Contents

Track:Backend EngineerData AnalystData EngineerFrontend Engineer

Frontend Engineer

Every concept a frontend engineer meets, in the order you actually need it.

1525 concepts, 231 of them core · jump toJuniorMid-levelSeniorStaffPrincipal

Junior

Build UI that works, ship small changes safely, ask good questions.

Core: start here

Programming Basics

  • Null / None / nilA value meaning "nothing here", and the source of countless crashes.
  • Truthy and FalsyNon-boolean values that act as true or false in conditions.
  • undefinedJavaScript's value for a variable or property that was never assigned.

Collections

Functional Programming

  • ClosureA function that remembers variables from the place it was defined.

Error Handling

  • Stack TraceThe chain of function calls that led to an error.

Concurrency & Async

  • async / awaitSyntax for writing asynchronous code that reads like synchronous code.
  • Promise / FutureAn object representing a value that will be available later.

Version Control (Git)

  • .gitignoreFiles Git should never track, like build output and .env.
  • AmendChanging the most recent commit's content or message.
  • BranchA movable pointer to a line of commits, for isolated work.
  • CloneCopying a remote repository, with its full history, to your machine.
  • CommitA snapshot of changes with a message explaining them.
  • Commit MessageA summary line plus a body explaining why a change was made.
  • DiffSeeing exactly what changed between commits, branches or your working copy.
  • GitThe distributed version control system almost everyone uses.
  • Log and HistoryBrowsing and filtering commit history.
  • Merge ConflictTwo branches changed the same lines and Git needs you to decide.
  • RebaseReplaying commits on top of another base for a linear history.

Pull Requests & Code Review

Debugging

Testing

Clean Code & Principles

Refactoring

  • RefactoringChanging code's structure without changing its behavior.

Developer Tooling

  • Development Environment SetupGetting a project running locally from a fresh machine.
  • FormatterA tool that rewrites code to a consistent style automatically.
  • LinterA tool that flags likely bugs and style issues.
  • LockfileA record of exact dependency versions so every install is identical.
  • Package ManagerA tool for installing and versioning dependencies, like npm, pip or cargo.
  • Reading DocumentationGoing to the official docs first, and knowing how to navigate them.
  • Searching EffectivelyFinding answers fast in error messages, issues, docs and forums.

AI-Assisted Development

Documentation & Writing

  • MarkdownThe plain-text formatting syntax used for READMEs, docs and PRs.
  • READMEThe front page of a project: what it is, how to run it, how to contribute.

HTTP

  • CORSCross-Origin Resource Sharing: how a server lets browsers call it from other origins.
  • HTTPThe request-response protocol of the web.
  • HTTP MethodsGET, POST, PUT, PATCH, DELETE and what each one means.
  • HTTP Status CodesThree-digit codes grouped 1xx–5xx describing the result.
  • HTTPSHTTP encrypted with TLS.
  • Path vs Query Parameters/users/42 vs /users?id=42, and when to use each.
  • Same-Origin PolicyThe browser rule that isolates content from different origins.
  • URLThe address of a resource: scheme, host, path, query and fragment.

API Styles & Formats

  • EndpointA specific URL and method an API exposes, like POST /orders.
  • JSONThe text data format most APIs speak.
  • Request and Response BodyThe payload sent with a request or returned in a response, usually JSON.
  • RESTAn API style built on resources, URLs and HTTP methods.

How Browsers Work

HTML

  • Form ValidationChecking input in the browser and, always, again on the server.
  • FormsInputs, labels, validation and submission.
  • Semantic HTMLUsing elements for their meaning, like <nav>, <main> and <button>.

CSS

  • Box ModelContent, padding, border and margin around every element.
  • CSS GridTwo-dimensional layout with rows and columns.
  • CSS Unitspx, rem, em, %, vw and vh, and when to use each.
  • FlexboxOne-dimensional layout along a row or a column.
  • Media QueryApplying styles based on screen size or user preferences.
  • Responsive DesignLayouts that adapt to any screen size.
  • SelectorThe pattern that chooses which elements a rule applies to.
  • SpecificityThe rules deciding which conflicting CSS declaration wins.

JavaScript & TypeScript

  • == vs ===Loose equality with coercion vs strict equality.
  • DebounceWaiting until events stop before acting, e.g. for search boxes.
  • DOM ManipulationReading and changing page elements with JavaScript.
  • ES Modulesimport and export: JavaScript's standard module system.
  • Event HandlingResponding to clicks, key presses and other user actions.
  • Fetch APIThe built-in way to make HTTP requests from JavaScript.
  • TypeScriptJavaScript with static types.
  • var, let and constJavaScript's three ways to declare variables, and how they're scoped.

UI Frameworks & Components

State Management & Data Fetching

Web Performance

Accessibility

Frontend Build Tooling

  • BundlerA tool that combines modules into files browsers can load, like Vite, webpack or esbuild.
  • Frontend Environment VariablesBuild-time variables, and why they're never secret in the browser.
  • npm ScriptsProject commands defined in package.json.
  • package.jsonThe manifest of a JavaScript project: its dependencies and scripts.
  • Source MapA mapping from built code back to the original source, for debugging.

UI/UX for Engineers

API Design

  • Double SubmissionA user clicking twice and creating two orders, and how to prevent it.

Authentication & Authorization

  • Authentication vs AuthorizationAuthentication proves who you are; authorization decides what you may do.
  • CookieA small piece of data the server asks the browser to store and send back automatically on later requests.
  • JWT (JSON Web Token)A signed, self-contained token carrying claims like user ID and expiry, verifiable without a database lookup.
  • Secrets in GitWhy passwords and keys must never be committed, and what to do when one is.

Web Application Security

Cloud Computing

CI/CD & Deployment

Observability

Working in Production

Agile & Delivery Process

Estimation & Planning

  • Breaking Down TasksSplitting work into pieces small enough to finish and estimate.
  • EstimationPredicting how long work will take, and communicating the uncertainty.

Communication

Junior Habits & First Job

Career Growth

491 more junior concepts

Programming Basics

  • ASCIIThe original 7-bit character set that UTF-8 is backward compatible with.
  • Base CaseThe condition that stops recursion.
  • Block Scope vs Function ScopeWhether a variable lives until the end of its block or of the whole function.
  • BooleanA true/false value.
  • Boolean Flag ArgumentsPassing true/false to switch a function's behavior, and why it hurts readability.
  • Character EncodingHow characters map to bytes: ASCII, UTF-8, UTF-16.
  • Code CommentText for humans in code, best used to explain why rather than what.
  • Conditional (if/else)Running different code depending on a condition.
  • ConstantA name bound to a value that cannot be reassigned.
  • Control FlowThe order in which statements execute: branches, loops, returns.
  • Data TypeThe kind of value something is, which determines what operations are valid on it.
  • Dates and TimesTime zones, UTC, ISO 8601, and why date bugs are everywhere.
  • Default ParameterA parameter value used when the caller omits it.
  • Expression vs StatementAn expression produces a value; a statement performs an action.
  • Floating-Point NumberA binary approximation of real numbers, and why 0.1 + 0.2 != 0.3.
  • FunctionA named, reusable block of code that takes inputs and returns an output.
  • Global VariableA variable visible everywhere, and why it makes code hard to reason about.
  • IntegerA whole-number type, usually with a fixed size and range.
  • ISO 8601The standard text format for dates and times, like 2026-10-10T09:00:00Z.
  • IterationStepping through the items of a collection one at a time.
  • LoopRepeating code with for, while, do-while or for-each.
  • Magic NumberAn unexplained literal in code that should be a named constant.
  • Naming ThingsChoosing names that reveal intent; one of the hardest parts of programming.
  • Off-by-One ErrorA loop or index that runs one step too many or too few.
  • OperatorA symbol that performs an operation on values, like +, == or &&.
  • Operator PrecedenceThe rules for which operators bind first in an expression.
  • Parameter vs ArgumentParameters are in the definition; arguments are the values passed at the call.
  • Primitive TypeA built-in basic type such as integer, float, boolean or character.
  • RecursionA function solving a problem by calling itself on smaller inputs.
  • Regular ExpressionA pattern language for matching and extracting text.
  • Return ValueThe result a function hands back to its caller.
  • ScopeThe region of code where a name is visible.
  • ShadowingAn inner variable hiding an outer one with the same name.
  • Short-Circuit Evaluation&& and || stopping as soon as the result is known.
  • Stack OverflowCrashing when the call stack runs out of space, usually from runaway recursion.
  • StringA sequence of characters, usually immutable.
  • String InterpolationEmbedding values directly inside a string literal.
  • Switch / MatchChoosing between many branches based on a value.
  • Ternary OperatorA compact inline if/else expression.
  • Time ZoneOffsets from UTC that change with location and daylight saving.
  • Type CoercionImplicit conversion by the language, like "5" + 1 in JavaScript.
  • Type ConversionTurning a value of one type into another, explicitly or implicitly.
  • UnicodeThe universal character set, and why string length is trickier than it looks.
  • Unix TimestampSeconds since 1970-01-01 UTC; a simple, unambiguous point in time.
  • UTF-8The dominant variable-length encoding of Unicode.
  • VariableA named reference to a value stored in memory.
  • Variadic FunctionA function that accepts any number of arguments.

Collections

  • ArrayAn ordered, indexed collection of elements.
  • Dictionary / MapA collection of key-value pairs with fast lookup by key.
  • Equality vs IdentitySame value vs same object in memory.
  • IndexingAccessing elements by position, usually starting at zero.
  • ListAn ordered collection; a dynamic array or a linked list depending on the language.
  • Map, Filter, ReduceThe three core operations for transforming collections.
  • Pass by Value vs ReferenceWhether a function receives a copy or a reference to the caller's data.
  • SetAn unordered collection of unique values.
  • SlicingTaking a sub-range of a sequence.
  • Sorting with a Key or ComparatorSorting by a custom key or comparison function.
  • TupleA fixed-size, ordered group of values, often of different types.

Object-Oriented Programming

Functional Programming

Error Handling

Type Systems

Concurrency & Async

Memory & Runtime

Version Control (Git)

  • Atomic CommitOne commit doing one logical thing, easy to review and revert.
  • BlameSeeing who last changed each line and in which commit.
  • Branch Naming ConventionsNames like feat/login-page that tell people what a branch is for.
  • Conventional CommitsA commit message convention like "feat:" and "fix:" that tools can parse.
  • Detached HEADChecking out a commit directly instead of a branch.
  • Force PushOverwriting remote history; use --force-with-lease and never on shared branches.
  • ForkYour own copy of someone else's repository, for contributing via pull requests.
  • Git ConfigYour name, email, aliases and defaults, at global or repository level.
  • HEADGit's pointer to the commit you currently have checked out.
  • MergeCombining the histories of two branches.
  • Push, Pull, FetchSending commits, downloading and merging, or only downloading.
  • RemoteAnother copy of the repository, usually "origin" on GitHub or GitLab.
  • RepositoryA project's files plus their complete history.
  • ResetMoving a branch pointer back, in soft, mixed or hard mode.
  • RevertCreating a new commit that undoes an earlier one.
  • SquashCombining several commits into one.
  • Staging AreaWhere you choose which changes go into the next commit.
  • StashTemporarily shelving uncommitted changes.
  • TagA named pointer to a commit, usually marking a release.
  • Version ControlTracking every change to code so you can review, revert and collaborate.

Branching & Releases

  • ChangelogA human-readable list of notable changes per release.
  • Feature BranchA short-lived branch for one change.
  • GitHub FlowBranch from main, open a PR, merge back to main.
  • HotfixAn urgent fix shipped outside the normal release cycle.
  • Protected BranchA branch that requires reviews and passing checks before merging.
  • Semantic VersioningMAJOR.MINOR.PATCH, and what each number promises about compatibility.

Pull Requests & Code Review

Debugging

Testing

Clean Code & Principles

Refactoring

Design Patterns

Developer Tooling

AI-Assisted Development

  • AI Coding AssistantTools like Copilot, Cursor or Claude Code that suggest and write code.
  • HallucinationAn AI confidently producing APIs, facts or code that don't exist.
  • Prompting for CodeGiving an AI enough context and constraints to produce useful code.
  • Vibe CodingAccepting AI code without reading it: fine for prototypes, risky in production.

Documentation & Writing

Data Structures

  • Binary TreeA tree where each node has at most two children.
  • Data StructureA way of organizing data so certain operations are efficient.
  • Dynamic ArrayAn array that grows by reallocating, with amortized O(1) appends.
  • Hash FunctionA function mapping data of any size to a fixed-size value.
  • Hash TableKey-value storage with average O(1) lookup via a hash function.
  • Linked ListNodes pointing to the next node: fast inserts, slow random access.
  • QueueA first-in, first-out collection.
  • StackA last-in, first-out collection.
  • TreeA hierarchy of nodes with one root and no cycles.

Algorithms

Math for Programmers

Computer Architecture

  • 32-bit vs 64-bitThe size of numbers and addresses a CPU handles natively.
  • CPUThe processor that executes instructions.
  • CPU CoreAn independent processing unit; modern CPUs have several.
  • RAMFast, temporary memory for running programs.
  • SSD vs HDDStorage types and their very different speeds.

Operating Systems

Compilers & Languages

Networking Fundamentals

  • DNSThe internet's phone book, turning names into IP addresses.
  • Domain NameA human-readable address like example.com.
  • IP AddressA numeric address identifying a device on a network.
  • Latency vs BandwidthHow long data takes to arrive vs how much can flow at once.
  • localhost / 127.0.0.1The address that always means "this machine".
  • PortA number identifying a specific service on a host.

HTTP

TLS & Certificates

  • Let's EncryptA free, automated certificate authority.
  • TLS CertificateA file proving a server controls a domain, signed by a trusted authority.

API Styles & Formats

  • APIAn interface that lets programs talk to each other.
  • Resource NamingPlural nouns, nested paths and consistent URL design.
  • SerializationConverting objects to bytes or text for storage or transfer.
  • YAMLA human-friendly data format common in configuration files.

How Browsers Work

  • Browser CacheThe browser storing responses so it doesn't download them again.
  • Browser CompatibilityMaking sure features work across browsers, e.g. by checking caniuse.
  • Browser StorageCookies, localStorage, sessionStorage and IndexedDB.
  • PolyfillCode that adds a missing feature to older browsers.
  • sessionStorageKey-value storage that's cleared when the tab closes.
  • Web BrowserThe program that fetches, renders and runs web pages.

Real-Time Communication

  • PollingAsking the server repeatedly whether something changed.

HTML

  • async and deferLoading scripts without blocking page rendering.
  • AttributeExtra information on an element, like href or alt.
  • Data AttributesCustom data-* attributes for storing extra info on elements.
  • Element and TagThe building blocks of HTML, like <p> and <a>.
  • Head and Meta TagsTitle, description, viewport and other page metadata.
  • HTMLThe markup language that structures web pages.
  • HTML EntitiesEscaped characters like &amp; and &lt;.
  • Input Typesemail, number, date and others, with the keyboards and validation they bring.
  • Open Graph TagsMetadata controlling how links preview on social media.
  • SVGVector graphics described in markup.
  • Viewport Meta TagThe tag that makes pages scale correctly on phones.

CSS

JavaScript & TypeScript

UI Frameworks & Components

State Management & Data Fetching

Rendering Strategies

Web Performance

Accessibility

  • Accessible FormsLabels, error messages and instructions that are announced correctly.
  • Screen ReaderSoftware that reads the interface aloud for blind and low-vision users.
  • Visible FocusNever removing the focus outline without a replacement.

Frontend Build Tooling

  • Dev ServerA local server that rebuilds as you edit.
  • Hot Module ReplacementSwapping changed modules into the running app without a reload.
  • node_modulesWhere installed packages live, and why it gets so big.
  • Static AssetsImages, fonts and files served as-is.
  • ViteA fast dev server and bundler for modern frontends.

UI/UX for Engineers

Backend Basics

API Design

Relational Databases & SQL

Indexing & Query Performance

  • Database IndexA lookup structure that speeds up queries at the cost of slower writes.
  • N+1 Query ProblemOne query for a list, then one more query for every item in it.

NoSQL & Other Data Stores

  • NoSQLDatabases not built on the relational table model.
  • Object StorageStoring files as objects, as in S3.

Schema Migrations

  • Seed DataInitial data loaded for development or tests.

Caching

Files & Media

  • CSV Import / ExportMoving tabular data in and out, with all its edge cases.
  • File StorageWhere uploaded files live: local disk, object storage or a CDN.
  • MIME TypeThe standard label for a file's format, like image/png.

Product Building Blocks

Architecture Styles

System Design Fundamentals

  • CDNA network of edge servers serving content close to users.
  • Load BalancerDistributing traffic across servers.
  • Static Content HostingServing files straight from storage or a CDN instead of your app.

Reliability & Resilience

  • BackupsCopies of data for restoring, and why untested backups don't count.

Performance & Scalability

  • LatencyThe time a single operation takes.

Authentication & Authorization

  • 401 Unauthorized vs 403 Forbidden401 means "I don't know who you are"; 403 means "I know who you are, and you can't do this."
  • API KeyA long random secret identifying a calling application rather than a user.
  • Basic AuthenticationSending a username and password with every request, Base64-encoded.
  • Bearer TokenA token that grants access to whoever presents it, sent in the Authorization header.
  • CredentialAnything used to prove identity: a password, key, token or certificate.
  • SessionServer-side memory of a logged-in user, referenced by a random ID the browser sends on each request.

Web Application Security

  • IDORReaching other users' data by changing an ID; a missing authorization check.
  • Input SanitizationCleaning untrusted input, and why validation and escaping matter more.
  • Output Encoding / EscapingEscaping data for the context it's inserted into.
  • SQL InjectionAttackers running SQL through unescaped input; prevented with parameterized queries.

Cryptography Basics

Secure Development

Privacy & Compliance

  • PIIPersonally identifiable information that needs special care.

Linux & Servers

Containers

Cloud Computing

CI/CD & Deployment

Observability

Incidents & SRE

  • IncidentAn unplanned event that disrupts or degrades service.

LLM & AI Engineering

Agile & Delivery Process

  • AgileDelivering in small increments and adapting to feedback.
  • BacklogThe prioritized list of work that hasn't started yet.
  • Backlog RefinementClarifying and sizing upcoming work.
  • Daily StandupA short daily sync on progress and blockers.
  • EpicA large body of work split into smaller stories.
  • KanbanVisualizing work on a board and limiting work in progress.
  • RetrospectiveA regular meeting to reflect on how the team works and improve it.
  • ScrumAn agile framework with sprints, roles and ceremonies.
  • Software Development LifecycleThe stages from idea to production to maintenance.
  • SprintA fixed period, often two weeks, to deliver planned work.
  • Sprint PlanningChoosing the work for the next sprint.
  • Sprint Review / DemoShowing what was built to stakeholders.
  • User Story"As a user, I want… so that…": a requirement from the user's point of view.
  • WaterfallSequential phases from requirements to release.

Estimation & Planning

Communication

Product Thinking

Junior Habits & First Job

Career Growth

Mid-level

Own a feature end to end without hand-holding.

Core: start here

Type Systems

  • Discriminated UnionA union whose members are told apart by a tag field.
  • GenericsCode that works over many types while keeping type safety.
  • Runtime ValidationChecking that untrusted data matches a type at runtime, e.g. with Zod or Pydantic.
  • Type NarrowingRefining a broad type to a specific one through checks.
  • Utility TypesBuilt-in TypeScript type transformers like Partial, Pick and Record.

Concurrency & Async

  • Event LoopA single thread running tasks from a queue, as in JavaScript and asyncio.
  • Race ConditionA bug where the result depends on unpredictable timing.

Version Control (Git)

  • Merge vs RebasePreserving history as it happened vs rewriting it to be linear.

Pull Requests & Code Review

Debugging

Testing

Clean Code & Principles

  • CohesionHow closely the parts of a module belong together; more is better.
  • CouplingHow much modules depend on each other's internals; less is better.
  • SOLID PrinciplesFive object-oriented design principles for maintainable code.

HTTP

  • HTTP CachingCache-Control, ETag and Last-Modified for reusing responses.

CSS

JavaScript & TypeScript

UI Frameworks & Components

State Management & Data Fetching

Rendering Strategies

Web Performance

Accessibility

  • Accessible NameThe text assistive technology announces for an element.
  • ARIAAttributes that add accessibility information when HTML alone isn't enough.
  • First Rule of ARIAUse a native HTML element instead of ARIA whenever possible.
  • Focus ManagementMoving focus sensibly in modals, route changes and dynamic content.
  • WCAGThe Web Content Accessibility Guidelines and their A, AA and AAA levels.

UI/UX for Engineers

Backend Basics

Authentication & Authorization

  • CSRFCross-Site Request Forgery: tricking a logged-in browser into sending a request the user didn't intend.
  • OAuth 2.0A framework for letting an app act on a user's behalf without seeing their password.
  • Refresh TokenA long-lived credential used only to get new short-lived access tokens without logging in again.

Web Application Security

Estimation & Planning

  • PrioritizationDeciding what to do first: impact vs effort, urgent vs important.

Communication

Product Thinking

Career Growth

  • ImpactOutcomes that matter to the business, not just output.
  • OwnershipTaking responsibility for outcomes, not just tasks.
538 more mid-level concepts

Programming Basics

  • Bitwise OperationOperating on individual bits: AND, OR, XOR and shifts.
  • Pattern MatchingBranching on the shape of data and destructuring it at the same time.
  • Tail RecursionRecursion where the call is the last action, which some languages turn into a loop.

Collections

  • GeneratorA function that lazily yields a sequence of values.
  • IteratorAn object that yields items one at a time from a sequence.
  • Lazy EvaluationComputing values only when they're actually needed.

Object-Oriented Programming

Functional Programming

Error Handling

Type Systems

Concurrency & Async

Memory & Runtime

  • Garbage CollectionAutomatic reclamation of memory that's no longer reachable.
  • Language Runtime / VMThe environment that executes your code: JVM, V8, CPython, CLR.
  • Memory LeakMemory that's never released, growing until the program slows or crashes.
  • Stack vs HeapShort-lived call frames vs dynamically allocated, longer-lived memory.

Version Control (Git)

Branching & Releases

Pull Requests & Code Review

Debugging

Testing

Clean Code & Principles

Refactoring

Design Patterns

  • AdapterWrapping an interface to make it match another.
  • Anti-PatternA common solution that looks right but causes problems.
  • BuilderConstructing complex objects step by step.
  • Chain of ResponsibilityPassing a request along handlers until one deals with it; how middleware works.
  • CommandTurning a request into an object you can queue, log or undo.
  • CompositeTreating individual objects and groups of them uniformly, as a tree.
  • DecoratorAdding behavior to an object by wrapping it.
  • Dependency InjectionPassing dependencies in instead of creating them inside.
  • Design PatternA named, reusable solution to a recurring design problem.
  • FacadeA simple interface over a complex subsystem.
  • Factory MethodLetting subclasses or functions decide which class to instantiate.
  • Gang of FourThe 1994 book that catalogued 23 classic patterns.
  • Inversion of ControlA framework calls your code rather than your code calling it.
  • Iterator PatternTraversing a collection without exposing its internals.
  • MiddlewareA pipeline of functions wrapped around request handling.
  • Null ObjectA do-nothing object used instead of null checks.
  • ObserverNotifying subscribers when something changes.
  • ProxyA stand-in that controls access to another object.
  • Publish-SubscribeSenders publish to topics; receivers subscribe without knowing each other.
  • SingletonEnsuring a class has exactly one instance; often an anti-pattern.
  • StateChanging an object's behavior when its internal state changes.
  • StrategySwapping algorithms behind a common interface.
  • Template MethodA base algorithm whose steps subclasses fill in.

Developer Tooling

AI-Assisted Development

Documentation & Writing

  • API DocumentationReference docs for an API's endpoints, parameters and errors.
  • Architecture DiagramA box-and-arrow picture of a system's components and data flow.
  • Class DiagramA diagram of classes, their fields and relationships.
  • Diagrams as CodeWriting diagrams as text, with tools like Mermaid or PlantUML.
  • Docs as CodeKeeping docs in the repository and reviewing them like code.
  • Onboarding DocumentationDocs that get a new teammate productive quickly.
  • RunbookStep-by-step instructions for operating or fixing a system.
  • Sequence DiagramA diagram of messages passed between components over time.
  • State DiagramA diagram of states and the transitions between them.
  • UMLA standard visual language for software diagrams.

Data Structures

  • Adjacency List vs MatrixTwo ways to store a graph's edges.
  • Binary Search TreeA binary tree ordered so each lookup can halve the search.
  • DequeA double-ended queue that adds and removes at both ends.
  • Directed Acyclic Graph (DAG)A graph with directed edges and no cycles, as in build systems and pipelines.
  • Doubly Linked ListA linked list with pointers in both directions.
  • GraphNodes connected by edges; models networks, dependencies and maps.
  • Hash CollisionTwo keys hashing to the same slot, and how tables handle it.
  • HeapA tree that keeps the min or max at the root; backs priority queues.
  • LRU CacheA cache evicting the least recently used item, built from a hash map and a linked list.
  • Priority QueueA queue that always returns the highest-priority item first.
  • Tree TraversalVisiting tree nodes in pre-order, in-order, post-order or level order.
  • TrieA tree of characters for fast prefix lookups.

Algorithms

Math for Programmers

Computer Architecture

Operating Systems

Compilers & Languages

Networking Fundamentals

  • Connect Timeout vs Read TimeoutWaiting to establish a connection vs waiting for data on it.
  • DNS Record TypesA, AAAA, CNAME, MX, TXT, NS and what each one does.
  • DNS TTL and PropagationHow long DNS answers are cached, and why changes take time to spread.
  • FirewallRules that allow or block network traffic.
  • IPv4 vs IPv632-bit vs 128-bit addresses, and why IPv6 exists.
  • Keep-Alive ConnectionsReusing one connection for many requests.
  • OSI ModelA seven-layer model of how network communication is structured.
  • PacketA unit of data sent over a network.
  • Round-Trip Time (RTT)The time for a message to go out and a reply to come back.
  • SocketAn endpoint for sending and receiving data over a network.
  • TCPReliable, ordered, connection-based transport.
  • TCP Three-Way HandshakeSYN, SYN-ACK, ACK: how a TCP connection starts.
  • TCP/IP ModelThe practical four-layer model the internet actually runs on.
  • ThroughputHow much work or data gets through per unit of time.
  • UDPFast, connectionless transport with no delivery guarantees.
  • VPNAn encrypted tunnel into another network.

HTTP

  • Cache-ControlThe header that directs how responses may be cached.
  • Content NegotiationClient and server agreeing on format and language through Accept headers.
  • ETagA version identifier used for conditional requests and caching.
  • HSTSA header telling browsers to always use HTTPS for a site.
  • HTTP Compressiongzip and Brotli shrinking responses on the wire.
  • HTTP ProxyAn intermediary that forwards HTTP requests.
  • HTTP/1.1The text-based HTTP version with one request at a time per connection.
  • HTTP/2Binary framing and many requests multiplexed over one connection.
  • Long PollingHolding a request open until the server has news.
  • multipart/form-dataThe encoding used to upload files from forms.
  • Preflight RequestThe OPTIONS request a browser sends before certain cross-origin calls.
  • Safe and Idempotent MethodsWhich HTTP methods shouldn't change state, and which can be retried safely.
  • Server-Sent EventsA one-way stream of events from server to browser over HTTP.
  • Synchronous vs Asynchronous APIsReturning the result in the response vs accepting work and reporting later.
  • WebhookAn HTTP callback: a service calls your URL when something happens.
  • Webhooks vs PollingBeing notified when something changes vs repeatedly asking.
  • WebSocketA persistent, two-way connection between browser and server.

TLS & Certificates

API Styles & Formats

  • API Client / SDKA library wrapping an API so callers don't hand-write HTTP.
  • GraphQLA query language that lets clients ask for exactly the data they need.
  • GraphQL Schema and ResolversTypes describing the data, and functions that fetch each field.
  • JSON SchemaA vocabulary for validating the structure of JSON.
  • OpenAPIA standard format for describing REST APIs.
  • Resource ModelingDeciding what your API's resources are and how they relate.
  • REST ConstraintsStatelessness, uniform interface, cacheability and REST's other rules.
  • RPCCalling a function on another machine as if it were local.
  • tRPCEnd-to-end type-safe APIs for TypeScript without a schema language.
  • XMLA verbose markup format still common in enterprise and legacy systems.

How Browsers Work

Real-Time Communication

HTML

CSS

JavaScript & TypeScript

UI Frameworks & Components

  • Component CompositionBuilding UIs from children and slots instead of configuration flags.
  • Headless ComponentsComponents that provide behavior and accessibility without styles.
  • Higher-Order ComponentA function that wraps a component to add behavior.
  • Hydration MismatchServer and client HTML differing, causing errors or flicker.
  • PortalsRendering a child into a different part of the DOM, e.g. for modals.
  • ReactivityAutomatically updating the UI when data changes.
  • ReconciliationHow a framework works out what changed between renders.
  • Render Props / SlotsPassing render functions or content into components.
  • SignalsFine-grained reactive values that update only what depends on them.
  • StorybookDeveloping and documenting components in isolation.
  • Virtual DOMAn in-memory UI tree diffed to find the minimal real DOM updates.

State Management & Data Fetching

Rendering Strategies

Web Performance

Accessibility

  • Accessibility TestingAutomated checks like axe plus manual keyboard and screen reader testing.
  • LandmarksRegions like header, nav and main that screen readers can jump between.
  • Reduced MotionRespecting users who ask for less animation.
  • Skip LinkA link that jumps past navigation to the main content.

Frontend Build Tooling

UI/UX for Engineers

Backend Basics

API Design

Relational Databases & SQL

Transactions & Concurrency Control

NoSQL & Other Data Stores

Caching

Queues & Async Processing

Email & Notifications

Files & Media

  • Data ExportLetting users download their data, often as a background job.
  • Image ProcessingResizing, cropping and converting images on upload.
  • PDF GenerationProducing PDFs like invoices and reports.
  • Presigned URLA temporary URL letting clients upload or download directly from storage.

Product Building Blocks

Architecture Styles

Domain-Driven Design

System Design Fundamentals

Distributed Systems

  • CAP TheoremDuring a network partition, you must choose consistency or availability.
  • Eventual ConsistencyReplicas converge once updates stop, but reads may be stale in the meantime.

Reliability & Resilience

Performance & Scalability

  • BatchingGrouping work to reduce per-item overhead.
  • BenchmarkingMeasuring performance under controlled conditions.
  • BottleneckThe component that limits overall throughput.
  • Cold StartThe delay when a serverless function or container starts fresh.
  • Payload SizeSending fewer bytes over the wire.
  • PerformanceHow fast and efficiently a system does its work.

Events & Integration

  • EventA record that something happened.
  • Unix PhilosophySmall tools that do one thing well and compose through pipes.

Cloud Design Patterns

  • Chatty I/OMany small network or database calls where one bigger one would do.
  • Over-FetchingRetrieving far more data than an operation needs.

Authentication & Authorization

  • Access TokenA short-lived token sent with each API request to prove the caller is authenticated.
  • Identity Provider (IdP)The service that authenticates users for other apps, like Okta, Auth0 or Google.
  • Multi-Factor Authentication (MFA)Requiring two or more kinds of proof: something you know, have, or are.
  • OpenID Connect (OIDC)An identity layer on top of OAuth 2.0 that adds login and a standard ID token.
  • Password Reset FlowDesigning reset links that are single-use, short-lived and don't leak account existence.
  • PKCEAn OAuth extension that stops stolen authorization codes from being exchanged by attackers.
  • SameSite CookiesA cookie attribute controlling whether cookies are sent on cross-site requests.
  • Token ExpiryChoosing how long tokens live, and handling what happens when they run out.

Web Application Security

Cryptography Basics

Secure Development

  • Attack SurfaceEvery point where an attacker could try to get in.
  • CVEA public identifier for a known vulnerability.
  • Defense in DepthSeveral layers of security, so one failure isn't fatal.
  • Dependency ScanningFinding known vulnerabilities in your dependencies.
  • SASTStatic analysis that looks for security bugs in source code.
  • Secrets ManagementKeeping API keys and passwords in a vault, not in code.
  • TyposquattingMalicious packages named like popular ones.
  • Zero-DayA vulnerability exploited before a fix exists.

Privacy & Compliance

  • Cookie ConsentAsking permission before non-essential tracking.
  • CopyleftLicenses that require derivative work to stay open source.
  • Data MinimizationCollecting only the data you actually need.
  • GDPRThe EU regulation on personal data: consent, access and deletion rights.
  • Open Source LicensesMIT, Apache, GPL, and what each one lets you do.

Linux & Servers

Containers

Cloud Computing

Infrastructure as Code

CI/CD & Deployment

Observability

Incidents & SRE

Working in Production

Data Engineering Basics

Machine Learning Basics

LLM & AI Engineering

Agile & Delivery Process

Estimation & Planning

Communication

Product Thinking

Career Growth

Senior

Own an app's architecture, performance, and failure modes.

Core: start here

Testing

Clean Code & Principles

  • Hyrum's LawWith enough users, every observable behavior becomes something someone depends on.

Documentation & Writing

CSS

UI Frameworks & Components

State Management & Data Fetching

Rendering Strategies

Web Performance

Accessibility

Architecture Styles

Secure Development

  • Threat ModelingSystematically asking what could go wrong and how to prevent it.

Observability

Incidents & SRE

  • SLOA service level objective: the target for an SLI.

Career Growth

  • Handling AmbiguityMaking progress when the problem isn't well defined.
  • ScopeHow big and ambiguous the problems you own are.

Technical Leadership

228 more senior concepts

Programming Basics

  • Integer OverflowA value exceeding its type's range and wrapping around or failing.

Functional Programming

  • MonadA pattern for chaining computations that carry context, like Option or Promise.
  • Referential TransparencyAn expression can be replaced by its value without changing behavior.

Type Systems

Concurrency & Async

  • BackpressureA slow consumer signalling a fast producer to slow down.
  • DeadlockTwo or more tasks waiting on each other forever.
  • ProcessA running program with its own memory space.
  • ThreadAn execution path within a process that shares its memory.

Memory & Runtime

Version Control (Git)

  • Git InternalsBlobs, trees, commits and refs: what Git actually stores.
  • Monorepo vs PolyrepoOne repository for everything vs one per project.
  • Patch FilesSharing changes as diff files instead of branches.
  • WorktreeSeveral working directories checked out from one repository.

Pull Requests & Code Review

  • Stacked PRsA chain of dependent pull requests, each reviewable on its own.

Debugging

Testing

  • FuzzingFeeding random inputs to find crashes and vulnerabilities.
  • Load TestingMeasuring behavior under expected traffic.
  • Mutation TestingChanging code on purpose to check that the tests notice.
  • Property-Based TestingGenerating many inputs to check that properties always hold.
  • Soak TestRunning under load for hours to find leaks and slow degradation.
  • Stress TestingPushing beyond capacity to find the breaking point.
  • Testing in ProductionValidating safely with real traffic using flags, canaries and monitoring.

Clean Code & Principles

Refactoring

Design Patterns

  • Abstract FactoryCreating families of related objects without naming concrete classes.
  • BridgeSeparating an abstraction from its implementation so both can vary.
  • FlyweightSharing common state among many small objects to save memory.
  • MediatorCentralizing communication between objects.
  • MementoCapturing state so it can be restored later, as in undo.
  • PrototypeCreating objects by cloning an existing one.
  • Service LocatorA registry for looking up dependencies, often seen as an anti-pattern.
  • Type ObjectDefining "kinds" of things as data instead of subclasses.
  • VisitorAdding operations to a structure without changing its classes.

Documentation & Writing

  • C4 ModelDiagramming software at four zoom levels: context, containers, components, code.
  • DiátaxisOrganizing docs into tutorials, how-to guides, reference and explanation.

Data Structures

  • B-TreeA wide, shallow tree optimized for disks; how database indexes work.
  • Balanced TreeTrees like AVL or red-black that stay shallow for guaranteed O(log n).
  • Bloom FilterA compact structure answering "definitely not" or "probably yes" for set membership.
  • Persistent Data StructureAn immutable structure that shares unchanged parts between versions.
  • Ring BufferA fixed-size buffer that wraps around.

Algorithms

Math for Programmers

Computer Architecture

Operating Systems

  • KernelThe core of the OS with full access to the hardware.

Compilers & Languages

Networking Fundamentals

  • Head-of-Line BlockingOne slow item holding up everything queued behind it.
  • QUICA UDP-based transport behind HTTP/3, with faster handshakes.

HTTP

TLS & Certificates

  • Certificate ChainLeaf, intermediate and root certificates linking to a trusted root.
  • TLS HandshakeHow client and server agree on keys before sending data.

API Styles & Formats

How Browsers Work

Real-Time Communication

  • CRDTData structures that merge concurrent edits without conflicts, used in collaborative editors.
  • Operational TransformationTransforming concurrent edits so they apply consistently, as in Google Docs.
  • PresenceShowing who is online or viewing something right now.
  • WebRTCPeer-to-peer audio, video and data in the browser.

HTML

CSS

JavaScript & TypeScript

UI Frameworks & Components

Rendering Strategies

UI/UX for Engineers

Backend Basics

  • Context PropagationCarrying request IDs, deadlines and trace context across threads and services.

API Design

NoSQL & Other Data Stores

  • Faceted SearchFiltering search results by categories with counts.
  • Fuzzy SearchMatching despite typos and spelling variations.
  • Geospatial DataStoring and querying locations: nearby search, distances, geohashes.

Caching

Queues & Async Processing

  • JitterRandomizing retry delays so clients don't all retry in sync.

Files & Media

Product Building Blocks

Architecture Styles

Domain-Driven Design

System Design Fundamentals

Distributed Systems

Reliability & Resilience

Performance & Scalability

  • Tail LatencyThe slowest requests (p99), which users notice most.

Events & Integration

  • Event BusA channel through which events reach their subscribers.

Cloud Design Patterns

Authentication & Authorization

  • Account EnumerationLeaking whether an email is registered through login, signup or reset responses.
  • Passkeys (WebAuthn)Phishing-resistant login with device-bound key pairs instead of passwords.
  • Refresh Token RotationIssuing a new refresh token on every refresh and invalidating the old one, so reuse of an old token reveals theft.
  • Single Sign-On (SSO)Logging in once with an identity provider and accessing many apps.

Web Application Security

Cryptography Basics

Secure Development

  • Bug BountyPaying outside researchers to report vulnerabilities.
  • CVSSA score rating how severe a vulnerability is.
  • DASTTesting a running app for vulnerabilities from the outside.
  • Penetration TestingAuthorized simulated attacks to find vulnerabilities.
  • Responsible DisclosureReporting vulnerabilities privately before going public.
  • SBOMA software bill of materials listing every component.
  • Security ReviewReviewing a design or change specifically for security risks.
  • Shift-Left SecurityFinding security issues early in development.
  • Software Supply Chain SecurityProtecting against compromised dependencies and build pipelines.
  • STRIDEA way to categorize threats: spoofing, tampering, repudiation, disclosure, denial of service, elevation.

Privacy & Compliance

Kubernetes & Orchestration

  • KubernetesThe dominant container orchestration platform.

Cloud Computing

CI/CD & Deployment

Observability

  • Actionable AlertsAlerting only on symptoms that need a human to act.
  • OpenTelemetryThe vendor-neutral standard for collecting telemetry.
  • SamplingRecording only a fraction of traces or logs to control cost.

Incidents & SRE

Machine Learning Basics

LLM & AI Engineering

  • AI Product UXDesigning interfaces for uncertain, streaming, sometimes-wrong AI output.
  • Choosing a ModelTrading off quality, speed and cost across model sizes and providers.
  • EvalsSystematically measuring the quality of LLM output.
  • Fine-TuningFurther training a model on your own examples.
  • GuardrailsChecks on model inputs and outputs for safety and correctness.
  • LLM Cost and LatencyManaging tokens, model choice and caching.
  • LLM-as-JudgeUsing one model to grade another model's output.

Agile & Delivery Process

Estimation & Planning

Communication

Product Thinking

Career Growth

Technical Leadership

Staff

Shape how many teams build, across apps.

Clean Code & Principles

  • Conway's LawSystems mirror the communication structure of the organizations that build them.

Documentation & Writing

  • RFCA request for comments: proposing a significant change for wide review.

Architecture Styles

System Design Fundamentals

Performance & Scalability

Secure Development

CI/CD & Deployment

  • DORA MetricsFour delivery metrics: deploy frequency, lead time, change failure rate and recovery time.

Incidents & SRE

Communication

Product Thinking

Career Growth

Technical Leadership

Principal

Set technical direction for the organization.

Career Growth

Technical Leadership