Astral has been acquired by OpenAI (News)

27 Mar 2026 · 11 min · 6 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

News roundup on AI coding agents and developer tooling, plus supply-chain security and open-source ecosystem maintenance.

Guests/backgrounds

No named guests; includes sponsor interviews (WorkOS founder/CEO Michael Greenwich) and mentions open-source founders (Ryan Leazy) and a maintainer who forked httpx to httpxyz.

Key claims

Astral (UV, Ruff, TY) is joining OpenAI’s Codex team; open-source work continues. Coding-agent tooling is shifting toward “agent-native” workflows. LightLM 1.8.2.8 was compromised via a supply-chain attack (malicious .pth executed at Python startup); affected installs should be treated as incidents. OpenCode hit #1 on Hacker News but removed Anthropic OAuth/references after legal pressure. Rust’s issues are mostly onboarding/ecosystem maturity, not “doomed.”

Notable examples

LightLM malicious .pth via PyPI; OpenCode terminal/IDE/LSP with BYO-model; WorkOS CLI device-grant flow; open-source TurboTax alternative; httpx fork to httpxyz due to unreleased fixes and eroding upstream trust.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Astral's Acquisition by OpenAI

0:46 to 1:55

Discussion on Astral's acquisition and its impact on Python development tools.

“Astral, the company behind UV, Ruff, and TY, says it has entered into an agreement to join OpenAI as part of the Codex team.”

Light LLM Supply Chain Attack

1:55 to 3:38

Analysis of the Light LLM security incident and its implications.

“Because it suggests the future is not just better linters, better package managers, better type checkers, and separate things.”

OpenCode's Rise and Challenges

3:38 to 6:00

Exploration of OpenCode's success and the challenges in the coding agent space.

“OpenCode blew up this week as the highest traction new coding agent launched on Hacker News.”

Rust Project Challenges and Solutions

6:00 to 7:22

Reflection on the Rust programming language's challenges and proposed improvements.

“Well, friends, I'm here with Michael Greenwich, founder and CEO of WorkOS.”

AI in Tax Software Development

7:28 to 8:38

Investigating the use of AI in building a free tax software alternative.

“Ryan Leazy got annoyed enough with TurboTax and the larger tax filing mess that he used AI coding tools to build a free open source alternative and then put it in the public.”

The HTTPX Fork and Its Implications

8:38 to 10:01

Discussion on the fork of HTTPX and the risks associated with project maintenance.

“Now, the real story is not just that somebody got frustrated and made a fork.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:29What's up friends, Adam here. This is Change. person in life and someone worth emulating. He has 10 principles to live by. Here are two of my favorites. Number one, I will forget the mistakes of the past and press on to greater achievements. And number two, I will always remain loyal to my God, my family and friends and my country. Okay, let's get into the news.

0:51Astro has been acquired by OpenAI. This is a big one, y 'all. Astral, the company behind UV, Ruff, and TY, says it has entered into an agreement to join OpenAI as part of the Codex team. And I think the reason why this hits so hard for me is that Astral is not some random AI startup getting acqui-hired. These are already some of the most important tools in modern Python development. So the obvious first question is, what happens to the tools? Astral says the open source work continues after the deal closes, And that matters a lot because UV and Ruff in particular are not side projects anymore.

1:26These are foundational pieces of a lot of Python workflows right now. If we zoom out, the bigger revelation is the center of gravity for developer tools keeps moving toward the coding agent stack. Astral started out making Python development dramatically faster. And now the same team is heading into Codex. That tells you where they think the highest leverage work is next. And if you're a Python developer, or honestly any developer paying attention to tools, this is one of those moments worth clocking. Because it suggests the future is not just better linters, better package managers, better type checkers, and separate things.

2:01The future is those tools getting pulled closer and closer into the agent itself. Light LLM compromised by a supply chain attack. LightLM 1.8 2.8 was reported to include a malicious.pth file that could execute on Python startup and potentially steal secrets from machines that installed it. Attackers published a fake LightLM 1.8 2.8 release directly to PyPy outside LightLM's normal GitHub release flow. The current explanation for how it got there is the real story. Light LLM says a publishing token was exposed through an unpinned Trivi security scan in CI. This was not just one bad package upload.

2:48It was a supply chain chain reaction, compromised security tooling, stolen published credentials, then poisoned releases pushed straight to PyPy. Light LLM is not some random edge dependency, though. For a lot of teams, it sits right in the middle of their AI stack, writing model calls, living right next to API keys, cloud credentials, and internal config. And the.pth file is a nasty delivery mechanism because it can execute when Python starts before anybody even imports the library. So if you're out there and you install the affected versions, treat this as an incident, not an upgrade bug. Check where it ran, rotate anything exposed, and look at CI and developer machines first.

3:31The takeaway is the AI middleware layer now belongs inside your real supply chain threat model. OpenCode tops Hacker News. OpenCode blew up this week as the highest traction new coding agent launched on Hacker News. OpenCode is an open source attempt to build the full coding agent surface area, terminal, IDE, desktop, multi-session workflows, LSP support with bring-your-own-model flexibility. The uncomfortable signal is in the timing. Right before OpenCode hit number one on Hacker News, the project had to strip Anthropic OAuth and Anthropic References after legal pressure. And if you've been on X lately, you've likely heard about the Claude OpenCode drama.

4:12This should tell us the open agent race is real, but it's still happening inside ecosystems controlled by model vendors. So my read on this is that OpenCode matters less because it's definitively the best agent today and more because it shows where this market is going next. The next fight is not just over model quality. It is over who owns the interface, the workflow, and the default home for coding with agents. Rust has challenges, but here's how we can address them. The Rust Project published a reality check. This is not a Rust is doomed post. It is not a victory lap either. More like we talked to a bunch of people, and yes, the problems you already think Rust has are in fact the problems people keep running into.

4:56The interesting part is the shape of those problems. Compile times are still a thing, but they're not really blockers for most people. The borrow checker is still brutal for beginners, but it bothers experts a lot less, which tells you some of that pain is onboarding pain, not necessarily evidence the language is broken. Async is still messy in the way Rust async has been messy for a while, except in this post, they are pretty explicit. There are actual next steps they think can help. And then you get to the ecosystem story, which is maybe the most important one. A healthy crate ecosystem is Rust's largest strength, but people do not always know which crates to trust, which ones are effectively standard, or whether the thing that they need exists yet in their domain.

5:40In worlds like embedded, GUI, and safety-critical work, that maturity gap gets a lot more obvious. I applaud this post because the intent behind it is awesome. I use Rust daily. I feel this pain every single day. Sure, Rust can be improved, but this shows the project is listening and it shows they have clear pain points to smooth out where there's friction. And now time for some sponsor news. Well, friends, I'm here with Michael Greenwich, founder and CEO of WorkOS. Michael, if you didn't know, CLIs are back. They're all the rage. And a major problem I personally have with my CLIs is authorization, authentication.

6:17What do you say about WorkOS and auth for CLI? Long live the CLI. We've had a resurgence of it, which I am so thrilled about. We actually have supported CLI auth for many years at WorkOS. This is something called the device grant flow. It lets you have that really smooth experience where from your CLI app you're building, you can link out to the browser and have the user authenticate through whatever system they have in your app and then bounce back into the browser. So nobody is pasting their credentials or their secrets into the shell itself. Kind of zero knowledge, zero trust way of building OAuth authorization.

6:49It works great for existing CLIs. It also works super great if you're building a CLI specifically for agents, which is kind of all the rage now as people are expanding upon that. So WorkOS, we think, is the fastest way to do it. And you can actually do it without migrating your entire user base. You can just layer on the CLI auth. Because WorkOS is so modular, you can just add that in front. We have people doing this for MCP as well, where they just use WorkOS for the MCP authentication gateway and not for the primary identity stack. So it's totally possible today. And I think WorkOS is the fastest way to ship off in your CLI app you're building.

7:22Well, friends, go to WorkOS.com. Try it today. Again, WorkOS.com. Learning to code by building TurboTax. Ryan Leazy got annoyed enough with TurboTax and the larger tax filing mess that he used AI coding tools to build a free open source alternative and then put it in the public. So tax professionals and, quote, actual programmers and, quote, can inspect it. The question is not whether AI can spit out code anymore. We are past that. The better question is whether these tools are good enough to help somebody take a real run at expensive, boring, incumbent software that normal people actually depend on.

8:01Tax software is a great test because it is high stakes, full of edge cases, and usually not something you could fake your way through with a polished demo. Ryan is not asking for your trust. He's doing the exact opposite. it. He's saying, hey, here's the app I made. It is open source. Vet it. If you're a pro, if you're a programmer, vet it, please. This isn't about a journalist suddenly becoming a 10x software tax engineer. It is whether or not AI lowers the cost enough for we the people to build credible public interest software in markets that used to belong entirely to incumbents. why i forked httpx this is one of those open source stories that sounds niche until you realize how much code quietly depends on it httpx is a very popular http client and michael has now forked it into httpxyz and the reason is there hasn't been a release of httpx since November 2024, fixes were sitting around unreleased and upstream trust has been eroding.

9:06Now, the real story is not just that somebody got frustrated and made a fork. The issue is project maintenance risk eventually turns into dependency risk. In this case, the fork author points to hidden issues, discussions being turned off, years of talk about a future 1.0, and a growing sense that a widely used package did not have a stable maintenance path anymore. HTTPX is not some obscure utility. It sits underneath a lot of Python software and even high-profile packages like OpenAI's and Anthropics Python SDKs. They've already begun guarding against a future 1.0 release. The fork's pitch is the interesting part.

9:46It is not a rewrite. It is not a revolution. Just a stable fork with the motto, quote, move a little faster and not break things, end quote. That is a pretty good summary of what a lot of developers actually want from infrastructure dependencies. Not novelty, just a maintainer story they can trust.

10:25I can't wait to release them. Things are getting stacked up over here, and it's so exciting. All right, that's it for this week's news. We'll see you next week.

From the publisher

Astral is joining OpenAI, which says a lot about where the center of gravity is moving for developer tools, LiteLLM got hit by a nasty supply-chain attack, and OpenCode blew up as the latest serious open source swing at the coding-agent stack. We've also got Rust doing a very public reality check on its own pain points, WorkOS pushing AuthKit into CLI auth, Ryan Lizza using AI to build an open source TurboTax alternative, and a fresh httpx fork that turns open source maintenance drama into a real dependency story. If nothing else, this week was a good reminder that tools, trust, and control all move together.

More from The Changelog: Software Development, Open Source

All 232 episodes
Astral has been acquired by OpenAI (News)The Changelog: Software Development, Open Source · 11 min
Listen in VO