHire #job #fachinformatiker #developer #entwickler #webdev #openSource
I spent some time this weekend writing not only about pizza but about programming, with a focus from python.
Heizungs-Fernsteuerung per SMS
Ich bin Fernpendler. In meiner "Arbeits"-Wohnung benutze ich nur mobiles Internet. Um die Heizung bei Bedarf anschalten zu können, habe ich eine Steuerung gebaut, die auf SMS reagiert.
#Wettbewerb_Frühling_2026 #Automatisierung #SMS #Python #gammu #Linux
#Linux #Python
Diese USB-schaltbare Steckdosenleiste beim Pearl-Versand gekauft 2009 funktioniert immer noch. Und die Links auf meiner Webseite zu Sourceforge tun auch noch.
Das nenn ich mal #Nachhaltigkeit 👍 👍 👍
https://www.wormser-region.de/index5482.html
nvim-ansible: My Neovim config for Ansible and Python just got a substantial refresh:
- modernized for Neovim 0.11 (vim.lsp.config, LspAttach, vim.filetype.add)
- ansible-lint now routed through Mason, sidestepping distro-related issues and ensuring a consistent version
- tighter lazy-loading, full README rewrite
#Python #cryptography library (yes, the one that criticizes everything and everyone) is now vibecoded. Our future is truly bright!
Noticed because apparently "Claude" wrote a test that OOM-ed my system. But hey, #RustLang protects against memory errors, so it's fine to vibecode your security critical components.
This is the old cooling configuration of my Raspberry Pi5. A simple aluminum block cooled by a relatively good yet small fan. There are different ways to read the fan and temperatures of this SBC which may need some simple Python programming
uMap – web application for creating and publishing custom interactive maps
uMap is a web application for creating and publishing custom interactive maps based on OpenStreetMap layers.
#javascript #python #scientific #web-apps
https://www.linuxlinks.com/umap-create-publish-custom-interactive-maps/
📺 https://peer.adalta.social/w/uRWrHsYt3MYqSPztwSAewF
🔗 [🇩🇪🇺🇸🇫🇷](https://adalta.info/articles/prstn_python_116483870317149124_de)
🔗 [ℹ️](https://leanpub.com/naming_shortguide")
Die strategische Chance, Buchautoren zu unterstützen
#python #javascript #java #computer_programming #web_development
Python: Paketbau und Installation
Ein Python-Skript zu schreiben, kann man schnell erlernen. Doch wie sieht es mit der Paketierung und der Installation aus? Dieser Artikel liefert Antworten.
#Linux #Python
Was rauskommt, wenn man die KI zu Knowledgegraph und Mastodon fragt, ist schon erstaunlich. Es ist ein gut dokumentiertes Pythonskrpt geworden.
Das Netz wabert bevor es eine stabile Form annimmt.
https://www.untergang.de/index.php/inhalt/knowledge-graph