Today I migrated some Go code to Python and made it 590x FASTER 😎
Anže
mastodon 4.7.3Writing Python
, Django
and surfing waves 🏄♂️
Projects:
🧑💻 https://fedidevs.com find awesome devs across the fediverse
💻 https://github.com/anze3db/django-tui a TUI for all your Django commands
With recent Python supply chain attacks (Trivy/LiteLLM), it’s worth mentioning uv’s `exclude-newer = "x days"` config.
It forces uv to only installs packages published more than x days ago, reducing risks since problematic packages should be yanked by then.
I asked Claude to come up with writing guidelines based on my blog posts:
> A few things I deliberately did not encode as guidelines: the frequent typos (characteristic of your fast publishing cadence)
88 blog post in 14 years is not fast publishing cadence 😅
My dog kept me in Zone 2 for 3kms. Then I had to drop him off and immediately made bad decisions. 💛
With all the supply chain attacks going around, we have to be very careful about how we update our dependencies. I've written a full blog post about it, but here is the TLDR:
1. Pin to hashes, not just versions
2. Automate the updates
3. Use dependency cooldowns
https://blog.pecar.me/how-to-safely-update-your-dependencies/
Everyone’s favorite web framework is now also in the gelato business 🤤
We benchmarked 15 models for triaging vulnerabilities.
* Kimi K3 came out on top but marked a true positive as a false positive ☠️
* Opus 5 refused to give a verdict on 11 vulnerabilities
* Sonnet 5 and Luna outperformed Terra and Sol
Full post 👇
https://www.fencer.dev/blog/llm-triage-sast-false-positives
I wrote a blog post about some of the options for adding type checking to your Django project!
Historically, Django projects have been tough to type-check, but the future feels bright, especially if PEP 827 gets accepted!
I wrote a post on how we tracked down slow imports in our Django app, fixed them by making imports lazy, and added a lint check to prevent regressions.
Now I’m waiting for Python 3.15 to make all of this easier! 🚀
https://blog.pecar.me/speeding-up-django-startup-times-with-lazy-imports/
We reviewed 4,978 mypy runs in our Django app:
• 4,731 green
• 246 failed
Of the 246 failures:
• 173 false positives
• 73 real issues
• 39 caught only by mypy and no other check!
Some noise, but it prevented real bugs from reaching production. 🎉
After 9 meetups full of talks, lightning talks, and even lightning turtles, it's time for the Python Lisbon Meetup to take it easy.
Join us at Linha d'Água on Thursday to relax and enjoy the summer in Lisbon with Python friends 🐢
https://www.meetup.com/python-lisbon-meetup/events/315420890/
Can't wait for lazy imports in Python 3.15! I spent a bunch of time and tokens over the weekend inlining heavy imports so that they don't get loaded during initial start of a Django app.
The `https://manage.py check` command is now 3.8x faster (9.45s down to 2.48s).
A bug that survived 15 years of upgrades.
One of my servers lost DNS after every reboot. ping 8.8.8.8 worked; ping https://google.com didn't resolve. I'd been "fixing" it by hand-editing /etc/resolv.conf, which, of course, was reset on the next boot. 🙈
Turned out to be a config from 2010. I finally debugged it properly with Claude.
https://blog.pecar.me/the-15-year-old-iptables-rule-that-broke-my-dns
I've finished #adventofcode 2025 and this is the first year that I managed to get all solutions under 100ms ⚡
All but two are under 10ms. Not bad for the slowest popular language out there 🐍, although I did have to use numpy a few times.
Another Python Lisbon Meetup in the books! Looking forward to the next one on May 7 👀
I'll be giving a talk about lazy imports at the next Python Lisbon Meetup!
See you there? 😀
Make sure to always reuse your botoclients. Initializing a fresh one on each task has A LOT of overhead!
I wrote a blog post about this year's Advent of Code. I had a blast and I am already looking forward to 2026!
* All my Python solutions were under 1s using pure Python and 100ms with a little help from mypy/scipy
• The AoC community is the best ❤️
Like pretty much everyone with a static blog site in the last 6 months, I asked Claude to migrate it to a different static site generator.
Here's a blog post about it, along with some of my general thoughts on agentic code.
The Claude usage page is very confusing. Since Sonnet has a separate bar I thought I'd be able to switch to it after I max out Opus, but nope.
Of course this all makes sense if you actually read the tooltip/labels but who does that today anyway? 😅
Oh, I didn’t know GitHub doesn’t have pagination in the Commits tab of a pull request. 😅

