Sr. Content Developer at Microsoft, working remotely in PA, TechBash conference organizer, former Microsoft MVP, Husband, Dad and Geek.
161989 stories
·
33 followers

How to Build Team Agents

1 Share
From: AIDailyBrief
Duration: 38:25
Views: 1,248

Nufar Gaspar joins this AIDB Operator’s Cut to explore how to build AI agents that work for an entire team. The conversation focuses on moving from individual AI use to shared agents that support collaborative work.

The AI Daily Brief helps you understand the most important news and discussions in AI.
Subscribe to the podcast version of The AI Daily Brief wherever you listen: https://pod.link/1680633614
Get it ad free at http://patreon.com/aidailybrief
Learn more about the show https://aidailybrief.ai/

Read the whole story
alvinashcraft
just a second ago
reply
Pennsylvania, USA
Share this story
Delete

#498 A Tiny Episode

1 Share
Topics covered in this episode:
Watch on YouTube

About the show

Sponsored by us! Support our work through:

Connect with the hosts

Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too.

Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it.

Calvin #1: MemTensor / MemoryOS PyPI package hijacked via a malicious build backend

  • On Sept 23 an attacker published backdoored MemoryOS 2.0.34 on PyPI and three bad versions (0.1.21, 0.1.23, 0.1.25) of MemTensor's OpenClaw plugin on npm. PyPI had no clean release that day, so 2.0.34 was the newest.
  • They pushed commits to MemTensor's own GitHub Actions release pipelines. On PyPI that was a custom Poetry build backend, and on npm a tweaked validation script. Both used BASH_ENV to hand the publish token to the attacker before the real publish ran. SafeDep couldn't confirm how the attacker got push access.
  • Runs on import, not install: A Go implant called sckit starts when the library loads, so --ignore-scripts won't save you.
  • It harvests credentials from your home directory (npm and PyPI tokens, GitHub tokens, SSH keys, cloud CLI tokens, .env files) and sends them to skyleen[.]fr servers.
  • It's a worm: It uses stolen tokens to copy itself into other repos and packages, so the victim list could grow.
  • If you installed it: Downgrade to MemoryOS 2.0.33 (plugin 0.1.20) and rotate every credential reachable from $HOME. Also kill any running sckit stage0 process and check repos you can push to for a stray runtime-update.yml workflow or .sckit/ directory.

Michael #2: TinyMongo

  • Want to use a MongoDB data interface, but swap out the storage engine?
    • Memory for testing/caching
    • JSON/TinyDB simple JSON files
    • SQLite for durable, high-perf reads with WAL
    • SQLIte shared for high write apps
    • DuckDB + Parquet for analytics apps
    • Postgres + MariaDB for multi-machine client/server
  • Great for teaching, examples, and simple deployments
  • Amazing story of paired AI development
    • Will completely run talkpython.fm after weeks of shared work together (in SQLite mode).

Calvin #3: Jev: what to know

  • What it is: Jev is a model from TypeSafe AI that answers with typed results (yes/no probabilities, scores, picks from your options) instead of prose. Real Python published a hands-on tutorial on 2026-09-24 and the buzz on hacker news is almost deafening.
  • It's proprietary: Jev is a hosted, closed-weight model. There are no weights to download and no self-hosting. Everything called "open Jev" is an independent reimplementation, not TypeSafe's model.
  • Your data leaves your machine: Every call sends your input text to a third-party API. In the tutorial that path goes through OpenRouter to TypeSafe. Think twice before sending customer messages, tickets or anything sensitive.
  • Cost and stability are open questions: The tutorial calls Jev "cheap, but not free" and says it's fast and cheap "at the moment." It also says whether that stays true is "something to keep an eye on."
  • Credit to Real Python: It's a good, practical intro. It shows the Noul, Score and Choice primitives, and its point that instruction wording matters more than thresholds is useful advice for any model. The tutorial itself says similar results are possible with a well-prompted LLM.
  • Open options to look at instead:
    • JevK5 (https://github.com/allebee/jevk5): Apache-2.0 weights and code, 4B or 9B parameters, and it accepts TypeSafe-style requests.
    • SemIf, formerly OpenJev (https://github.com/TheoLeeCJ/openjev): MIT-licensed, small models, and it can run CPU-only.
    • openjev-sglang (https://github.com/ekzhang/openjev-sglang): a Jev-compatible endpoint running Qwen3.6-35B-A3B, but no license is stated, so check before commercial use.
  • The catch: These copy Jev's interface, not its model or training. Results will differ, and I haven't run any of them. Benchmarks are self-reported, and JevK5 is English-only.

Michael #4: One innocent dict read makes attribute access permanently slower

Timofei Ivankov benchmarks a CPython internals surprise: since 3.11, attribute access skips the instance dict entirely. A specialized opcode reads the attri.bute at a fixed byte offset in the object's inline values array. Read obj.__dict__ once, though, and the dict gets materialized, the object loses that specialized path for the rest of its life, and a million-iteration loop goes from 33 ms to 51 ms on CPython 3.14. vars() and copy.copy() trigger the same thing, so a debugging print or a shallow copy in code touching your hot objects quietly makes every later attribute access roughly 1.5x slower.

  • The slowdown is permanent and nothing about it looks like a performance decision: ordinary code far from the hot loop can trigger it, and the function that gets slower never changes.
  • Materializing dict produces a split table, and the LOAD_ATTR_WITH_HINT fallback declines split tables, so the object ends up with no specialization at all
  • vars(), 'x' in o.dict, and copy.copy() all materialize it; copy.copy is the realistic trap since nobody treats a shallow copy as a performance decision
  • slots instances read attributes at exactly the same speed and cannot fall into the trap since there is no dict to materialize
  • On the free-threaded build both effects grow: atomic incref on reads plus an object lock on writes push the penalty from 17.6 to 25.4 ns
  • Credit: this item was surfaced by the PyCoder's Weekly newsletter

Extras

Calvin:

  • whatsnewt - a TUI text adventure through what's new in Python 3.15; playful but niche.

Joke: Shipping a button in 2026…





Download audio: https://pythonbytes.fm/episodes/download/498/a-tiny-episode.mp3
Read the whole story
alvinashcraft
17 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

Coffee and Open Source Conversation - Carter Rabasa

1 Share
From: Isaac Levin
Duration: 1:03:41
Views: 6

Carter Rabasa is a Seattle-based developer community organizer and investor in developer tool startups. He organizes SeattleJS and CascadiaJS.

You can follow Carter on Social Media
https://github.com/crtr0
https://twitter.com/crtr0

Also check out these links from Carter
https://seattlejs.com
http://cascadiajs.com

PLEASE SUBSCRIBE TO THE PODCAST

- Spotify: http://isaacl.dev/podcast-spotify
- Apple Podcasts: http://isaacl.dev/podcast-apple
- Google Podcasts: http://isaacl.dev/podcast-google
- RSS: http://isaacl.dev/podcast-rss

You can check out more episodes of Coffee and Open Source on https://www.coffeeandopensource.com

Coffee and Open Source is hosted by Isaac Levin (https://twitter.com/isaacrlevin)

Read the whole story
alvinashcraft
23 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

The Return on Returns: Turning Reverse Logistics Into a Competitive Advantage

1 Share

Returns have become a defining part of online shopping, with U.S. retail returns reaching an estimated $849.9 billion in 2025. In this episode of Mailin’ It, Karla Kirby and Jeff Marino explore how retailers can move beyond viewing returns as simply a cost and instead make them a strategic part of the customer experience.

Nagee Jackson, Director of New Business Acquisition at the U.S. Postal Service, explains why an effective returns strategy starts with understanding customer expectations, product value, return rates and the true cost of bringing merchandise back. He discusses how different products—from clothing and perishables to collectibles and electronics—can require very different approaches.

The conversation also examines USPS return solutions, including Ground Advantage, Priority Mail Return and scan-based returns, which can help businesses align costs with actual return activity. Nagee emphasizes the importance of planning ahead for peak season, analyzing historical return data, establishing clear policies and preparing for the physical volume of merchandise coming back.

For consumers, the episode offers practical advice on what to look for in a retailer’s return policy, including return windows, shipping costs and return methods.

The episode concludes with a look at how USPS sales teams can work directly with businesses to develop customized shipping and returns strategies. In the “Did You Know?” segment, Karla and Jeff highlight John Wanamaker, the pioneering retailer and former Postmaster General whose innovations helped shape both American retail and the Postal Service.


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.





Download audio: https://afp-920619-injected.calisto.simplecastaudio.com/f32cca5f-79ec-4392-8613-6b30c923629b/episodes/4c0bbb6b-0a40-4623-8eab-47564753d561/audio/128/default.mp3?aid=rss_feed&awCollectionId=f32cca5f-79ec-4392-8613-6b30c923629b&awEpisodeId=4c0bbb6b-0a40-4623-8eab-47564753d561&feed=bArttHdR
Read the whole story
alvinashcraft
38 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

Random.Code() - Yet Another Accessibility Issue in Rocks With Nested Types, Part 2

1 Share
From: Jason Bock
Duration: 1:17:29
Views: 39

Well, the first attempt did not work out. I thought about it for a while, and I think I have a pseudo-solution.

https://github.com/JasonBock/Rocks/issues/435

#dotnet #csharp

Read the whole story
alvinashcraft
47 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

WSLC Architecture deep dive

1 Share

WSL containers is now generally available! Check out this blog post to learn more about this overall feature enabling seamless access to Linux containers on Windows via the new “wslc.exe” command. This new Linux container platform comes with multiple architectures changes compared to WSL, which we’ll detail in this post.

Session model

Similarly to WSL, client processes call into “wslservice.exe”, which is a privileged Windows service. That service has the capability to create virtual machines (via HCS), and use those to run Linux workflows.

A key difference with WSL’s architecture though is that wslservice.exe does not retain ownership of the virtual machine. Instead, it creates a child process, wslcsession.exe, which runs on behalf of the calling user and will perform all session operations (creating containers, mounting directories, binding networking ports, etc) on behalf of the user.

This new model allows WSLC to have both strong isolation between sessions, since they live in different processes, but also reinforced security boundaries, since sessions operations are executed in a less privileged process than wslservice.exe. The below diagram gives an overview of how a WSLC session is created:

wslc arch image

Storage

WSLC offers several primitives to store data within a WSLC session, or in the Windows storage stack. This section details the different storage options, and how they’re designed. Session VHDs Each WSLC session has its own storage VHD. This VHD is use to store the state of sessions (available images, containers, networks, volumes, etc).

When using wslc.exe, these VHDs are stored in %AppData%\Local\wslc\sessions Container volumes Container volumes allow containers to store data outside of their scratch space (which is discarded when the container is deleted).

The simplest usecase is to use a volume to share a Windows path with a container, like this:

$ wslc container run -v C:\Windows\System32\drivers\etc:/volume -it debian:latest ls /volume
hosts hosts.ics lmhosts.sam networks protocol services

Under the hood, these volumes are implemented by mounting virtiofs shares inside the Linux virtual machine, and making them available to the container. Inside the virtual machine, these mounts are created under /mnt, and then attached to the container as bind mounts:

wslc storage image

On the Windows side, the mountpoint is accessed over virtiofs, which is high performance filesystem designed specifically for interoperability between a hypervisor and a virtual machine. Compared to plan9, virtiofs is about twice as fast. VHD volumes VHD volumes are a special kind of container volumes that is backed by a VHD instead of a Windows path. This kind of volume is useful when a container needs a native linux filesystem or wants to enforce a limit how the volume size. Here’s an example on how to create a VHD volume:

$ wslc volume create --driver vhd -o SizeBytes=200000000 my-volume my-volume

Once created, the volume can be mounted by name in one or multiple containers:

$ wslc container run -v my-volume:/volume -it debian:latest findmnt /volume TARGET SOURCE FSTYPE OPTIONS /volume /dev/sdf ext4 rw,relatime,stripe=4

Networking

WSLC offers network connectivity through a new networking model: Consommé. This networking setup allows WSLC to have fine control over the networking behavior for the Linux Virtual machine (which is needed for advanced scenarios like port mapping, host loopback, …) while integrating with the Windows networking stack. In this model, all the Linux virtual machines’ traffic is sent as ethernet frames to a virtio queue, which is then read by a Windows process running on behalf of the user.

That process then provides access to various networking service to the virtual machine, such as:

  • Answering DNS queries
  • Routing for UDP & TCP traffic
  • Port mapping

One of the major advantages that this approach offers is that the traffic that’s routed out of the virtual machine is sent on behalf of the user owning the wslc session, so traffic flows as it was emitted by a regular Windows process, which provides extensive compatibility with VPNs and firewalls. Below is an example flow for a scenario where a container runs nginx with port 8000 mapped to port 80 into the container:

wslc network image

Learning more

Would you like to learn more about WSLC’s technical details? WSLC is open source! Head over to microsoft/WSL to read the code, build your own, and contribute!

The post WSLC Architecture deep dive appeared first on Windows Command Line.

Read the whole story
alvinashcraft
56 seconds ago
reply
Pennsylvania, USA
Share this story
Delete
Next Page of Stories