Sr. Content Developer at Microsoft, working remotely in PA, TechBash conference organizer, former Microsoft MVP, Husband, Dad and Geek.
162419 stories
·
33 followers

JetBrains Joins the Open Source Security Foundation

1 Share

JetBrains has joined the Open Source Security Foundation (OpenSSF) as a general member. OpenSSF is a cross-industry initiative of the Linux Foundation that works to secure the software supply chain on which the industry depends. The foundation announced our membership today, together with other new members, at OpenSSF Community Day Europe in Prague, co-located with Open Source Summit Europe.

OpenSSF is home to projects that many teams already rely on, including Sigstore for signing and verifying software and SLSA for supply chain integrity. Its AI/ML Security Working Group publishes guidance on signing machine learning models and on writing safe instructions for AI code assistants.

Open Source Security Foundation General Member

Why we are joining

As coding agents take on more development work, code becomes cheaper to produce but more expensive to verify, and much of that verification is security work. Developers need to know where their code and dependencies come from, and AI adds new questions about how to trust the models and assistants that help write it.

JetBrains Air is how we are working on these questions in our own products, helping developers understand and verify what agents produce. OpenSSF is where we can work on the same questions out in the open, with the wider industry.

“Software development is at an inflection point. AI is changing how software is built and creating new security challenges, making it more important than ever that developers can understand, verify, and trust the software they produce.

JetBrains has supported professional software development for more than two decades, and we believe staying ahead of these challenges is best done collaboratively and in the open. OpenSSF brings together some of the strongest expertise in the industry, and we are glad to join the community and help shape the future of secure software development.”

– Katherine Druckman, Head of Community and Partnership Engagement, JetBrains

We want to stay ahead of the security questions AI raises, and help guide how the industry answers them. OpenSSF is the right place to do both.

Looking ahead

Developers trust JetBrains tools with their code every day. We take that trust seriously, and supporting the community working to make software more secure is part of how we aim to keep earning it. We look forward to working alongside the rest of the OpenSSF community.

Read the whole story
alvinashcraft
just a second ago
reply
Pennsylvania, USA
Share this story
Delete

Critter Stack Update with Jeremy Miller

1 Share
The Critter Stack is growing! Carl and Richard talk with Jeremy Miller about the latest Critter Stack updates, including Marten, Wolverine, and more! First up is the stack's expansion with Polecat and Fisher, versions of Marten built for SQL Server 2025 and SQLite, respectively. Jeremy also talks about the evolution of event sourcing and how the framework continues to advance to take advantage of new approaches to managing fast, timely data flows. The conversation also digs into how AI is impacting frameworks, including the continued need for reliable frameworks so you can focus on providing value to your customer. But also in the AI vein is the AI Skills for the Critter Stack - so your AI development tools can work as effectively as possible, and get your application built!



Download audio: https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/75608463/dotnetrocks_2023_critter_stack_update.mp3
Read the whole story
alvinashcraft
26 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

PPP 524 | Why More Discipline May Not Be the Answer, with 100 Days of Rejection expert Jia Jiang

1 Share

Summary

In this episode, Andy talks with Jia Jiang, bestselling author of Rejection Proof and creator of the 100 Days of Rejection experiment, about his new book, Easy Discipline. Growing up in Beijing, Jia was taught the value of chi ku, or "eating bitterness," the idea that the more pain you can tolerate, the more you can achieve. The problem? He was terrible at it. Over time, he discovered that his best work came when he was having the most fun.

Andy and Jia explore what easy discipline does and doesn't mean, why action goals can work better than outcome goals, and how stepping into a character, like a consultant instead of a salesperson, can change your results. They also discuss how project leaders can build a momentum loop early, how a single one-action goal can help turn around a struggling project, why some efforts work best as time-boxed sprints, and how to tell normal resistance from work that simply doesn't fit who you are. Jia closes with stories of how he and his wife apply easy discipline as parents.

If you're looking for a more sustainable way to stay consistent without constantly fighting yourself, this episode is for you!

Sound Bites

  • "It literally translates into English as eating bitterness.... The idea is the more bitterness, the more pain you can tolerate, the higher achievement you can go to."
  • "If work ethic is the only thing that matters, the best factory workers will be the richest people in the world, right?"
  • "It's really the inner drive that takes us to go a long way."
  • "I did programming to achieve a goal, to achieve some sort of success. He did programming for fun."
  • "The things I didn't like to do? I failed miserably. For the things I like to do, I was doing them so well."
  • "If you can tap into the 'play' part of yourself, the enjoyment part, that's where you are at your best, even at work."
  • "Having a deadline, having a finish line is sometimes magical."
  • "The key for me as a parent is this: How do I enjoy being with them more?"

Chapters

  • 00:00 Introduction
  • 01:58 Start of Interview
  • 02:08 Seen as Lazy and Hopeless: Learning to "Eat Bitterness"
  • 04:53 Grind Culture and the Myth of Hard Work Alone
  • 06:21 Elon Musk and the Power of Inner Drive
  • 08:00 What Easy Discipline Doesn't Mean
  • 09:11 Chasing the Bill Gates Dream
  • 11:42 Fired and Rehired by the Same Boss
  • 13:26 Applying Easy Discipline to Losing Weight
  • 16:05 Outcome Goals vs. Action Goals
  • 17:48 What Jia Still Hasn't Made Enjoyable
  • 20:28 Getting Into Character
  • 22:36 Accessing a Real Part of Yourself at Work
  • 23:43 Building a Momentum Loop Early in a Project
  • 26:05 Delivering Early and Finding Stakeholder Support
  • 27:14 One Action Goal for a Struggling Project
  • 29:22 Why Jia Told a CEO to Stop After 100 Days
  • 31:03 When Fast-Tracking Everything Backfires
  • 32:33 Normal Resistance or the Wrong Work?
  • 35:22 Living Someone Else's Dream
  • 37:23 Easy Discipline as Parents
  • 41:02 End of Interview
  • 41:44 Andy Comments After the Interview
  • 45:27 Outtakes

Learn More

You can learn more about Jia and his work at JiaJiang.com. You can also watch his TED Talk, What I Learned from 100 Days of Rejection.

For more learning on this topic, check out:

  • Episode 522 with Ross Blankenship and Maggie Sass. Their book Friction shares related ideas about reducing the friction in what we do.
  • Episode 377 with Cassie Holmes. She's a happiness researcher who shares evidence-based approaches to live and work with more meaning and joy.
  • Episode 242 with James Clear about his bestselling book, Atomic Habits, which has a lot in common with turning hard things into habits.

Chat with PMeLa

You can chat directly with PMeLa, the podcast's AI persona, to get episode recommendations and answers to your project management and leadership questions. Visit PeopleAndProjectsPodcast.com/PMeLa to chat with her.

Join Us for LEAD52

I know you want to be a more confident leader–that's why you listen to this podcast. LEAD52 is a global community of people like you who are committed to transforming their ability to lead and deliver. It's 52 weeks of leadership learning, delivered right to your inbox, taking less than 5 minutes a week. And it's all for free. Learn more and sign up at GetLEAD52.com. Thanks!

Thank you for joining me for this episode of The People and Projects Podcast!

Talent Triangle: Power Skills

Topics: Discipline, Motivation, Habits, Goal Setting, Momentum, Project Management, Leadership, Stakeholder Engagement, Career Development, Self-Awareness, Intrinsic Motivation, Parenting

The following music was used for this episode:

Music: Imagefilm 034 by Sascha Ende
License (CC BY 4.0): https://filmmusic.io/standard-license

Music: Laughing Children Full Version by MusicLFiles
License (CC BY 4.0): https://filmmusic.io/standard-license





Download audio: https://traffic.libsyn.com/secure/peopleandprojectspodcast/524-JiaJiang.mp3?dest-id=107017
Read the whole story
alvinashcraft
33 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

MBW 1045: The iCup Specialist - Will We Finally See an Apple Smart Home Device?

1 Share

We could finally see Apple launch new smart home products this month. iPhone Duo apparently has a 'replaceable' folding display layer to help minimize crease visibility. Apple is changing Full Disk Access in macOS. And Apple's latest AirPods, AirPods 5, get a better reparability score from iFixit!... from 0 to 2.

  • Apple is finally ready to enter its next big category: the smart home.
  • 'Get Ready' to pre-order the iPhone Duo starting October 12.
  • Apple says iPhone Duo has 'replaceable' folding display layer to minimize crease.
  • iPhone Duo inner display has a replaceable $19 top layer.
  • Apple's reportedly developing a smart home camera that doesn't record video.
  • iCup Supply Specialist.
  • iOS 27.2 adds new Messages feature that's already a favorite.
  • iPhone 18 Pro Max cameras are Apple's best yet, but only when you squint.
  • Apple is changing Full Disk Access in macOS.
  • iFixit teardown of the new AirPods 5 reveals first real repairability improvement.
  • Apple & American Academy of Pediatrics team up for new Screen Time guide.
  • Watch Elton John give the first-ever performance at Apple Music Hall.
  • Apple's $634 million Apple Watch patent bill just got even bigger.
  • Don't change the subject, Apple tells OpenAI over its lawsuit.
  • Apple Music is getting a new logo.
  • Ron Johnson "Shop Different" review.

Picks of the Week

  • Christina's Pick: VMPal
  • Leo's Picks: Mac Studio Server & Hermes Conduit
  • Andy's Pick: True Lemon Packets
  • Jason's Pick: The Universe, Controlled

Hosts: Leo Laporte, Andy Ihnatko, Jason Snell, and Christina Warren

Download or subscribe to MacBreak Weekly at https://twit.tv/shows/macbreak-weekly.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:





Download audio: https://pdst.fm/e/pscrb.fm/rss/p/mgln.ai/e/294/cdn.twit.tv/cap/mbw_1045/3a783bb7-514b-4487-aef8-b2bb4bf6a4ca.mp3
Read the whole story
alvinashcraft
39 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

Cloudflare Edge Workers with Bob Fornal

1 Share

What can Cloudflare do for you? While at KCDC in Kansas City, Richard chatted with Bob Fornal about how his organization uses Cloudflare - not just for content delivery or DDoS protection, but also edge compute - and more! Bob talks about moving workloads between the client and server, where Cloudflare Workers can run some code and save time while staying secure. This leads to a broader conversation about introducing these tools to your organization - it's not likely something web developers will ask for. Still, it can help them, and collaboration between development and operations is always a positive in an organization!

Links

Recorded Sep 11, 2026





Download audio: https://cdn.simplecast.com/media/audio/transcoded/5379899c-61c5-43c3-aa3f-1128cffd9ef4/c2165e35-09c6-4ae8-b29e-2d26dad5aece/episodes/audio/group/315ad7f1-d4d6-4b6a-b45e-f88aeb834693/group-item/bef1df95-c518-4b39-84e3-2997d22cfc5a/128_default_tc.mp3?aid=rss_feed&feed=cRTTfxcT
Read the whole story
alvinashcraft
45 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

#499 So many questions??

1 Share
Topics covered in this episode:
Watch on YouTube

About the show

Sponsored by us! Support our work through:

Connect with the hosts

Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too.

Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.

Michael #1: PEP 824 brings ?? and ??= to Python for None handling

PEP 824, a new draft from Marc Mueller sponsored by Guido van Rossum, proposes None-coalescing operators for Python 3.16. The ?? operator returns its left-hand side unless that value is None, and ??= assigns a fallback only when the target is None. It revives the long-deferred PEP 505 from over a decade ago, trimmed to just these two operators, with None-aware access split off into PEP 823. The goal is replacing verbose is None checks with something closer to or, but keyed on None instead of truthiness.

  • Every Python codebase has piles of if x is None fallback code, and this is the first serious move in ten years to give it real syntax.
  • user.age ?? "unknown" is like or but only falls back on None, so 0, "", and [] pass through instead of getting clobbered
  • user.name ??= "unknown" replaces the two-line check-then-assign pattern, with left-side subexpressions evaluated and cached exactly once
  • Precedence sits between or and conditional expressions, matching JavaScript and C#, and ?? lands as a BoolOp in the AST next to and and or
  • Unlike +=, ??= is a conditional assignment that skips the right side entirely, which is why it gets its own AST node rather than AugAssign
  • Still draft status targeting 3.16, with a working reference implementation and an online demo to try, and it notably rejects a soft keyword like otherwise in favor of the familiar ??
  • Discussion-worthy: the PEP answers the old objection that making None easier will proliferate its use, pointing out None is already everywhere and the status quo just produces uglier code
# OG way
user = db.get_user()
city = None
if user is not None:
    if user.address is not None:
        if user.address.city is not None:
            city = user.address.city

# Michael's preferred way
user = db.get_user()
city = user?.address?.city

Calvin #2: Python 3.15 gets a surprise RC3, and Python 3.10 reaches end of life

  • The release team added a surprise third release candidate for Python 3.15 to fix last-minute lazy-import release blockers. They wanted time to test the fixes properly.
  • That pushes the 3.15.0 final release from October 2 to October 9, 2026.
  • RC3 has about 156 fixes from 82 contributors. The headline features are explicit lazy imports (PEP 810), the new frozendict (PEP 814) and sentinel (PEP 661) built-ins, and UTF-8 as the default encoding (PEP 686).
  • No more ABI changes are coming, so library authors should be building 3.15 wheels now. uv 0.12.23 already added CPython 3.15.0rc3.
  • On October 1, Python 3.10.22, 3.11.17, 3.12.15, 3.13.16 and 3.14.8 shipped together with nine common security fixes. They cover SSL validation, tarfile and zipfile handling, and urllib credentials.
  • Python 3.10.22 is the final 3.10 release. After five years it gets no more security updates, so anyone still on 3.10 should upgrade.
  • Python 3.13.16 is the last full maintenance release of 3.13, which now moves to security-only fixes. Only 3.13.16 and 3.14.8 have Windows and macOS installers, and the older releases are source-only.
  • Python 3.11 gets security fixes through October 2027, and 3.12 through October 2028.
  • A natural way to tie the two together: one version is nearly out the door and one is officially gone, and the same week is the time to test your code on 3.15 and move off 3.10.

Michael #3: asyncio.shield

Where async code can be cancelled

In async Python, every await is a point where your coroutine can be stopped. If someone cancels the task, asyncio raises CancelledError at whichever await the coroutine is paused on, and nothing after that line runs. Quart does this on purpose. When the client disconnects, it cancels the request's task. From quart/asgi.py:

elif message["type"] == "http.disconnect":
    self._disconnected = True
    request.body.disconnect()
    request_task.cancel()

That's reasonable for a slow page nobody is waiting on anymore. It's a problem for a handler that writes to the database in two steps:

await downloads.insert_one(event)            # 1. log the download
await totals.update_one(..., {'$inc': ...})  # 2. bump the episode's total

A podcast app requests the MP3, gets what it needs, and hangs up. If it hangs up while step 2 is in flight, step 1 has already landed and step 2 never runs. Nothing is logged and nothing reaches Sentry, because a cancelled request isn't an error. The two collections just drift apart. Under WSGI this couldn't happen. A disconnect didn't stop your view; the view finished both writes and the server only failed later, when it tried to send the response.

The demo

I ran this on Python 3.14. The "client" hangs up 15 ms into a pair of 10 ms writes:

async def record_download():
    await db_write('events')
    await db_write('total')
_pending: set[asyncio.Task] = set()
async def record_download_shielded():
    task = asyncio.create_task(record_download())
    _pending.add(task)
    task.add_done_callback(_pending.discard)
    await asyncio.shield(task)
record_download            events=1 total=0
record_download_shielded   events=1 total=1

The unshielded version loses the increment. The shielded version finishes it, even though the request was cancelled. The full script is in the scratchpad as shield_demo.py if you want it for the show.

What asyncio.shield does, and its traps

shield(task) protects the inner task from a cancellation aimed at the outer one. The handler still gets CancelledError immediately, so nothing after that line runs, but the inner task keeps going until both writes finish. The traps:

  1. Keep a reference to the task. The event loop only holds weak references to tasks, so a task with no other reference can be garbage-collected mid-run. The asyncio docs warn about this. That's what _pending is for.
  2. Its errors go nowhere by default. If a shielded write fails after the handler has already been cancelled, nobody awaits the result. You only get a "Task exception was never retrieved" warning. Log errors from inside the task, or in the done callback.
  3. It doesn't survive a process shutdown. If the event loop is closing, as during a Granian worker recycle or a deploy, pending tasks are still cancelled. The window is tiny, but it isn't zero.
  4. It hides hangs. A shielded write to a stuck database lives forever. Put a timeout inside the shielded task (asyncio.timeout(...)), not outside it.
  5. It makes the pair finish, not atomic. A crash between the two writes still splits them. The real fix is one operation that can't half-happen. That's what the SQLite move gets: an insert and an upsert in one synchronous transaction, with no await in the middle. Shield is the right patch for the Mongo code until then. The general lesson: in async code, related writes made one after another are only as reliable as the client's patience. Before shipping something like that, check whether your framework cancels on disconnect. Quart does, and I believe Django 5's async views do too. I don't think Starlette cancels a plain endpoint, but I haven't checked any of these other frameworks' source, so verify them before you say it on air.

Calvin #4: Pyxel: the retro game engine for Python

  • Pyxel is a free, MIT-licensed retro game engine for Python, built and maintained by a single developer. It has been in development since 2018 and has passed 18,000 GitHub stars.
  • It's modeled on classic game consoles and deliberately limits you to 16 colors and 4 sound channels, which keeps scope small and games finishable.
  • Built-in editors cover pixel art, tilemaps, sound and music, so you can make the graphics, audio and game logic in one place.
  • The engine is implemented in Rust and compiled to WebAssembly, but you write your games in plain Python.
  • Pyxel Code Maker is a browser playground with a code editor, resource tools and a run button. It loads projects from local files, GitHub Gists or URLs, and saves back to a Gist for sharing.
  • Games can also run on the web, so sharing one can be as simple as sending a link.
  • It's a fun, low-barrier way into game development, good for beginners and for teaching kids.

Extras

Calvin:

Joke: I was there.





Download audio: https://pythonbytes.fm/episodes/download/499/so-many-questions.mp3
Read the whole story
alvinashcraft
54 seconds ago
reply
Pennsylvania, USA
Share this story
Delete
Next Page of Stories