Skip to main content
The Changelog

Han shot first (Friends)

120 min episode · 3 min read
·
Brett Cannon

Episode

120 min

Read time

3 min

Topics

Productivity, Fundraising & VC, Leadership

AI-Generated Summary

Key Takeaways

  • Lock File Standardization Timeline: Brett spent four years (six from initial Twitter mention) developing PyLock.toml, a standardized lock file format for Python. The delay stemmed from needing to reimplement PIP from scratch as a proof of concept, including writing a custom resolver and metadata reader, because PIP's components weren't available as reusable libraries. The first attempt failed when the community rejected a security-focused approach that excluded source distributions, forcing a complete restart.
  • Python Packaging Complexity: Python's packaging system handles prebuilt binaries for C code across platforms, solving problems other ecosystems haven't addressed. This creates complexity around version compatibility, platform-specific dependencies, and flat namespace requirements (one version per package). Node's package-lock.json couldn't be adapted because Python allows multiple binary versions per platform, requires handling Mac-specific versus Windows-specific packages, and maintains a flat namespace unlike Node's nested node_modules structure.
  • Steering Council Governance Model: Python's five-seat steering council operates through annual elections using STAR voting (Score Then Automatic Runoff), where candidates are rated zero to five. The council serves as final arbiter for Python Enhancement Proposals (PEPs) but has devolved packaging decisions permanently to specialized delegates. Only six candidates ran for five seats in the most recent election, suggesting time commitment and code of conduct enforcement responsibilities deter volunteers.
  • Workflow Tool Evolution: UV, Hatch, and PDM popularized unified workflow tools that handle Python installation, virtual environment creation, and dependency management in single commands (like "uv run"). These tools leverage Python Build Standalone to auto-download relocatable Python binaries, eliminating the multi-step process of manual Python installation, virtual environment setup, and package installation. UV's performance and marketing created rapid adoption, raising concerns about vendor lock-in despite MIT licensing.
  • Voting System Selection Crisis: Choosing Python's governance model after Guido van Rossum's resignation took four months (July to November) and caused significant stress among core developers. The team had to decide how to decide without any existing voting mechanism, relying on mailing list consensus and "soft power" from long-time contributors. The final choice was approval voting initially, later switching to STAR voting to allow preference expression beyond binary approve/reject decisions.

What It Covers

Brett Cannon discusses his six-year journey creating Python's standardized lock file format (PEP), navigating the Python Steering Council's governance structure, and the rise of UV and Astral in the Python ecosystem. The conversation explores voting systems, package management complexity, and the challenges of standardizing tools across a volunteer-driven community with competing workflow solutions.

Key Questions Answered

  • Lock File Standardization Timeline: Brett spent four years (six from initial Twitter mention) developing PyLock.toml, a standardized lock file format for Python. The delay stemmed from needing to reimplement PIP from scratch as a proof of concept, including writing a custom resolver and metadata reader, because PIP's components weren't available as reusable libraries. The first attempt failed when the community rejected a security-focused approach that excluded source distributions, forcing a complete restart.
  • Python Packaging Complexity: Python's packaging system handles prebuilt binaries for C code across platforms, solving problems other ecosystems haven't addressed. This creates complexity around version compatibility, platform-specific dependencies, and flat namespace requirements (one version per package). Node's package-lock.json couldn't be adapted because Python allows multiple binary versions per platform, requires handling Mac-specific versus Windows-specific packages, and maintains a flat namespace unlike Node's nested node_modules structure.
  • Steering Council Governance Model: Python's five-seat steering council operates through annual elections using STAR voting (Score Then Automatic Runoff), where candidates are rated zero to five. The council serves as final arbiter for Python Enhancement Proposals (PEPs) but has devolved packaging decisions permanently to specialized delegates. Only six candidates ran for five seats in the most recent election, suggesting time commitment and code of conduct enforcement responsibilities deter volunteers.
  • Workflow Tool Evolution: UV, Hatch, and PDM popularized unified workflow tools that handle Python installation, virtual environment creation, and dependency management in single commands (like "uv run"). These tools leverage Python Build Standalone to auto-download relocatable Python binaries, eliminating the multi-step process of manual Python installation, virtual environment setup, and package installation. UV's performance and marketing created rapid adoption, raising concerns about vendor lock-in despite MIT licensing.
  • Voting System Selection Crisis: Choosing Python's governance model after Guido van Rossum's resignation took four months (July to November) and caused significant stress among core developers. The team had to decide how to decide without any existing voting mechanism, relying on mailing list consensus and "soft power" from long-time contributors. The final choice was approval voting initially, later switching to STAR voting to allow preference expression beyond binary approve/reject decisions.
  • Open Source Sustainability Challenges: The Python Steering Council faces declining volunteer participation, with only six candidates for five seats, partly due to code of conduct enforcement requirements. Members must handle reports about community members, learning information they'd prefer not to know, even when issues don't warrant action. This emotional labor, combined with weekly meetings, office hours, and PEP review responsibilities, creates barriers to participation in volunteer-driven governance.
  • Enterprise Integration Strategy: Brett works to prevent UV vendor lock-in by standardizing virtual environment locations and getting python.org to distribute prebuilt binaries, not just Python Build Standalone. The goal is making UV an option rather than requirement, allowing Astral to focus on enterprise features (like private package indexes) while the community maintains baseline functionality. This approach mirrors successful open source models where companies serve enterprise needs without controlling core infrastructure.

Notable Moment

Brett revealed he began choking at a restaurant due to stress from Python's governance transition after Guido van Rossum resigned. The crisis stemmed from having to decide how to decide on a voting system without any existing mechanism, forcing reliance on mailing list consensus and informal power dynamics among long-time contributors to reach agreement on fundamental governance structures.

Know someone who'd find this useful?

Episode Transcript

Welcome to Change Log and Friends, a weekly talk show about open source voting systems. Thanks as always to our partners at fly.io, the platform for devs who just wanna ship. Build fast, run any code fearlessly at fly.io. Okay. Let's talk. Well, friends, I don't know about you, but something bothers me about GitHub Actions. I love the fact that it's there. I love the fact that it's so ubiquitous. I love the fact that agents that do my coding for me believe that my CICD workflow begins with drafting TOML files for GitHub Actions. That's great. It's all great until, yes, until your builds start moving like molasses. GitHub Actions is slow. It's just the way it is. That's how it works. I'm sorry. But I'm not sorry because our friends at namespace, they fix that. Yes. We use namespace dot so to do all of our builds so much faster. Namespace is like GitHub actions, but faster. I mean, like, way faster. It caches everything smartly. It caches your dependencies, your docker layers, your build artifacts, so your CI can run super fast. You get shorter feedback loops, happier developers because we love our time, and you get fewer, I'll be back after this coffee and my build finishes. So that's that's not cool. The best part is it's drop in. It works right alongside your existing GitHub actions with almost zero config. It's a one line change. So you get speed up your builds, you get to let your team, and you can finally stop pretending that build time is focus time. It's not. Learn more. Go to namespace.so. That's namespace.so, just like it sounds, like it said. Go there. Check them out. We use them. We love them, and you should too. Namespace.so. Well, it's been far too long, but finally, Brett Cannon is back on ChangeLog and Friends. Thanks for having me back, guys. John Wick and Dune and we're just not talking about the three, though. We're skipping that. We're skipping that. Maybe even a little bit of Andor. You know? Andor. Yeah. I actually watched Andor specifically, to come back on for, I think, backstage before he stopped doing it. And we're not doing that at all now. But you know what? I'll I'll mention that, I've had the pleasure since the holiday break Mhmm. Like, some of December, January, and then obviously, we're here in February now. My son, my oldest son has gotten into Star Wars. And so we've watched all nine of the main movie shows, you know, the main movie shows. Yeah. You know? And then now Which order did you do? More chronological. So this is this is a really interesting phenomenon, I think, that was is it really a phenomenon? Maybe it's not. Maybe it's just a luxury, is that, you know, we grew up in an era where we got we had to watch them out of order. And so we kinda watched, you know, …

Get the full transcript (24,769 words) + summary by email — free

One-time email with the complete transcript and AI summary of this episode. No account needed.

One email, no spam. We’ll also show you what SignalCast does.

Browse all The Changelog transcripts →

You just read a 3-minute summary of a 117-minute episode.

Get The Changelog summarized like this every Monday — plus up to 2 more podcasts, free.

Pick Your Podcasts — Free

Keep Reading

Books, tools, and gear mentioned in this episode

SignalCast may earn commission on purchases via these links.

Tools

  • These tools leverage Python Build Standalone to auto-download relocatable Python binaries, eliminating the multi-step process of manual Python installation, virtual environment setup, and package installation.
  • by Astral

    UV, Hatch, and PDM popularized unified workflow tools that handle Python installation, virtual environment creation, and dependency management in single commands (like "uv run"). These tools leverage Python Build Standalone to auto-download relocatable Python binaries.
  • UV, Hatch, and PDM popularized unified workflow tools that handle Python installation, virtual environment creation, and dependency management in single commands.
  • UV, Hatch, and PDM popularized unified workflow tools that handle Python installation, virtual environment creation, and dependency management in single commands.
  • The delay stemmed from needing to reimplement PIP from scratch as a proof of concept, including writing a custom resolver and metadata reader, because PIP's components weren't available as reusable libraries.

More from The Changelog

We summarize every new episode. Want them in your inbox?

Similar Episodes

Related episodes from other podcasts

Explore Related Topics

This podcast is featured in Best Cybersecurity Podcasts (2026) — ranked and reviewed with AI summaries.

You're clearly into The Changelog.

Every Monday, we deliver AI summaries of the latest episodes from The Changelog and 192+ other podcasts. Free for one show.

Start My Monday Digest

No credit card · Unsubscribe anytime