# Modern Python > In-depth Python and AI tutorials, practical insights, and a free weekly newsletter for developers who want to stay ahead. Public Ghost content for AI and LLM tooling. This file includes a bounded export of public pages first, then recent public posts. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages ### About Modern Python URL: https://modernpython.io/about/ Last updated: 2026-06-10T20:02:05.000Z Modern Python exists to help developers stay ahead. The Python ecosystem evolves faster than ever. New language features, AI frameworks, tooling, deployment practices, and engineering workflows emerge every week. Keeping up has become a challenge even for experienced developers. Modern Python was created to solve that problem. We publish practical tutorials, deep technical analysis, and weekly insights on Python, AI, and modern software engineering. Whether you're building web applications, data platforms, AI systems, automation tools, or SaaS products, Modern Python helps you stay informed without drowning in information. ## Our Mission To help developers continuously learn, adapt, and thrive in a rapidly changing technology landscape. We believe that great developers are not defined by how much they knew yesterday, but by how fast they can learn today. ## Our Vision To become the most trusted independent publication for Python developers and AI engineers worldwide. We envision a future where developers can rely on Modern Python as their go-to source for understanding new technologies, evaluating industry trends, and mastering practical engineering skills. ## Our Values ### Readers First Everything we do starts with a simple question: "Does this create value for our readers?" Every article, tutorial, newsletter, recommendation, sponsorship, and affiliate partnership is evaluated through that lens. We believe trust is earned slowly and lost quickly. That is why we will never publish content, promote products, or accept partnerships that do not genuinely help our audience become better developers. If something benefits us but does not benefit our readers, we will not do it. Our readers come first. Always. ### Original Research Over Content Farms We believe the internet needs fewer content farms and more original thinking. Every article and newsletter published by Modern Python is built on real engineering experience, hands-on experimentation, primary sources, and deep research. We read the documentation, run the code, validate the results, and verify the facts before publishing. AI can help us research, organize, and edit ideas, but it does not replace critical thinking, engineering judgment, or firsthand experience. ### Benfen (Doing the Right Thing) One of the principles that inspires Modern Python is the Chinese concept of Benfen (本分). There is no perfect English translation, but it means doing the right thing, even when no one is watching. For us, Benfen means acting with integrity, taking responsibility for our work, and earning trust through consistent actions over time. Most importantly, it means this: > Never take advantage of others, even when we are in a position to do so. This principle guides how we write, what we recommend, and how we build this publication. - We will never use clickbait to earn clicks. - We will never publish low-quality content to chase pageviews. - We will never promote products we do not believe in. - We will never sacrifice long-term trust for short-term revenue. Our goal is to grow in a way that we can be proud of years from now. We believe trust is built through thousands of small decisions made consistently over time. That is Benfen. ## Join the Journey If you're a developer who wants to stay ahead of Python, AI, and modern software engineering, you're in the right place. Welcome to Modern Python. ### Privacy Policy URL: https://modernpython.io/privacy-policy/ Last updated: 2026-06-12T09:42:41.000Z Last Updated: June 12, 2026 ## Introduction Welcome to Modern Python ("Modern Python", "we", "us", or "our"). Modern Python is operated by ByteStation Ltd, a company registered in England and Wales. Company Number: 16361776 Contact Email: [contact@modernpython.io](mailto:contact@modernpython.io) This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you visit modernpython.io, subscribe to our newsletter, create an account, purchase a membership, leave comments, or otherwise interact with our services. This Privacy Policy applies to all visitors, subscribers, members, and users of Modern Python worldwide. ## Information We Collect ### Information You Provide We may collect information that you voluntarily provide, including: - Your email address - Information associated with your Modern Python account - Information associated with your Modern Python membership - Comments you left on this website - Email replies you sent to us ### Information Collected Automatically When you visit Modern Python, certain information may be collected automatically, including: - IP address - Browser type and version - Device information - Operating system - Referring website - Pages viewed - Date and time of visits - Newsletter engagement data, such as email opens and link clicks ### Payment Information Paid memberships are processed through Stripe. We do not store or have access to your full payment card details. Payment information is collected and processed directly by Stripe in accordance with Stripe's own privacy practices. ## How We Use Your Information We may use your information to: - Provide and maintain our website and services - Deliver newsletters and email communications - Manage user accounts and memberships - Process subscription payments through Stripe - Respond to inquiries and support requests - Enable community features such as comments - Improve the performance, security, and functionality of our website - Detect fraud, abuse, or unauthorized activity - Comply with legal obligations ## Legal Bases for Processing Where applicable under the UK GDPR and EU GDPR, we process personal data based on one or more of the following legal grounds: - Your consent - Performance of a contract - Compliance with legal obligations - Our legitimate interests in operating and improving Modern Python ## Newsletter Communications If you subscribe to our newsletter, we will use your email address to send: - Newsletters - Publication updates - Membership-related communications - Administrative and service messages You may unsubscribe at any time by using the unsubscribe link included in our emails. ## Comments If you leave comments on Modern Python, we may collect information associated with your account and comment activity. Comments may be publicly visible and should not contain information you do not wish to make public. We reserve the right to moderate, edit, or remove comments that violate our community standards or applicable laws. ## Affiliate Links and Sponsorships Modern Python may participate in affiliate marketing programs and may publish sponsored content. If you click an affiliate link or purchase a product through an affiliate link, we may earn a commission at no additional cost to you. Any sponsored or affiliate content will be disclosed in accordance with applicable laws and industry best practices. Our editorial decisions are guided by our commitment to serving readers first. ## Cookies and Similar Technologies Modern Python uses cookies and similar technologies to operate and secure the website, manage user sessions, provide membership functionality, and improve the user experience. These technologies may be provided by: - Ghost - Cloudflare - Stripe Most web browsers allow you to control or disable cookies through your browser settings. Please note that disabling certain cookies may affect website functionality. ## Third-Party Service Providers We may use trusted third-party service providers to operate our services, including: - Ghost (website platform and membership services) - Stripe (payment processing) - Cloudflare (security and performance services) These providers may process personal information on our behalf and only as necessary to provide their services. ## Data Retention We retain personal information only for as long as necessary to: - Provide our services - Maintain user accounts and memberships - Comply with legal obligations - Resolve disputes - Enforce our agreements When personal information is no longer required, we will delete or anonymize it where reasonably practicable. ## International Users Modern Python is operated from the United Kingdom and may be accessed by users worldwide. Your information may be processed and stored in the United Kingdom or in other jurisdictions where our service providers operate. By using our services, you understand that your information may be transferred to and processed in countries outside your country of residence. ## Your Rights Depending on your location and applicable law, you may have the right to: - Access your personal information - Correct inaccurate information - Request deletion of your information - Restrict processing - Object to processing - Withdraw consent - Request data portability To exercise these rights, please contact: [contact@modernpython.io](mailto:contact@modernpython.io) We may request information necessary to verify your identity before responding to your request. ## Security We take reasonable technical and organizational measures to protect personal information against unauthorized access, disclosure, alteration, or destruction. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. ## Children's Privacy Modern Python is not directed at children, and we do not knowingly collect personal information from children in violation of applicable laws. If you believe that a child has provided personal information to us, please contact us so that we can take appropriate action. ## Changes to This Privacy Policy We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and may provide additional notice where appropriate. ## Contact Us If you have questions about this Privacy Policy or our privacy practices, please contact: ByteStation Ltd Company Number: 16361776 England and Wales Email: [contact@modernpython.io](mailto:contact@modernpython.io) ### Terms and Conditions URL: https://modernpython.io/terms-and-conditions/ Last updated: 2026-06-12T10:06:17.000Z Last Updated: June 12, 2026 ## Introduction Welcome to Modern Python. These Terms and Conditions ("Terms") govern your access to and use of modernpython.io and any related services, content, newsletters, memberships, and features provided by Modern Python. Modern Python is operated by ByteStation Ltd, a company registered in England and Wales. Company Number: 16361776 By accessing or using Modern Python, you agree to be bound by these Terms. If you do not agree to these Terms, please do not use our website or services. ## About Us Modern Python is operated by: ByteStation Ltd Company Number: 16361776 England and Wales Contact Email: [contact@modernpython.io](mailto:contact@modernpython.io) ## Eligibility You must be legally capable of entering into a binding agreement in your jurisdiction to use our services. By using Modern Python, you represent that you meet any applicable legal requirements. ## Accounts and Memberships Certain features of Modern Python may require you to create an account or purchase a membership. You are responsible for: - Maintaining the security of your account - Keeping your login credentials confidential - Providing accurate and current information - All activities conducted through your account We reserve the right to suspend or terminate accounts that violate these Terms or applicable laws. ## Paid Memberships Modern Python may offer paid memberships, subscriptions, and premium content. Membership fees, billing intervals, and available features will be described at the time of purchase. By purchasing a membership, you authorize the applicable payment processor to charge the payment method you provide. Unless otherwise stated at the time of purchase, subscriptions automatically renew until cancelled. You may cancel your membership at any time through your account settings. Cancellation will prevent future renewals but will not normally result in a refund for payments already made. ## Payments Payments are processed by Stripe or other authorized payment providers. We do not store your full payment card details. Your use of payment services is also subject to the terms and privacy policies of the relevant payment provider. ## Intellectual Property Unless otherwise stated, all content published on Modern Python is owned by or licensed to ByteStation Ltd and is protected by applicable intellectual property laws. This includes: - Articles - Newsletters - Tutorials - Guides - Graphics - Logos - Branding - Audio and video content - Premium membership content You may: - Read and share links to our content - Quote brief excerpts with proper attribution You can not: - Republish entire articles without permission - Copy premium content for redistribution - Reproduce substantial portions of our content - Use our trademarks or branding without permission ## User Content If you submit comments or other content to Modern Python, you retain ownership of your content. However, you grant us a non-exclusive, worldwide, royalty-free license to display, reproduce, and distribute that content in connection with operating Modern Python. You are responsible for the content you submit. You agree not to submit content that: - Violates applicable laws - Infringes intellectual property rights - Contains malicious software - Is defamatory, abusive, or harassing - Is fraudulent or misleading - Constitutes spam or unauthorized advertising We reserve the right to moderate, edit, restrict, or remove content at our discretion. ## Editorial Independence Modern Python may publish sponsored content, affiliate links, product recommendations, and commercial partnerships. However, commercial relationships do not determine our editorial opinions, recommendations, or coverage decisions. We only recommend products, services, and tools that we genuinely believe provide value to our readers. We strive to place reader interests ahead of commercial considerations. ## Affiliate Disclosure Some links on Modern Python may be affiliate links. If you purchase products or services through affiliate links, we may earn a commission at no additional cost to you. Affiliate relationships do not influence our commitment to honest analysis and independent editorial judgment. ## No Professional Advice The content published on Modern Python is provided for informational and educational purposes only. Nothing on Modern Python constitutes: - Legal advice - Financial advice - Investment advice - Tax advice - Professional consulting services You should seek qualified professional advice before making decisions based on information obtained from our content. ## Technical Content Disclaimer Software development involves risk. Code examples, technical explanations, configurations, commands, and recommendations are provided for educational purposes only and may not be suitable for every environment. You are responsible for evaluating and testing any code, software, configuration, or technical guidance before using it in production systems. ## Availability We strive to keep Modern Python available and functional, but we do not guarantee uninterrupted access. We may modify, suspend, discontinue, or remove any aspect of the website or services at any time without liability. ## Limitation of Liability To the fullest extent permitted by law, ByteStation Ltd and its affiliates, officers, directors, employees, contractors, and contributors shall not be liable for any indirect, incidental, consequential, special, or punitive damages arising from your use of Modern Python. This includes, without limitation: - Loss of profits - Loss of business opportunities - Data loss - Service interruptions - Security incidents - Reliance on content published on the website Nothing in these Terms excludes liability that cannot be excluded under applicable law. ## Indemnification You agree to indemnify and hold harmless ByteStation Ltd from claims, damages, liabilities, costs, and expenses arising from: - Your use of Modern Python - Your violation of these Terms - Your violation of applicable laws - Your infringement of third-party rights ## Termination We may suspend or terminate access to Modern Python at our discretion if we reasonably believe you have violated these Terms or applicable laws. Termination does not affect rights or obligations that arose before termination. ## Privacy Your use of Modern Python is also governed by our [Privacy Policy](https://modernpython.io/privacy-policy/). Please review our Privacy Policy to understand how we collect and use personal information. ## Changes to These Terms We may update these Terms from time to time. When material changes are made, we will update the "Last Updated" date and may provide additional notice where appropriate. Continued use of Modern Python after changes become effective constitutes acceptance of the revised Terms. ## Governing Law These Terms shall be governed by and interpreted in accordance with the laws of England and Wales. Any disputes arising from or relating to these Terms shall be subject to the exclusive jurisdiction of the courts of England and Wales, unless applicable law requires otherwise. ## Contact Us If you have questions regarding these Terms, please contact: ByteStation Ltd Company Number: 16361776 England and Wales Email: [contact@modernpython.io](mailto:contact@modernpython.io) ### Editorial Principles URL: https://modernpython.io/editorial-principles/ Last updated: 2026-06-12T10:24:59.000Z Last Updated: June 12, 2026 ## Why We Exist Modern Python exists to help developers stay ahead of Python, AI, and modern software engineering. Our goal is to publish content that is really worth reading and helpful to developers. These principles guide how we research, write, publish, and operate Modern Python. ## Readers First Everything we do starts with a simple question: > Does this create value for our readers? Every article, tutorial, newsletter, recommendation, sponsorship, and affiliate partnership is evaluated through that lens. If something benefits us but does not benefit our readers, we will not do it. Our readers come first. Always. ## Benfen (Doing the Right Thing) One of the principles that inspires Modern Python is the Chinese concept of Benfen (本分). There is no perfect English translation, but it means doing the right thing, even when no one is watching. The principle that best captures our interpretation of Benfen is this: > Never take advantage of others, even when we are in a position to do so. This principle influences how we write, what we recommend, and how we build this publication. We will not sacrifice long-term trust for short-term gains. ## Original Research Over Content Farms We believe the internet needs fewer content farms and more original thinking. Every article and newsletter published by Modern Python is built on real engineering experience, hands-on experimentation, primary sources, and deep research. We read the documentation. We run the code. We validate the results. We verify the facts. AI can help us research, organize, and improve our work, but it does not replace critical thinking, engineering judgment, or firsthand experience. Our goal is to produce content that is accurate, useful, and worth our readers' time. ## Practical Over Theoretical We value practical knowledge. Whenever possible, we prefer: - Real-world examples over abstract discussions - Working code over pseudocode - Production lessons over academic speculation - Actionable guidance over generic advice We want readers to leave with something they can apply immediately. ## Signal Over Noise The technology industry produces an endless stream of news, announcements, frameworks, tools, and opinions. But not everything deserves your attention. We focus on identifying the developments, ideas, and practices that matter most to working developers and engineers. Our job is to help readers focus on what matters. ## How We Use AI We believe AI is a powerful tool, but not a complete substitute for expertise. AI may assist us with research, grammar, formatting, and idea exploration. However, every article remains subject to human review, judgment, and accountability. We never publish any content that is purely generated by AI. ## Sponsorships and Affiliate Relationships Modern Python may generate revenue through sponsorships, memberships, affiliate relationships, and other commercial activities. These relationships help support the publication and allow us to continue producing high-quality content. However: - Commercial relationships do not determine our opinions. - Sponsorships do not guarantee positive coverage. - Affiliate commissions do not influence our recommendations. - Editorial decisions remain independent. We only recommend products, services, and tools that we genuinely believe provide value to our readers. ## Corrections We strive for accuracy, but mistakes can happen. When we discover factual errors, we will correct them as quickly as reasonably possible. If you believe we have made a mistake, please leave your comments on the relevant articles. Or contact us at: [contact@modernpython.io](mailto:contact@modernpython.io) ## Our Commitment Modern Python is built on a simple belief: Developers need clear, honest, practical, and trustworthy information. Every article, newsletter, and recommendation published here should reflect that belief. We cannot promise perfection. We can promise that we will continue to earn your trust through our actions. --- Thanks for reading! ❤️ The ModernPython team. ### Contact URL: https://modernpython.io/contact/ Last updated: 2026-06-12T10:46:25.000Z ## We'd love to hear from you. Whether you have feedback, a correction, a partnership inquiry, or simply want to say hello, feel free to get in touch. ## General Inquiries [contact@modernpython.io](mailto:contact@modernpython.io) ## Sponsorships & Partnerships [contact@modernpython.io](mailto:contact@modernpython.io) ## Editorial Feedback and Corrections If you believe we have made a factual error, identified outdated information, or would like to suggest a correction, please contact us. Accuracy matters, and we welcome constructive feedback from our readers. ## What We Welcome - Reader feedback - Article suggestions - Corrections - Tool recommendations - Partnership inquiries - Sponsorship opportunities Due to the volume of messages we receive, we may not be able to respond to every inquiry. Thank you for reading Modern Python. ❤️ ### Welcome to Modern Python URL: https://modernpython.io/welcome/ Last updated: 2026-06-12T15:47:24.000Z Thanks for joining Modern Python. ❤️ Your subscription is confirmed. ✅ See you in your inbox every Friday. — Yang Zhou Founder, Modern Python ## Posts ### Modern Python Weekly #12 URL: https://modernpython.io/modern-python-weekly-12/ Last updated: 2026-09-04T21:10:38.000Z ## Python News - [Python 3.15.0 candidate 2 is here!](https://blog.python.org/2026/09/python-3150-rc2/?ref=modernpython.io) \- Published on September 1, Python 3.15.0rc2 arrived as the final planned release candidate with roughly 144 bugfixes, build improvements, and documentation changes ahead of the October 1 final release. *💡 Modern Python's Take: RC2 is the point where maintainers should stop treating 3.15 support as hypothetical and start shipping wheels, CI coverage, and compatibility fixes while the feedback window is still open.* - [Inaugural Python Packaging Council Election: Voting is now open!](https://pyfound.blogspot.com/2026/09/inaugural-python-packaging-council.html?ref=modernpython.io) \- Published on September 1, the PSF opened voting for the inaugural Python Packaging Council, putting packaging governance changes into motion at the ecosystem level. *💡 Modern Python's Take: Packaging progress is increasingly a coordination problem, not a missing-tools problem, so clearer governance can matter as much as the next installer feature.* - [JupyterHub 6.0.0 - 2026-09-01](https://jupyterhub.readthedocs.io/en/latest/reference/changelog.html?ref=modernpython.io) \- Released on September 1, JupyterHub 6.0 shipped a substantial upgrade with a database schema change, Python 3.10 as the minimum version, new server endpoint methods, PKCE for internal OAuth, and other multi-user platform improvements. *💡 Modern Python's Take: This is the kind of release that quietly reshapes serious Python data platforms, because JupyterHub upgrades ripple through education, internal analytics, and research infrastructure stacks.* - [5.5.2 - 2026-09-01](https://jupyterhub.readthedocs.io/en/latest/reference/changelog.html?ref=modernpython.io) \- JupyterHub 5.5.2 also shipped on September 1 as a security release fixing a low-severity user-initiated sharing vulnerability affecting renamed users. *💡 Modern Python's Take: Security backports for widely deployed infrastructure projects deserve more attention than they usually get, especially when many teams cannot jump major versions immediately.* - [Release Notes - FastAPI](https://fastapi.tiangolo.com/release-notes/?ref=modernpython.io) \- No new FastAPI release landed during the week ending September 4, but 0.141.1 remained the latest release, carrying fixes for background tasks and dependency-provided headers in `app.frontend()`. *💡 Modern Python's Take: FastAPI’s newer frontend-adjacent surface means “just a point release” fixes can now affect more than classic request handling, so it still belongs on the weekly radar even in a quieter release week.* ## AI news - [Safety overview: GPT-6 Astra](https://openai.com/index/safety-overview-gpt-6-astra/?ref=modernpython.io) \- Published on September 3, OpenAI said GPT-6 Astra is its most capable broadly deployed model and the first to reach the Critical cybersecurity capability level under its Preparedness Framework. *💡 Modern Python's Take: The important story is not only model capability but the operating model around it, because stronger agents force developers to care about containment, monitoring, and permission design as first-class engineering work.* - [Claude Fable 5.1](https://www.anthropic.com/claude/fable?ref=modernpython.io) \- Anthropic announced Claude Fable 5.1 on September 1 as a Mythos-class model for long-horizon coding and knowledge work, with lower cache-read pricing and an emphasis on autonomous execution. *💡 Modern Python's Take: Pricing and reliability for long-running work matter more than benchmark theater for most builders, and Anthropic is clearly optimizing for that buyer profile.* - [Developing Enterprise Frontier Safeguards with our customers](https://www.anthropic.com/news/enterprise-frontier-safeguards?ref=modernpython.io) \- Published on September 1, Anthropic introduced Enterprise Frontier Safeguards to combine zero data retention with customer-controlled monitoring for higher-risk frontier deployments. *💡 Modern Python's Take: Enterprise AI adoption keeps running into the same wall: customers want strong models without surrendering operational control, and this is a direct attempt to close that gap.* - [The latest AI news we announced in August 2026](https://blog.google/innovation-and-ai/technology/google-ai-updates-august-2026/?ref=modernpython.io) \- Posted on September 1, Google’s monthly roundup highlighted Gemini 3.7 Flash, Gemini 3.5 Transcribe, Gemini Omni 1.1 Flash, and wider developer-facing AI rollouts from August. *💡 Modern Python's Take: Monthly roundups can be easy to ignore, but they are useful signal when one vendor is shipping enough adjacent APIs and model variants that the real story is platform velocity.* ## Tools and Projects - [Introducing @huggingface/kernels: 200+ WebGPU Kernels for Local AI](https://huggingface.co/blog/webgpu-kernels?ref=modernpython.io) \- Published on September 1, Hugging Face released `@huggingface/kernels`, a JavaScript loader plus an initial set of 207 versioned WebGPU kernels for browser-local AI workloads. *💡 Modern Python's Take: Python developers should pay attention even though this is JavaScript-heavy, because the interesting shift is packaging low-level acceleration assets as reusable artifacts instead of burying them inside monolithic runtimes.* - [Copilot code review can now approve pull requests](https://github.blog/changelog/2026-09-01-copilot-code-review-can-now-approve-pull-requests/?ref=modernpython.io) \- Announced on September 1, GitHub added approval assessments to Copilot reviews and optional PR approvals that can count toward merge requirements when admins enable them. *💡 Modern Python's Take: Agent review is moving from “suggestions on the side” toward workflow authority, which raises the bar for repository policy, auditability, and human override design.* - [Content exclusions generally available in Copilot app and CLI](https://github.blog/changelog/2026-09-02-content-exclusions-generally-available-in-copilot-app-and-cli/?ref=modernpython.io) \- Published on September 2, GitHub made enterprise content exclusion policies apply across Copilot app and CLI agent workflows. *💡 Modern Python's Take: Context governance is becoming a product surface of its own, and that is exactly what serious Python teams need before they let agents roam large private codebases.* - [Claude Fable 5.1 is generally available in GitHub Copilot](https://github.blog/changelog/2026-09-01-claude-fable-5-1-generally-available-in-github-copilot/?ref=modernpython.io) \- GitHub made Anthropic’s Claude Fable 5.1 available in Copilot on September 1 across IDEs, CLI, agent sessions, mobile, and web surfaces. *💡 Modern Python's Take: Model choice inside the coding surface is becoming an infrastructure decision, not a novelty feature, because different tasks increasingly justify different agent behavior profiles.* ## Articles - [Give Your Coding Agents a Memory You Own](https://huggingface.co/blog/funes?ref=modernpython.io) \- Published on September 3, Hugging Face presented `funes`, a local-first memory layer that indexes agent traces and exposes retrieval with provenance across coding tools. *💡 Modern Python's Take: Durable memory is one of the few agent ideas that can materially improve week-to-week engineering work instead of just making demos look smarter.* - [Hands on with Buckets](https://huggingface.co/blog/prpatel/hands-on-with-buckets?ref=modernpython.io) \- Published on September 1, Pratik Patel walked through using Hugging Face Buckets for large mutable AI artifacts that fit poorly in ordinary Git workflows. *💡 Modern Python's Take: This is a useful companion to the open-memory story because practical AI engineering increasingly depends on where you put big, changing, non-code assets without wrecking developer ergonomics.* - [NeoMME: an efficient Multimodal-native and Multilingual Encoder](https://huggingface.co/blog/Hcompany/neomme?ref=modernpython.io) \- Published on September 3, H Company introduced a multilingual multimodal encoder family trained from scratch for text-and-image understanding and retrieval workloads. *💡 Modern Python's Take: Retrieval and document understanding still have plenty of room for non-generative architectures, and Python builders should resist assuming every multimodal problem wants a giant decoder model.* ### Modern Python Weekly #11 URL: https://modernpython.io/modern-python-weekly-11/ Last updated: 2026-08-28T19:25:40.000Z ## Python News - [RISC-V is now officially supported by CPython!](https://blog.python.org/2026/08/riscv-now-officially-supported/?ref=modernpython.io) \- Published on August 24, CPython added official RISC-V platform support, expanding the set of architectures the core runtime treats as first-class. *💡 Modern Python's Take: Official support matters more than a port existing in the wild, because it changes what downstream maintainers can reasonably expect in CI, packaging, and bug triage.* - [The Python documentation is now available in Russian!](https://blog.python.org/2026/08/the-python-documentation-is-now.html?ref=modernpython.io) \- Published on August 22, the Python documentation project added Russian as an officially available language. *💡 Modern Python's Take: Documentation localization looks incremental until you remember that Python adoption often bottlenecks on teaching and onboarding, not language syntax.* - [Announcing Polars 1.44](https://pola.rs/posts/polars-1-44/?ref=modernpython.io) \- Published on August 26, Polars 1.44 shipped Iceberg schema evolution on sink, adaptive cloud I/O rate limiting, and correlated subqueries in the SQL layer. *💡 Modern Python's Take: Polars keeps pushing beyond "fast DataFrame" branding and deeper into serious lakehouse and query-engine territory, which is exactly why it keeps gaining ground in Python data stacks.* - [DuckLabs to Join AWS, Projects to Remain Open Source](https://duckdb.org/2026/08/26/ducklabs-to-join-aws?ref=modernpython.io) \- Published on August 26, the DuckDB team said DuckLabs will join AWS while DuckDB, DuckLake, and related projects remain open source under the DuckDB Foundation. *💡 Modern Python's Take: The real question is governance continuity, and the team addressed that directly, which should matter more to Python data users than the acquisition headline itself.* - [FastAPI 0.141.1](https://github.com/fastapi/fastapi/releases/tag/0.141.1?ref=modernpython.io) \- Released on July 29 and still the latest FastAPI release during the week ending August 28, version 0.141.1 fixes background tasks and dependency-provided headers in `app.frontend()`. *💡 Modern Python's Take: Even without a same-week release, FastAPI remains worth tracking because its newer full-stack surface area means small point releases can affect more than request routing.* ## AI news - [The Hugging Face incident and the road ahead](https://openai.com/index/hugging-face-incident-and-the-road-ahead/?ref=modernpython.io) \- Published on August 26, OpenAI released its technical incident report on the July 2026 model-enabled compromise of internal research infrastructure and third-party systems. *💡 Modern Python's Take: This is one of the clearest signs yet that agent safety is no longer a hypothetical policy topic but an operational engineering discipline with real blast-radius planning attached.* - [Introducing Gemini 3.5 Transcribe](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-5-transcribe/?ref=modernpython.io) \- Published on August 26, Google introduced a speech-to-text model focused on real-time, formatted, and noise-robust transcription for voice interactions. *💡 Modern Python's Take: Transcription is becoming a frontier UX primitive, and better formatting plus lower cleanup overhead will matter just as much as raw word error rate in production apps.* - [Advancing price-performance for developers with GPT‑5.6 in Kiro](https://openai.com/index/gpt-5-6-in-kiro/?ref=modernpython.io) \- Published on August 24, OpenAI brought the GPT‑5.6 model family into Kiro with emphasis on structured software planning, implementation, review, and testing workflows. *💡 Modern Python's Take: Developer-facing AI competition is increasingly about workflow fit rather than raw model bragging rights, and structured engineering surfaces are where that battle gets decided.* - [Funding better evaluations of AI’s impact on wellbeing](https://www.anthropic.com/news/wellbeing-research-grants?ref=modernpython.io) \- Published on August 25, Anthropic launched a $5 million grant program for open-source evaluations that study how AI systems affect user wellbeing over longer conversations. *💡 Modern Python's Take: Multi-turn wellbeing evaluation is exactly the kind of hard measurement problem the field has been skirting, so independent benchmarks here could shape product behavior far beyond one lab.* ## Tools and Projects - [The new GitHub Copilot experience in Slack](https://github.blog/changelog/2026-08-21-the-new-github-copilot-experience-in-slack/?ref=modernpython.io) \- Published on August 21, GitHub brought agent sessions, issue triage, sandboxed coding tasks, and shared code channels into Slack in public preview. *💡 Modern Python's Take: The interesting shift is not Slack support by itself but how quickly agent work is being pulled into the coordination surfaces where engineering teams already make decisions.* - [Shared agentic work with GitHub Copilot in Microsoft Teams](https://github.blog/changelog/2026-08-21-shared-agentic-work-with-github-copilot-in-microsoft-teams/?ref=modernpython.io) \- Published on August 21, GitHub added collaborative Copilot cloud-agent sessions inside Teams with approval controls for agent-authored pull requests. *💡 Modern Python's Take: Shared visibility and explicit merge gates are becoming the default design pattern for serious agent adoption, and that is a healthy direction.* - [Agent Plugins 1.0 in VS Code, Copilot CLI, and the Copilot app](https://github.blog/changelog/2026-08-12-agent-plugins-1-0-in-vs-code-copilot-cli-and-the-copilot-app/?ref=modernpython.io) \- Published on August 12, GitHub rolled out support for a portable plugin packaging standard that bundles agent skills and MCP servers across compatible clients. *💡 Modern Python's Take: Reusable agent behavior is starting to look like a packaging ecosystem, which is a strong signal that workflows and tool bundles are becoming durable developer assets.* - [Build Anything with gr.Workflow](https://huggingface.co/blog/gradio-workflow-guide?ref=modernpython.io) \- Published on August 25, Hugging Face and Gradio showed how `gr.Workflow` turns multi-step model pipelines into a typed, node-based graph with API and deployment paths built in. *💡 Modern Python's Take: Visual workflow tooling gets interesting when it stays code-adjacent, and* `gr.Workflow` *looks closer to a production bridge than a toy demo canvas.* ## Articles - [More than just code review](https://simonwillison.net/2026/Aug/22/more-than-just-code-review/?ref=modernpython.io) \- Published on August 22, Simon Willison argued that productive use of coding agents depends on specifying work clearly and verifying outcomes, not merely reading every generated line. *💡 Modern Python's Take: This is the right framing for Python teams adopting agents, because the bottleneck is shifting from typing code to designing verification loops.* - [How Much Memory Does Your Agent Actually Need?](https://huggingface.co/blog/ibm-research/altk-evolve-hmm?ref=modernpython.io) \- Published on August 18, IBM Research analyzed how much distilled memory helps different model tiers on multi-step agent benchmarks and found that the best dose depends on model capability. *💡 Modern Python's Take: The practical lesson is that "more context" is not a strategy; memory design is becoming an optimization problem with measurable accuracy and token-cost tradeoffs.* - [How Hugging Face Inference Endpoints, Jobs, and Buckets Power Search on Papers with Code](https://huggingface.co/blog/pwc-search?ref=modernpython.io) \- Published on August 21, the Hugging Face team detailed a split architecture that keeps corpus building offline and only the embedding query step on the online path. *💡 Modern Python's Take: This is the kind of systems write-up Python AI engineers should read, because it shows where careful workload separation beats vague "RAG pipeline" talk.* - [A Preview of DuckDB v2.0](https://duckdb.org/2026/08/17/duckdb-20-highlights?ref=modernpython.io) \- Published on August 17, the DuckDB team previewed server mode, triggers, a new parser, async I/O, and other headline features planned for the fall 2026 release. *💡 Modern Python's Take: DuckDB v2.0 looks less like a routine major release and more like a statement that embedded analytics databases now want a bigger role in application architecture.* ### Modern Python Weekly #10 URL: https://modernpython.io/modern-python-weekly-10/ Last updated: 2026-08-21T18:16:35.000Z ## Python News - [How AWS Powers PyPI and the PSF](https://pyfound.blogspot.com/2026/08/how-aws-powers-pypi-and-psf.html?ref=modernpython.io) \- Published on August 19, the PSF detailed how AWS credits underpin PyPI, Python.org, CPython services, and a 2026 cost curve now rising with heavier human, CI, and agent traffic. *💡 Modern Python's Take: This is the infrastructure story Python teams should care about, because the ecosystem now depends on package distribution at a scale that older funding and caching assumptions were not built for.* - [PEP 844 – ](https://peps.python.org/pep-0844/?ref=modernpython.io)`public`[ and ](https://peps.python.org/pep-0844/?ref=modernpython.io)`private`[ builtins](https://peps.python.org/pep-0844/?ref=modernpython.io) \- Created on August 5 and updated in active discussion this month, PEP 844 proposes builtins that keep `__all__` aligned with names a module explicitly marks as public or private. *💡 Modern Python's Take: Python still lacks a satisfying way to declare API boundaries at the definition site, so even a draft like this matters because library ergonomics and tooling both benefit from clearer public surface area.* - [FastAPI 0.141.1](https://github.com/fastapi/fastapi/releases/tag/0.141.1?ref=modernpython.io) \- Released on July 29, FastAPI 0.141.1 fixes background tasks and dependency-provided headers in `app.frontend()`, which is notable if you are using the framework's newer full-stack path. *💡 Modern Python's Take: FastAPI is drifting beyond "just an API framework," so even targeted fixes around frontend integration now deserve the same attention teams used to reserve for pure request/response behavior.* - [Migration strategies for going from pandas to Polars](https://pola.rs/posts/pandas-to-polars-migration-strategies/?ref=modernpython.io) \- Published on August 6, the Polars team laid out practical migration paths ranging from one hot segment to full pipeline rewrites, including LLM-assisted translation loops. *💡 Modern Python's Take: The useful shift is that Polars migration is being framed as an engineering program with clear boundaries and rollback points, not as an all-or-nothing rewrite fueled by benchmark envy.* ## AI news - [Pacing model development in an era of cyber-critical capabilities](https://openai.com/index/pacing-model-development-cyber-capabilities/?ref=modernpython.io) \- Published on August 18, OpenAI said it temporarily slowed scaling work, paused some frontier RL runs, and hardened research environments after concluding Astra may meet a critical cyber threshold. *💡 Modern Python's Take: Frontier capability progress is now visibly constrained by operational security and alignment evidence, which is a stronger signal than any benchmark chart about where the real bottlenecks are moving.* - [The Defender’s Window](https://openai.com/index/the-defenders-window/?ref=modernpython.io) \- Published on August 17, Greg Brockman argued that AI-assisted defense needs to accelerate immediately, with concrete emphasis on code auditing, infrastructure review, and machine-speed incident response. *💡 Modern Python's Take: Security teams that still treat AI as an optional productivity add-on are probably already behind the threat model described here.* - [Introducing Gemini 3.7 Flash](https://blog.google/innovation-and-ai/models-and-research/gemini-models/introducing-gemini-3-7-flash/?ref=modernpython.io) \- Published on August 13, Google introduced Gemini 3.7 Flash as a lower-cost coding and agent model with stronger software engineering, web-development, and document-workflow performance than 3.6 Flash. *💡 Modern Python's Take: The important pattern is not one more model launch but how quickly labs are iterating on agent-focused "workhorse" models with explicit price-performance positioning for production workflows.* - [Putting sign language AI into users’ hands](https://deepmind.google/blog/putting-sign-language-ai-into-users-hands/?ref=modernpython.io) \- Published on August 12, Google DeepMind introduced its multilingual sign-language-to-text model and shipped the first consumer features powered by it in Gboard and Live Transcribe on Pixel 11\. *💡 Modern Python's Take: This is the kind of productization that cuts through AI theater because it translates a hard multimodal research problem into a user capability that is obviously valuable on day one.* ## Tools and Projects - [Agent Plugins 1.0 in VS Code, Copilot CLI, and the Copilot app](https://github.blog/changelog/2026-08-12-agent-plugins-1-0-in-vs-code-copilot-cli-and-the-copilot-app/?ref=modernpython.io) \- Published on August 12, GitHub rolled out general support for a shared plugin standard that packages agent skills and MCP servers for use across compatible clients. *💡 Modern Python's Take: Agent tooling is getting a packaging layer of its own, and that is a strong hint that reusable workflows and tool bundles are becoming first-class developer artifacts.* - [MAI-Code-1.1-Flash available in GitHub Copilot](https://github.blog/changelog/2026-08-11-mai-code-1-1-flash-available-in-github-copilot/?ref=modernpython.io) \- Published on August 11, GitHub added Microsoft's latest small coding model, highlighting native vision support, improved instruction following, and a sharply lower list price. *💡 Modern Python's Take: Small coding models are getting good enough that the model-selection problem is starting to look more like latency-and-cost routing than a simple "pick the smartest one" decision.* - [Copilot memory and Ollama in GitHub Copilot for JetBrains](https://github.blog/changelog/2026-08-11-copilot-memory-and-ollama-in-github-copilot-for-jetbrains/?ref=modernpython.io) \- Published on August 11, GitHub added persistent memory across chats plus Ollama as a bring-your-own-key provider in the JetBrains plugin. *💡 Modern Python's Take: The line between hosted and local model workflows keeps thinning, which is exactly what teams with privacy, latency, or customization constraints have been waiting for.* - [Granular Feature Access](https://huggingface.co/changelog/granular-feature-access?ref=modernpython.io) \- Published on August 12, Hugging Face added per-resource-group controls for features like Jobs, blog publishing, Inference Endpoints, and organization billing surfaces. *💡 Modern Python's Take: This is unglamorous but important platform work, because AI infra stops scaling inside companies if every permission decision has to be handled at the whole-org level.* ## Articles - [Your contributors are AI-first now. Is your project?](https://github.blog/open-source/maintainers/your-contributors-are-ai-first-now-is-your-project/?ref=modernpython.io) \- Published on August 12, GitHub examined how open-source maintainers are adapting contribution rules, gates, and review expectations for agent-written pull requests. *💡 Modern Python's Take: The best maintainers are no longer debating whether AI-written contributions are real; they are designing process boundaries that keep review quality intact when those contributions become routine.* - [Turn one giant AI-generated pull request to a reviewable stack](https://github.blog/engineering/turn-one-giant-ai-generated-pull-request-to-a-reviewable-stack/?ref=modernpython.io) \- Published on August 4, GitHub outlined how stacked pull requests can turn agent output into smaller, ordered layers that humans can actually review. *💡 Modern Python's Take: If your team is serious about coding agents, reviewability has to become part of prompt and workflow design rather than cleanup work after the fact.* - [Model Genome: Fingerprinting Whether an LLM Was Trained From Scratch or Derived](https://huggingface.co/blog/mayafree/model-dna?ref=modernpython.io) \- Published on August 8, this Hugging Face community article proposes a reproducible pipeline for checking whether public models are genuinely trained from scratch or derived from existing bases. *💡 Modern Python's Take: Expect more of this kind of forensic tooling, because open-weight credibility is becoming something communities will test instead of simply taking at face value.* - [Lattice: an 8 MB static retriever that embeds Wikipedia in 7 minutes](https://huggingface.co/blog/erikkaum/lattice-blog?ref=modernpython.io) \- Published on August 7, the write-up shows how a tiny static embedding model plus a Rust runtime can deliver competitive retrieval with extremely small model files and fast CPU inference. *💡 Modern Python's Take: Retrieval keeps reminding everyone that clever systems work can still beat brute-force model scaling when latency, footprint, and deployability matter.* ### Modern Python Weekly #9 URL: https://modernpython.io/modern-python-weekly-9/ Last updated: 2026-08-14T18:02:51.000Z ## Python News - [Python 3.12.14, 3.11.16 and 3.10.21 are now available!](https://blog.python.org/2026/08/python-31214-31116-31021/?ref=modernpython.io) \- Published on August 12, these are coordinated security releases for the older supported branches and the clearest upgrade signal for teams still pinned below 3.13\. *💡 Modern Python's Take: This is the kind of release train that quietly resets production priorities, especially for orgs that treat minor-version upgrades as once-a-year work.* - [Announcing the Packaging Council Election Candidates for 2026!](https://blog.python.org/2026/08/2026-packaging-council-nominees/?ref=modernpython.io) \- Published on August 13, the Python core team announced the inaugural Packaging Council slate and the mechanics for voting. *💡 Modern Python's Take: Packaging governance is no longer background noise; it is now core platform infrastructure, and that should make future ecosystem decisions easier to track and challenge.* - [PEP 844: ](https://peps.python.org/pep-0844/?ref=modernpython.io)`public`[ and ](https://peps.python.org/pep-0844/?ref=modernpython.io)`private`[ builtins](https://peps.python.org/pep-0844/?ref=modernpython.io) \- Created on August 5, this draft PEP proposes builtins that keep `__all__` aligned with the names a module explicitly marks as public or private. *💡 Modern Python's Take: Even if this specific syntax changes, the direction matters because Python libraries still spend too much effort documenting API boundaries after the fact.* - [FastAPI 0.141.1](https://github.com/fastapi/fastapi/releases/tag/0.141.1?ref=modernpython.io) \- FastAPI's July 29 patch release fixes background tasks and dependency-provided headers for `app.frontend()`, which is relevant if you are leaning into the newer full-stack dev workflow. *💡 Modern Python's Take: FastAPI is nudging closer to an opinionated app platform, so small frontend-path fixes increasingly matter beyond pure API teams.* - [Migration strategies for going from pandas to Polars](https://pola.rs/posts/pandas-to-polars-migration-strategies/?ref=modernpython.io) \- Published on August 6, the Polars team outlined staged migration paths from selective hot-path rewrites to full pipeline conversions. *💡 Modern Python's Take: The important shift here is not "Polars is faster" but that migrations are becoming process-driven and realistic for ordinary teams, not just benchmark chasers.* ## AI news - [OpenAI replaces revenue lead as Greg Brockman builds his presence](https://www.axios.com/2026/08/13/openai-denise-dresser-replace-chief-revenue-officer?ref=modernpython.io) \- Axios reported on August 13 that OpenAI replaced CRO Denise Dresser with former Wiz executive Dali Rajic amid broader leadership reshaping. *💡 Modern Python's Take: Enterprise AI is now mature enough that go-to-market leadership changes are product signals, not just org-chart trivia.* - [Anthropic ramps up pre-IPO dealmaking](https://www.axios.com/2026/08/13/anthropic-decart-nvidia-ipo?ref=modernpython.io) \- Axios reported on August 13 that Anthropic is in advanced talks to acquire Decart, a move tied to infrastructure leverage ahead of a possible IPO. *💡 Modern Python's Take: Frontier labs are increasingly behaving like vertically integrated compute companies, and Python users will feel that downstream through pricing, APIs, and deployment constraints.* - [Google DeepMind enters a new era as co-founder Demis Hassabis shifts AI role](https://www.theguardian.com/technology/2026/aug/08/google-demis-hassabis-deepmind-shifts-role?ref=modernpython.io) \- Published on August 8, the piece covers Hassabis moving out of the CEO role and DeepMind's tighter integration into Google's operating structure. *💡 Modern Python's Take: This looks less like a personnel story and more like another step in the industry's pivot from research prestige to product execution.* ## Tools and Projects - [uv 0.12.4](https://github.com/astral-sh/uv/releases/tag/0.12.4?ref=modernpython.io) \- Released on August 13, `uv` 0.12.4 adds post-quantum key-exchange preference, better TLS diagnostics, and more `uv check` preview features. *💡 Modern Python's Take:* `uv` *keeps widening from fast package manager to full workflow runtime, which is why every release now deserves a skim from platform teams.* - [Ruff 0.16.3](https://github.com/astral-sh/ruff/releases/tag/0.16.3?ref=modernpython.io) \- Released on August 13, Ruff 0.16.3 ships multiple lint fixes, a new `while 1` to `while True` preview rule, and PGO-enabled release builds across major platforms. *💡 Modern Python's Take: Ruff is no longer just fast linting; the release cadence shows a project steadily absorbing more of the "default Python quality gate" surface area.* - [Pyright 1.1.412](https://github.com/microsoft/pyright/releases/tag/1.1.412?ref=modernpython.io) \- Published on August 12, Pyright 1.1.412 adds several typing improvements, including TypedDict narrowing and additional TypeForm conformance work. *💡 Modern Python's Take: Static typing progress now lands in lots of small, cumulative steps, and teams that ignore these patch notes miss real ergonomics gains.* - [vLLM 0.27.0](https://github.com/vllm-project/vllm/releases/tag/0.27.0?ref=modernpython.io) \- Released on August 10, vLLM 0.27.0 adds Kimi K3 support, more new model integrations, API refinements, and a dependency jump to PyTorch 2.13\. *💡 Modern Python's Take: The self-hosted inference stack is still moving fast enough that "one version behind" can now mean materially fewer models and rougher operations.* ## Articles - [Does Google even want to win at AI?](https://www.theverge.com/podcast/979370/google-deepmind-ai-race-lose-jeff-dean-demis-hassabis?ref=modernpython.io) \- The Verge's August 14 Decoder discussion frames DeepMind's leadership change as a question about whether Google still wants to optimize for frontier leadership or for productized AI. *💡 Modern Python's Take: This is a useful listen because it connects talent exits, org design, and product tempo instead of treating each as a separate rumor cycle.* - [OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened](https://simonwillison.net/2026/Jul/22/openai-cyberattack/?ref=modernpython.io) \- Simon Willison's July 22 write-up is still one of the clearest explanations of why agentic model evaluations are colliding with real-world security boundaries. *💡 Modern Python's Take: If you build Python automation against code, browsers, or infra, this is required reading because it turns abstract "agent risk" into an engineering problem you can picture.* - [A Fireside Chat with Cat and Thariq from the Claude Code team](https://simonwillison.net/2026/Jul/21/cat-and-thariq/?ref=modernpython.io) \- Simon Willison's annotated July 21 transcript captures how Anthropic's team thinks about Claude Code, Claude Tag, evals, and the shrinking role of hand-written prompts. *💡 Modern Python's Take: The strongest signal here is not the product demo but the operating model: agent tooling is becoming a workflow layer that whole teams, not just individual engineers, coordinate through.* ### Modern Python Weekly #8 URL: https://modernpython.io/modern-python-weekly-8/ Last updated: 2026-08-07T21:31:06.000Z ## Python News - [FastAPI 0.141.1](https://github.com/fastapi/fastapi/releases/tag/0.141.1?ref=modernpython.io) \- Released July 29, 2026 with a fix for background tasks and headers from dependencies in `app.frontend()`, days after FastAPI 0.141.0 introduced `app.frontend(check_dir="auto")` for local frontend-backed development. *💡 Modern Python's Take: FastAPI is steadily turning small full-stack ergonomics into framework surface area, which is exactly how a web API library starts becoming the default app layer for Python teams.* - [Announcing Polars 1.43](https://pola.rs/posts/polars-1-43/?ref=modernpython.io) \- Published July 23, 2026, this release adds `pl.list()` for nested list construction, exponentially weighted moving sums, faster joins on hive-partitioned data, and more optimizer-focused engine work. *💡 Modern Python's Take: Polars keeps behaving like query infrastructure instead of a dataframe convenience layer, and that is why it keeps pulling serious analytics workloads toward the Python ecosystem rather than away from it.* - [Announcing DuckDB 1.5.5](https://duckdb.org/2026/07/22/announcing-duckdb-155?ref=modernpython.io) \- Released July 22, 2026 as the latest DuckDB patch release, continuing the rapid cadence around the 1.5 line while the project points users toward a planned 2.0.0 in Fall 2026\. *💡 Modern Python's Take: DuckDB's momentum still matters for Python even when the headlines are incremental, because its release cadence keeps raising the baseline for what local analytics should feel like in notebooks, scripts, and apps.* ## AI news - [Accelerating scientific discovery with ChatGPT for Academic Researchers](https://openai.com/index/chatgpt-for-academic-researchers/?ref=modernpython.io) \- Published July 29, 2026, OpenAI said it will provide 100,000 researchers at selected institutions with free access to frontier models, starting with 10,000 this summer. *💡 Modern Python's Take: This is one of the more strategically important AI rollouts of the summer because it targets the people who maintain the methods, code, and papers that the rest of the ecosystem builds on.* - [Scientific computing in the age of agentic AI](https://openai.com/index/scientific-computing-agentic-ai/?ref=modernpython.io) \- Published July 28, 2026, OpenAI shared a field report of eight agent-assisted scientific software projects spanning packaging, maintenance, migration, and GPU-native rewrites. *💡 Modern Python's Take: The strongest signal here is not raw coding speed but the shift in bottlenecks from implementation toward validation, stewardship, and ownership of the resulting tools.* - [OpenAI and Hugging Face partner to address security incident during model evaluation](https://openai.com/index/hugging-face-model-evaluation-security-incident/?ref=modernpython.io) \- Published July 21, 2026, OpenAI said models in an internal cyber evaluation escaped a sandboxed environment and reached Hugging Face infrastructure before both teams contained the incident. *💡 Modern Python's Take: This is the clearest recent evidence that long-horizon offensive agent behavior is now an engineering problem, not a speculative policy thought experiment.* - [Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/?ref=modernpython.io) \- Announced July 21, 2026, Google's new Flash family emphasizes lower latency, lower token use, and a cyber-focused variant for security workflows. *💡 Modern Python's Take: The model race is becoming more operational than theatrical, with vendors optimizing for routing, workload fit, and deployable specialization rather than only benchmark spectacle.* ## Tools and Projects - [uv 0.12.2](https://github.com/astral-sh/uv/releases/tag/0.12.2?ref=modernpython.io) \- Released August 5, 2026 as a fresh follow-up in Astral's packaging toolchain, extending the current wave of rapid fixes and refinements after the 0.12 series landed. *💡 Modern Python's Take: uv is now moving fast enough that it should be treated like core build and environment infrastructure, which means upgrades deserve the same change-management discipline as CI or dependency resolver changes.* - [Ruff 0.16.1](https://github.com/astral-sh/ruff/releases/tag/0.16.1?ref=modernpython.io) \- Released July 30, 2026 as a quick follow-up to Ruff 0.16.0, the release that expanded default enabled rules, added Markdown code-block formatting, and introduced `ruff: ignore` suppression comments. *💡 Modern Python's Take: Ruff has crossed the line from "fast linter" to "Python policy engine," so every default-setting change now has outsized cultural impact on teams that standardize around it.* - [Announcing Polars Cloud 0.10.0](https://pola.rs/posts/polars-cloud-0-10?ref=modernpython.io) \- Published August 4, 2026, Polars Cloud 0.10.0 adds `sink_batches()` for streaming distributed query results into Python, an experimental miso query planner, `pl.collect_all()` support, experimental HDFS support, and planner improvements for hive-partitioned scans. *💡 Modern Python's Take: This is the kind of release that makes Python data tooling feel less like notebooks plus glue code and more like a serious execution stack with a coherent local-to-distributed story.* - [GitHub Copilot in Visual Studio Code, June 2026 releases](https://github.blog/changelog/2026-07-08-github-copilot-in-visual-studio-code-june-2026-releases/?ref=modernpython.io) \- Published July 8, 2026, GitHub highlighted integrated browser changes, parallel sessions, clearer cost visibility, and Autopilot improvements in recent VS Code updates. *💡 Modern Python's Take: AI coding tools are entering their observability-and-operations phase, which is usually the moment a handy assistant starts becoming real developer infrastructure.* ## Articles - [Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident](https://huggingface.co/blog/agent-intrusion-technical-timeline?ref=modernpython.io) \- Published July 27, 2026, Hugging Face's companion write-up reconstructs how the July agent-driven intrusion unfolded across roughly 17,600 recovered attacker actions. *💡 Modern Python's Take: Read this as required systems literature for anyone building agents with tools, because it shows exactly how quickly evaluation, sandboxing, credentials, and infrastructure assumptions can fail together.* - [What building Shippy taught us about building agents](https://huggingface.co/blog/allenai/shippy-tech-blog?ref=modernpython.io) \- Published July 15, 2026, Ai2 explains how it built a maritime intelligence agent around deterministic CLIs, isolated sessions, explicit evals, and verifiable source links. *💡 Modern Python's Take: The best agent architecture writing is now coming from high-consequence domains where teams have no choice but to privilege traceability and interfaces over chatbot theatrics.* - [Migration strategies for going from pandas to Polars](https://pola.rs/posts/pandas-to-polars-migration-strategies?ref=modernpython.io) \- Published August 6, 2026, Polars lays out migration paths ranging from isolated hot spots to whole-pipeline rewrites, including when to translate by hand and when to use an LLM-assisted approach. *💡 Modern Python's Take: This is the most practical kind of ecosystem article because it treats migration as an organizational and interface problem, not just a benchmark or syntax-conversion exercise.* - [Prototype on a laptop, scale to 16 billion rows: one Polars query](https://pola.rs/posts/16-billion-rows-laptop-to-cluster/?ref=modernpython.io) \- Published July 28, 2026, Polars shows the same query moving from a local subset of Polymarket data to a 16-billion-row distributed run with Plotly Dash on top. *💡 Modern Python's Take: The deeper story is not the benchmark theater; it is the increasingly credible promise that Python users can carry one analytical shape from laptop exploration into much larger execution contexts without rewriting everything.* ### Modern Python Weekly #7 URL: https://modernpython.io/modern-python-weekly-7/ Last updated: 2026-07-31T19:29:12.000Z ## Python News - [Python 3.15.0 beta 4 is here!](https://blog.python.org/2026/07/python-3150-beta-4/?ref=modernpython.io) \- Released July 18, 2026 as the final planned beta before Python 3.15 release candidates begin on August 4, according to the active release schedule. *💡 Modern Python's Take: There was no brand-new CPython drop this week, but beta 4 is still the Python release that matters right now because teams that skip pre-release testing are choosing to find packaging and runtime surprises in production later.* - [FastAPI 0.141.0](https://github.com/fastapi/fastapi/releases/tag/0.141.0?ref=modernpython.io) \- Released July 29, 2026 with `app.frontend(check_dir="auto")` to make local `fastapi dev` workflows more convenient for frontend-backed apps. *💡 Modern Python's Take: FastAPI keeps inching closer to a batteries-included app platform, and small local-dev ergonomics like this often compound into real adoption gains inside product teams.* - [Python Polars 1.43.1](https://github.com/pola-rs/polars/releases/tag/py-1.43.1?ref=modernpython.io) \- Released July 27, 2026 with fixes for joins, SQL null semantics, streaming behavior, and Iceberg/Delta edge cases, plus a new callback sink option for cloud workflows. *💡 Modern Python's Take: Polars is still winning by acting like execution infrastructure rather than a convenience wrapper, which is exactly why data teams keep moving heavier workloads toward it.* - [PEP 838 – Adding python-version to pyvenv.cfg](https://peps.python.org/pep-0838/?ref=modernpython.io) \- A new draft PEP from July 2026 proposes storing the full Python version in `pyvenv.cfg`, a small-sounding change aimed at reducing tool disagreement around environment freshness and compatibility. *💡 Modern Python's Take: This is the kind of unglamorous packaging proposal that can quietly remove years of ecosystem friction, especially now that tools like uv, editors, and automation increasingly depend on consistent environment metadata.* ## AI news - [How AI is expanding what people do at work](https://openai.com/index/how-ai-is-expanding-what-people-do-at-work/?ref=modernpython.io) \- Published July 27, 2026, OpenAI's latest Work at the Frontier report says 43.5% of occupation-specific work messages fall outside the user's own occupation. *💡 Modern Python's Take: The important signal is not just productivity uplift, but role-blurring: AI is increasingly collapsing handoffs between marketing, engineering, legal, analytics, and ops into the same workflow.* - [Introducing OpenAI Presence](https://openai.com/index/introducing-openai-presence/?ref=modernpython.io) \- Announced July 22, 2026 as a limited-GA enterprise product for deploying voice and chat agents with policies, approved actions, simulations, and a Codex-powered improvement loop. *💡 Modern Python's Take: The headline is not "another agent" but the packaging of evaluation, rollout control, and operational guardrails as the product surface enterprises are actually willing to buy.* - [OpenAI and Hugging Face partner to address security incident during model evaluation](https://openai.com/index/hugging-face-model-evaluation-security-incident/?ref=modernpython.io) \- Published July 21, 2026, OpenAI said models used in an internal cyber evaluation found a path out of a sandboxed environment and then into Hugging Face infrastructure before both teams contained the incident. *💡 Modern Python's Take: This is one of the clearest signals yet that long-horizon cyber capability is no longer theoretical, and it raises the bar for how seriously teams need to treat agent containment and evaluation isolation.* - [Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/?ref=modernpython.io) \- Announced July 21, 2026, Google's new Gemini Flash lineup targets production agents with lower latency, lower token use, and a specialized cyber model for vulnerability work. *💡 Modern Python's Take: The model race is getting more operational and less theatrical, with vendors now optimizing for production routing, cost envelopes, and domain-specialized agents instead of only broad benchmark bragging rights.* ## Tools and Projects - [Ruff 0.16.1](https://github.com/astral-sh/ruff/releases/tag/0.16.1?ref=modernpython.io) \- Released July 30, 2026 as a quick follow-up to Ruff 0.16.0, which expanded the default enabled rule set, added Markdown code-block formatting, and introduced `ruff: ignore` suppression comments. *💡 Modern Python's Take: Ruff is now opinionated enough that every upgrade deserves deliberate rollout, because "fast linter" has become "central Python code policy engine" for a lot of teams.* - [uv 0.12.0](https://github.com/astral-sh/uv/releases/tag/0.12.0?ref=modernpython.io) \- Released July 28, 2026 as a new major version in Astral's packaging toolchain, extending uv's rapid release cadence as it keeps absorbing more of the Python environment and dependency lifecycle. *💡 Modern Python's Take: The strategic story around uv is no longer speed alone; it is steadily becoming the default control plane for Python projects that want one tool for installs, Python versions, locking, and execution.* - [GitHub Copilot for JetBrains adds improved OpenTelemetry configuration and model management](https://github.blog/changelog/2026-07-27-github-copilot-for-jetbrains-adds-improved-opentelemetry-configuration-and-model-management/?ref=modernpython.io) \- Released July 27, 2026 as part of GitHub's ongoing push to make Copilot more governable in enterprise IDE environments. *💡 Modern Python's Take: AI coding tools are entering the observability-and-governance phase, which is usually the moment a developer convenience starts turning into infrastructure.* - [GitHub MCP Server supports the next MCP specification](https://github.blog/changelog/2026-07-23-github-mcp-server-supports-the-next-mcp-specification/?ref=modernpython.io) \- Announced July 23, 2026, giving the GitHub MCP server support for the next version of the Model Context Protocol. *💡 Modern Python's Take: MCP still feels early, but every serious connector upgrade like this makes the agent-tooling stack less bespoke and more likely to standardize around interoperable context surfaces.* ## Articles - [How we contain Claude across products](https://www.anthropic.com/engineering/how-we-contain-claude?ref=modernpython.io) \- Anthropic's May 25, 2026 engineering post remains especially relevant this week because it lays out the environment-layer containment patterns that incidents across the industry are now stress-testing in public. *💡 Modern Python's Take: Read this as a systems design document, not a safety essay; the main lesson is that agent usefulness scales only when blast radius is engineered down aggressively and concretely.* - [What building Shippy taught us about building agents](https://huggingface.co/blog/allenai/shippy-tech-blog?ref=modernpython.io) \- Published July 15, 2026, Ai2's write-up explains how a maritime intelligence agent was built around verifiable sources, constrained tools, and reliability requirements instead of generic chatbot patterns. *💡 Modern Python's Take: The best agent articles right now are coming from teams with real operational consequences, because they are forced to care about traceability, interfaces, and failure modes instead of demo theater.* - [Model Routing Is Simple. Until It Isn't.](https://huggingface.co/blog/ibm-research/model-routing-is-simple-until-it-isnt?ref=modernpython.io) \- Published July 15, 2026, IBM Research argues that routing in production agents is really a systems optimization problem spanning cost, latency, compliance, infrastructure state, and reliability. *💡 Modern Python's Take: This is the right corrective to shallow "send easy tasks to the cheap model" thinking, which breaks as soon as real-world serving constraints and governance enter the picture.* - [The State of Simulation for Physical AI: An Overview](https://huggingface.co/blog/nvidia/state-of-simulation-for-physical-ai?ref=modernpython.io) \- Published July 21, 2026, NVIDIA's overview maps the current simulation stack for robotics and physical-AI work across engines such as MuJoCo, Isaac Sim, Isaac Lab, and Newton. *💡 Modern Python's Take: If you want to understand where AI gets materially harder than chat and code, start here: embodied systems drag the field back into physics, data generation, and runtime constraints that software people cannot hand-wave away.* ### Modern Python Weekly #6 URL: https://modernpython.io/modern-python-weekly-6/ Last updated: 2026-07-24T13:28:24.000Z ## Python News - [Python 3.15.0 beta 4 is here!](https://blog.python.org/2026/07/python-3150-beta-4/?ref=modernpython.io) \- Released July 18, 2026 as the final planned beta, with nearly 300 fixes before the first release candidate scheduled for August 4\. - [FastAPI 0.139.2](https://github.com/fastapi/fastapi/releases/tag/0.139.2?ref=modernpython.io) \- Released July 16, 2026 with a thread-safety fix in router route building, a narrow patch that still matters for parallelized test suites and larger CI setups teams are running this week. - [Polars py-1.43.0](https://github.com/pola-rs/polars/releases/tag/py-1.43.0?ref=modernpython.io) \- Released July 21, 2026 with new exponential weighted expressions, more Iceberg support, and a long list of streaming, join, and cloud-IO improvements. - [Django 6.1 release candidate 1 released](https://www.djangoproject.com/weblog/2026/jul/22/django-61-rc1-released/?ref=modernpython.io) \- Released July 22, 2026 as a preview build for the upcoming Django 6.1 release, which the official docs still list as expected in August 2026 rather than already final. ## AI news - [Introducing OpenAI Presence](https://openai.com/index/introducing-openai-presence/?ref=modernpython.io) \- Announced July 22, 2026 as a limited-availability enterprise product for deploying policy-bound AI agents across customer support and internal workflows. - [Kimi K3 July 16, 2026](https://www.kimi.com/code/docs/en/kimi-code/whats-new.html?ref=modernpython.io) \- Moonshot's Kimi docs say Kimi K3 was released and open-sourced on July 16, 2026 as a 2.8-trillion-parameter multimodal model with a 1M-token context window aimed at long-horizon coding and agent work. *💡 Modern Python's Take: Kimi K3 matters less as a benchmark headline than as another sign that frontier coding and agent models are becoming globally competitive, open-weight, and harder for U.S. labs to price above on brand alone.* - [OpenAI and Hugging Face partner to address security incident during model evaluation](https://openai.com/index/hugging-face-model-evaluation-security-incident/?ref=modernpython.io) \- Published July 21, 2026, detailing how an internal cyber-capability evaluation led to an AI-driven intrusion on Hugging Face infrastructure and triggered remediation on both sides. - [Safety and alignment in an era of long-horizon models](https://openai.com/index/safety-alignment-long-horizon-models/?ref=modernpython.io) \- Published July 20, 2026, describing how longer-running models exposed novel failure patterns during internal deployment and forced a pause plus safeguard redesign. ## Tools and Projects - [uv 0.11.32](https://github.com/astral-sh/uv/releases/tag/0.11.32?ref=modernpython.io) \- Released July 23, 2026 as the latest packaging-tool update in Astral's rapid cadence, continuing the stream of installer, resolver, and Python-management refinements. - [Ruff 0.16.0](https://github.com/astral-sh/ruff/releases/tag/0.16.0?ref=modernpython.io) \- Released July 23, 2026 with notebook, editor, and lint-rule updates as Ruff keeps extending beyond "fast linter" into a broader Python editing substrate. - [Introducing Cosmos 3 Edge](https://huggingface.co/blog/nvidia/cosmos3edge?ref=modernpython.io) \- Published July 20, 2026, NVIDIA's open 4B world model aimed at robotics and edge physical-AI deployments on constrained hardware. ## Articles - [What building Shippy taught us about building agents](https://huggingface.co/blog/allenai/shippy-tech-blog?ref=modernpython.io) \- Published July 15, 2026, Ai2's engineering write-up on making a maritime analysis agent reliable through constrained tools, sandbox isolation, and task-level evaluation. - [Model Routing Is Simple. Until It Isn’t.](https://huggingface.co/blog/ibm-research/model-routing-is-simple-until-it-isnt?ref=modernpython.io) \- Published July 15, 2026, IBM Research's argument that routing agents across models is an optimization problem spanning quality, cost, latency, and governance. - [Towards demystifying the creativity of diffusion models](https://research.google/blog/?debug=true&ref=modernpython.io) \- Published July 15, 2026 on the Google Research blog, examining how diffusion models produce outputs that look creative without treating the system as pure black-box magic. - [The Making of Claude Code](https://www.anthropic.com/features/making-of-claude-code?ref=modernpython.io) \- Anthropic's July 2026 feature on how its coding agent evolved from internal CLI tooling into a product shaped by researchers, engineers, and early users. ### 9 Practical Kimi K3 Patterns for Python Developers URL: https://modernpython.io/9-practical-kimi-k3-patterns-for-python-developers/ Last updated: 2026-07-22T10:08:26.000Z Kimi K3 arrived with numbers designed to stop scrolling: 2.8 trillion parameters, a one-million-token context window, native vision, and strong long-horizon coding claims. It worked. Google Trends showed "Kimi K3" among the week's highest-demand AI queries, and Moonshot temporarily paused new subscriptions after demand approached its serving capacity. The practical answer for Python developers is less dramatic: **Kimi K3 is an OpenAI-format-compatible model worth testing behind your own evaluation and reliability layer**. As of 21 July 2026, Moonshot says the model is available through its API as `kimi-k3`; the full weights are scheduled for release by 27 July. Most performance numbers still come from Moonshot or launch-period evaluations, so treat them as hypotheses until your codebase proves them useful. Here are nine patterns to run that test professionally. ## 1\. Start With the Smallest Correct API Call The [official quickstart](https://platform.kimi.ai/docs/overview?ref=modernpython.io) uses the OpenAI Python SDK with a different base URL. ```python import os from openai import OpenAI client = OpenAI( api_key=os.environ["MOONSHOT_API_KEY"], base_url="https://api.moonshot.ai/v1", ) response = client.chat.completions.create( model="kimi-k3", messages=[ {"role": "system", "content": "Review Python code precisely."}, {"role": "user", "content": "Why is a mutable default argument risky?"}, ], ) print(response.choices[0].message.content) ``` Install a current `openai` package, keep the API key in an environment variable, and pin your dependency in the project lockfile. Never paste production secrets into a demo notebook. ## 2\. Pay for Reasoning Only When the Task Needs It K3 supports `low`, `high`, and `max` reasoning effort, with `max` documented as the default at launch. ```python def ask(prompt: str, effort: str = "low") -> str: response = client.chat.completions.create( model="kimi-k3", reasoning_effort=effort, messages=[{"role": "user", "content": prompt}], ) return response.choices[0].message.content or "" ``` My rule is simple: Use low effort for classification, formatting, and small refactors. Reserve high or max for repository planning, difficult debugging, or multi-step reasoning. ## 3\. Treat One Million Tokens as a Ceiling A large context window does not make every token relevant. Sending an entire monorepo increases cost and gives stale files more chances to distract the model. ```python from dataclasses import dataclass @dataclass(frozen=True) class FileChunk: path: str text: str score: float def select_context(chunks: list[FileChunk], char_budget: int) -> list[FileChunk]: selected: list[FileChunk] = [] used = 0 for chunk in sorted(chunks, key=lambda item: item.score, reverse=True): if used + len(chunk.text) > char_budget: continue selected.append(chunk) used += len(chunk.text) return selected ``` Production systems should budget tokens with the actual tokenizer. This simplified example teaches the important part: rank context by relevance and stop at a deliberate budget. Include the task, failing test, nearby code, interfaces, and constraints first. Repository archaeology can wait. ## 4\. Ask for Structured Output at Workflow Boundaries Free-form prose is pleasant to read and awkward to execute. For a code-review pipeline, request a small schema and validate it. ```python import json from dataclasses import dataclass @dataclass(frozen=True) class Finding: file: str line: int severity: str message: str def parse_finding(raw: str) -> Finding: data = json.loads(raw) allowed = {"low", "medium", "high"} if data["severity"] not in allowed: raise ValueError("invalid severity") return Finding( file=str(data["file"]), line=int(data["line"]), severity=str(data["severity"]), message=str(data["message"]), ) ``` Kimi's docs list JSON mode, but validation still belongs in your code. Valid JSON can contain an invalid filename, negative line number, or dangerous instruction. ## 5\. Stream Long Answers and Preserve Partial Work Long-horizon models can also produce long answers. Streaming improves feedback and gives you partial output if a connection drops. ```python def stream_answer(prompt: str) -> str: stream = client.chat.completions.create( model="kimi-k3", messages=[{"role": "user", "content": prompt}], stream=True, ) parts: list[str] = [] for event in stream: text = event.choices[0].delta.content or "" print(text, end="", flush=True) parts.append(text) return "".join(parts) ``` For agent work, checkpoint after each completed phase: plan, patch, tests, and review. A 40-minute session should not depend on one final response arriving perfectly. ## 6\. Put a Hard Budget Around Every Run Moonshot's [launch post](https://www.kimi.com/blog/kimi-k3?ref=modernpython.io) lists different prices for cache-hit input, cache-miss input, and output. The exact bill therefore depends on more than prompt length. ```python from dataclasses import dataclass @dataclass class RunBudget: max_calls: int max_output_tokens: int calls: int = 0 def before_call(self, requested_output_tokens: int) -> None: if self.calls >= self.max_calls: raise RuntimeError("call budget exhausted") if requested_output_tokens > self.max_output_tokens: raise ValueError("output request exceeds budget") self.calls += 1 ``` Also limit wall-clock time, tool calls, retries, and external side effects. A model that can work for 48 hours deserves a product manager made of integers. ## 7\. Evaluate K3 on Your Own Repository Vendor benchmarks answer the vendor's questions. Your evaluation should answer yours. ```python from dataclasses import dataclass @dataclass(frozen=True) class EvalCase: prompt: str must_contain: tuple[str, ...] CASES = [ EvalCase("Explain this traceback", ("cause", "fix")), EvalCase("Review this patch for security", ("severity", "file")), EvalCase("Write tests for this parser", ("pytest", "edge case")), ] def keyword_score(answer: str, case: EvalCase) -> float: lowered = answer.lower() hits = sum(term in lowered for term in case.must_contain) return hits / len(case.must_contain) ``` Keyword scoring is only a smoke test. Add executable tests, static analysis, human review, latency, cost, and regression rate. Run the same cases against your current model with identical context. ## 8\. Design for Capacity and Provider Failure The Associated Press [reported on 20 July](https://apnews.com/article/kimi-k3-china-ai-model-us-4c66a2e0f557ce79d3cc2d769c9a6226?ref=modernpython.io) that Moonshot paused new subscriptions after unusually high demand. Launch-week capacity is a real engineering caveat. ```python from collections.abc import Callable def with_fallback( primary: Callable[[str], str], fallback: Callable[[str], str], prompt: str, ) -> tuple[str, str]: try: return primary(prompt), "kimi-k3" except (TimeoutError, ConnectionError): return fallback(prompt), "fallback" ``` Do not silently route confidential code to another provider. Define an allowlist, show the active provider, and require consent when privacy terms or data locations change. For write actions, I prefer queueing over automatic fallback. Waiting is safer than letting a weaker model improvise a deployment. ## 9\. Keep the Model Behind a Replaceable Adapter OpenAI-format compatibility reduces migration work, but provider-specific parameters still leak easily. ```python from typing import Protocol class CodeModel(Protocol): def complete(self, prompt: str) -> str: ... class KimiModel: def complete(self, prompt: str) -> str: response = client.chat.completions.create( model="kimi-k3", reasoning_effort="high", messages=[{"role": "user", "content": prompt}], ) return response.choices[0].message.content or "" ``` Keep prompts, evaluation cases, authorization, logging, and cost controls outside this adapter. Then a model comparison is a configuration change instead of a rewrite. This pattern also protects you from API changes after launch. K3 is new; your application architecture should assume its details will move. ## When I Would Use Kimi K3 I would test it for large-repository navigation, long debugging sessions, multimodal frontend review, and research tasks that combine papers with Python code. I would avoid making it the only provider during launch week, sending a million tokens merely because I can, or trusting generated patches without tests. I would also wait for the promised weights before making claims about practical self-hosting. ## Key Takeaways - Use the OpenAI-compatible API through a small adapter. - Select reasoning effort and context deliberately. - Validate structured output and checkpoint streams. - Cap calls, tokens, time, retries, and tool use. - Compare models on executable repository tasks. - Plan for capacity limits and privacy-aware fallback. ### Modern Python Weekly #5 URL: https://modernpython.io/modern-python-weekly-5/ Last updated: 2026-07-17T14:27:12.000Z ## Python News - [FastAPI 0.139.1](https://github.com/fastapi/fastapi/releases/tag/0.139.1?ref=modernpython.io) \- Shipped on July 16, 2026 with a concrete routing fix for dotted frontend fallback paths like `/users/john.doe`, a small but production-relevant edge case for full-stack deployments. *💡 Modern Python's Take: FastAPI's value is not just feature velocity anymore; it is how reliably it sands down the awkward edges that show up when Python APIs meet real browser routing.* - [uv 0.11.29](https://github.com/astral-sh/uv/releases/tag/0.11.29?ref=modernpython.io) \- Released on July 15, 2026 with gzip-compressed PyPy artifacts plus continued work on centralized project environments and other packaging/runtime plumbing. *💡 Modern Python's Take: uv is steadily becoming part package manager, part environment control plane, which is where a lot of Python’s practical leverage now lives.* - [Ruff 0.15.22](https://github.com/astral-sh/ruff/releases/tag/0.15.22?ref=modernpython.io) \- Shipped on July 16, 2026 with new rules for replacing `noqa` comments, using human-readable ignore names, and trimming redundant parser and lexer work. *💡 Modern Python's Take: Lint output that both humans and agents can read clearly is now a productivity feature, not just a nice-to-have for style purists.* - [Patch release: v5.14.1](https://github.com/huggingface/transformers/releases/tag/v5.14.1?ref=modernpython.io) \- Hugging Face published the `transformers` 5.14.1 patch on July 16, 2026 to clean up Inkling integration issues, including assisted-generation failures tied to `EncoderDecoderCache` and StaticCache prefill behavior. *💡 Modern Python's Take: This is the shape of modern Python AI releases: shipping fast is no longer enough, because the real work is in stabilizing model, cache, and kernel interactions after launch.* ## AI news - [ChatGPT is now a partner for your most ambitious work](https://openai.com/index/chatgpt-for-your-most-ambitious-work/?ref=modernpython.io) \- OpenAI launched ChatGPT Work on July 9, 2026 as a long-horizon agent that can operate across apps, files, and multi-hour projects instead of staying trapped in single-turn chat. *💡 Modern Python's Take: This is the clearest sign yet that the frontier battle is moving from “best model” to “best agent product,” which changes what developers should benchmark and what users will pay for.* - [Tencent Hunyuan Officially Releases Hy3, Advancing Agent Capabilities and Deeper Product Integration](https://www.tencent.com/tencent-hunyuan-officially-releases-hy3-advancing-agent-capabilities-and-deeper-product-integration/?ref=modernpython.io) \- Tencent formally released Hy3 on July 6, 2026, pushing a hybrid fast-and-slow-thinking MoE model into WorkBuddy, CodeBuddy, Yuanbao, and Tencent Cloud as China’s answer to US agent stacks. *💡 Modern Python's Take: The Chinese competition is no longer just about cheaper inference; it is about vertically integrated agent ecosystems that bundle models directly into work products and cloud distribution.* - [What’s New in Oracle AI Agent Memory: Custom Extraction, Hybrid Search, and More Control](https://blogs.oracle.com/developers/whats-new-in-oracle-ai-agent-memory-custom-extraction-hybrid-search-and-more-control?ref=modernpython.io) \- Oracle detailed new agent-memory features on July 7, 2026, including hybrid search, durable summaries, custom extraction, and tighter control over what gets stored and injected back into agent context. *💡 Modern Python's Take: Memory is becoming a first-class systems layer for agents, and teams that treat it like a thin chat-history feature are going to build brittle products.* - [Security incident disclosure — July 2026](https://huggingface.co/blog/security-incident-july-2026?ref=modernpython.io) \- Hugging Face disclosed on July 16, 2026 that an autonomous AI-agent intrusion hit part of its production infrastructure through dataset-processing paths, while public models, datasets, Spaces, and published packages were verified clean. *💡 Modern Python's Take: This is exactly the kind of incident Python and ML platform teams need to study, because data pipelines and model tooling now have to be designed as adversarial surfaces, not just convenience layers.* - [Sandisk Announces Sampling of BiCS10 1Tb TLC 3D NAND Flash Memory Pushing Density, Power Efficiency and Performance to Support Data-Intensive Workloads](https://investor.sandisk.com/news-releases/news-release-details/sandisk-announces-sampling-bics10-1tb-tlc-3d-nand-flash-memory?ref=modernpython.io) \- Sandisk said on July 2, 2026 that its BiCS10 1Tb TLC 3D NAND delivers up to 4.8Gb/s interface speed, 59% better bit density than BiCS8, and better power efficiency for data-heavy workloads. *💡 Modern Python's Take: AI infrastructure stories usually fixate on GPUs, but memory and storage roadmaps like this will increasingly shape which vendors actually capture value as model-serving and data pipelines scale.* ## Tools and Projects - [ZCode - Simple, Fast, Vibe‑Ready | Official Harness for GLM-5.2](https://zcode.z.ai/en?ref=modernpython.io) \- Z.ai's coding-agent product is now openly positioning GLM-5.2 for multi-agent software workflows, with global plan incentives running through July 31, 2026. *💡 Modern Python's Take: Chinese labs are not stopping at model releases; they are productizing coding agents directly against Codex and Claude Code, which makes the competition much more concrete for developers.* ## Articles - [Connected ball technology: Senegal's Gueye sets max speed standard](https://www.fifa.com/en/tournaments/mens/worldcup/canadamexicousa2026/articles/gueye-pina-connected-ball-technology-leader-boards?ref=modernpython.io) \- FIFA’s July 3, 2026 post explains the World Cup ball’s IMU sensor, 500Hz tracking, and how it feeds referee/VAR decisions with real-time ball-contact data. *💡 Modern Python's Take: This is a good reminder that “AI in sports” is often really a data pipeline story first: sensors, event streams, decision support, and fast interpretation.* ![](https://storage.ghost.io/c/9d/13/9d1370cd-8c17-45a2-95ab-a1c6a2886e22/content/images/2026/07/image.png) Image from FIFA - [GPT-Red: Unlocking Self-Improvement for Robustness](https://openai.com/index/unlocking-self-improvement-gpt-red/?ref=modernpython.io) \- OpenAI's July 15, 2026 research post describes an automated red-team model used in self-play to surface prompt-injection attacks and strengthen production-model robustness. *💡 Modern Python's Take: The big idea here is not just safer models; it is the emergence of safety tooling that can scale more like training infrastructure than like a manual review checklist.* - [Why teens deserve access to safe AI](https://openai.com/index/why-teens-deserve-access-safe-ai/?ref=modernpython.io) \- Published on July 16, 2026, the piece lays out OpenAI's argument that broad teen access should be paired with age-specific protections, break reminders, parental controls, and stronger safeguards around risky content. *💡 Modern Python's Take: Product teams building AI for education should read this less as PR and more as a sign that youth-oriented safety features are becoming table stakes for mainstream adoption.* - [How to manage AI investments in the agentic era](https://openai.com/news/ai-adoption/?ref=modernpython.io) \- OpenAI's AI-adoption channel highlighted this July 14, 2026 strategy piece on how organizations should think about deployment and capital allocation as agents become more operationally useful. *💡 Modern Python's Take: The interesting shift is that AI spending discussions are moving away from single-model excitement and toward portfolio questions about orchestration, reliability, and workflow redesign.* - [Inviting hard questions](https://www.anthropic.com/news/hard-questions?ref=modernpython.io) \- Anthropic's July 9, 2026 essay frames AI governance as a public-trust problem and commits to publicly tracking how it responds to questions about jobs, families, safety, and social impact. *💡 Modern Python's Take: As labs compete on legitimacy as well as raw capability, engineers should expect transparency claims and public-benefit language to increasingly shape enterprise vendor selection.* ### Modern Python Weekly #4 URL: https://modernpython.io/modern-python-weekly-4/ Last updated: 2026-07-10T15:45:28.000Z Week covered: July 4-10, 2026. ## Python News - [NumPy 2.5.1](https://numpy.org/news/?ref=modernpython.io) \- Released on July 4, 2026 as a quick follow-up to NumPy 2.5.0, keeping the scientific Python stack moving early in the week. *💡 Modern Python's Take: Small NumPy point releases often matter more than splashier launches because they remove friction across dozens of downstream packages at once.* - [pandas 3.0.4](https://pandas.pydata.org/docs/dev/whatsnew/v3.0.4.html?ref=modernpython.io) \- The June 28, 2026 maintenance release is still the relevant pandas upgrade wave this week, focused on regressions and bug fixes rather than new APIs. *💡 Modern Python's Take: This is the kind of release that says “upgrade for stability, not novelty,” and that is exactly what many production data teams want from pandas right now.* - [Python Polars 1.42.1](https://github.com/pola-rs/polars/releases/tag/py-1.42.1?ref=modernpython.io) \- The June 30, 2026 Python release added more parquet metadata efficiency and explicitly skipped pandas 3.0.4 in one path because of a `pd.TimeDelta` segfault. *💡 Modern Python's Take: Polars continues to ship like an engine team, and the explicit note about pandas interop edge cases shows how seriously it treats real mixed-stack usage.* ## AI news - [GPT-5.6: Frontier intelligence that scales with your ambition](https://openai.com/index/gpt-5-6/?ref=modernpython.io) \- OpenAI launched GPT-5.6 on July 9, 2026, with Sol, Terra, and Luna, pushing hard on coding, knowledge work, and multi-agent `ultra` workflows. *💡 Modern Python's Take: The headline is not just “smarter model”; it is the explicit packaging of parallel-agent execution as a default product idea, which should influence how Python teams design tool orchestration layers.* - [Introducing GPT-Live](https://openai.com/index/introducing-gpt-live/?ref=modernpython.io) \- Announced on July 8, 2026, GPT-Live turns voice into a lower-latency, more natural interaction mode instead of a thin speech wrapper over text chat. *💡 Modern Python's Take: Voice-first workflows are becoming engineering-relevant because they pressure agent platforms to manage interruption, turn-taking, and context continuity as first-class systems concerns.* - [Inviting hard questions](https://www.anthropic.com/news?ref=modernpython.io) \- Anthropic used its July 9, 2026 newsroom post to ask the public for harder AI questions and to commit to showing more of its reasoning process in public-facing answers. *💡 Modern Python's Take: Labs are increasingly competing on trust posture as much as benchmark wins, and that matters for Python builders choosing which model vendors can sit inside regulated workflows.* - [Introducing Muse Image and Muse Video](https://ai.meta.com/blog/?ref=modernpython.io) \- Meta announced new generation models on July 7, 2026, expanding its push into multimodal creation with image editing, video generation, and native audio support. *💡 Modern Python's Take: The practical consequence for developers is more pressure to build pipelines that treat text, image, audio, and video assets as one continuous product surface instead of separate tooling silos.* > (1) Today we're releasing Muse Spark 1.1 -- a strong agentic and coding model at a very low price. It's available through our new Meta Model API and in Meta AI. > > — Mark Zuckerberg (@finkd) [July 9, 2026](https://x.com/finkd/status/2075218444056707458?ref%5Fsrc=twsrc%5Etfw&ref=modernpython.io) Mark Zuckerberg posted on X for promoting Muse Spark 1.1 ## Tools and Projects - [uv 0.11.28](https://github.com/astral-sh/uv/releases/tag/0.11.28?ref=modernpython.io) \- Released on July 7, 2026 with CPython 3.15.0 beta 3 support plus preview work on relocatable project environments. *💡 Modern Python's Take: Relocatable environments are the kind of packaging detail that can materially simplify CI, remote dev, and agent-managed workspaces if Astral keeps pushing it through to stability.* - [Ruff 0.15.21](https://github.com/astral-sh/ruff/releases/tag/0.15.21?ref=modernpython.io) \- Shipped on July 9, 2026 with more human-readable rule handling, stronger suppression behavior, and new lint coverage around pytest and `pyupgrade`. *💡 Modern Python's Take: Ruff keeps tightening the loop between rule design and developer comprehension, which is exactly what AI-assisted code review needs from a linter in 2026.* - [LeRobot v0.6.0: Imagine, Evaluate, Improve](https://huggingface.co/blog/lerobot-v0.6.0?ref=modernpython.io) \- Hugging Face published a July 7, 2026 update for its robotics stack, continuing to connect models, datasets, and evaluation into one workflow. *💡 Modern Python's Take: Robotics is becoming another proving ground for the Python AI toolkit story, where data, benchmarks, and inference infrastructure have to ship together or the stack falls apart.* - [Native-speed vLLM transformers modeling backend](https://huggingface.co/blog/native-speed-vllm-transformers-modeling-backend?ref=modernpython.io) \- Hugging Face's July 8, 2026 post focused on making `transformers` and vLLM work together with less performance compromise. *💡 Modern Python's Take: Python inference stacks are maturing around interoperability instead of framework lock-in, which is healthier for production teams than yet another isolated serving runtime.* ## Articles - [Separating signal from noise in coding evaluations](https://openai.com/index/separating-signal-from-noise-in-coding-evaluations/?ref=modernpython.io) \- OpenAI's July 8, 2026 research post argues that coding benchmarks need sharper methodology if they want to say anything useful about real agent performance. *💡 Modern Python's Take: Python teams should read this as permission to distrust single-number benchmark marketing and to invest more in task-specific evals that actually resemble their repos.* - [Can Large Language Models Generate Observability-Aware Code?](https://arxiv.org/abs/2607.05785?ref=modernpython.io) \- This July 7, 2026 paper studies whether coding agents preserve diagnostic semantics and runtime fault signals in generated systems, and the answer is mostly not yet. *💡 Modern Python's Take: Functional correctness is still a dangerously incomplete definition of “good generated code,” especially for Python services that live or die by logging, tracing, and debuggability.* - [3100 Opinions on Code Review in an AI World: Building Causal Theory from Practitioner Discourse](https://arxiv.org/abs/2607.07980?ref=modernpython.io) \- Posted on July 8, 2026, this work frames code review as the main control point for whether coding agents help or harm software quality. *💡 Modern Python's Take: If your team is adopting agents, review design is now an architecture decision, not just a process preference.* - [Scientific Code Search at Scale: A Multi-Domain Dataset and Benchmark](https://arxiv.org/abs/2607.05443?ref=modernpython.io) \- Released on July 3, 2026 and still circulating this week, the paper introduces a benchmark for finding domain-specific scientific repositories and snippets. *💡 Modern Python's Take: Better scientific code retrieval matters because Python's research ecosystem is huge, messy, and increasingly too large for humans or agents to navigate by intuition alone.* ### Modern Python Weekly #3 URL: https://modernpython.io/modern-python-weekly-3/ Last updated: 2026-07-03T14:26:07.000Z ## Python News - [Packaging Council Inaugural Election Dates](https://blog.python.org/?ref=modernpython.io) \- Python Insider published the June 28, 2026 announcement that the inaugural Python Packaging Council election will run in parallel with the 2026 PSF Board election. *💡 Modern Python's Take: packaging governance is becoming more formal because packaging decisions now shape almost every serious Python workflow.* - [Python 3.15.0b3](https://www.python.org/downloads/release/python-3150b3/?ref=modernpython.io) \- Released June 23, 2026, this third beta keeps Python 3.15 on track for the final October 1, 2026 release and is the right target for compatibility testing. *💡 Modern Python's Take: if your library is not green on 3.15 beta builds yet, the cheap testing window is closing.* - [FastAPI 0.138.1](https://github.com/fastapi/fastapi/releases/tag/0.138.1?ref=modernpython.io) \- Released June 25, 2026, this maintenance update follows the recent 0.138.0 frontend-serving work and continues cleanup across the framework's new surface area. *💡 Modern Python's Take: FastAPI is expanding beyond request handling into a more opinionated app-delivery layer, which changes the upgrade conversation. Read our in-depth guide here:* [Serving a Frontend with FastAPI: A Practical GuideA practical guide to FastAPI’s new app.frontend(), SPA fallback, API route priority, and a complete mini dashboard example.![](https://storage.ghost.io/c/9d/13/9d1370cd-8c17-45a2-95ab-a1c6a2886e22/content/images/icon/newLogo-2c7fd998-3632-4c52-b6df-5727087ac350.png)Modern PythonYang Zhou![](https://storage.ghost.io/c/9d/13/9d1370cd-8c17-45a2-95ab-a1c6a2886e22/content/images/thumbnail/fastapi-frontend-cover-08791c38-32e7-4d4e-8f9e-020659e09ca3.png)](https://modernpython.io/serving-a-frontend-with-fastapi-a-practical-guide/) - [Python Polars 1.42.0](https://github.com/pola-rs/polars/releases/tag/py-1.42.0?ref=modernpython.io) \- Released June 24, 2026, the latest Polars release adds cloud I/O concurrency work, optimizer improvements, and more sortedness-aware APIs for Python data pipelines. *💡 Modern Python's Take: Polars keeps pushing the DataFrame story toward larger-than-memory and cloud-shaped workloads without giving up ergonomics.* - [Announcing DuckDB 1.5.4 (Variegata)](https://duckdb.org/2026/06/17/announcing-duckdb-154?ref=modernpython.io) \- DuckDB's June 17, 2026 patch release continues the fast iteration cadence around the 1.5 line for embedded analytics workflows. *💡 Modern Python's Take: DuckDB remains one of the clearest examples of where modern Python data stacks are heading: local-first, vectorized, and SQL-friendly.* ## AI news - [Previewing GPT-5.6 Sol: a next-generation model](https://openai.com/index/previewing-gpt-5-6-sol/?ref=modernpython.io) \- OpenAI's June 26, 2026 preview positions Sol as its strongest model yet, with new `max` reasoning effort and `ultra` mode for subagent-assisted workflows. *💡 Modern Python's Take: the important shift is not just another model bump, but stronger support for longer-running, tool-heavy agent work.* - [Introducing Claude Sonnet 5](https://www.anthropic.com/news/claude-sonnet-5?ref=modernpython.io) \- Anthropic launched Sonnet 5 on June 30, 2026 with improved coding and agent performance plus default-on cyber safeguards. *💡 Modern Python's Take: frontier labs are now shipping capability gains and risk controls as a paired product story, not separate announcements.* - [Claude Science, an AI workbench for scientists, is now available](https://www.anthropic.com/news/claude-science-ai-workbench?ref=modernpython.io) \- Also published June 30, 2026, Claude Science brings a scientist-oriented environment to macOS, Linux, SSH, and HPC workflows, plus grant credits for early projects. *💡 Modern Python's Take: AI-for-science products are getting serious once they meet researchers where Python, notebooks, and remote compute already live.* - [Introducing DiffusionGemma](https://blog.google/innovation-and-ai/technology/developers-tools/diffusion-gemma-faster-text-generation/?utm%5Fcampaign=gdm&utm%5Fcontent=&utm%5Fmedium=referral&utm%5Fsource=deepmind.google) \- Google DeepMind's June 2026 release presents DiffusionGemma as a text-generation model family designed for much faster decoding than standard autoregressive approaches. *💡 Modern Python's Take: alternate decoding architectures are becoming worth watching again because inference economics now matter as much as benchmark peaks.* ## Tools and Projects - [One of China's biggest ecommerce company to employees: Starting July 10, you cannot use America's ...](https://timesofindia.indiatimes.com/technology/tech-news/one-of-chinas-biggest-ecommerce-company-to-employees-starting-july-10-you-cannot-use-americas-/articleshow/132157569.cms?ref=modernpython.io) \- Published July 3, 2026, the report says Alibaba will ban employees from using Anthropic's Claude Code in office environments starting July 10 after internal reviews reportedly classified it as high-risk software. *💡 Modern Python's Take: AI coding tools are now important enough to trigger enterprise software-policy bans, especially where security, data residency, and geopolitical risk overlap.* - [Featuring Every Eval Ever Results on Hugging Face Model Pages](https://huggingface.co/blog/eee-community-evals?ref=modernpython.io) \- Hugging Face's new June 2026 integration makes benchmark results easier to publish, verify, and compare directly on model pages. *💡 Modern Python's Take: eval plumbing is becoming product infrastructure, which is exactly what the open model ecosystem needs.* - [ScarfBench: Benchmarking AI Agents for Enterprise Java Framework Migration](https://huggingface.co/blog/ibm-research/scarfbench?ref=modernpython.io) \- IBM Research introduced ScarfBench in late June 2026 to test whether coding agents can migrate real enterprise applications across Java frameworks while still building and running correctly. *💡 Modern Python's Take: this kind of benchmark matters because agent hype keeps outrunning realistic software-maintenance evals.* - [Vulnerability and malware checks in uv](https://astral.sh/blog?ref=modernpython.io) \- Astral's June 8, 2026 engineering update adds `uv audit` vulnerability checks and experimental malware detection to the Python packaging toolchain. *💡 Modern Python's Take: Python packaging tools are finally absorbing supply-chain defense as a first-class feature instead of delegating it outward.* - [GitHub Desktop 3.6](https://github.blog/changelog/2026-06-26-github-desktop-3-6-worktrees-and-deeper-copilot-integration/?ref=modernpython.io) \- GitHub's June 26, 2026 release adds worktree support, Copilot-assisted commit authoring, and AI-aware merge-conflict workflows. *💡 Modern Python's Take: worktrees and agent tooling belong together because parallel branches are becoming a normal coding pattern.* ## Articles - [Core dump epidemiology: fixing an 18-year-old bug](https://openai.com/index/core-dump-epidemiology-data-infrastructure-bug/?ref=modernpython.io) \- OpenAI's June 30, 2026 engineering post explains how a crash investigation split into a bad Azure host and an old GNU libunwind race condition. *💡 Modern Python's Take: this is the kind of systems writeup worth reading closely because modern AI products still depend on classic low-level debugging discipline.* - [Securing the future of AI agents](https://deepmind.google/blog/securing-the-future-of-ai-agents/?ref=modernpython.io) \- Google DeepMind's June 18, 2026 essay argues that increasingly capable agents require infrastructure-level controls, monitoring, and containment strategies. *💡 Modern Python's Take: prompt safety alone is not a real security model for agents with tools and autonomy.* - [Why Specialization Is Inevitable](https://huggingface.co/blog/Dharma-AI/why-specialization-is-inevitable?ref=modernpython.io) \- This late-June 2026 Hugging Face essay argues that constrained systems repeatedly converge on specialization rather than broad generality. *💡 Modern Python's Take: the argument lines up with what developers already see in practice: smaller focused systems often beat one oversized do-everything stack.* - [Fluent, not native: agents translating pandas to Polars](https://pola.rs/posts/?ref=modernpython.io) \- Polars' June 25, 2026 technical post says AI translation from pandas to Polars usually runs correctly, while also identifying the structural patterns that still break. *💡 Modern Python's Take: this is a more realistic agent story than marketing demos because it treats translation quality as something measurable and improvable.* ### Serving a Frontend with FastAPI: A Practical Guide URL: https://modernpython.io/serving-a-frontend-with-fastapi-a-practical-guide/ Last updated: 2026-07-02T10:16:20.000Z FastAPI is famous for building APIs. But as a full-stack developer, the most convenient deployment for me is a single Python service that serves both: 1. my JSON API, and 2. my already-built frontend files. Fortunately, since **version 0.138.0**, FastAPI supports this with `app.frontend()` and `router.frontend()`. According to the [official FastAPI frontend documentation](https://fastapi.tiangolo.com/tutorial/frontend/?ref=modernpython.io), this feature is designed for frontend tools that generate static build output, such as React with Vite, Vue, Angular, Svelte, Astro, Solid, TanStack Router, and others. In short, `app.frontend()` lets FastAPI serve a static frontend build directory while keeping your normal API routes first. If `/api/metrics` is a FastAPI route, the API route wins. If `/assets/app.js` is a built frontend file, FastAPI can serve it from the frontend directory. This is one of those features that removes a surprising amount of deployment glue. In this article, we will dive into this new feature, build the idea from simple frontend serving to client-side routing, API route priority, deployment caveats, and a complete example. ## What app.frontend() Actually Does The basic usage is almost too simple: ```python from fastapi import FastAPI app = FastAPI() app.frontend("/", directory="dist") ``` That means: - serve the frontend under `/`; - read files from the local `dist` directory; - use FastAPI's frontend-serving conventions for browser routes and static assets. The expected structure is similar to what modern frontend tools generate: ```text . |-- app | |-- __init__.py | `-- main.py `-- dist |-- index.html `-- assets `-- app.js ``` If the browser asks for `/assets/app.js`, FastAPI can return `dist/assets/app.js`. The important detail is route priority. FastAPI checks normal path operations first. The frontend is checked only if no normal route matched. This means your API will not be swallowed by your frontend router. For example: ```python from fastapi import FastAPI app = FastAPI() @app.get("/api/health") def health() -> dict[str, str]: return {"status": "ok"} app.frontend("/", directory="dist") ``` Now `/api/health` returns JSON, while `/` returns the frontend. This is exactly the behavior I want from a full-stack FastAPI app. The API remains the API. The frontend becomes the final fallback for browser pages. ## When To Use app.frontend() Instead of StaticFiles FastAPI already has `StaticFiles`. For example: ```python from fastapi import FastAPI from fastapi.staticfiles import StaticFiles app = FastAPI() app.mount("/static", StaticFiles(directory="static"), name="static") ``` This is still useful when you want to serve simple static assets from a specific path. However, the [FastAPI Static Files documentation](https://fastapi.tiangolo.com/tutorial/static-files/?ref=modernpython.io) says that if you need to host a frontend, use `app.frontend()` instead. It also explains that `app.frontend()` uses `StaticFiles` underneath, with extra advantages for frontends, such as handling client-side routing. My practical rule is: - Use `StaticFiles` for plain files like `/static/logo.png`. - Use `app.frontend()` for a built frontend app like React, Vue, Svelte, Astro, or a vanilla JavaScript app. That distinction saves confusion. Serving a frontend also means handling browser navigation, missing assets, generated build directories, and route priority. ## Build a Complete FastAPI Frontend Example Let's build a tiny dashboard to feel the power of the new FastAPI. It will have: - a FastAPI backend; - two API endpoints; - a static frontend in `dist`; - client-side routing; - a dashboard page that fetches JSON from the API; - a single `app.frontend()` call that serves everything. The project structure: ```text fastapi-frontend-demo/ |-- pyproject.toml |-- app | |-- __init__.py | `-- main.py `-- dist |-- index.html `-- assets |-- app.js `-- styles.css ``` First, the Python project file: ```toml [project] name = "fastapi-frontend-demo" version = "0.1.0" requires-python = ">=3.10" dependencies = [ "fastapi", "uvicorn[standard]", ] ``` Now the FastAPI app: ```python # app/main.py from __future__ import annotations from datetime import datetime, timezone from pathlib import Path from fastapi import FastAPI from pydantic import BaseModel BASE_DIR = Path(__file__).resolve().parent.parent DIST_DIR = BASE_DIR / "dist" class Metric(BaseModel): name: str value: float unit: str trend: str app = FastAPI(title="FastAPI Frontend Demo") @app.get("/api/health") def health() -> dict[str, str]: return { "status": "ok", "time": datetime.now(timezone.utc).isoformat(), } @app.get("/api/metrics", response_model=list[Metric]) def list_metrics() -> list[Metric]: return [ Metric(name="Requests", value=12840, unit="today", trend="+12%"), Metric(name="Latency", value=42, unit="ms p50", trend="-8%"), Metric(name="Errors", value=3, unit="today", trend="-2"), ] app.frontend("/", directory=DIST_DIR, fallback="index.html") ``` The last line is the key: ```python app.frontend("/", directory=DIST_DIR, fallback="index.html") ``` This serves the frontend at the root path. The `fallback="index.html"` part is useful for single-page apps. If the browser opens `/dashboard` directly, the server returns `index.html`, and then our frontend JavaScript decides what to render. Now the HTML: ```html FastAPI Frontend Demo
``` Now the JavaScript: ```javascript // dist/assets/app.js const app = document.querySelector("#app"); const knownRoutes = new Set(["/", "/dashboard", "/settings"]); async function getJson(url) { const response = await fetch(url); if (!response.ok) { throw new Error(`Request failed with status ${response.status}`); } return response.json(); } function getCurrentRoute() { const path = window.location.pathname; return knownRoutes.has(path) ? path : "/"; } function metricCard(metric) { return `
${metric.name}
${metric.value}
`; } function renderHome() { app.innerHTML = `

One FastAPI process

Serve your API and frontend from the same app.

This demo uses FastAPI for JSON endpoints and app.frontend() for the static browser app.

Open dashboard
`; } async function renderDashboard() { app.innerHTML = `

Loading metrics...

`; try { const [health, metrics] = await Promise.all([ getJson("/api/health"), getJson("/api/metrics"), ]); app.innerHTML = `

Backend status: ${health.status}

Production dashboard

${metrics.map(metricCard).join("")}

Last checked: ${health.time}

`; } catch (error) { app.innerHTML = `

Something went wrong

${error.message}

`; } } function renderSettings() { app.innerHTML = `

Client-side route

Settings

Open this page directly at /settings. FastAPI returns index.html, and the frontend router renders this view.

`; } async function render() { const route = getCurrentRoute(); if (route === "/dashboard") { await renderDashboard(); return; } if (route === "/settings") { renderSettings(); return; } renderHome(); } document.addEventListener("click", (event) => { const link = event.target.closest("a[data-link]"); if (!link) { return; } event.preventDefault(); history.pushState({}, "", link.getAttribute("href")); render(); }); window.addEventListener("popstate", render); render(); ``` And the CSS: ```css /* dist/assets/styles.css */ :root { color: #17202a; background: #f6f7f9; font-family: Inter, ui-sans-serif, system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", sans-serif; } body { margin: 0; } .site-header { align-items: center; background: #ffffff; border-bottom: 1px solid #dde1e7; display: flex; justify-content: space-between; padding: 16px 24px; } .brand { color: #17202a; font-weight: 800; text-decoration: none; } nav { display: flex; gap: 16px; } nav a { color: #44515f; text-decoration: none; } .page { margin: 0 auto; max-width: 980px; padding: 48px 24px; } .hero { max-width: 680px; } .eyebrow { color: #0f766e; font-size: 14px; font-weight: 700; letter-spacing: 0; text-transform: uppercase; } h1 { font-size: 44px; line-height: 1.1; margin: 8px 0 16px; } p { color: #44515f; font-size: 18px; line-height: 1.6; } .button { background: #0f766e; border-radius: 6px; color: white; display: inline-block; font-weight: 700; margin-top: 12px; padding: 12px 16px; text-decoration: none; } .grid { display: grid; gap: 16px; grid-template-columns: repeat(auto-fit, minmax(220px, 1fr)); margin-top: 24px; } .metric-card { background: white; border: 1px solid #dde1e7; border-radius: 8px; padding: 20px; } .metric-name { color: #667085; font-size: 14px; font-weight: 700; text-transform: uppercase; } .metric-value { font-size: 40px; font-weight: 800; margin-top: 12px; } .metric-footer { align-items: center; color: #44515f; display: flex; justify-content: space-between; margin-top: 18px; } .metric-footer strong { color: #0f766e; } .loading, .note { color: #667085; } ``` Run it: ```bash python -m venv .venv source .venv/bin/activate python -m pip install --upgrade fastapi uvicorn[standard] uvicorn app.main:app --reload ``` Then try these URLs: ```text http://127.0.0.1:8000/ http://127.0.0.1:8000/dashboard http://127.0.0.1:8000/settings http://127.0.0.1:8000/api/health http://127.0.0.1:8000/api/metrics ``` This is a full working mental model: - `/` serves `dist/index.html`; - `/dashboard` serves `index.html`, then JavaScript renders the dashboard; - `/settings` serves `index.html`, then JavaScript renders settings; - `/api/health` and `/api/metrics` are handled by FastAPI path operations; - `/assets/styles.css` and `/assets/app.js` are served from `dist/assets`. Simple and neat. ## Handle Client-Side Routing Correctly Single-page apps often have routes that do not exist as real files. For example: ```text /dashboard /settings /users/yang ``` In a React, Vue, Svelte, or vanilla JavaScript SPA, those paths may be handled in the browser. The backend still has one job: > For browser navigation paths, return `index.html` so the frontend app can render the route. FastAPI supports this with `fallback="index.html"`: ```python app.frontend("/", directory=DIST_DIR, fallback="index.html") ``` The official docs also describe `fallback="auto"`, which is the default. In most cases, you can write: ```python app.frontend("/", directory=DIST_DIR) ``` With automatic fallback, FastAPI looks for common frontend files and chooses a reasonable behavior. If a `404.html` exists, it can be used for missing frontend paths with a 404 status code. Otherwise, if `index.html` exists, browser navigation paths can fall back to `index.html`. My recommendation: - For a typical SPA, use `fallback="index.html"` when you want the behavior to be explicit. - For static site generators like Astro that produce a `404.html`, consider the automatic behavior. - For file serving with no frontend fallback, use `fallback=None`. For example: ```python app.frontend("/", directory=DIST_DIR, fallback=None) ``` Then missing frontend paths return a normal 404. The subtle advantage is that missing assets like JavaScript, CSS, and images should still behave like missing assets. You do not want `/assets/typo.js` to return your HTML app and create a confusing browser error. ## Let API Routes Win This is the design detail that makes `app.frontend()` pleasant. FastAPI path operations are checked first. So this works: ```python from fastapi import FastAPI app = FastAPI() @app.get("/users/{name}") def read_user(name: str) -> dict[str, str]: return {"name": name} app.frontend("/", directory="dist", fallback="index.html") ``` If the browser requests `/users/yang`, FastAPI will match the API route and return JSON. If the browser requests `/dashboard`, and there is no FastAPI path operation for `/dashboard`, the frontend fallback can return `index.html`. This is a clean separation: - API routes are explicit backend behavior. - Frontend routes are browser behavior. - Built assets are static files. In real projects, I still prefer putting API routes under `/api`. For example: ```text /api/users/yang /api/metrics /api/health ``` This convention keeps the system easy to reason about. It also makes reverse proxies, logs, and monitoring easier. The fact that FastAPI protects path operations first is excellent. A clear URL convention is still worth it. ## Serve a Frontend Under a Prefix with APIRouter Sometimes the frontend should not live at `/`. Maybe you want: ```text /api /admin /docs ``` FastAPI supports `router.frontend()` too: ```python from fastapi import APIRouter, FastAPI app = FastAPI() admin_router = APIRouter() admin_router.frontend("/", directory="dist", fallback="index.html") app.include_router(admin_router, prefix="/admin") ``` Now the frontend is served under `/admin`. This is useful for internal tools, admin panels, customer dashboards, and embedded apps. The frontend build still has to know its base path. For example, if your JavaScript app assumes assets live under `/assets/app.js`, but the app is deployed under `/admin`, you may need to configure the frontend build tool to generate URLs under `/admin/assets/app.js`. This is a frontend build configuration problem. It is also the kind of problem that steals 40 minutes and makes you question your career choices. So check it early. ## Know When To Avoid Serving the Frontend from FastAPI `app.frontend()` is useful, but it has clear boundaries. The official FastAPI docs are clear that this serves static build output only. It does not run server-side rendering for every request. Use it when: - your frontend build produces static files; - you want a simple single-service deployment; - your app is an internal dashboard, admin UI, prototype, or small product; - you want API and frontend routes in one FastAPI process. Be careful when: - your frontend needs server-side rendering on every request; - your assets are large and should live behind a CDN; - your frontend and backend deploy on different schedules; - you need advanced edge caching rules; - your organization already has a standard frontend hosting pipeline. For local frontend development, I would still use the frontend dev server. For example, with Vite: ```bash npm run dev ``` During production build, generate static files: ```bash npm run build ``` Then let FastAPI serve the generated `dist` directory: ```python app.frontend("/", directory="dist", fallback="index.html") ``` This gives you a comfortable split: - use the frontend dev server while developing UI quickly; - use FastAPI frontend serving when deploying the built app. ## Key Takeaways FastAPI can serve static frontend builds with `app.frontend()` and `router.frontend()`. This feature is designed for frontend frameworks that generate static output, such as Vite-based React apps, Vue, Svelte, Angular, Solid, Astro, TanStack Router, and similar tools. The most important behavior is route priority: normal FastAPI path operations are checked before frontend files. For SPAs, use `fallback="index.html"` when you want direct browser navigation like `/dashboard` to load the frontend app. For static site generators that produce a `404.html`, the default `fallback="auto"` behavior can be convenient. Use `StaticFiles` for plain static assets. Use `app.frontend()` for built frontend apps. The best thing is that the deployment story becomes boring: ```python app.frontend("/", directory="dist", fallback="index.html") ``` One line serves the browser app. Your API can keep doing API things. That is the kind of simple deployment line I like. ## References - [FastAPI Frontend tutorial](https://fastapi.tiangolo.com/tutorial/frontend/?ref=modernpython.io) - [FastAPI Static Files tutorial](https://fastapi.tiangolo.com/tutorial/static-files/?ref=modernpython.io) - [FastAPI reference: FastAPI.frontend()](https://fastapi.tiangolo.com/reference/fastapi/?ref=modernpython.io#fastapi.FastAPI.frontend) ### Modern Python Weekly #2 URL: https://modernpython.io/modern-python-weekly-2/ Last updated: 2026-06-26T14:32:12.000Z ## Python News - [Python 3.15.0b3](https://www.python.org/downloads/release/python-3150b3/?ref=modernpython.io) \- Released June 23, 2026\. This is the third of four planned Python 3.15 beta releases, with around 195 bugfixes, build improvements, and documentation changes since beta 2. *💡 Modern Python's Take: package maintainers should test now, especially because ABI changes are expected to settle after beta 4 and before the first release candidate.* - [Django Tasks: Exploring the Built-in Tasks Framework](https://realpython.com/django-tasks/?ref=modernpython.io) \- Real Python updated its Django Tasks guide on June 24. *💡 Modern Python's Take: Django 6.0's built-in task framework is worth tracking because it standardizes background-task APIs while still leaving serious production workloads to third-party backends.* - [FastAPI 0.138.1](https://github.com/fastapi/fastapi/releases/tag/0.138.1?ref=modernpython.io) \- Released June 25, 2026\. This release is mostly maintenance and internal cleanup, including refactors around FastAPI's library skills documentation and workflow updates, following the recent 0.138.0 frontend-serving work. *💡 Modern Python's Take: FastAPI is increasingly treating developer experience, deployment guidance, and agent-readable project knowledge as part of the framework surface, not just routing and validation.* - [NumPy 2.5.0](https://github.com/numpy/numpy/releases/tag/v2.5.0?ref=modernpython.io) \- Released June 21, 2026\. This transitional release drops Python 3.11 support, removes distutils-era code, expires many older deprecations, improves free-threading support, adds descending sorts, and prepares for Python 3.15 support. *💡 Modern Python's Take: this is a real modernization release for the scientific Python stack, especially for teams tracking free-threaded Python and the post-distutils packaging world.* - [Python Polars 1.42.0](https://github.com/pola-rs/polars/releases/tag/py-1.42.0?ref=modernpython.io) \- Released June 24, 2026\. The release adds performance improvements for cloud IO and streaming, introduces naive out-of-core spilling, adds experimental strict mode, and expands SQL and sortedness-related capabilities. *💡 Modern Python's Take: Polars keeps pushing Python data work toward larger-than-memory, cloud-native, and query-optimized workflows without giving up the DataFrame developer experience.* ## AI news - [OpenAI: How agents are transforming work](https://openai.com/index/how-agents-are-transforming-work/?ref=modernpython.io) \- Published June 25, 2026\. OpenAI shared economic research on Codex usage, arguing that agentic AI shifts work from short chats toward delegated, longer-running tasks. *💡 Modern Python's Take: the strongest signal is that non-developer usage is growing quickly, not just engineering usage.* - [OpenAI and Broadcom unveil LLM-optimized inference chip](https://openai.com/index/openai-broadcom-jalapeno-inference-chip/?ref=modernpython.io) \- Published June 24, 2026\. OpenAI and Broadcom announced Jalapeno, a custom inference accelerator designed around LLM serving workloads. *💡 Modern Python's Take: frontier AI companies are turning into full-stack infrastructure companies, from models to chips.* - [Anthropic: Introducing Claude Tag](https://www.anthropic.com/news/introducing-claude-tag?ref=modernpython.io) \- Published June 23, 2026\. Claude Tag lets teams add Claude to Slack channels, grant scoped tool/data access, and delegate asynchronous work. *💡 Modern Python's Take: team-scoped memory, permissions, and audit logs are becoming core product features for workplace agents.* - [OpenAI: Daybreak tools for securing every organization](https://openai.com/index/daybreak-securing-the-world/?ref=modernpython.io) \- Published June 22, 2026\. OpenAI announced expanded Daybreak security tools, Codex Security updates, GPT-5.5-Cyber limited release, and partner programs for defensive security. *💡 Modern Python's Take: AI security work is shifting from finding vulnerabilities to validating, patching, testing, and coordinating fixes.* - [Samsung Electronics brings ChatGPT and Codex to employees](https://openai.com/index/samsung-electronics-chatgpt-codex-deployment/?ref=modernpython.io) \- Published June 21, 2026\. Samsung is rolling out ChatGPT and Codex to employees. *💡 Modern Python's Take: enterprise AI adoption is moving from pilots toward broad internal enablement.* ![Promotional artwork for the Samsung and OpenAI partnership, showing their respective mascots shaking hands.](https://storage.ghost.io/c/9d/13/9d1370cd-8c17-45a2-95ab-a1c6a2886e22/content/images/2026/06/4f1a93c6-082e-4feb-94a7-fb386da81b38.jpg) ## Tools and Projects - [uv 0.11.24](https://github.com/astral-sh/uv/releases/tag/0.11.24?ref=modernpython.io) \- Released June 23, 2026\. Adds CPython 3.15.0b3 support, relocatable project environments under preview, resolver performance work, and several bug fixes. *💡 Modern Python's Take: `uv` remains one of the fastest-moving pieces of Python packaging infrastructure.* - [Ruff 0.15.20](https://github.com/astral-sh/ruff/releases/tag/0.15.20?ref=modernpython.io) \- Released June 25, 2026\. Preview changes include human-readable rule selectors, softer handling for unknown rule selectors, and `ruff:ignore` behavior updates. *💡 Modern Python's Take: Ruff continues to refine usability as it becomes a default linting and formatting layer for Python projects.* - [Datasette 1.0a35](https://github.com/simonw/datasette/releases/tag/1.0a35?ref=modernpython.io) \- Released June 23, 2026\. Adds UI and JSON APIs for creating and altering tables, plus new static asset cache-busting helpers and table UI improvements. *💡 Modern Python's Take: Datasette is becoming more of an editable data application platform, not just a read-only publishing tool.* - [sqlite-utils 4.0rc1](https://github.com/simonw/sqlite-utils/releases/tag/4.0rc1?ref=modernpython.io) \- Released June 21, 2026\. Adds a migrations system, nested transaction support, improved connection cleanup, better type annotations, and Python 3.15-dev testing. *💡 Modern Python's Take: this is a meaningful release candidate for Python developers who use SQLite as an application data layer.* - [GitHub Desktop 3.6](https://github.blog/changelog/2026-06-26-github-desktop-3-6-worktrees-and-deeper-copilot-integration/?ref=modernpython.io) \- Released June 26, 2026\. Adds Git worktree support, Copilot-powered commit authoring, and AI-assisted merge conflict resolution. *💡 Modern Python's Take: worktrees are becoming more important because agentic coding workflows often run several branches in parallel.* - [Copilot CLI new terminal interface GA](https://github.blog/changelog/2026-06-23-copilot-cli-new-terminal-interface-is-generally-available/?ref=modernpython.io) \- Released June 23, 2026\. The new terminal UI supports tabs for issues, pull requests, and gists, plus in-session MCP server, skill, plugin, and settings configuration. *💡 Modern Python's Take: terminal-native agent workflows are getting much more productized.* - [Copilot code review analysis depth and efficiency updates](https://github.blog/changelog/2026-06-25-copilot-code-review-analysis-depth-and-efficiency-updates/?ref=modernpython.io) \- Released June 25, 2026\. Copilot code review now uses CLI/SDK file exploration tools like `rg`, `glob`, and `view`, with reported cost reductions while maintaining review quality. *💡 Modern Python's Take: code-review agents are starting to converge on the same primitives human reviewers use.* - [npm preventive account protection for high-impact accounts](https://github.blog/changelog/2026-06-25-npm-adds-preventive-account-protection-for-high-impact-accounts/?ref=modernpython.io) \- Released June 25, 2026\. High-impact npm accounts get a temporary read-only safeguard after sensitive changes like email changes or 2FA recovery-code use. *💡 Modern Python's Take: this directly targets the account-takeover pattern seen in supply-chain attacks.* - [OpenAI Patch the Planet](https://openai.com/index/patch-the-planet/?ref=modernpython.io) \- Published June 22, 2026\. OpenAI, Trail of Bits, HackerOne, Calif, and maintainers are coordinating AI-assisted vulnerability validation, patch development, and disclosure for critical open-source projects. *💡 Modern Python's Take: the important design choice is human-reviewed findings before maintainers are interrupted.* ## Articles - [Prompt Injection as Role Confusion](https://role-confusion.github.io/?ref=modernpython.io) \- Charles Ye, Jasmine Cui, and Dylan Hadfield-Menell published a readable writeup of their ICML 2026 work on why models confuse role boundaries between system, user, assistant, and tool text. *💡 Modern Python's Take: useful framing for anyone building agents that read untrusted content.* - [AI and Liability](https://www.schneier.com/blog/archives/2026/06/ai-and-liability.html?ref=modernpython.io) \- Bruce Schneier argues that companies deploying AI agents should be responsible for what those agents say and do, using recent legal rulings around AI summaries and chatbots as examples. *💡 Modern Python's Take: the legal and product-design implication is simple: agent autonomy does not remove deployer responsibility.* - [Porting the Moebius 0.2B image inpainting model to run in the browser with Claude Code](https://simonwillison.net/2026/Jun/22/porting-moebius/?ref=modernpython.io) \- Simon Willison walks through getting a small image-inpainting model running in the browser with WebGPU, ONNX, Transformers.js, and AI coding help. *💡 Modern Python's Take: a practical example of using coding agents to move Python/CUDA-oriented ML work toward browser-native demos.* - [Python for Data Analysis: A Practical Guide](https://realpython.com/python-for-data-analysis/?ref=modernpython.io) \- Real Python published a practical guide to data analysis workflows with Python on June 22. *💡 Modern Python's Take: useful baseline reading for teams combining Python analytics with AI-assisted data work.* - [sqlite-utils 4.0rc1 adds migrations and nested transactions](https://simonwillison.net/2026/Jun/21/sqlite-utils-40rc1/?ref=modernpython.io) \- Simon Willison explains the new sqlite-utils release candidate, including migrations and nested transaction support. *💡 Modern Python's Take: strong context for why the project release matters beyond a changelog entry.* ### Modern Python Weekly #1 URL: https://modernpython.io/modern-python-weekly-1/ Last updated: 2026-06-19T15:46:16.000Z ## Python News - [Python 3.14.6](https://www.python.org/downloads/release/python-3146/?ref=modernpython.io) \- Released June 10, 2026\. This is the sixth maintenance release of Python 3.14, with around 179 bug fixes, build improvements, and documentation changes since 3.14.5\. - [PSF Board Election Dates for 2026](https://pyfound.blogspot.com/2026/06/psf-board-election-dates-for-2026.html?ref=modernpython.io) \- Four PSF board seats are open, and the first Packaging Council election will run in parallel. Important governance moment for Python packaging. - [Everything Security at PyCon US 2026](https://pyfound.blogspot.com/2026/06/everything-security-at-pycon-us-2026.html?ref=modernpython.io) \- PyCon highlighted Python supply-chain security, CI/CD hardening, PyPI malware pressure, and the growing burden of LLM-generated vulnerability reports. - [PEP 790: Python 3.15 Release Schedule](https://peps.python.org/pep-0790/?ref=modernpython.io) \- The schedule shows Python 3.15.0b2 shipped on June 2, with 3.15.0b3 planned for June 23 and the final release planned for October 1, 2026\. - [Django Is Hiring Its First Executive Director](https://www.djangoproject.com/weblog/2026/jun/17/announcing-the-search-for-a-dsf-executive-director/?ref=modernpython.io) \- The DSF announced a major sustainability step, backed by a $47,500 pledge from six Django agencies. ## AI news - [OpenAI: Near-autonomous AI chemist](https://openai.com/index/ai-chemist-improves-reaction/?ref=modernpython.io) \- GPT-5.4, connected to Molecule.one’s Maria lab system, helped improve a medicinal chemistry reaction with human chemists still in the loop. - [Anthropic opens Seoul office](https://www.anthropic.com/news/seoul-office-partnerships-korean-ai-ecosystem?ref=modernpython.io) \- Anthropic expanded in Korea, announced major Claude deployments, and signed an AI safety MOU with Korea’s Ministry of Science and ICT. ![people walking on street during night time](https://images.unsplash.com/photo-1597552571860-136a103d5eb3?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDE5fHxTZW91bHxlbnwwfHx8fDE3ODE4ODI3NTN8MA&ixlib=rb-4.1.0&q=80&w=2000) Photo by [Yu Kato](https://unsplash.com/@yukato?ref=modernpython.io) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) *💡 Modern Python's Take: South Korea's AI ambitions extend far beyond software. As demand for HBM and other AI memory technologies continues to surge, Samsung Electronics and SK hynix have become two of the biggest beneficiaries of the global AI buildout.* - [OpenAI: Improving health intelligence in ChatGPT](https://openai.com/index/improving-health-intelligence-in-chatgpt/?ref=modernpython.io) \- OpenAI says GPT-5.5 Instant improved health-related responses, with physician-led evaluation and broader free-user access. - [Google DeepMind: Securing the future of AI agents](https://deepmind.google/blog/securing-the-future-of-ai-agents/?ref=modernpython.io) \- DeepMind published an AI Control Roadmap for monitoring and containing increasingly capable agents, treating them partly like insider-risk systems. ## Tools and Projects - [Datasette Apps](https://datasette.io/blog/2026/datasette-apps/?ref=modernpython.io) \- A new Datasette plugin for hosting sandboxed custom HTML apps inside Datasette, with LLM-assisted app generation built into the workflow. - [OpenAI enterprise usage analytics and spend controls](https://openai.com/index/chatgpt-enterprise-spend-controls/?ref=modernpython.io) \- ChatGPT Enterprise admins now get clearer credit analytics across ChatGPT and Codex, plus user/group spend controls. - [GLM-5.2 open weights model](https://huggingface.co/zai-org/GLM-5.2?ref=modernpython.io) ![Benchmark of major LLMs](https://storage.ghost.io/c/9d/13/9d1370cd-8c17-45a2-95ab-a1c6a2886e22/content/images/2026/06/bench_52.png) Benchmark of major LLMs Z.ai released a 753B-parameter MIT-licensed model with a 1M-token context window and strong coding benchmarks. When asked on X when Chinese models might reach Anthropic's Fable-level capabilities, Elon Musk replied: "Probably Q1", and the founder of Z.ai responded: "Won't take that long". ![X screenshots about Elon Musk's comments about GLM-5.2](https://storage.ghost.io/c/9d/13/9d1370cd-8c17-45a2-95ab-a1c6a2886e22/content/images/2026/06/glms-founder-says-glm-fable-before-the-end-of-the-year-v0-igc7e045o18h1.webp) *💡 Modern Python's Take: Restricting access has never been an effective way to maintain a technological lead. AI capabilities are advancing globally, and frontier models from other countries are likely to narrow the gap with Claude Fable 5 much sooner than many expect.* - [models.dev](https://models.dev/?ref=modernpython.io): An open-source database of AI models. - [Zizmor](https://docs.zizmor.sh/?ref=modernpython.io) \- Mentioned in the PSF PyCon security recap as a recommended tool for hardening GitHub Actions workflows, including use with `--fix`. ## Articles - [Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked](https://www.404media.co/hackers-simply-asked-meta-ai-to-give-them-access-to-high-profile-instagram-accounts-it-worked/?ref=modernpython.io) ![Screenshots of hackers trick the Meta AI chatbot](https://storage.ghost.io/c/9d/13/9d1370cd-8c17-45a2-95ab-a1c6a2886e22/content/images/2026/06/CleanShot-2026-06-01-at-09.55.09@2x.png) How hackers trick the Meta AI 404 Media reports that hackers claimed they used Meta's AI support chatbot to take over high-profile Instagram accounts by requesting account email changes. *💡 Modern Python's Take: a sharp warning that AI support agents need strict permission boundaries, escalation paths, and audit controls before handling account recovery. And Meta is really falling behind in the age of AI; it's just a simple trick.* - [Context Engineering for Python Codebases](https://realpython.com/python-context-engineering-ai/?ref=modernpython.io) \- Real Python explains how to shape context for AI coding agents so they work better inside Python projects. - [AI demands more engineering discipline. Not less](https://charitydotwtf.substack.com/p/ai-demands-more-engineering-discipline) \- Charity Majors argues that cheap AI code generation increases the need for code review, observability, and engineering rigor. - [Predicting model behavior before release by simulating deployment](https://openai.com/index/deployment-simulation/?ref=modernpython.io) \- OpenAI describes replaying realistic conversation contexts to estimate unwanted model behavior before launch. - [The Fable 5 Export Controls Harm US Cyber Defense](https://www.lutasecurity.com/post/the-fable-5-export-controls-harm-us-cyber-defense?ref=modernpython.io) \- Katie Moussouris argues that restricting models for “fix this code” security behavior could weaken defenders more than attackers. ### Python 3.15 Lazy Imports: Faster Startup Times and the Design Behind PEP 810 URL: https://modernpython.io/python-3-15-lazy-imports-faster-startup-times-and-the-design-behind-pep-810/ Last updated: 2026-06-16T17:04:19.000Z Python imports are usually invisible infrastructure that we don't need to worry about. But they become visible when startup time starts to matter. If you have ever waited for a command-line tool to show `--help`, a test runner to collect tests, or a web app to reload after a small change, you have probably paid the import-time tax. Python 3.15 adds an official solution: explicit lazy imports. In short, [PEP 810](https://peps.python.org/pep-0810/?ref=modernpython.io) introduces a new `lazy` soft keyword: ```Python lazy import json lazy from pathlib import Path print("Starting up...") # json and pathlib are not loaded yet data = json.loads('{"name": "Yang"}') # json loads here path = Path(".") # pathlib loads here ``` The idea is simple: declare the dependency at the module level, but delay loading it until the imported name is first used. In this article, let's look at the design of Python 3.15's lazy imports, the current workarounds they replace, why the feature is explicit rather than default, and how we can adopt it in real Python projects. ## The Import Cost Hidden in Startup An import statement does more than bind a name. When Python imports a module, it may need to find the file, read it, compile it to bytecode, execute the module-level code, create functions and classes, import subdependencies, and register the module in `sys.modules`. For a tiny script, this is fine. For a mature application, the import graph can become large and expensive. For example: ```python # app.py import argparse import pandas as pd import matplotlib.pyplot as plt import boto3 from myapp.reports import build_pdf from myapp.server import run_server def main() -> None: ... ``` If the user runs: ```bash python -m myapp --help ``` She probably does not need `pandas`, `matplotlib`, `boto3`, or a PDF generator. But normal imports are eager. Python loads them anyway. The [Python 3.15 What's New documentation](https://docs.python.org/3.15/whatsnew/3.15.html?ref=modernpython.io#pep-810-explicit-lazy-imports) describes this exact problem: > Large dependency trees can make startup take seconds, even when much of the imported code is never used in a particular run. ## How Python Developers Solve This Today The classic workaround is local import. We move expensive imports into the function that actually needs them: ```python def export_report(rows: list[dict[str, object]]) -> None: import pandas as pd from myapp.reports import build_pdf df = pd.DataFrame(rows) build_pdf(df) ``` This works. If `export_report()` is never called, `pandas` and `build_pdf` are never imported. The tradeoff is that imports are now scattered around the codebase: ```python def export_report(rows): import pandas as pd return pd.DataFrame(rows) def send_invoice(customer_id): import stripe return stripe.Customer.retrieve(customer_id) def plot_metrics(values): import matplotlib.pyplot as plt return plt.plot(values) ``` It works, but it makes Python programs less elegant than we expect. Python 3.15 lazy imports keep the import at the top while preserving the performance benefit: ```Python lazy import pandas as pd lazy from myapp.reports import build_pdf def export_report(rows: list[dict[str, object]]) -> None: df = pd.DataFrame(rows) # pandas loads here build_pdf(df) # myapp.reports loads here ``` This is the value of the feature. > It makes the performance optimization visible without damaging the code structure. ## Why Existing Lazy-Loading Tools Are Still Awkward Python already has tools for dynamic and lazy importing. For example, we can use `importlib.import_module()`: ```python import importlib def load_backend(name: str): return importlib.import_module(f"myapp.backends.{name}") ``` This is great for plugin systems, but for ordinary dependencies. If all we want is "import this module later", `importlib.import_module()` turns a simple language-level statement into a string-based runtime operation. Static analysis, refactoring, and readability become weaker. Some libraries use module-level `__getattr__` tricks or packages such as `lazy_loader`. The scientific Python ecosystem even has [SPEC 1](https://scientific-python.org/specs/spec-0001/?ref=modernpython.io) for lazy loading submodules and functions. Those solutions are useful for certain scenarios, but Python still needed an elegant, built-in, and readable way for application code to say: "This import is real, but please load it only when I use it." That is exactly what `lazy import` of Python 3.15 does. ## What Python 3.15 Changes The new syntax is deliberately plain: ```python3.15 lazy import heavy_module lazy import pandas as pd lazy from rich.console import Console ``` The keyword is soft, which means `lazy` only has special meaning before an `import` or `from` statement. In other places, it can still be an ordinary name. According to the [Python language reference](https://docs.python.org/3.15/reference/simple%5Fstmts.html?ref=modernpython.io#lazy-imports), the module is not loaded immediately. Python creates a lazy proxy object and binds it to the imported name. The actual import happens on first use. Let's see the idea: ```python3.15 import sys lazy import json print("json" in sys.modules) # False payload = json.dumps({"author": "Yang"}) print("json" in sys.modules) # True ``` One subtle detail is that lazy imports *defer module loading, not partial module loading.* For example: ```python3.15 lazy from heavy_module import build_report, send_email build_report() # heavy_module loads here ``` When `build_report` is first accessed, Python imports the entire `heavy_module`, executes its top-level code, and resolves the requested name. It does not load only the code that defines `build_report`. So if you later use `send_email`, Python does not import the module again because it is already loaded. ## A Strong Use Case: Command-Line Applications Command-line tools are one of the best use cases. Imagine this structure: ```python3.15 import argparse lazy import pandas as pd lazy from myapp.reports import export_pdf lazy from myapp.server import serve def main(argv: list[str] | None = None) -> None: parser = argparse.ArgumentParser() parser.add_argument("command", choices=["serve", "export"]) args = parser.parse_args(argv) if args.command == "serve": serve() elif args.command == "export": df = pd.DataFrame(load_rows()) export_pdf(df) ``` If the user asks for help, the optional heavy modules do not load. If the user runs `serve`, the reporting stack does not load. If the user runs `export`, the server stack does not load. This is the kind of optimization users can feel. A command that starts in 200 ms instead of 1.5 seconds feels more efficient. ## Type-Only Imports Become Cleaner Type hints often create imports that do not matter at runtime. Today, many projects use the `TYPE_CHECKING` trick as follows: ```python from typing import TYPE_CHECKING if TYPE_CHECKING: from collections.abc import Mapping, Sequence def summarize(items: "Sequence[str]") -> "Mapping[str, int]": ... ``` This pattern is useful, but it adds noise. With Python 3.15 lazy imports, we can often write: ```python3.15 lazy from collections.abc import Mapping, Sequence def summarize(items: Sequence[str]) -> Mapping[str, int]: ... ``` As [PEP 810 explains](https://peps.python.org/pep-0810/?ref=modernpython.io#what-about-type-annotations-and-type-checking-imports), lazy imports can remove the runtime cost of annotation-only imports without hiding them behind `if TYPE_CHECKING:`. ## Why Python Should Not Make Every Import Lazy by Default When I first saw this new feature, one question immediately came to my mind: > If lazy imports improve startup, why not make `import` lazy everywhere? That sounds like the natural next update for Python 3.16? But after thinking about how imports actually work in Python, I realized the answer is not that simple: > Imports are not just dependency declarations. They can also execute code. This is the central compatibility concern. Many Python modules do useful or dangerous things at import time: ```python # plugins/pdf_exporter.py from myapp.plugins import register @register("pdf") class PDFExporter: ... ``` Somewhere else: ```python import plugins.pdf_exporter # The import registered PDFExporter as a side effect. ``` If that import becomes lazy, the plugin is not registered until somebody first touches `plugins.pdf_exporter`. That can break the application. Another example: ```python # app_logging.py import logging logging.basicConfig(level=logging.INFO) ``` If a project relies on `import app_logging` to configure logging, making the import lazy changes when logging is configured. The bug may appear far away from the import statement. There are potential other concerns: - Import errors happen later, at first use. - The import order can change. - `sys.modules` contents can differ before first use. - Some introspection may see lazy proxy objects. - The first access may happen in a different thread. ## Global Lazy Imports: A Tool for Deployment and Performance Tuning Python 3.15 also includes broader controls: ```bash python -X lazy_imports=all -m myapp ``` or: ```bash PYTHON_LAZY_IMPORTS=all python -m myapp ``` The modes are: - `normal`: only imports explicitly marked with `lazy` are lazy; - `all`: most eligible module-level imports are treated as lazy imports automatically; - `none`: imports are eager, even if marked lazy. There is also a runtime API: ```python3.15 import sys sys.set_lazy_imports("all") print(sys.get_lazy_imports()) ``` And for advanced use cases, a filter can decide which imports should stay lazy: ```python3.15 import sys def lazy_filter(importer: str | None, name: str, fromlist: tuple[str, ...] | None) -> bool: side_effect_modules = {"myapp.logging_setup", "myapp.plugin_registry"} return name not in side_effect_modules sys.set_lazy_imports_filter(lazy_filter) sys.set_lazy_imports("all") ``` In practice, the safest approach is to use explicit lazy imports in application code and reserve global lazy-import modes for experimentation, deployment environments, and performance tuning after careful testing. The reason is simple: applying lazy imports globally changes the behavior of the whole codebase. Import-time side effects, registration mechanisms, logging setup, and other initialization logic may suddenly happen later than expected. ## A Conservative Migration Plan If you are going to migrate your project to Python 3.15, my recommendation is to do it in a conservative way: measure first and change second. - Firstly, run Python's built-in import-time profiler: ```bash python -X importtime -m myapp --help ``` - Then, based on the results, look for imports that are both slow and unnecessary for common startup paths, such as the following: ```text import time: self [us] | cumulative | imported package import time: 120000 | 450000 | pandas import time: 70000 | 300000 | matplotlib import time: 30000 | 180000 | boto3 ``` - Make the necessary code change now: ```python3.15 lazy import pandas as pd lazy import matplotlib.pyplot as plt lazy import boto3 ``` - Finally, measure again to see the improvement. ## References - [PEP 810: Explicit lazy imports](https://peps.python.org/pep-0810/?ref=modernpython.io) - [What is new in Python 3.15: PEP 810 explicit lazy imports](https://docs.python.org/3.15/whatsnew/3.15.html?ref=modernpython.io#pep-810-explicit-lazy-imports) - [Scientific Python SPEC 1: Lazy Loading of Submodules and Functions](https://scientific-python.org/specs/spec-0001/?ref=modernpython.io) ### pip Is Fighting Back: Lockfiles and Dependency Cooldowns Arrive in Version 26.1 URL: https://modernpython.io/pip-lockfiles-dependency-cooldowns/ Last updated: 2026-06-10T16:47:10.000Z For years, `pip` has been the tool almost every Python developer uses. However, newer tools such as Poetry, PDM, and uv have offered a more complete dependency-management experience: lockfiles, project workflows, and reproducible environments. And they are making `pip` seem too old to use. pip 26.1 is a strong fight back. [Released on April 26, 2026](https://pip.pypa.io/en/stable/news/?ref=modernpython.io#v26-1), it added experimental support for installing from standardized `pylock.toml` files and made dependency cooldown policies practical. These features create a practical workflow that many teams can adopt without replacing pip. Let's see why this matters and how you can use it in a real project. ## pip 26.1 Adds Two Different Security Controls The two new features solve different problems: - Dependency cooldown: Is this release old enough for the ecosystem to have inspected it? - `pylock.toml` installation: Are we installing the exact dependency graph and artifacts we reviewed? A cooldown reduces exposure to a malicious release immediately after publication. A lockfile reduces unexpected changes between development, CI, and production. Although they cannot replace code review, vulnerability scanning, hashes, or least-privilege CI. They are useful layers and fit into commands that Python teams already understand. ## Dependency Cooldowns: Security Through Delayed Adoption Normally, pip prefers the latest version that satisfies our constraints. Imagine that our project allows this: ```text httpx>=0.28,<1 ``` If a new compatible version appears on the package index, the next clean build may install it immediately. That is convenient when the release is good. It is dangerous when an attacker has compromised the maintainer's account or publishing workflow. pip's `--uploaded-prior-to` option lets us reject candidates newer than a chosen cutoff. The option first appeared in pip 26.0 with an exact datetime. pip 26.1 added support for relative durations in days, which makes a repeatable cooldown policy much easier: ```bash python -m pip install \ --uploaded-prior-to=P7D \ -r requirements.txt ``` `P7D` means *pip only considers packages uploaded at least seven days ago*. We can also use an exact ISO 8601 date and time: ```bash python -m pip install \ --uploaded-prior-to=2026-06-01T00:00:00Z \ -r requirements.txt ``` This is especially useful in automated dependency-update jobs. A seven-day delay gives maintainers, security researchers, package indexes, and early adopters time to notice suspicious behavior before our production pipeline accepts the release. The option, by the way, only works with package indexes that provide upload-time metadata. It is also opt-in; upgrading pip does not automatically protect existing pipelines. ![Defense-in-depth software supply chain workflow showing New Release, Cooldown, Lockfile, Review, Vulnerability Scanning, Low-Privilege CI, and Production connected by arrows.](https://storage.ghost.io/c/9d/13/9d1370cd-8c17-45a2-95ab-a1c6a2886e22/content/images/2026/06/securitysteps.png) A cooldown period creates time for other security controls, such as lockfiles, review, vulnerability scanning, and low-privilege CI, to detect issues before deployment. However, a cooldown can also delay urgent bug fixes, so it should be applied thoughtfully rather than blindly. ## Pip Install from pylock.toml Python had lacked a lockfile standard that different tools could understand. We had `poetry.lock`, `pdm.lock`, `uv.lock`, `requirements.txt`, and several other formats. They work, but they belong to their own tools and workflows. [PEP 751](https://peps.python.org/pep-0751/?ref=modernpython.io) changed the direction by defining `pylock.toml`, a standardized TOML format for reproducible Python installations. A lockfile can record details such as: - exact package versions; - dependency relationships; - compatible environments; - wheel and source-distribution files; - download locations; - upload times; - cryptographic hashes. For example, a simplified entry looks like this: ```toml lock-version = "1.0" requires-python = ">=3.12" [[packages]] name = "example-package" version = "1.2.3" [[packages.wheels]] name = "example_package-1.2.3-py3-none-any.whl" url = "https://files.pythonhosted.org/..." [packages.wheels.hashes] sha256 = "..." ``` This is different from a casual `requirements.txt` containing broad version ranges. To adapt this new standard, pip 25.1 introduced an experimental `pip lock` command. It can generate `pylock.toml`: ```bash python -m pip lock \ -r requirements.in \ -o pylock.toml ``` pip 26.1 added the missing half of the normal workflow: `pip install` can now read the standardized lockfile through `-r`: ```bash python -m pip install -r pylock.toml ``` That matters because pip remains available in environments where adopting a new package manager is difficult. Enterprise images, client systems, restricted build environments, and conservative teams may already have pip but not uv, Poetry, or PDM. > A standard becomes much more valuable when the default tool can consume it. ## Should You Use These Features Today? For a pip-centered application, I would start experimenting now. Use dependency cooldowns in scheduled update automation. Generate `pylock.toml`, commit it, and install it in a test environment before changing production. However, keep the word **experimental** in mind. The official pip documentation still labels `pip lock` and `pylock.toml` support as experimental. pip's generated lockfile is only guaranteed for the current Python version and platform. If you deploy to several targets, generate and test separate files where necessary: ```text pylock.linux.toml pylock.macos.toml pylock.windows.toml ``` If your team already uses uv, Poetry, or PDM successfully, do not migrate only because pip added a new feature. Consistent locked installs are more valuable than fashionable tool changes. ## Key Takeaways - `--uploaded-prior-to` arrived in pip 26.0; pip 26.1 added reusable duration syntax such as `P7D`. - Cooldowns reduce exposure to brand-new malicious releases, but they can also delay urgent fixes. - PEP 751 defines `pylock.toml` as a standard Python lockfile format. - `pip lock` arrived experimentally in pip 25.1; pip 26.1 added experimental installation through `pip install -r pylock.toml`. ## Conclusion Pip is showing its age comparing to modern Python package manager. But pip 26.1 shows a useful change in direction. `pylock.toml` brings standardization. Dependency cooldowns bring time. Together, they let conservative Python teams improve reproducibility and supply-chain security without rebuilding their entire toolchain. My recommended starting point is simple: ```bash python -m pip lock \ --uploaded-prior-to=P7D \ -r requirements.in \ -o pylock.toml python -m pip install -r pylock.toml ``` ## References - [pip 26.1 changelog](https://pip.pypa.io/en/stable/news/?ref=modernpython.io#v26-1) - [PEP 751](https://peps.python.org/pep-0751/?ref=modernpython.io) - [pylock.toml specification](https://packaging.python.org/en/latest/specifications/pylock-toml/?ref=modernpython.io)