Files & Data19
Append a line to a file
Add one line to an existing file without reading or rewriting it — the shape of every log, history, and queue-file write.
files →Check if a file or directory exists
Answer "is this path there?" before touching config, cache or lock files — and treat the answer as a hint, not a promise.
filesystem →Compute a running total (cumulative sum)
A running total sums every row up to and including the current one — the classic window-function job, no self-join and no subquery.
sql →Copy or move a file
Duplicate a file or relocate it.
files →Create and clean up a temp file
Create a uniquely named scratch file, use it, then delete it — the backbone of atomic-save patterns, handing work to external programs, and keeping tests from littering the filesystem.
temp-files →Deep clone a nested value
A shallow copy duplicates the outer container and shares everything nested — mutate a field one level down and both copies change.
clone →Get a file's size and modified time
Ask the filesystem for a file's size and last-modified time in a single stat call — the raw input to cache invalidation ('re-download unless the remote file is newer'), staleness banners, log-rotation checks, and directory listings.
files →Group a list of items by a key
Every real program groups things: orders by customer, errors by type, events by day.
group-by →Paginate with keyset (seek) instead of OFFSET
OFFSET pagination walks past N rows on every page — page 1000 re-reads 999 pages of data, and any insert between requests shifts rows so items repeat or vanish.
sql →Read a CSV file
Parse a CSV file row by row.
csv →Read a file line by line
Iterate a text file one line at a time without holding it in memory — the shape of every log scan and batch feed.
files →Read a JSON file
Read a JSON config from disk into a usable value in one step.
json →Read an entire file into a string
Slurp a whole file into a string in one call — the right shape for configs, templates and other small inputs, and the wrong one for multi-gigabyte logs: these calls allocate file-sized memory, sometimes twice during the byte-to-character decode, and the streaming primitive is what you want past a few dozen megabytes.
files →Remove duplicates from a list, keeping order
Deduplicating looks trivial — put it in a set — and that is exactly where two bugs live.
dedupe →Select the top N rows per group
Keep the top N rows inside every group — the top 3 earners per department, the latest order per customer.
sql →Sort a list of objects by a field
Sort a list of objects by a field — the everyday sort.
sort →Upsert a row (INSERT or UPDATE in one statement)
An upsert inserts the row if it does not exist and updates it if it does — in ONE statement, no read-then-write race.
sql →Walk a directory recursively
Enumerate every entry beneath a root, depth-first.
filesystem →Write a pretty-printed JSON file
Serialize an in-memory value to JSON with indentation a human can read — the right default for config files, fixtures, and anything headed for a diff or a code review.
json →Text & Parsing10
Build and parse URL query strings
Query strings look like string concatenation and punish it: values containing &, =, spaces, or non-ASCII corrupt the URL the moment you skip encoding — and hand-rolling the encoding invites the classic + vs %20 mixup.
url →Compare strings case-insensitively
Decide whether two strings are 'the same' ignoring case — matching user input, header names, enum values.
strings →Extract a substring safely (slice semantics)
Every language slices differently the moment bounds go bad: Python and JavaScript clamp out-of-range indices and never throw, while Go panics, Rust panics twice over (out of range AND non-char-boundary), and Java, Kotlin and C# throw when the start runs past the end.
string →Join array elements into a delimited string
Flatten a list into one delimited string — CSV lines, IN-clauses, log fields.
strings →Parse a key=value string into a map
Turn a 'k=v k2=v2' string — query-ish config, CLI tags, env dumps — into a lookup structure.
parsing →Replace all occurrences in a string
Swap every occurrence of a substring for another.
strings →Reverse a string (Unicode-safe)
Reverse 'café Foo' without corrupting it.
strings →Slugify a string (URL-safe)
Turn any title into a URL-safe slug: lowercase, fold accents, everything non-alphanumeric becomes a dash, dashes collapse and trim.
slug →Split a string on any whitespace
Tokenize input on any run of whitespace — spaces, tabs, newlines — rather than one literal character.
strings →Truncate a string without breaking characters
Truncating "to 10 characters" breaks three ways: bytes cut a multi-byte UTF-8 sequence in half, code points cut surrogate pairs apart, and neither matches what a human calls a character — flags and skin-tone emoji are single GRAPHEMES built from several code points.
truncate →HTTP & APIs5
Make a GET request
Fetch a resource over HTTP with GET — the read verb of the web, used for REST endpoints, health checks, and pulling any payload a server exposes.
http →Parse a JWT payload
A JWT is three dot-separated base64url parts: header.payload.signature.
jwt →POST JSON and read the JSON response
The task every API client starts with.
http →Retry with exponential backoff
Retry logic is easy to write wrong in four ways: no attempt cap (infinite loop), no jitter (every client retries in lockstep and re-knocks the server down), retrying permanent 4xx errors that can never succeed, and leaking the failed response's connection before sleeping.
retry →Send an HTTP GET request with a timeout
A request without a timeout can hang forever — most clients default to minutes, some to infinity.
http →Crypto & Encoding5
Base64 encode and decode
Base64 is an encoding, not encryption — anyone can reverse it; it just makes binary safe for text channels.
base64 →Generate a UUID
UUIDv4 (122 random bits) is the default identifier everywhere.
uuid →Hash a string with SHA-256
SHA-256 turns any input into a fixed 32-byte fingerprint — one-way, deterministic, and NOT encryption.
sha256 →Sign and verify with HMAC-SHA256
HMAC bolts a secret key onto a hash — the standard way to prove a message came from someone holding the key (webhook signatures, API auth).
hmac →URL-encode and decode a string
Percent-encode a string so it is safe to drop into a URL — and decode it back.
url →Dates & Time3
Convert a timestamp between timezones
Converting an instant between zones is the most-misunderstood date task: a timezone is a RULE (with DST transitions), not a fixed offset, so "add 6 hours" is wrong twice a year for most zones.
timezone →Format a timestamp as ISO 8601
ISO 8601 (in practice, its profile RFC 3339: 2026-08-25T09:30:00Z) is the one timestamp format APIs agree on — logs, JSON, databases all sort correctly as plain strings.
iso8601 →Humanize a timestamp as "3 hours ago"
Humans read "3 hours ago", not timestamps.
relative-time →System & CLI4
Graceful shutdown on SIGINT/SIGTERM
Graceful shutdown is finishing in-flight work when SIGINT/SIGTERM arrives instead of dying mid-request.
signals →Parse command-line arguments
Read what the user typed after your program's name.
cli →Read environment variables with defaults
Configuration belongs in the environment — but getenv returns a string or nothing, and every consumer downstream wants typed values.
env →Run a subprocess and capture its output
Running a command and capturing its output has one security rule and one deadlock rule.
subprocess →Testing & QA3
Mock a function or dependency in a test
Replace a real dependency with a fake during a test — the network call, the clock, the random source.
mocking →Write a snapshot test
A snapshot test records a function's output once, stores it, and fails when the output changes — the test you write without writing the expectation.
testing →Write a table-driven test
The table-driven test is one loop over cases: input, expected, name.
testing →Concurrency & Parallelism3
Increment a counter atomically across threads
The innocuous counter++ is three operations — load, add, store — and two threads interleaving it lose increments.
atomic →Limit concurrency to N tasks at a time
Run a thousand tasks but only N at a time — the bounded pool that protects downstream services and memory.
concurrency →Map over items in parallel, results in input order
Map a function over N items in parallel and get the results back IN INPUT ORDER — the requirement everyone forgets until the outputs arrive shuffled.
parallelism →Algorithms & Data Structures3
Binary search: index, insertion point, or presence
The most-copied algorithm and the most-mis-copied: off-by-one bounds, integer overflow in mid = (lo + hi) / 2, and three different questions that share one name — exact index, insertion point, or boolean presence.
binary-search →LRU cache: O(1) get and put, evict least-recently-used
An LRU cache evicts the least-recently-used entry when full — the interview classic that is ALSO real infrastructure (memoization with a cap, caches bounded by memory).
lru →Shuffle an array without bias (Fisher-Yates)
The unbiased shuffle: walk the array backwards, swap each element with a RANDOM ONE FROM THE REMAINING PREFIX — every permutation exactly equally likely.
shuffle →Regex & Text Processing3
Named capture groups in regex
Named capture groups turn match positions into a readable contract: (?<year>\d{4}) beats m[1] in every review.
regex →Replace regex matches with a callback function
Replace every match with the result of a function — the pattern behind template engines, syntax highlighting, and escaping.
regex →Split a string but keep the separators
Split a string but KEEP the separators — tokenizing code, CSV-ish streams, breaking text on punctuation without losing it.
split →Databases & SQL3
Bulk-insert thousands of rows
Insert thousands of rows fast: one round trip with N value tuples, not N round trips of one row each — the difference between milliseconds and minutes at scale.
sql →Run a prepared statement (bind, don't concatenate)
A prepared statement sends the query and the data as separate messages — the database compiles the template once and binds values forever after.
sql →Run a SQL transaction (all-or-nothing)
A transaction makes N statements atomic: all commit or none do.
sql →Files & Streams3
Read and write JSONL (JSON Lines) files
JSON Lines — one JSON value per physical line — is the streaming data format: append-only logs, bulk export/import, LLM training files.
jsonl →Stream a file line by line (without loading it)
Reading a file line by line without loading it is the difference between constant and O(file) memory — the convenient APIs (read(), file_get_contents(), ReadFile, Files.readAllLines) slurp everything, and a multi-gigabyte log becomes an OOM.
files →Write a file atomically (tmp + fsync + rename)
Write a file so readers never see a half-written version: write to a temporary name in the SAME directory, fsync it, then rename over the target — rename within one filesystem is atomic, and every reader sees either the old file or the new one, never a mix.
files →Frontend & DOM3
Debounce a function call
Debounce waits for quiet: the callback fires only after N milliseconds of silence, so a keystroke storm costs one call instead of one per key.
debounce →Escape HTML output (XSS-safe)
Escape untrusted text before it lands in HTML — the XSS line of defense.
xss →Throttle a function call
Throttle guarantees at most one call per interval while events keep arriving — the scroll/resize/mousemove tool, where debounce would wait for a silence that never comes.
throttle →Security Hardening4
Compare secrets in constant time
Comparing secrets with ordinary equality leaks how many leading bytes matched: string comparison returns at the first difference, and response timing amplifies that into a prefix oracle.
security →Generate a secure random token
A token is only as strong as its entropy source: Math.random, rand(), mt_rand and default seeds are predictable, and predictable tokens are forged tokens.
security →Hash and verify a password
Password hashing must be SLOW on purpose: SHA-256 finishes in nanoseconds, and a GPU farm tries billions of SHA-256 guesses per second — a password hash needs a tuned cost (CPU, memory, or both) so each guess costs milliseconds.
password →Rate limiting with a token bucket
A token bucket drains at a fixed rate and refills one token per interval — allow a burst, then throttle to the average: the shape almost every API rate limit takes.
rate-limit →