Brett Cannon
OpenAI is buying Astral https://openai.com/index/openai-to-acquire-astral/
1. I'm happy Astral got their exit (which we all knew was the end goal)
2. I'm glad no one will accuse me of trying to kill the company anymore by working on standards or saying there are other workflow tools
3. I'm taking a wait-and-see view (e.g. Astral already said more AI is coming to their tools https://blog.pamelafox.org/2026/03/learnings-from-pyai-conference.html#:~:text=Astral%20is%20also%20re%2Dprioritizing%20based%20off%20the%20move%20towards%20100%25%20agentic%20coding%2C%20with%20less%20emphasis%20on%20tools%20that%20would%20be%20used%20solely%20by%20a%20developer%20who%20is%20manually%20typing.)
4. I'm going to continue to work on standards for a baseline workflow experience to make my kid happy someday
I said digital attestations and `pylock.toml` would have helped with the litellm attack. People asked for more details, so I wrote a blog post explaining why. It also hopefully acts at motivation for people to use:
- Trusted publishing
- Digital attestations
- Lock files, and `pylock.toml` specifically
https://snarky.ca/why-pylock-toml-includes-digital-attestations/
So yes, @jni@fosstodon.org , I have a "human-readable intro" because I wrote one for you (and the other folks asking me questions on the subject). 😁
Wasmtime now has GC and exception handling support!
https://bytecodealliance.org/articles/wasmtime-gc
The GC support is useful for having much smaller Wasm files when you compile straight to Wasm (i.e. my WASI builds won't use it).
The exception handling support should help with long jumps in C code. For Python that would be useful for porting MicroPython to WASI.
RE: @dangoodin@infosec.exchange
Notice how the compromised releases were directly uploaded. This is why `pylock.toml` includes attestation data and trusted publishing is important. If the project used trusted publishing then their the lack of attestation data could have been noticed in a diff of the lock file as it would have suddenly disappeared (which is also why `pylock.toml` was designed to be human-readable).
For those interested in a very simple build back-end for Python extension modules, I came across https://just-buildit.github.io/just-buildit/ .
I should mention that the redirect file solution was directly inspired by @simon to solve his "I keep my code in cloud backup directory, so I don't want my venv backed up as well" problem which is known as the "Simon Willison Problem" in my head (and I was so tempted to brand that term in the PEP)
My latest blog post got into the recent edition of the Crux by @daedalus@eigenmagic.net and now I feel like I've met a goal I didn't know I had (been a reader for while now). Next goal: to be called a "friend-of-the-Crux" in a future newsletter 😁
The final release of Python 3.9 is out!
https://discuss.python.org/t/the-final-python-3-9-security-fix-release-is-out/104666
May you all enjoy using the features added in Python 3.10 if that's now your oldest version. 😁
Wrote a blog post to give a status update on WASI support for CPython as PEP 816 got accepted!
https://snarky.ca/state-of-wasi-support-for-cpython-march-2026/
@judy2k @pauleveritt I'm competing against the creator of the PEP process and someone who sits on stage w/ Paul reminiscing about the early days of Python for 3rd place. It's going to take Barry retiring from contributing for me to catch up.
@digiglean@fosstodon.org I just listened to episode 292 and you can tell the other Christopher that I appreciate the support with PEP 832 and that some version of the PEP will get submitted if simply because I think I have enough support from tool authors to make it worth it.
The Q&A from EuroPython for the special 20 minute preview cut of the Python documentary that covered @mariatta@fosstodon.org and @mitsuhiko@hachyderm.io 's sections is now up!