Tech dictionary and glossary
This is the public Digital 26 page for tech terminology. 1329 working terms. Free to read. Open the live search at /dictionary.
Aliases: /glossary, /tech-dictionary, /tech-terms, /terminology.
- .env — .env is a local file of environment variables.
- .gitattributes — .gitattributes is per-path rules for line endings, diffs, and linguist overrides.
- .gitignore — .gitignore is the file that lists paths Git should not track, such as node_modules and .
- <a> — <a> (HTML a element) is the HTML <a> element: a hyperlink.
- <abbr> — <abbr> (HTML abbr element) is the HTML <abbr> element: an abbreviation with an optional expansion.
- <address> — <address> (HTML address element) is the HTML <address> element: contact information for the article or page author.
- <area> — <area> (HTML area element) is the HTML <area> element: a hot-spot in an image map.
- <article> — <article> (HTML article element) is the HTML <article> element: a self-contained composition, such as a dictionary entry or blog post.
- <aside> — <aside> (HTML aside element) is the HTML <aside> element: tangential content, such as a pull quote or related links.
- <audio> — <audio> (HTML audio element) is the HTML <audio> element: an embedded sound player.
- <b> — <b> (HTML b element) is the HTML <b> element: offset text without extra importance.
- <base> — <base> (HTML base element) is the HTML <base> element: the base URL for relative links in the document.
- <bdi> — <bdi> (HTML bdi element) is the HTML <bdi> element: isolates bidirectional text so a name in another script does not flip nearby words.
- <bdo> — <bdo> (HTML bdo element) is the HTML <bdo> element: overrides text direction.
- <blockquote> — <blockquote> (HTML blockquote element) is the HTML <blockquote> element: a quoted block from another source.
- <body> — <body> (HTML body element) is the HTML <body> element: the visible document content.
- <br> — <br> (HTML br element) is the HTML <br> element: a line break inside text, not a spacing tool.
- <button> — <button> (HTML button element) is the HTML <button> element: a control that does an action.
- <canvas> — <canvas> (HTML canvas element) is the HTML <canvas> element: a bitmap drawing surface scripted with JavaScript.
- <caption> — <caption> (HTML caption element) is the HTML <caption> element: the title of a table.
- <cite> — <cite> (HTML cite element) is the HTML <cite> element: the title of a cited work.
- <code> — <code> (HTML code element) is the HTML <code> element: a fragment of computer code.
- <col> — <col> (HTML col element) is the HTML <col> element: column attributes in a table column group.
- <colgroup> — <colgroup> (HTML colgroup element) is the HTML <colgroup> element: a group of table columns.
- <data> — <data> (HTML data element) is the HTML <data> element: content with a machine-readable value attribute.
- <datalist> — <datalist> (HTML datalist element) is the HTML <datalist> element: autocomplete options for an input.
- <dd> — <dd> (HTML dd element) is the HTML <dd> element: the description in a description list.
- <del> — <del> (HTML del element) is the HTML <del> element: text that was removed, useful in diffs.
- <details> — <details> (HTML details element) is the HTML <details> element: a disclosure widget the user can open.
- <dfn> — <dfn> (HTML dfn element) is the HTML <dfn> element: the defining instance of a term.
- <dialog> — <dialog> (HTML dialog element) is the HTML <dialog> element: a native modal or non-modal dialog.
- <div> — <div> (HTML div element) is the HTML <div> element: a generic block with no meaning.
- <dl> — <dl> (HTML dl element) is the HTML <dl> element: a description list of terms and definitions.
- <dt> — <dt> (HTML dt element) is the HTML <dt> element: the term in a description list.
- <em> — <em> (HTML em element) is the HTML <em> element: stress emphasis that changes the meaning of a sentence.
- <embed> — <embed> (HTML embed element) is the HTML <embed> element: an external embedded resource, less common than iframe.
- <fieldset> — <fieldset> (HTML fieldset element) is the HTML <fieldset> element: groups related form controls with a legend.
- <figcaption> — <figcaption> (HTML figcaption element) is the HTML <figcaption> element: the caption of a figure.
- <figure> — <figure> (HTML figure element) is the HTML <figure> element: self-contained media with an optional caption.
- <footer> — <footer> (HTML footer element) is the HTML <footer> element: the footer of a section or page.
- <form> — <form> (HTML form element) is the HTML <form> element: a set of controls that submit to a URL.
- <h1> — <h1> (HTML h1 element) is the HTML <h1> element: the top heading of a page or section.
- <h2> — <h2> (HTML h2 element) is the HTML <h2> element: a section heading under h1.
- <h3> — <h3> (HTML h3 element) is the HTML <h3> element: a subsection heading.
- <h4> — <h4> (HTML h4 element) is the HTML <h4> element: a heading level you should rarely need if the outline is clean.
- <h5> — <h5> (HTML h5 element) is the HTML <h5> element: an even deeper heading.
- <h6> — <h6> (HTML h6 element) is the HTML <h6> element: the deepest heading level.
- <head> — <head> (HTML head element) is the HTML <head> element: metadata, title, scripts, and links, not visible text.
- <header> — <header> (HTML header element) is the HTML <header> element: introductory content for a section or page.
- <hgroup> — <hgroup> (HTML hgroup element) is the HTML <hgroup> element: groups a heading with subtitles.
- <hr> — <hr> (HTML hr element) is the HTML <hr> element: a thematic break, not a decorative line.
- <html> — <html> (HTML html element) is the HTML <html> element: the root element of an HTML document.
- <i> — <i> (HTML i element) is the HTML <i> element: an alternate voice, such as a technical term.
- <iframe> — <iframe> (HTML iframe element) is the HTML <iframe> element: a nested browsing context.
- <img> — <img> (HTML img element) is the HTML <img> element: an image with a required alt that describes the purpose.
- <input> — <input> (HTML input element) is the HTML <input> element: a form control whose type changes its job.
- <ins> — <ins> (HTML ins element) is the HTML <ins> element: inserted text, the pair of del.
- <kbd> — <kbd> (HTML kbd element) is the HTML <kbd> element: keyboard input, used in docs.
- <label> — <label> (HTML label element) is the HTML <label> element: the name of a control.
- <legend> — <legend> (HTML legend element) is the HTML <legend> element: the caption of a fieldset.
- <li> — <li> (HTML li element) is the HTML <li> element: an item in a list.
- <link> — <link> (HTML link element) is the HTML <link> element: a relationship to an external resource, such as a stylesheet.
- <main> — <main> (HTML main element) is the HTML <main> element: the dominant content of the page.
- <map> — <map> (HTML map element) is the HTML <map> element: an image map container.
- <mark> — <mark> (HTML mark element) is the HTML <mark> element: highlighted text for reference.
- <menu> — <menu> (HTML menu element) is the HTML <menu> element: a semantic list of commands in supporting browsers.
- <meta> — <meta> (HTML meta element) is the HTML <meta> element: document-level metadata such as description and viewport.
- <meter> — <meter> (HTML meter element) is the HTML <meter> element: a scalar gauge within a known range.
- <nav> — <nav> (HTML nav element) is the HTML <nav> element: a set of navigation links.
- <noscript> — <noscript> (HTML noscript element) is the HTML <noscript> element: fallback content when scripts are off.
- <object> — <object> (HTML object element) is the HTML <object> element: an embedded external resource, mostly legacy.
- <ol> — <ol> (HTML ol element) is the HTML <ol> element: an ordered list.
- <optgroup> — <optgroup> (HTML optgroup element) is the HTML <optgroup> element: a labeled group of select options.
- <option> — <option> (HTML option element) is the HTML <option> element: a choice inside a select or datalist.
- <output> — <output> (HTML output element) is the HTML <output> element: the result of a calculation in a form.
- <p> — <p> (HTML p element) is the HTML <p> element: a paragraph of text.
- <picture> — <picture> (HTML picture element) is the HTML <picture> element: art-direction for images with multiple sources.
- <pre> — <pre> (HTML pre element) is the HTML <pre> element: preformatted text that keeps spaces and line breaks.
- <progress> — <progress> (HTML progress element) is the HTML <progress> element: a progress bar for a task.
- <q> — <q> (HTML q element) is the HTML <q> element: a short inline quotation.
- <rp> — <rp> (HTML rp element) is the HTML <rp> element: fallback parentheses for ruby annotations.
- <rt> — <rt> (HTML rt element) is the HTML <rt> element: the annotation of a ruby run.
- <ruby> — <ruby> (HTML ruby element) is the HTML <ruby> element: East Asian pronunciation annotations.
- <s> — <s> (HTML s element) is the HTML <s> element: text that is no longer accurate.
- <samp> — <samp> (HTML samp element) is the HTML <samp> element: sample output from a program.
- <script> — <script> (HTML script element) is the HTML <script> element: executable code or a JSON-LD block.
- <search> — <search> (HTML search element) is the HTML <search> element: a landmark for a search form.
- <section> — <section> (HTML section element) is the HTML <section> element: a thematic grouping with a heading.
- <select> — <select> (HTML select element) is the HTML <select> element: a dropdown or multi-select control.
- <slot> — <slot> (HTML slot element) is the HTML <slot> element: a placeholder in a shadow tree for projected light-DOM children.
- <small> — <small> (HTML small element) is the HTML <small> element: side comments, not a way to make legal text unreadable.
- <source> — <source> (HTML source element) is the HTML <source> element: an alternative media file for picture, audio, or video.
- <span> — <span> (HTML span element) is the HTML <span> element: a generic inline box with no meaning.
- <strong> — <strong> (HTML strong element) is the HTML <strong> element: strong importance, not only bold styling.
- <style> — <style> (HTML style element) is the HTML <style> element: embedded CSS.
- <sub> — <sub> (HTML sub element) is the HTML <sub> element: subscript.
- <summary> — <summary> (HTML summary element) is the HTML <summary> element: the visible label of a details widget.
- <sup> — <sup> (HTML sup element) is the HTML <sup> element: superscript.
- <table> — <table> (HTML table element) is the HTML <table> element: tabular data.
- <tbody> — <tbody> (HTML tbody element) is the HTML <tbody> element: the body rows of a table.
- <td> — <td> (HTML td element) is the HTML <td> element: a data cell.
- <template> — <template> (HTML template element) is the HTML <template> element: inert markup you clone with script or a framework.
- <textarea> — <textarea> (HTML textarea element) is the HTML <textarea> element: a multiline text control.
- <tfoot> — <tfoot> (HTML tfoot element) is the HTML <tfoot> element: the footer rows of a table.
- <th> — <th> (HTML th element) is the HTML <th> element: a header cell for a row or column.
- <thead> — <thead> (HTML thead element) is the HTML <thead> element: the header rows of a table.
- <time> — <time> (HTML time element) is the HTML <time> element: a machine-readable date or time.
- <title> — <title> (HTML title element) is the HTML <title> element: the document title shown in the tab.
- <tr> — <tr> (HTML tr element) is the HTML <tr> element: a table row.
- <track> — <track> (HTML track element) is the HTML <track> element: timed text for video or audio, such as captions.
- <u> — <u> (HTML u element) is the HTML <u> element: a non-textual annotation, such as a misspelling underline.
- <ul> — <ul> (HTML ul element) is the HTML <ul> element: an unordered list.
- <var> — <var> (HTML var element) is the HTML <var> element: a variable in a mathematical or programming expression.
- <video> — <video> (HTML video element) is the HTML <video> element: an embedded video player.
- <wbr> — <wbr> (HTML wbr element) is the HTML <wbr> element: a hint where the browser may break a long word.
- 0.0.0.0 — 0.0.0.0 is in servers, bind all IPv4 interfaces.
- 100 — 100 (HTTP 100 Continue) is HTTP status 100 Continue: the server got the headers and the client may send the body.
- 101 — 101 (HTTP 101 Switching Protocols) is HTTP status 101 Switching Protocols: the server is switching, for example to a WebSocket.
- 102 — 102 (HTTP 102 Processing) is HTTP status 102 Processing: WebDAV: the server accepted the request and is still working.
- 103 — 103 (HTTP 103 Early Hints) is HTTP status 103 Early Hints: the server is sending preload hints before the final response.
- 12-factor — 12-factor is a set of rules for SaaS apps: one codebase, explicit deps, config in the environment, and more.
- 200 — 200 (HTTP 200 OK) is HTTP status 200 OK: the request succeeded and the body is the result.
- 201 — 201 (HTTP 201 Created) is HTTP status 201 Created: a new resource exists, usually after POST.
- 202 — 202 (HTTP 202 Accepted) is HTTP status 202 Accepted: the work is queued, not finished.
- 203 — 203 (HTTP 203 Non-Authoritative Information) is HTTP status 203 Non-Authoritative Information: the payload was transformed by a proxy.
- 204 — 204 (HTTP 204 No Content) is HTTP status 204 No Content: success with an empty body, common after DELETE.
- 205 — 205 (HTTP 205 Reset Content) is HTTP status 205 Reset Content: success; the client should reset the form.
- 206 — 206 (HTTP 206 Partial Content) is HTTP status 206 Partial Content: a range request succeeded, used for media seeking.
- 207 — 207 (HTTP 207 Multi-Status) is HTTP status 207 Multi-Status: WebDAV: the body lists several status results.
- 208 — 208 (HTTP 208 Already Reported) is HTTP status 208 Already Reported: WebDAV: members were already listed in a DAV binding.
- 226 — 226 (HTTP 226 IM Used) is HTTP status 226 IM Used: the response is a delta from an instance manipulation.
- 2FA — 2FA (Two-Factor Authentication) is a second proof besides the password, such as a TOTP app or a key.
- 300 — 300 (HTTP 300 Multiple Choices) is HTTP status 300 Multiple Choices: there are several representations the client could pick.
- 301 — 301 (HTTP 301 Moved Permanently) is HTTP status 301 Moved Permanently: update your links; the resource lives at a new URL.
- 302 — 302 (HTTP 302 Found) is HTTP status 302 Found: a temporary redirect.
- 303 — 303 (HTTP 303 See Other) is HTTP status 303 See Other: redirect the client to GET another URL, typical after a POST.
- 304 — 304 (HTTP 304 Not Modified) is HTTP status 304 Not Modified: the cached copy is still good; no body is sent.
- 307 — 307 (HTTP 307 Temporary Redirect) is HTTP status 307 Temporary Redirect: redirect but keep the original method.
- 308 — 308 (HTTP 308 Permanent Redirect) is HTTP status 308 Permanent Redirect: permanent, and keep the original method.
- 400 — 400 (HTTP 400 Bad Request) is HTTP status 400 Bad Request: the server cannot parse or accept the request as sent.
- 401 — 401 (HTTP 401 Unauthorized) is HTTP status 401 Unauthorized: you need to authenticate.
- 402 — 402 (HTTP 402 Payment Required) is HTTP status 402 Payment Required: reserved for digital payments; few public APIs use it.
- 403 — 403 (HTTP 403 Forbidden) is HTTP status 403 Forbidden: the server knows you and still refuses.
- 404 — 404 (HTTP 404 Not Found) is HTTP status 404 Not Found: no resource at this URL, or the server does not want to admit it exists.
- 405 — 405 (HTTP 405 Method Not Allowed) is HTTP status 405 Method Not Allowed: the URL exists but not for this verb.
- 406 — 406 (HTTP 406 Not Acceptable) is HTTP status 406 Not Acceptable: the server cannot produce a type listed in Accept.
- 407 — 407 (HTTP 407 Proxy Authentication Required) is HTTP status 407 Proxy Authentication Required: authenticate to the proxy first.
- 408 — 408 (HTTP 408 Request Timeout) is HTTP status 408 Request Timeout: the server closed an idle incoming request.
- 409 — 409 (HTTP 409 Conflict) is HTTP status 409 Conflict: the current state does not allow this change, such as a duplicate apply.
- 410 — 410 (HTTP 410 Gone) is HTTP status 410 Gone: the resource used to exist and will not come back.
- 411 — 411 (HTTP 411 Length Required) is HTTP status 411 Length Required: send a Content-Length.
- 412 — 412 (HTTP 412 Precondition Failed) is HTTP status 412 Precondition Failed: an If-Match or similar header was not satisfied.
- 413 — 413 (HTTP 413 Content Too Large) is HTTP status 413 Content Too Large: the body is bigger than the server will accept.
- 414 — 414 (HTTP 414 URI Too Long) is HTTP status 414 URI Too Long: the URL itself is too big, often a GET that should have been POST.
- 415 — 415 (HTTP 415 Unsupported Media Type) is HTTP status 415 Unsupported Media Type: the Content-Type is not one the server handles.
- 416 — 416 (HTTP 416 Range Not Satisfiable) is HTTP status 416 Range Not Satisfiable: the requested byte range is outside the resource.
- 417 — 417 (HTTP 417 Expectation Failed) is HTTP status 417 Expectation Failed: the Expect header cannot be met.
- 418 — 418 (HTTP 418 I'm a teapot) is HTTP status 418 I'm a teapot: an April Fools code people still use as an easter egg.
- 421 — 421 (HTTP 421 Misdirected Request) is HTTP status 421 Misdirected Request: the request was sent to a server that cannot produce a response.
- 422 — 422 (HTTP 422 Unprocessable Content) is HTTP status 422 Unprocessable Content: JSON parsed but the values failed validation.
- 423 — 423 (HTTP 423 Locked) is HTTP status 423 Locked: WebDAV: the resource is locked.
- 424 — 424 (HTTP 424 Failed Dependency) is HTTP status 424 Failed Dependency: WebDAV: a previous request in the set failed.
- 425 — 425 (HTTP 425 Too Early) is HTTP status 425 Too Early: the server refuses to process a request that might be replayed.
- 426 — 426 (HTTP 426 Upgrade Required) is HTTP status 426 Upgrade Required: the client should switch protocols.
- 428 — 428 (HTTP 428 Precondition Required) is HTTP status 428 Precondition Required: the server wants If-Match to avoid lost updates.
- 429 — 429 (HTTP 429 Too Many Requests) is HTTP status 429 Too Many Requests: you hit a rate limit.
- 431 — 431 (HTTP 431 Request Header Fields Too Large) is HTTP status 431 Request Header Fields Too Large: headers, cookies, or the URL blew a size cap.
- 451 — 451 (HTTP 451 Unavailable For Legal Reasons) is HTTP status 451 Unavailable For Legal Reasons: the resource is blocked by law.
- 500 — 500 (HTTP 500 Internal Server Error) is HTTP status 500 Internal Server Error: the server threw.
- 501 — 501 (HTTP 501 Not Implemented) is HTTP status 501 Not Implemented: the method or feature is not supported.
- 502 — 502 (HTTP 502 Bad Gateway) is HTTP status 502 Bad Gateway: a proxy got an invalid response from upstream.
- 503 — 503 (HTTP 503 Service Unavailable) is HTTP status 503 Service Unavailable: overloaded or down for maintenance.
- 504 — 504 (HTTP 504 Gateway Timeout) is HTTP status 504 Gateway Timeout: a proxy waited too long for upstream.
- 505 — 505 (HTTP 505 HTTP Version Not Supported) is HTTP status 505 HTTP Version Not Supported: the server refuses that HTTP version.
- 506 — 506 (HTTP 506 Variant Also Negotiates) is HTTP status 506 Variant Also Negotiates: a misconfigured content negotiation loop.
- 507 — 507 (HTTP 507 Insufficient Storage) is HTTP status 507 Insufficient Storage: WebDAV: the server cannot store the representation.
- 508 — 508 (HTTP 508 Loop Detected) is HTTP status 508 Loop Detected: WebDAV: an infinite loop while processing.
- 510 — 510 (HTTP 510 Not Extended) is HTTP status 510 Not Extended: the request needs an HTTP extension the server does not have.
- 511 — 511 (HTTP 511 Network Authentication Required) is HTTP status 511 Network Authentication Required: a captive portal wants you to log in to the network.
- A record — A record is a DNS record that points a name at an IPv4 address.
- a11y — a11y (Accessibility) is the numeronym for accessibility: a, then 11 letters, then y.
- AAAA record — AAAA record is a DNS record that points a name at an IPv6 address.
- AbortController — AbortController is a way to cancel fetch and other async work with a signal.
- accent-color — accent-color (CSS accent-color) is the CSS accent-color property: the accent used by native checkboxes and radios.
- Acceptance criteria — Acceptance criteria is the concrete checks that tell you a story works for the user.
- Accessibility — Accessibility (a11y) is building so people who use keyboards, screen readers, or other aids can complete the same tasks.
- ACID — ACID (Atomicity Consistency Isolation Durability) is the four properties people expect from a serious relational transaction.
- ACM — ACM (AWS Certificate Manager) is Amazon's service for provisioning and attaching TLS certificates.
- Action — Action is a reusable unit you call from a step, such as actions/checkout.
- active record — active record is an ORM style where a row is an object with save().
- ADR — ADR (Architecture Decision Record) is a short file that captures a decision, the context, and the consequences.
- AEAD — AEAD (Authenticated Encryption with Associated Data) is encryption that also detects tampering, such as AES-GCM.
- AES — AES (Advanced Encryption Standard) is the default symmetric cipher for data at rest and in TLS.
- agent — agent is a loop that lets a model use tools and look at results until it stops.
- aggregation — aggregation is computing counts, sums, and groups rather than returning raw rows.
- Agile — Agile is the family of iterative delivery ideas.
- AGPL — AGPL is GPL for network software: modified servers must offer source to users.
- AJAX — AJAX (Asynchronous JavaScript and XML) is the old name for updating a page without a full reload.
- align-items — align-items (CSS align-items) is the CSS align-items property: alignment along the cross axis.
- align-self — align-self (CSS align-self) is the CSS align-self property: a single item overriding align-items.
- amend — amend (git commit --amend) is replacing the latest commit.
- Angular — Angular is a full TypeScript framework from Google with batteries included: routing, forms, HTTP, and dependency injection.
- animation — animation (CSS animation) is the CSS animation property: the shorthand for keyframed motion.
- Ansible — Ansible is agentless automation that SSHes into machines and applies YAML playbooks.
- Anycast — Anycast is announcing the same IP from many places so users hit a nearby edge.
- Apache 2.0 — Apache 2.0 is a permissive license with an explicit patent grant.
- API key — API key is a secret string that identifies a client to an API.
- Apollo — Apollo is a popular GraphQL client and server toolkit.
- Approve — Approve is a review state that says the change is good to merge under the branch rules.
- Argon2 — Argon2 is the current preferred password hashing family, memory-hard against GPU cracking.
- ARIA — ARIA (Accessible Rich Internet Applications) is attributes that explain widgets to assistive tech when native HTML is not enough.
- ARN — ARN (Amazon Resource Name) is the long name that uniquely identifies an AWS resource.
- ArrayBuffer — ArrayBuffer is a raw binary buffer in memory.
- Artifact — Artifact is a built file you store, such as a Docker image, a JAR, or a static zip.
- ASCII — ASCII is the 7-bit character set for English letters and control codes.
- ASP.NET — ASP.NET is Microsoft's web stack on .
- aspect-ratio — aspect-ratio (CSS aspect-ratio) is the CSS aspect-ratio property: the preferred width-to-height ratio of the box.
- Assembly — Assembly (ASM) is the human-readable form of machine instructions for a CPU family, used when you must control every cycle or register.
- Assignee — Assignee is the person currently responsible for an Issue or PR.
- AST — AST (Abstract Syntax Tree) is the tree a parser builds from source so linters and compilers can rewrite it.
- Astro — Astro is a site framework that ships zero JS by default and hydrates islands only where needed.
- asymmetric encryption — asymmetric encryption is a public key encrypts or verifies, a private key decrypts or signs.
- async/await — async/await is syntax that pauses a function until a Promise settles, so async code reads top to bottom.
- atomic — atomic is an operation that appears indivisible to other threads.
- attention — attention is the mechanism that lets a model decide which earlier tokens matter for the next one.
- audit log — audit log is an append-only record of who did what.
- Aurora — Aurora is Amazon's MySQL/Postgres-compatible database with a custom storage layer.
- Auto-merge — Auto-merge is a PR setting that merges as soon as required checks pass.
- Autoprefixer — Autoprefixer is a PostCSS plugin that adds vendor prefixes from Can I Use data.
- autoscaling — autoscaling is adding or removing instances from a metric such as CPU or request count.
- autosquash — autosquash is rebase -i --autosquash applying fixup and squash commits automatically.
- AWS — AWS (Amazon Web Services) is Amazon's cloud: compute, storage, databases, and a thousand named products.
- AZ — AZ (Availability Zone) is an isolated data-center group inside a region.
- Azure — Azure is Microsoft's cloud, the default in many enterprises already on 365.
- B-tree — B-tree is the balanced tree most relational indexes use.
- Babel — Babel is the classic JS compiler that transforms syntax and plugins through a pipeline.
- backdrop-filter — backdrop-filter (CSS backdrop-filter) is the CSS backdrop-filter property: filters applied to what is behind a box, used for frosted glass.
- background — background (CSS background) is the CSS background property: the shorthand for color, images, and layers behind the content.
- Background job — Background job is work you do after responding to the user, such as sending mail or generating a PDF.
- background-color — background-color (CSS background-color) is the CSS background-color property: the flat color behind the content.
- background-image — background-image (CSS background-image) is the CSS background-image property: one or more images or gradients layered behind the content.
- background-size — background-size (CSS background-size) is the CSS background-size property: how background images are scaled, such as cover or contain.
- Backlog — Backlog is the ordered list of work not yet started.
- backpressure — backpressure is slowing producers when consumers cannot keep up.
- backup — backup is a copy you can restore.
- bandwidth — bandwidth is how much data you can move per second.
- base64 — base64 is an encoding that turns bytes into ASCII.
- Bash — Bash (Bourne Again Shell) is the default command language on most Linux servers, used to glue programs together in scripts and CI.
- bcrypt — bcrypt is a widely used password hashing function.
- BDD — BDD (Behavior-Driven Development) is describing behavior in a shared language, often with Given/When/Then.
- Bearer token — Bearer token is an access token sent in the Authorization header as 'Bearer …', whoever holds it is treated as the user.
- BEM — BEM (Block Element Modifier) is a class naming method: block__element--modifier, meant to keep CSS predictable.
- BigInt — BigInt is integers of arbitrary size, written with an n suffix.
- Biome — Biome is a fast Rust linter and formatter aiming to replace ESLint plus Prettier for many repos.
- bisect — bisect (git bisect) is binary-searching history to find the commit that introduced a bug.
- bit — bit is a 0 or 1, the smallest unit of digital information.
- Bitbucket — Bitbucket is Atlassian's Git host, common in Jira-heavy companies.
- Blame — Blame (git blame) is annotating each line with the last commit that touched it.
- blame view — blame view is the web UI for git blame.
- Blob — Blob is an immutable blob of bytes, used for files and downloads.
- Block storage — Block storage is a virtual disk you attach to a VM, such as EBS.
- blue team — blue team is the defenders who detect and respond.
- Blue-green deploy — Blue-green deploy is running two production environments and switching traffic when the new one is healthy.
- BOM — BOM (Browser Object Model) is the browser objects around the page, such as window, navigator, and location.
- BOM — BOM (byte order mark) is a Unicode signature at the start of a file that will break shebangs and JSON if you are not looking.
- border — border (CSS border) is the CSS border property: the line around the padding edge.
- border-radius — border-radius (CSS border-radius) is the CSS border-radius property: how round the corners are.
- bot — bot is an automated client.
- bottom — bottom (CSS bottom) is the CSS bottom property: the inset from the bottom edge when the box is positioned.
- Bounded context — Bounded context is a clear border where a word such as Order has one meaning and one model.
- box-shadow — box-shadow (CSS box-shadow) is the CSS box-shadow property: one or more drop or inset shadows.
- box-sizing — box-sizing (CSS box-sizing) is the CSS box-sizing property: whether width includes padding and border.
- Branch — Branch is a movable name for a commit, so work can diverge and later merge.
- Branch protection — Branch protection is rules that block force-push or require reviews and green CI before merge.
- Breakpoint — Breakpoint is a width where the layout rules change, such as 768px or 1100px.
- Brownfield — Brownfield is work inside an existing production system.
- brute force — brute force is trying many guesses.
- Bug — Bug is behavior that does not match the intended contract.
- bug bounty — bug bounty is paying outsiders who report vulns under rules.
- bulkhead — bulkhead is isolating pools of resources so one noisy neighbor cannot take the whole process down.
- Bun — Bun is a fast JavaScript runtime and toolkit that aims to replace Node, npm, and bundlers for many apps.
- Bundle — Bundle is the packaged JS/CSS a bundler emits for the browser.
- Bundler — Bundler is a tool such as Vite, webpack, or esbuild that graphs modules and emits files the browser can load.
- byte — byte is eight bits, the addressable unit in almost every machine you will ship to.
- C — C is a low-level language that maps closely to machine memory and still sits under operating systems, databases, and embedded firmware.
- C# — C# (CSharp) is a Microsoft language on .
- C++ — C++ (CPP) is C with abstractions for objects, templates, and zero-cost performance, used in games, browsers, and finance engines.
- CA — CA (Certificate Authority) is an org browsers trust to sign certificates, or your internal signer for private hosts.
- Cache — Cache is a store of recent results so you do not recompute or refetch the same work.
- Cache API — Cache API is the service-worker store for Request/Response pairs.
- cache busting — cache busting is changing a URL or query so clients drop an old file.
- cache stampede — cache stampede is many clients missing a cache at once and slamming the origin.
- Cache-Control — Cache-Control is the header that says whether a response may be stored and for how long.
- call stack — call stack is the stack of functions currently running.
- Canary deploy — Canary deploy is sending a small slice of traffic to the new version before a full rollout.
- CAPTCHA — CAPTCHA is a challenge meant to tell humans from bots.
- caret-color — caret-color (CSS caret-color) is the CSS caret-color property: the color of the text insertion caret.
- Cascade — Cascade is the rules that decide which CSS declaration wins when several apply.
- CCPA — CCPA is California's privacy law, the US cousin people mention next to GDPR.
- CD — CD (Continuous Delivery) is automatically taking a green build to a deployable (or deployed) state.
- CDN — CDN (Content Delivery Network) is edge caches around the world that serve static files closer to the user.
- CDN purge — CDN purge is telling the edge to drop a cached file so the next hit refetches origin.
- Certificate — Certificate (TLS certificate) is a signed document that binds a public key to a hostname so clients can trust HTTPS.
- Changelog — Changelog is a human list of user-facing changes between versions.
- changeset — changeset is a small file that describes a version bump, used by Changesets in monorepos.
- changeset bot — changeset bot is the GitHub bot that opens a Version Packages PR from changeset files.
- Checkout — Checkout is switching the working tree to a branch or commit.
- Cherry-pick — Cherry-pick is copying a single commit onto your current branch.
- chmod — chmod is changing file permissions.
- chown — chown is changing file ownership.
- CI — CI (Continuous Integration) is automatically building and testing every change so main stays green.
- circuit breaker — circuit breaker is stopping calls to an unhealthy dependency so it can recover.
- CLA — CLA (Contributor License Agreement) is a legal doc some projects require before they accept your PR.
- class — class is syntax over prototypes for constructing objects with methods.
- clean architecture — clean architecture is a layered style that keeps the domain independent of frameworks.
- clear — clear (CSS clear) is the CSS clear property: how far a box must sit below floated siblings.
- clickjacking — clickjacking is tricking a user into clicking a hidden iframe.
- Client Component — Client Component is a React component that must run in the browser because it uses state, effects, or events.
- clip-path — clip-path (CSS clip-path) is the CSS clip-path property: a shape that clips painting of the box.
- Clipboard API — Clipboard API is reading and writing the clipboard with permissions.
- Clojure — Clojure is a Lisp on the JVM that treats immutability as the default and is used for data-heavy backends.
- Clone — Clone is copying a remote repo onto your machine, including history.
- closure — closure is a function that remembers variables from the scope where it was created.
- Cloudflare — Cloudflare is DNS, CDN, WAF, Workers, and R2: the edge company many sites sit on.
- CloudFront — CloudFront is Amazon's CDN.
- CNAME — CNAME is a DNS record that aliases one name to another.
- code point — code point is a Unicode number for a character, such as U+1F4A1.
- Code review — Code review is humans reading a diff for correctness, security, and clarity before it merges.
- Code splitting — Code splitting is breaking a bundle into chunks loaded when a route or widget needs them.
- CODE_OF_CONDUCT — CODE_OF_CONDUCT is the rules for how humans treat each other in a project.
- CODEOWNERS — CODEOWNERS is a file that maps paths to required reviewers.
- Codeowners review — Codeowners review is an automatic review request from the CODEOWNERS file.
- CodeQL — CodeQL is GitHub's semantic code analysis that looks for vulnerability patterns.
- Codespaces — Codespaces is cloud VS Code / Cursor-compatible environments defined by a repo.
- cold start — cold start is the delay when a serverless function or free-tier host wakes from idle.
- color — color (CSS color) is the CSS color property: the foreground text color.
- column-gap — column-gap (CSS column-gap) is the CSS column-gap property: the gutter between those columns.
- columns — columns (CSS columns) is the CSS columns property: newspaper-style multi-column flow.
- Commit — Commit is a snapshot with a message, author, and parent pointer.
- Commit hash — Commit hash (SHA) is the 40-character (or short) id of a commit, computed from its contents.
- commit-msg — commit-msg is a hook that can reject a commit message that does not match the team's style.
- CommonJS — CommonJS (CJS) is Node's older module format with require and module.
- compare view — compare view is the /compare URL that shows a diff between refs.
- compare-and-swap — compare-and-swap (CAS) is the CPU primitive many lock-free structures use.
- compiler — compiler is a program that translates source to another form, such as tsc or rustc.
- Compose — Compose (Docker Compose) is a YAML file that runs several containers together on one machine.
- composition over inheritance — composition over inheritance is build behavior by combining small pieces instead of deep class trees.
- compromised maintainer — compromised maintainer is when a popular package owner's account is taken and a new version is evil.
- Connection pool — Connection pool is a set of reusable database connections so each request does not open a new TCP session.
- constant-time compare — constant-time compare is comparing secrets without leaking length or match progress through timing.
- contain — contain (CSS contain) is the CSS contain property: a performance hint that limits how layout and paint leak out of the box.
- Container — Container is a packaged process with its filesystem and deps, isolated but sharing the host kernel.
- content-visibility — content-visibility (CSS content-visibility) is the CSS content-visibility property: skipping rendering of off-screen subtrees.
- Context — Context (React Context) is React's built-in way to pass values down without props, easy to overuse.
- context window — context window is how many tokens the model can see at once.
- CONTRIBUTING — CONTRIBUTING is the file that tells outsiders how to open issues and PRs.
- Controlled input — Controlled input is an input whose value lives in React state, not only in the DOM.
- controller — controller is the HTTP adapter that parses a request and calls a service.
- Conventional Commits — Conventional Commits is a commit message style such as feat: or fix: that tools can turn into changelogs.
- Cookie — Cookie is a small piece of data a server asks the browser to store and send back on later requests to the same site.
- cookie consent — cookie consent is the banner required when you store non-essential cookies in some jurisdictions.
- Copilot — Copilot (GitHub Copilot) is GitHub's AI pair programmer that suggests code from comments and surrounding files.
- copyleft — copyleft is licenses that require derivatives to stay open under the same license.
- coroutine — coroutine is a cooperative lightweight thread, the model async/await uses.
- CORS — CORS (Cross-Origin Resource Sharing) is the browser rule that lets a page on one origin call an API on another only when the API opts in with headers.
- cosign — cosign is a tool for signing and verifying container images.
- Coverage — Coverage (code coverage) is the percent of lines or branches tests executed.
- CQRS — CQRS (Command Query Responsibility Segregation) is splitting write models from read models so each can scale and shape data differently.
- Create a merge commit — Create a merge commit is the GitHub merge style that keeps all PR commits plus a merge commit.
- credential stuffing — credential stuffing is trying leaked username/password pairs from other breaches.
- Critical CSS — Critical CSS is the minimum CSS needed for the first screen so the rest can load later.
- CRLF — CRLF is Windows line endings.
- Cron — Cron is a time-based scheduler on Unix; in the cloud it is usually a managed scheduled job.
- CRUD — CRUD (Create Read Update Delete) is the four basic storage operations every admin screen ends up growing.
- CSP — CSP (Content Security Policy) is a header that tells the browser which scripts, styles, and frames a page may load.
- CSR — CSR (Client-Side Rendering) is shipping a shell and letting JavaScript build the page in the browser.
- CSRF — CSRF (Cross-Site Request Forgery) is an attack where a victim's browser is tricked into sending a state-changing request to a site they are already logged into.
- CSS — CSS (Cascading Style Sheets) is the stylesheet language that controls layout, color, type, and motion of HTML without changing document meaning.
- CSS modules — CSS modules is CSS files whose class names are hashed so they cannot collide across components.
- CSS-in-JS — CSS-in-JS is writing styles in JavaScript files, for example styled-components or Emotion.
- CSV — CSV (Comma-Separated Values) is a plain table dumped as text rows, the lowest common denominator for exporting spreadsheets.
- cURL — cURL is the command-line HTTP client every docs page should include.
- cursor — cursor (CSS cursor) is the CSS cursor property: the pointer shape.
- Cursor — Cursor is an AI-first editor based on VS Code, used heavily at this studio.
- cursor pagination — cursor pagination is paging with a pointer to the last item, more stable than offset on changing lists.
- Custom element — Custom element is an HTML tag you define in JS, such as <brand-mark>.
- Custom property — Custom property (CSS variable) is a --token you set on a selector and reuse with var(), the base of a design system.
- CVE — CVE (Common Vulnerabilities and Exposures) is a public id for a known vulnerability, such as CVE-2024-1234.
- CVSS — CVSS (Common Vulnerability Scoring System) is the 0–10 score people use to argue about severity.
- CVSS score — CVSS score is the numeric severity.
- CWE — CWE (Common Weakness Enumeration) is a catalog of weakness types, such as CWE-79 for XSS.
- daemon — daemon is a long-running background process, often named with a trailing d.
- DAO — DAO (Data Access Object) is an object that hides CRUD for a storage backend.
- DAP — DAP (Debug Adapter Protocol) is the sibling of LSP for debuggers.
- Dart — Dart is the language behind Flutter, used to build one UI that compiles to mobile, web, and desktop.
- DAST — DAST (Dynamic Application Security Testing) is attacking a running app to find issues you cannot see in source.
- data mapper — data mapper is an ORM style where a separate layer maps objects to tables, as Prisma and Hibernate do.
- data retention — data retention is how long you keep a class of data.
- data URL — data URL is a URL that embeds the file inline as base64 or text.
- DCO — DCO (Developer Certificate of Origin) is a Signed-off-by line that says you have the right to submit the change.
- DDoS — DDoS (Distributed Denial of Service) is many machines flooding a target so real users cannot get through.
- Deadlock — Deadlock is two transactions each waiting on the other's lock, so the database aborts one.
- deadlock — deadlock (thread deadlock) is two threads each holding what the other needs.
- debounce — debounce is waiting until events pause before running a function, used on search boxes.
- declarative shadow DOM — declarative shadow DOM is server-rendered shadow trees so components paint before JS.
- deep copy — deep copy is copying an object through every nested layer.
- Default branch — Default branch is the branch GitHub treats as main, used for PRs and the repo home.
- Defense in depth — Defense in depth is stacking independent controls so one failure does not open the whole system.
- Definition of done — Definition of done is the checklist that says a task is actually finished: tests, review, docs, deploy.
- DELETE — DELETE is the method that removes a resource.
- Deno — Deno is a secure-by-default JavaScript and TypeScript runtime with built-in tooling, created by Node's original author.
- Denormalization — Denormalization is copying data into a table on purpose so reads stay fast.
- Dependabot — Dependabot is GitHub's bot that opens PRs when dependencies have updates or known CVEs.
- dependency inversion — dependency inversion is depend on abstractions, not on concrete low-level modules.
- Deploy key — Deploy key is an SSH key limited to one repo, used by servers that only need that clone.
- Design doc — Design doc is a written proposal so review happens before the expensive implementation.
- design pattern — design pattern is a named solution to a recurring design problem.
- Design token — Design token is a named value for color, space, or type that products share across web and native.
- destructuring — destructuring is unpacking arrays or objects into variables in one statement.
- Detached HEAD — Detached HEAD is when you check out a raw commit instead of a branch, so new commits have no branch name.
- devDependency — devDependency is a package needed to build or test, not to run in production.
- Diff — Diff is the line-by-line change between two trees, commits, or the working copy.
- DigitalOcean — DigitalOcean is a developer cloud known for droplets, spaces, and simple pricing.
- direction — direction (CSS direction) is the CSS direction property: ltr or rtl.
- disaster recovery — disaster recovery (DR) is the plan and the tested backups for losing a whole region.
- Discussion — Discussion is GitHub's forum-style threads, lighter than Issues for Q&A.
- display — display (CSS display) is the CSS display property: how a box participates in layout: block, flex, grid, none, and more.
- Django — Django is a batteries-included Python web framework with an ORM, admin, and auth.
- DNS — DNS (Domain Name System) is the tree that turns names such as digital26.
- Docker — Docker is the common tool for building and running containers from a Dockerfile.
- Dockerfile — Dockerfile is the recipe of FROM, RUN, COPY, and CMD that builds an image.
- DOM — DOM (Document Object Model) is the in-memory tree of a page that JavaScript reads and mutates.
- Domain-driven design — Domain-driven design (DDD) is modeling software around the language of the business, with bounded contexts.
- dotenv — dotenv is a library that loads .
- Draft PR — Draft PR is a pull request marked not ready, so reviewers know it is still in progress.
- DRY — DRY (Don't Repeat Yourself) is avoid duplicating knowledge.
- DTO — DTO (Data Transfer Object) is a shape you send across a boundary, not necessarily your database model.
- duplicate — duplicate is an issue that already exists.
- dynamic import — dynamic import is import() that returns a Promise, the basis of route-level code splitting.
- DynamoDB — DynamoDB is Amazon's managed key-value and document database.
- E2E test — E2E test (end-to-end) is a test that drives the product like a user, often in a real browser.
- Eager load — Eager load is fetching a resource immediately because you know it will be needed.
- EBNF — EBNF (Extended Backus–Naur Form) is a notation for describing the grammar of programming languages and parsers.
- EBS — EBS (Elastic Block Store) is Amazon's network disks for EC2.
- EC2 — EC2 (Elastic Compute Cloud) is Amazon's virtual machines.
- ECDSA — ECDSA is elliptic-curve signatures, smaller keys than RSA for the same strength.
- ECS — ECS (Elastic Container Service) is Amazon's container orchestrator, simpler than EKS for many teams.
- Ed25519 — Ed25519 is a modern signature curve used for SSH keys and many new systems.
- edge function — edge function is a small function that runs at a CDN POP instead of a single region.
- Edge location — Edge location is a CDN or DNS point of presence closer to users than a full region.
- EditorConfig — EditorConfig is a tiny file that aligns indent and line endings across editors.
- EFS — EFS (Elastic File System) is Amazon's managed NFS for many instances at once.
- EKS — EKS (Elastic Kubernetes Service) is Amazon's managed Kubernetes.
- Elasticsearch — Elasticsearch is a search engine for full-text and analytics, often the backend of logs and product search.
- Electron — Electron is Chromium plus Node packaged as a desktop app, used by VS Code, Slack, and many IDEs.
- Elixir — Elixir is a functional language on the Erlang VM used for highly concurrent, fault-tolerant systems such as Phoenix apps.
- embedding — embedding is a vector that represents meaning so you can search by similarity.
- encryption — encryption is turning data into ciphertext you can decrypt with a key.
- endianness — endianness is the byte order of multi-byte numbers: little-endian is what x86 and most ARM use.
- Endpoint — Endpoint is a specific URL plus method that a client can call, such as POST /api/auth/google.
- env var — env var (environment variable) is a key/value the process inherits.
- envelope encryption — envelope encryption is encrypting data with a data key, then encrypting that key with KMS.
- Environment — Environment (GitHub Environment) is a named deploy target with its own secrets and optional reviewers.
- Epic — Epic is a large theme split into many stories.
- Erlang — Erlang is the language behind WhatsApp-scale concurrency, with isolated processes and 'let it crash' supervision.
- Error boundary — Error boundary is a React component that catches render errors below it so the whole app does not white-screen.
- Error budget — Error budget is the amount of unreliability you allow so you can still ship features.
- esbuild — esbuild is an extremely fast bundler and minifier written in Go.
- ESLint — ESLint is the common JS linter, configurable until it hurts.
- ESM — ESM (ECMAScript Modules) is the official name for import/export modules.
- ETag — ETag (Entity Tag) is a fingerprint of a response body used for conditional GET and 304 Not Modified.
- eval — eval (model eval) is a fixed set of tasks you score so prompt or model changes do not silently regress.
- event emitter — event emitter is an object with on and emit, Node's EventEmitter being the classic.
- event loop — event loop is the loop that takes callbacks from queues so JavaScript can be single-threaded and still wait on I/O.
- Event sourcing — Event sourcing is storing every change as an event and rebuilding state by replay.
- EXPLAIN — EXPLAIN is the command that shows a query plan so you can see sequential scans and bad joins.
- exponential backoff — exponential backoff is waiting longer after each retry, often with jitter so clients do not sync.
- Express — Express is the minimal Node HTTP framework most Node APIs still start from.
- extension — extension (editor extension) is a plugin that adds language support, themes, or tools to an editor.
- factory — factory is a function or object that creates other objects so callers do not new the concrete class.
- falsy — falsy is a value that becomes false: false, 0, -0, 0n, '', null, undefined, NaN.
- Fast-forward — Fast-forward is a merge that just moves the branch pointer because there was no divergence.
- FastAPI — FastAPI is a Python API framework with type hints, OpenAPI docs, and async support.
- Fastify — Fastify is a high-performance Node framework with a schema-first plugin model.
- fault tolerance — fault tolerance is continuing to serve when parts fail, through replicas and fallbacks.
- Favicon — Favicon is the small icon in the browser tab, usually a 32px or SVG mark.
- Feature branch — Feature branch is a short-lived branch for one change, opened from main and merged back through a PR.
- Feature flag — Feature flag is a runtime switch that hides unfinished work so you can merge to main safely.
- fetch — fetch is the browser (and Node) API for HTTP that returns Promises and Response objects.
- File — File is a Blob with a name and lastModified, from an input or drop.
- FileReader — FileReader is an older API to read files as text or data URLs.
- filter — filter (CSS filter) is the CSS filter property: graphical effects such as blur and brightness.
- filtering — filtering is narrowing a list by query params or a body.
- Fine-grained token — Fine-grained token is a newer PAT that is limited to selected repos and permissions.
- fine-tune — fine-tune is further training a model on your examples.
- fingerprinting — fingerprinting is putting a content hash in the filename, such as app.
- firewall — firewall is rules that allow or drop packets.
- Fixture — Fixture is known test data you load so assertions are stable.
- fixup — fixup is a commit meant to be squashed into an earlier one during rebase.
- Flaky test — Flaky test is a test that fails without a real product bug, usually timing or shared state.
- Flask — Flask is a tiny Python web framework you grow with extensions.
- flex — flex (CSS flex) is the CSS flex property: the shorthand for grow, shrink, and basis on a flex item.
- flex-direction — flex-direction (CSS flex-direction) is the CSS flex-direction property: the main axis: row or column, optionally reversed.
- flex-wrap — flex-wrap (CSS flex-wrap) is the CSS flex-wrap property: whether flex items wrap to a new line.
- Flexbox — Flexbox (Flexible Box) is a one-dimensional CSS layout for rows or columns, alignment, and wrapping.
- float — float (CSS float) is the CSS float property: an older way to wrap text around a box.
- Flutter — Flutter is Google's UI toolkit that paints its own pixels from Dart, used for mobile and more.
- Fly.io — Fly.io is a platform that runs containers close to users on anycast.
- font — font (CSS font) is the CSS font property: the shorthand for style, weight, size, line-height, and family.
- font-family — font-family (CSS font-family) is the CSS font-family property: the list of typefaces the browser should try.
- font-size — font-size (CSS font-size) is the CSS font-size property: the size of the text.
- font-style — font-style (CSS font-style) is the CSS font-style property: normal, italic, or oblique.
- font-weight — font-weight (CSS font-weight) is the CSS font-weight property: the thickness of the text, 100 to 900 or keywords.
- Force push — Force push is overwriting the remote branch tip.
- Force with lease — Force with lease is a safer force-push that fails if someone else updated the remote since you last fetched.
- Foreign key — Foreign key is a column that points at a primary key in another table, enforcing a relation.
- forensics — forensics is collecting evidence after an incident without trampling the trail.
- Fork — Fork is your server-side copy of someone else's repo so you can push branches and open a pull request back.
- fork network — fork network is the graph of forks GitHub shows under Insights.
- Formatter — Formatter is a tool that rewrites style automatically, such as Prettier or Black.
- FormData — FormData is a set of key/value fields you can send as multipart, including files.
- Forward proxy — Forward proxy is a proxy clients choose so their requests leave through another host.
- FTP — FTP (File Transfer Protocol) is an old file protocol that should not face the modern internet without TLS, and usually not even then.
- gap — gap (CSS gap) is the CSS gap property: gutters between flex or grid items.
- GC — GC (Garbage Collector) is the runtime system that frees memory you no longer reference.
- GCP — GCP (Google Cloud Platform) is Google's cloud, strong in data, Kubernetes, and AI.
- GDPR — GDPR is the EU privacy law that forces lawful basis, access, and deletion rights.
- generator — generator is a function* that can pause with yield and produce a sequence.
- Geolocation API — Geolocation API is asking the user for a location.
- GET — GET is the method that fetches a resource and must not cause side effects you cannot repeat.
- gh — gh (GitHub CLI) is the official command-line for PRs, Issues, and Actions.
- GIN — GIN (Generalized Inverted Index) is a Postgres index type used for arrays, JSONB, and full text.
- Gist — Gist is a lightweight snippet repo for sharing a file or two.
- GiST — GiST (Generalized Search Tree) is a Postgres index family used for geometry and ranges.
- Git — Git is the distributed version-control system that records snapshots of a project so many people can branch, merge, and audit history.
- git add — git add is the command that copies working-tree changes into the index.
- git clean — git clean is removing untracked files.
- git commit — git commit is the command that writes a new snapshot from the index.
- git diff --staged — git diff --staged is seeing what will go into the next commit.
- git fetch — git fetch is downloading remote commits without changing your working tree.
- Git Flow — Git Flow is a heavier branching model with develop, release, and hotfix branches.
- git init — git init is creating a new repository in the current folder.
- git log — git log is reading history.
- git merge — git merge is combining another branch into yours, often creating a merge commit.
- git mv — git mv is renaming a tracked file so Git records it as a rename when it can.
- git pull — git pull is fetch plus integrate: you download remote commits and merge or rebase them into your branch.
- git push — git push is sending local commits to a remote branch.
- git rebase — git rebase is replaying your commits on top of another tip so history looks linear.
- git rebase -i — git rebase -i (interactive rebase) is rewriting a range of commits: squash, reword, reorder, or drop before you push.
- git rm — git rm is removing a tracked file and staging the deletion.
- git show — git show is printing one commit and its diff.
- git status — git status is showing the branch, staged changes, and dirty files.
- GitHub — GitHub is the hosting product for Git repos with pull requests, Issues, Actions, and a social graph of developers.
- GitHub Actions — GitHub Actions is GitHub's CI/CD: YAML workflows that run on events such as push or pull_request.
- GitHub App — GitHub App is an integration that acts as itself, with webhooks and finer permissions than a classic OAuth app.
- GitHub Flow — GitHub Flow is a simple branching model: branch, PR, review, merge to main, deploy.
- GitHub Gists secret — GitHub Gists secret is a gist that is unlisted, not private.
- GitHub Packages — GitHub Packages is GitHub's npm, container, and other package registry.
- GitHub Pages — GitHub Pages is static hosting from a repo branch or Action, used for docs and simple sites.
- GitHub wiki — GitHub wiki is a side Git repo of docs attached to a project.
- GitLab — GitLab is a Git host that also bundles CI, registries, and a full DevOps suite, often self-hosted.
- Go — Go (Golang) is a language from Google designed for simple concurrency, fast compile times, and straightforward backend services.
- good first issue — good first issue is a label meant for newcomers.
- GPL — GPL (GNU General Public License) is a copyleft license that requires sharing source of derivatives under the same terms.
- GPT — GPT (Generative Pre-trained Transformer) is OpenAI's family of decoder transformers, and a casual name people use for any chat model.
- graceful degradation — graceful degradation is keeping core flows alive when a non-critical piece fails.
- Grafana — Grafana is the dashboard layer people put on Prometheus and other datasources.
- grapheme — grapheme is what a user thinks of as one character, which may be several code points.
- GraphQL — GraphQL is a query language where the client asks for the exact JSON shape, sitting on one endpoint instead of many REST routes.
- GraphQL playground — GraphQL playground is an in-browser explorer for a GraphQL schema.
- GraphQL SDL — GraphQL SDL (Schema Definition Language) is the typed schema text that describes GraphQL types, queries, and mutations.
- Greenfield — Greenfield is a new codebase with no production users yet.
- Grid — Grid (CSS Grid) is a two-dimensional CSS layout for rows and columns together.
- grid-column — grid-column (CSS grid-column) is the CSS grid-column property: which column lines an item spans.
- grid-row — grid-row (CSS grid-row) is the CSS grid-row property: which row lines an item spans.
- grid-template-areas — grid-template-areas (CSS grid-template-areas) is the CSS grid-template-areas property: named areas you can place items into.
- grid-template-columns — grid-template-columns (CSS grid-template-columns) is the CSS grid-template-columns property: the track list for columns.
- grid-template-rows — grid-template-rows (CSS grid-template-rows) is the CSS grid-template-rows property: the track list for rows.
- Groovy — Groovy is a JVM scripting language used heavily in Jenkins pipelines.
- gRPC — gRPC is Google's RPC stack on HTTP/2 with Protocol Buffers, common for service-to-service calls.
- guard — guard is a check that decides whether a request may continue, used for auth.
- guardrail — guardrail is filters and policies around a model so it does not dump secrets or unsafe content.
- hallucination — hallucination is a confident false answer.
- Hard reset — Hard reset is moving HEAD and forcing the index and working tree to match, discarding uncommitted work.
- hard wrap — hard wrap is inserting real newlines at a column, common in some commit and email cultures.
- hash — hash is a one-way fingerprint of bytes.
- Haskell — Haskell is a purely functional language used when you want strong types and fewer runtime surprises, often in compilers and finance.
- HATEOAS — HATEOAS is the REST constraint where responses include links to the next actions.
- HEAD — HEAD is like GET but only returns headers, used to check existence or caching without the body.
- HEAD — HEAD is the pointer to the commit you have checked out right now.
- head-of-line blocking — head-of-line blocking is when one lost packet stalls every later message on the same connection.
- Header — Header (HTTP header) is a name/value pair sent with a request or response, such as Content-Type or Authorization.
- heap — heap is the memory region for dynamically allocated objects.
- height — height (CSS height) is the CSS height property: the vertical size of the box.
- Helm — Helm is the package manager for Kubernetes charts.
- help wanted — help wanted is a label that says the maintainers would take an outside PR.
- Heroku — Heroku is the original friendly PaaS.
- hexagonal architecture — hexagonal architecture (ports and adapters) is the domain in the middle, with adapters for HTTP, DB, and queues at the edge.
- high availability — high availability (HA) is designing so planned and unplanned downtime stay inside the SLO.
- HMAC — HMAC (Hash-based Message Authentication Code) is a keyed hash that proves a webhook or cookie was not forged.
- Hoc — Hoc (Higher-Order Component) is a function that takes a component and returns a wrapped one.
- hoisting — hoisting is the way var and function declarations are treated as if they exist for the whole scope.
- Hook — Hook (React Hook) is a function such as useState that lets function components hold state and effects.
- hooks — hooks (Git hooks) is scripts that run on commit, push, and other events, stored in .
- horizontal scaling — horizontal scaling is adding more machines.
- Hot Module Replacement — Hot Module Replacement (HMR) is updating a module in a running dev server without a full reload.
- HSTS — HSTS (HTTP Strict Transport Security) is a header that forces browsers to use HTTPS for a host after the first visit.
- HTML — HTML (HyperText Markup Language) is the markup language that describes the structure of a web page as a tree of elements, not a programming language.
- HTTP — HTTP (Hypertext Transfer Protocol) is the application protocol browsers and APIs use to request and send documents and JSON over TCP, usually via TLS today.
- HTTP 100 — HTTP 100 (Continue) is the Continue status (100): the server got the headers and the client may send the body.
- HTTP 101 — HTTP 101 (Switching Protocols) is the Switching Protocols status (101): the server is switching, for example to a WebSocket.
- HTTP 102 — HTTP 102 (Processing) is the Processing status (102): WebDAV: the server accepted the request and is still working.
- HTTP 103 — HTTP 103 (Early Hints) is the Early Hints status (103): the server is sending preload hints before the final response.
- HTTP 200 — HTTP 200 (OK) is the OK status (200): the request succeeded and the body is the result.
- HTTP 201 — HTTP 201 (Created) is the Created status (201): a new resource exists, usually after POST.
- HTTP 202 — HTTP 202 (Accepted) is the Accepted status (202): the work is queued, not finished.
- HTTP 203 — HTTP 203 (Non-Authoritative Information) is the Non-Authoritative Information status (203): the payload was transformed by a proxy.
- HTTP 204 — HTTP 204 (No Content) is the No Content status (204): success with an empty body, common after DELETE.
- HTTP 205 — HTTP 205 (Reset Content) is the Reset Content status (205): success; the client should reset the form.
- HTTP 206 — HTTP 206 (Partial Content) is the Partial Content status (206): a range request succeeded, used for media seeking.
- HTTP 207 — HTTP 207 (Multi-Status) is the Multi-Status status (207): WebDAV: the body lists several status results.
- HTTP 208 — HTTP 208 (Already Reported) is the Already Reported status (208): WebDAV: members were already listed in a DAV binding.
- HTTP 226 — HTTP 226 (IM Used) is the IM Used status (226): the response is a delta from an instance manipulation.
- HTTP 300 — HTTP 300 (Multiple Choices) is the Multiple Choices status (300): there are several representations the client could pick.
- HTTP 301 — HTTP 301 (Moved Permanently) is the Moved Permanently status (301): update your links; the resource lives at a new URL.
- HTTP 302 — HTTP 302 (Found) is the Found status (302): a temporary redirect.
- HTTP 303 — HTTP 303 (See Other) is the See Other status (303): redirect the client to GET another URL, typical after a POST.
- HTTP 304 — HTTP 304 (Not Modified) is the Not Modified status (304): the cached copy is still good; no body is sent.
- HTTP 307 — HTTP 307 (Temporary Redirect) is the Temporary Redirect status (307): redirect but keep the original method.
- HTTP 308 — HTTP 308 (Permanent Redirect) is the Permanent Redirect status (308): permanent, and keep the original method.
- HTTP 400 — HTTP 400 (Bad Request) is the Bad Request status (400): the server cannot parse or accept the request as sent.
- HTTP 401 — HTTP 401 (Unauthorized) is the Unauthorized status (401): you need to authenticate.
- HTTP 402 — HTTP 402 (Payment Required) is the Payment Required status (402): reserved for digital payments; few public APIs use it.
- HTTP 403 — HTTP 403 (Forbidden) is the Forbidden status (403): the server knows you and still refuses.
- HTTP 404 — HTTP 404 (Not Found) is the Not Found status (404): no resource at this URL, or the server does not want to admit it exists.
- HTTP 405 — HTTP 405 (Method Not Allowed) is the Method Not Allowed status (405): the URL exists but not for this verb.
- HTTP 406 — HTTP 406 (Not Acceptable) is the Not Acceptable status (406): the server cannot produce a type listed in Accept.
- HTTP 407 — HTTP 407 (Proxy Authentication Required) is the Proxy Authentication Required status (407): authenticate to the proxy first.
- HTTP 408 — HTTP 408 (Request Timeout) is the Request Timeout status (408): the server closed an idle incoming request.
- HTTP 409 — HTTP 409 (Conflict) is the Conflict status (409): the current state does not allow this change, such as a duplicate apply.
- HTTP 410 — HTTP 410 (Gone) is the Gone status (410): the resource used to exist and will not come back.
- HTTP 411 — HTTP 411 (Length Required) is the Length Required status (411): send a Content-Length.
- HTTP 412 — HTTP 412 (Precondition Failed) is the Precondition Failed status (412): an If-Match or similar header was not satisfied.
- HTTP 413 — HTTP 413 (Content Too Large) is the Content Too Large status (413): the body is bigger than the server will accept.
- HTTP 414 — HTTP 414 (URI Too Long) is the URI Too Long status (414): the URL itself is too big, often a GET that should have been POST.
- HTTP 415 — HTTP 415 (Unsupported Media Type) is the Unsupported Media Type status (415): the Content-Type is not one the server handles.
- HTTP 416 — HTTP 416 (Range Not Satisfiable) is the Range Not Satisfiable status (416): the requested byte range is outside the resource.
- HTTP 417 — HTTP 417 (Expectation Failed) is the Expectation Failed status (417): the Expect header cannot be met.
- HTTP 418 — HTTP 418 (I'm a teapot) is the I'm a teapot status (418): an April Fools code people still use as an easter egg.
- HTTP 421 — HTTP 421 (Misdirected Request) is the Misdirected Request status (421): the request was sent to a server that cannot produce a response.
- HTTP 422 — HTTP 422 (Unprocessable Content) is the Unprocessable Content status (422): JSON parsed but the values failed validation.
- HTTP 423 — HTTP 423 (Locked) is the Locked status (423): WebDAV: the resource is locked.
- HTTP 424 — HTTP 424 (Failed Dependency) is the Failed Dependency status (424): WebDAV: a previous request in the set failed.
- HTTP 425 — HTTP 425 (Too Early) is the Too Early status (425): the server refuses to process a request that might be replayed.
- HTTP 426 — HTTP 426 (Upgrade Required) is the Upgrade Required status (426): the client should switch protocols.
- HTTP 428 — HTTP 428 (Precondition Required) is the Precondition Required status (428): the server wants If-Match to avoid lost updates.
- HTTP 429 — HTTP 429 (Too Many Requests) is the Too Many Requests status (429): you hit a rate limit.
- HTTP 431 — HTTP 431 (Request Header Fields Too Large) is the Request Header Fields Too Large status (431): headers, cookies, or the URL blew a size cap.
- HTTP 451 — HTTP 451 (Unavailable For Legal Reasons) is the Unavailable For Legal Reasons status (451): the resource is blocked by law.
- HTTP 500 — HTTP 500 (Internal Server Error) is the Internal Server Error status (500): the server threw.
- HTTP 501 — HTTP 501 (Not Implemented) is the Not Implemented status (501): the method or feature is not supported.
- HTTP 502 — HTTP 502 (Bad Gateway) is the Bad Gateway status (502): a proxy got an invalid response from upstream.
- HTTP 503 — HTTP 503 (Service Unavailable) is the Service Unavailable status (503): overloaded or down for maintenance.
- HTTP 504 — HTTP 504 (Gateway Timeout) is the Gateway Timeout status (504): a proxy waited too long for upstream.
- HTTP 505 — HTTP 505 (HTTP Version Not Supported) is the HTTP Version Not Supported status (505): the server refuses that HTTP version.
- HTTP 506 — HTTP 506 (Variant Also Negotiates) is the Variant Also Negotiates status (506): a misconfigured content negotiation loop.
- HTTP 507 — HTTP 507 (Insufficient Storage) is the Insufficient Storage status (507): WebDAV: the server cannot store the representation.
- HTTP 508 — HTTP 508 (Loop Detected) is the Loop Detected status (508): WebDAV: an infinite loop while processing.
- HTTP 510 — HTTP 510 (Not Extended) is the Not Extended status (510): the request needs an HTTP extension the server does not have.
- HTTP 511 — HTTP 511 (Network Authentication Required) is the Network Authentication Required status (511): a captive portal wants you to log in to the network.
- HTTP/2 — HTTP/2 is a binary multiplexed revision of HTTP that sends many streams on one connection, reducing handshake waste.
- HTTP/3 — HTTP/3 is HTTP running on QUIC and UDP so lost packets hurt one stream instead of stalling the whole connection.
- HttpOnly — HttpOnly is a cookie flag that hides the cookie from JavaScript so XSS cannot steal it as easily.
- HTTPS — HTTPS (HTTP Secure) is HTTP wrapped in TLS so the path is encrypted and the server can present a certificate.
- hub — hub is an older community CLI that wrapped git with GitHub commands.
- Husky — Husky is Git hook helper people use to run lint-staged before commit.
- Hydration — Hydration is attaching event handlers to server-rendered HTML so it becomes an interactive app.
- hyphens — hyphens (CSS hyphens) is the CSS hyphens property: automatic hyphenation, locale-aware when lang is set.
- i18n — i18n (Internationalization) is designing software so it can be translated and adapted to locales without rewriting logic.
- IaC — IaC (Infrastructure as Code) is storing servers, DNS, and policies in Git instead of clicking consoles.
- IAM — IAM (Identity and Access Management) is the users, roles, and policies that decide who can call which cloud API.
- ICE — ICE (Interactive Connectivity Establishment) is the WebRTC process that tries STUN and TURN candidates until a path works.
- Idempotency key — Idempotency key is a client-chosen token so retries of a payment or create do not double-charge.
- Idempotent — Idempotent is a request you can send twice with the same effect as once, which is why PUT and DELETE can be retried.
- IDOR — IDOR (Insecure Direct Object Reference) is changing an id in a URL or body and seeing someone else's record.
- IIFE — IIFE (Immediately Invoked Function Expression) is a function you run as you define it, used before modules to hide scope.
- Image — Image (container image) is the immutable snapshot a container starts from.
- IMAP — IMAP (Internet Message Access Protocol) is the protocol mail apps use to read a mailbox that stays on the server.
- immutability — immutability is updating data by creating new values instead of mutating old ones, which makes renders and undo easier.
- immutable cache — immutable cache is caching a fingerprinted file forever, because the URL changes when the bytes change.
- import maps — import maps is a browser feature that maps bare specifiers to URLs so ESM can run without a bundler.
- Incident — Incident is an unplanned production problem that needs a coordinated response.
- Index — Index (database index) is a side structure that makes lookups on a column fast, at the cost of write time and space.
- IndexedDB — IndexedDB is a structured client database for larger offline data.
- Ingress — Ingress is the Kubernetes object that routes HTTP from the outside to services.
- Insomnia — Insomnia is another HTTP GUI used for API design and requests.
- Integration test — Integration test is a test that exercises several real pieces together, such as API plus database.
- IntelliSense — IntelliSense is the product name for rich completions in VS Code and Visual Studio.
- interceptor — interceptor is middleware by another name, common in HTTP clients and NestJS.
- interface segregation — interface segregation is do not force clients to depend on methods they do not use.
- interpreter — interpreter is a program that executes source or bytecode directly.
- Intersection Observer — Intersection Observer is watching when an element enters the viewport, used for lazy load and analytics.
- IPv4 — IPv4 is the 32-bit address family, still what most people mean by an IP.
- IPv6 — IPv6 is the 128-bit address family that exists because IPv4 ran out.
- isolation — isolation (CSS isolation) is the CSS isolation property: whether the box creates a stacking context, useful with mix-blend-mode.
- Isolation level — Isolation level is how much a transaction can see of other in-flight work, from read uncommitted to serializable.
- ISR — ISR (Incremental Static Regeneration) is regenerating a static page in the background after a TTL so you keep CDN speed with fresher data.
- Issue — Issue is a tracked bug, task, or discussion thread on a GitHub repo.
- iterable — iterable is an object you can for-of, such as arrays, maps, and strings.
- iterator — iterator is an object with next() that produces { value, done }.
- IV — IV (Initialization Vector) is the starting value for a block cipher mode.
- Java — Java is a statically typed language that runs on the JVM and still powers a large share of enterprise backends and Android.
- JavaScript — JavaScript (JS) is the language of the web browser and of most modern frontend toolchains, now also common on servers through Node and similar runtimes.
- JavaScriptCore — JavaScriptCore (JSC) is Apple's JavaScript engine in Safari.
- JIT — JIT (Just-In-Time compilation) is compiling hot code at runtime, which is how V8 gets fast.
- jitter — jitter is variation in latency, painful for calls and games.
- Job — Job is a set of steps that run on one runner inside a workflow.
- JSON — JSON (JavaScript Object Notation) is a text format for nested objects and arrays that APIs and config files use everywhere.
- JSON-LD — JSON-LD is structured data in a script tag that search engines use for rich results.
- JSON.parse — JSON.parse is turning a JSON string into a value.
- JSON.stringify — JSON.stringify is turning a value into a JSON string.
- JSONB — JSONB is Postgres's binary JSON type that can be indexed and queried.
- JSX — JSX (JavaScript XML) is the HTML-like syntax React compiles into element trees inside JavaScript.
- justify-content — justify-content (CSS justify-content) is the CSS justify-content property: alignment along the main axis.
- JVM — JVM (Java Virtual Machine) is the process that runs compiled Java bytecode and many other languages that target the same portable machine.
- JWT — JWT (JSON Web Token) is a signed (and sometimes encrypted) token that carries claims such as user id and expiry so APIs can trust a bearer without a server session store.
- Kafka — Kafka is a durable log for event streams that many services can read at their own pace.
- Kanban — Kanban is a flow board with work-in-progress limits instead of fixed sprints.
- kernel — kernel is the core of the OS that talks to hardware and schedules processes.
- Key — Key (React key) is the stable id React uses to match list items across renders.
- kibibyte — kibibyte (KiB) is 1024 bytes.
- KISS — KISS (Keep It Simple, Stupid) is prefer the design you can explain on a whiteboard.
- KMS — KMS (Key Management Service) is a cloud service that holds encryption keys and performs encrypt/decrypt.
- Koa — Koa is a slimmer Express successor from the same people, built on async middleware.
- Kotlin — Kotlin is a JVM language that is the default for modern Android and also used for multiplatform and backend work.
- KPI — KPI (Key Performance Indicator) is a number leadership watches, sometimes too hard.
- Kubernetes — Kubernetes (K8s) is the orchestrator that schedules containers across machines, with services, probes, and rolling updates.
- l10n — l10n (Localization) is the actual translation and locale data for one market.
- Label — Label is a colored tag on Issues and PRs such as bug, docs, or good first issue.
- Lambda — Lambda (AWS Lambda) is Amazon's function-as-a-service: upload code, get an HTTP or event trigger.
- Laravel — Laravel is the dominant PHP framework for elegant MVC apps and APIs.
- latency — latency is how long one request waits before the first useful byte.
- Lazy load — Lazy load is waiting to fetch an image, route, or script until it is near the viewport or requested.
- Least privilege — Least privilege is giving a user or token only the access it needs for the job.
- left — left (CSS left) is the CSS left property: the inset from the left edge when the box is positioned.
- Legacy — Legacy is code that still earns money and scares the team.
- Less — Less is another CSS preprocessor still found in older Ant Design and admin themes.
- Let's Encrypt — Let's Encrypt is the free automated CA that made HTTPS normal on small sites.
- letter-spacing — letter-spacing (CSS letter-spacing) is the CSS letter-spacing property: extra space between characters.
- lexer — lexer (tokenizer) is the first pass that splits source into tokens.
- LF — LF is Unix line endings.
- LFS — LFS (Git Large File Storage) is an extension that stores large binaries outside the normal Git object store.
- LICENSE — LICENSE is the file that states how other people may use the code.
- LICENSE SPDX — LICENSE SPDX is a short identifier such as MIT or Apache-2.
- line-height — line-height (CSS line-height) is the CSS line-height property: the height of a line box, the main tool for readable paragraphs.
- Lint — Lint is a static check for style and obvious mistakes, such as ESLint or Ruff.
- lint-staged — lint-staged is running linters only on staged files so hooks stay fast.
- Linux — Linux is the kernel (and the family of OSes) that runs most servers and Android.
- Liskov substitution — Liskov substitution is subtypes must be usable wherever the parent type is expected.
- list-style — list-style (CSS list-style) is the CSS list-style property: the marker of a list.
- LLM — LLM (Large Language Model) is a neural net trained to predict the next token, the engine behind ChatGPT, Claude, and most vibe-coding tools.
- Load balancer — Load balancer is a service that spreads incoming connections across many app instances.
- localhost — localhost is the loopback name for this machine, usually 127.
- localStorage — localStorage is a synchronous origin-scoped string store that lasts across visits.
- lock — lock is any mechanism that serializes access to shared state.
- lockfile — lockfile is the file that pins exact versions, such as package-lock.
- lockfile poisoning — lockfile poisoning is changing resolved versions in a lockfile so CI installs a hostile package.
- Logging — Logging is append-only records of what the process did, ideally structured JSON.
- LSP — LSP (Language Server Protocol) is the protocol that lets one language service power many editors with completions and diagnostics.
- Lua — Lua is a small embeddable language used in games, Nginx, Redis, and Neovim configuration.
- macOS — macOS is Apple's desktop OS, the common laptop for many web developers.
- main — main is the modern default branch name, replacing master in most new repos.
- Map — Map is a key/value collection that accepts any key type and keeps insertion order.
- margin — margin (CSS margin) is the CSS margin property: space outside the border.
- Markdown — Markdown (MD) is a lightweight markup for README files, issues, and docs that GitHub renders in the browser.
- Marketplace — Marketplace (GitHub Marketplace) is the catalog of Actions and apps you can add to a repo.
- mask — mask (CSS mask) is the CSS mask property: an image or gradient that controls which parts of the box are visible.
- mass assignment — mass assignment is binding a request body straight onto a model so attackers set role=admin.
- master — master is the historical default branch name, still present in older repos.
- materialized view — materialized view is a stored query whose result is cached on disk and refreshed on a schedule.
- max-height — max-height (CSS max-height) is the CSS max-height property: the largest height the box will grow to.
- max-width — max-width (CSS max-width) is the CSS max-width property: the largest width the box will grow to.
- MCP — MCP (Model Context Protocol) is a standard for exposing tools and data to AI apps, used in Cursor and other IDEs.
- MD5 — MD5 is a broken hash.
- MDX — MDX is Markdown that can include JSX components, used in modern doc sites.
- memoize — memoize is caching a function's result for the same arguments.
- memory leak — memory leak is retaining objects you no longer need, so memory grows until the tab dies.
- Mention — Mention is typing @username so GitHub notifies that person.
- Merge conflict — Merge conflict is when two commits changed the same lines and Git refuses to guess, so a human must edit the file.
- Merge queue — Merge queue is GitHub's lineup that rebases PRs onto the latest main before merge to keep CI honest.
- Merge request — Merge request (MR) is GitLab's name for a pull request.
- Metric — Metric is a number over time, such as request rate, error rate, or CPU.
- MFA — MFA (Multi-Factor Authentication) is the broader name for 2FA and stronger combinations.
- Microservice — Microservice is a separately deployable service that owns a slice of the domain and talks over the network.
- microtask — microtask is a job that runs after the current stack and before the next paint, such as Promise then-callbacks.
- middleware — middleware is a function that sits in a pipeline, such as Express or Next middleware, and can pass or stop a request.
- Migration — Migration is a versioned change to the database schema, applied in order across environments.
- Milestone — Milestone is a grouping of Issues and PRs toward a date or version.
- min-height — min-height (CSS min-height) is the CSS min-height property: the smallest height the box will shrink to.
- min-width — min-width (CSS min-width) is the CSS min-width property: the smallest width the box will shrink to.
- Minify — Minify is stripping comments and shortening names so files are smaller, not more secret.
- minimal reproduction — minimal reproduction is a tiny repo that fails, not your whole monorepo.
- MIT license — MIT license is a short permissive license.
- mix-blend-mode — mix-blend-mode (CSS mix-blend-mode) is the CSS mix-blend-mode property: how the box blends with what is behind it.
- mixed content — mixed content is an HTTPS page loading HTTP scripts or images.
- Mixed reset — Mixed reset is moving HEAD and clearing the index, leaving changes unstaged.
- Mob programming — Mob programming is the whole team at one problem, rotating the driver.
- Mobile-first — Mobile-first is writing the small-screen CSS as the default and adding complexity at larger breakpoints.
- Mock — Mock is a fake collaborator that records calls so you can assert interactions.
- Modular monolith — Modular monolith is a single process with hard internal boundaries, often the right step before microservices.
- module — module (ES module) is a file with import and export, the standard way to split JS.
- MongoDB — MongoDB is a document database that stores JSON-like BSON and scales out with replica sets and shards.
- Monolith — Monolith is one deployable that holds many features.
- Monorepo — Monorepo is one repository that holds many packages or apps, with shared tooling.
- MPA — MPA (Multi-Page Application) is the classic model where each URL is a full document from the server.
- mTLS — mTLS (mutual TLS) is both client and server present certificates, common between services.
- Mutation Observer — Mutation Observer is watching the DOM for additions and attribute changes.
- mutex — mutex is a lock only one thread can hold.
- MVC — MVC (Model View Controller) is the classic split: data, presentation, and the glue that handles input.
- MVP — MVP (Minimum Viable Product) is the smallest thing you can put in front of users to learn if the idea is real.
- MVP pattern — MVP pattern (Model View Presenter) is another UI split where a presenter updates a passive view.
- MVVM — MVVM (Model View ViewModel) is a UI split common on mobile and in some web stacks.
- MX record — MX record is the DNS record that says which hosts receive mail for a domain.
- MySQL — MySQL is the other widely hosted relational database, common on shared hosts and older LAMP stacks.
- n-day — n-day is a known vuln you have not patched.
- N+1 query — N+1 query is fetching a list, then running one extra query per row instead of a join or include.
- Nameserver — Nameserver is the server that answers DNS queries for a zone.
- NaN — NaN (Not a Number) is the IEEE result of invalid math.
- NAT — NAT (Network Address Translation) is rewriting private addresses so many devices share one public IP.
- NestJS — NestJS is an opinionated Node framework that feels like Angular on the server.
- Netlify — Netlify is a JAMstack host with Git deploys, functions, and forms.
- Next.js — Next.js is the React meta-framework for routing, SSR, SSG, and API routes, widely used on Vercel.
- NFS — NFS (Network File System) is a protocol for mounting a remote filesystem.
- Node.js — Node.js (Node) is a JavaScript runtime built on V8 that lets you run JS on servers, CLIs, and build tools.
- nonce — nonce is a number used once with a key so two encryptions of the same text do not match.
- Normalization — Normalization is structuring tables so each fact lives in one place, reducing update anomalies.
- normalization — normalization (Unicode normalization) is canonicalizing equivalent Unicode sequences so comparisons work.
- NoSQL — NoSQL (Not Only SQL) is a family of databases that store documents, key-value pairs, graphs, or wide columns instead of rigid tables.
- Notification API — Notification API is system notifications after the user grants permission.
- npm — npm is Node's default package manager and the public registry at registry.
- npm publish — npm publish is putting a package on the registry.
- npx — npx is npm's runner that executes a package without a global install.
- NS record — NS record is the DNS record that names the authoritative name servers for a zone.
- null — null is the intentional empty reference.
- nullish coalescing — nullish coalescing is the ?
- Nuxt — Nuxt is the Vue meta-framework equivalent of Next for server-rendered and static Vue apps.
- OAuth — OAuth (Open Authorization) is a delegation protocol so a user can let an app act on their behalf without sharing their password.
- OAuth 2.0 — OAuth 2.0 is the current OAuth family used by Google, GitHub, and most 'Sign in with' buttons.
- OAuth app — OAuth app is a GitHub app that users authorize to act with their scopes.
- Object storage — Object storage is files addressed by key, not a POSIX disk, such as S3.
- Object URL — Object URL is a blob: URL created with URL.
- object-fit — object-fit (CSS object-fit) is the CSS object-fit property: how replaced content such as img fills its box.
- object-position — object-position (CSS object-position) is the CSS object-position property: the anchor of that fitted content.
- Objective-C — Objective-C is Apple's previous main language, still present in older iOS codebases next to Swift.
- Observability — Observability is being able to ask new questions about a live system using logs, metrics, and traces.
- observer — observer is a publish/subscribe relationship, the ancestor of event emitters and reactive stores.
- OCSP — OCSP (Online Certificate Status Protocol) is a live check of whether a certificate was revoked.
- Octokit — Octokit is the official client libraries for the GitHub API.
- offset pagination — offset pagination is paging with OFFSET and LIMIT.
- OIDC — OIDC (OpenID Connect) is an identity layer on OAuth 2.
- OKR — OKR (Objectives and Key Results) is a goal format: qualitative objective, measurable key results.
- On-call — On-call is the rotation of humans who get paged when production breaks at 3 a.
- Onboarding — Onboarding is the path that gets a new person productive: access, docs, first PR.
- opacity — opacity (CSS opacity) is the CSS opacity property: how opaque the whole box including children is, from 0 to 1.
- Open Graph — Open Graph (OG) is meta tags that control the title, description, and image when a link is shared.
- open redirect — open redirect is a redirect that takes a user-controlled URL, used in phishing.
- open-closed principle — open-closed principle is open for extension, closed for modification, usually via interfaces.
- OpenAPI — OpenAPI (Swagger) is the standard YAML/JSON description of an HTTP API, used to generate docs and clients.
- OpenTelemetry — OpenTelemetry (OTel) is the vendor-neutral standard for traces, metrics, and logs.
- optional chaining — optional chaining is the ?
- OPTIONS — OPTIONS is the method browsers send for CORS preflights and that APIs use to advertise allowed methods.
- Origin — Origin is the conventional name of the primary remote.
- origin server — origin server is the server the CDN fetches from when the edge does not have the object.
- ORM — ORM (Object-Relational Mapping) is a layer that lets you work with tables as objects and relations instead of raw SQL.
- ORM impedance mismatch — ORM impedance mismatch is the friction between objects in memory and tables in a database.
- ORM migration drift — ORM migration drift is when the live database no longer matches the migration history.
- Outdated comment — Outdated comment is a review comment on a line that later commits changed.
- outline — outline (CSS outline) is the CSS outline property: a line outside the border that does not take layout space, used for focus.
- overflow — overflow (CSS overflow) is the CSS overflow property: what happens when content does not fit: visible, hidden, auto, or clip.
- overflow-x — overflow-x (CSS overflow-x) is the CSS overflow-x property: horizontal overflow behavior.
- overflow-y — overflow-y (CSS overflow-y) is the CSS overflow-y property: vertical overflow behavior.
- overscroll-behavior — overscroll-behavior (CSS overscroll-behavior) is the CSS overscroll-behavior property: whether scroll chaining to the parent is allowed.
- OWASP — OWASP (Open Worldwide Application Security Project) is the community behind the Top 10 and a lot of practical app-sec guidance.
- OWASP Top 10 — OWASP Top 10 is the widely cited list of the most common web app risks.
- package.json — package.json is the manifest of a Node project: name, scripts, and dependencies.
- packet loss — packet loss is datagrams that never arrive.
- padding — padding (CSS padding) is the CSS padding property: space inside the border, around the content.
- pagination — pagination is splitting a list into pages with limit/offset or cursors.
- Pair programming — Pair programming is two people at one problem, often one driving the keyboard.
- parser — parser is the program that turns text into a structured tree.
- partial clone — partial clone is cloning without every blob, then fetching on demand.
- Partition — Partition is splitting one table into pieces by range or hash while still querying it as one.
- Passkey — Passkey is a phishing-resistant credential stored on a device or password manager, based on WebAuthn.
- password hash — password hash is a one-way transform of a password, ideally with a slow algorithm such as bcrypt, scrypt, or Argon2.
- PATCH — PATCH is the method that applies a partial update to a resource.
- Patch — Patch is a diff formatted so it can be applied elsewhere, including GitHub suggestion blocks.
- patch Tuesday — patch Tuesday is Microsoft's monthly patch drop, and a reminder that updates are a process.
- PATH — PATH is the list of directories the shell searches for commands.
- Path parameter — Path parameter is a variable segment in a route such as /users/:id.
- path traversal — path traversal is using .
- Payload — Payload is the body of a request or response, usually JSON, that carries the actual data.
- peer dependency — peer dependency is a package the host app must provide, common for React plugins.
- penetration test — penetration test (pentest) is a time-boxed authorized attack with a report.
- pepper — pepper is a secret mixed into hashes and stored apart from the database.
- Perl — Perl is an older text-processing language that still appears in sysadmin scripts and legacy CGI.
- Permalink — Permalink is a URL that is meant to stay stable so other people can cite it later.
- permalink line — permalink line is pressing Y on a file to lock the URL to a commit so line comments stay valid.
- permissive license — permissive license is MIT, BSD, Apache: few restrictions beyond attribution.
- Personal access token — Personal access token (PAT) is a GitHub token you generate for HTTPS Git and APIs.
- phishing — phishing is tricking a human into giving a secret or clicking a bad link.
- PHP — PHP (PHP: Hypertext Preprocessor) is a server language that still runs a huge fraction of the web, including WordPress, Laravel, and many host-shared sites.
- PID — PID (Process ID) is the number the OS assigns to a process.
- PII — PII (Personally Identifiable Information) is data that can identify a person.
- pinning — pinning (certificate pinning) is hard-coding which certs a client will accept.
- Pipeline — Pipeline is the sequence of CI/CD jobs from lint to test to deploy.
- PITR — PITR (Point-In-Time Recovery) is restoring a database to a specific moment using a base backup plus WAL.
- PKI — PKI (Public Key Infrastructure) is the CAs, certificates, and revocation that make TLS identities work.
- place-items — place-items (CSS place-items) is the CSS place-items property: align-items plus justify-items.
- Playbook — Playbook is a broader documented way of working, not only for outages.
- pnpm — pnpm is a package manager that shares a content store and is strict about the dependency tree.
- Pod — Pod is the smallest Kubernetes unit: one or more containers that share network and storage.
- pointer — pointer is an address of a value in memory, first-class in C and hidden in managed languages.
- pointer-events — pointer-events (CSS pointer-events) is the CSS pointer-events property: whether the box can be the target of pointer hits.
- Polyfill — Polyfill is code that implements a modern API on older browsers.
- Polyrepo — Polyrepo is the opposite of a monorepo: each service or package has its own repository.
- POP3 — POP3 is an older mail-download protocol that often deletes mail from the server.
- port — port is a 16-bit number that multiplexes TCP or UDP on a host, such as 443.
- Portal — Portal is rendering a React tree into a DOM node outside the parent, used for modals and nav bars.
- position — position (CSS position) is the CSS position property: the positioning scheme: static, relative, absolute, fixed, or sticky.
- POSIX — POSIX is the family of Unix APIs for files, processes, and threads.
- POST — POST is the method that submits a new action or resource, not safe and not always idempotent.
- PostCSS — PostCSS is a CSS transformer that Autoprefixer and Tailwind sit on.
- Postgres — Postgres (PostgreSQL) is a powerful open-source relational database with JSON, full text, and serious SQL.
- Postman — Postman is a GUI for sending HTTP requests and sharing collections.
- Postmortem — Postmortem (incident review) is the write-up of what failed, what you changed, and how you will prevent a repeat.
- PowerShell — PowerShell is a Microsoft shell and scripting language that treats command output as objects, not only text.
- pre-commit — pre-commit is a hook that runs before a commit is created.
- pre-push — pre-push is a hook that runs before a push.
- Preconnect — Preconnect is opening DNS, TCP, and TLS to a host before you actually request a file.
- Prefetch — Prefetch is hinting the browser to download a likely next resource in spare time.
- Preload — Preload is telling the browser a resource is needed for this navigation, with high priority.
- Prepared statement — Prepared statement is a query with placeholders so user values cannot change the SQL shape.
- Prettier — Prettier is the common JS/TS formatter.
- Primary — Primary (leader) is the database instance that accepts writes in a replicated setup.
- Primary key — Primary key is the column or set of columns that uniquely identifies a row.
- principle of least astonishment — principle of least astonishment is software should behave the way a careful user expects.
- Prisma — Prisma is a TypeScript ORM with a declarative schema and generated client.
- private package — private package is a package you do not publish publicly.
- privilege escalation — privilege escalation is a user or bug gaining rights they should not have.
- process — process is an OS instance of a running program with its own memory.
- progressive enhancement — progressive enhancement is starting with a working HTML page and adding JS, not the other way around.
- Project — Project (GitHub Projects) is GitHub's kanban or table for planning Issues and PRs.
- projection — projection is selecting only the fields a client needs.
- Prometheus — Prometheus is a pull-based metrics system with a time-series database and Alertmanager.
- Promise — Promise is an object that represents a future value, the foundation of async JavaScript.
- prompt — prompt is the text you give a model.
- prompt engineering — prompt engineering is writing specs, examples, and constraints so a model produces usable work.
- proprietary — proprietary is code you may not use without a separate grant.
- Props — Props is the inputs a component receives from its parent.
- Protected branch — Protected branch is a branch with rules so casual pushes cannot land.
- prototype — prototype is the object JavaScript walks when a property is missing on the instance.
- prototype pollution — prototype pollution is writing to Object.
- provenance — provenance is signed metadata about how an artifact was built, so you can refuse mystery binaries.
- Proxy — Proxy is an object that intercepts operations, used by Vue's reactivity and some ORMs.
- pub/sub — pub/sub (publish/subscribe) is publishers emit events, subscribers listen, without knowing each other.
- Pull request — Pull request (PR) is GitHub's review unit: a branch asking to merge into another, with discussion and checks.
- pure function — pure function is a function that does not mutate the outside world and returns the same output for the same input.
- purple team — purple team is red and blue working together on the same exercise.
- PUT — PUT is the method that replaces a resource at a URL, meant to be idempotent.
- PWA — PWA (Progressive Web App) is a website that can be installed, work offline, and feel like an app using a service worker and manifest.
- Python — Python is a high-level language used for scripts, APIs, data work, and AI glue, famous for readable syntax and a huge package index.
- query plan — query plan is the steps the database chose to run a statement.
- Query string — Query string is the part of a URL after ?
- Queue — Queue is a list of work items consumers pull so producers do not wait on slow jobs.
- QUIC — QUIC is a UDP-based transport that TLS 1.
- R — R is a language built for statistics and plots, still standard in research and some data-science teams.
- R2 — R2 is Cloudflare's S3-compatible object store with no egress fees to the internet.
- RabbitMQ — RabbitMQ is a message broker that routes jobs and events with queues and exchanges.
- race condition — race condition is a bug that depends on timing.
- RAG — RAG (Retrieval-Augmented Generation) is fetching documents and stuffing them into the prompt so the model can cite real files.
- Rails — Rails (Ruby on Rails) is the convention-over-configuration framework that defined modern MVC web apps.
- Railway — Railway is a PaaS aimed at fast app and database deploys.
- rainbow table — rainbow table is a precomputed map of hashes to passwords, defeated by unique salts.
- Rate limit — Rate limit is a cap on how many requests a client may make in a window so one user cannot starve everyone else.
- raw file — raw file is the unrendered file bytes, useful when a README widget lies.
- RCE — RCE (Remote Code Execution) is an attacker running their code on your machine.
- RDS — RDS (Relational Database Service) is Amazon's managed relational databases.
- React — React is a UI library that renders components as functions of state and props, now the default mental model for many web apps.
- React Native — React Native is React for iOS and Android, bridging to native views.
- README — README is the first document GitHub shows on a repo.
- Rebase and merge — Rebase and merge is a GitHub merge style that replays PR commits onto the base without a merge commit.
- Reconciliation — Reconciliation is React's process of diffing trees and applying DOM updates.
- red team — red team is people paid to attack you so you find holes first.
- Redirect — Redirect is an HTTP response that tells the client to request a different URL, with 301, 302, 307, or 308.
- Redis — Redis is an in-memory store used for caches, queues, rate limits, and sessions.
- ReDoS — ReDoS (Regular Expression Denial of Service) is a regex that explodes on certain strings and pins the CPU.
- Redux — Redux is a predictable state container that became the default React global store for years.
- Refactor — Refactor is changing structure without changing behavior, so the next change is safer.
- Reflect — Reflect is a built-in of default object operations, the pair of Proxy traps.
- Reflog — Reflog is Git's local diary of where HEAD has been, the usual way to recover a 'lost' commit.
- Reflow — Reflow is the browser recalculating layout after DOM or CSS changes, which is expensive if you do it in a loop.
- RegEx — RegEx (Regular Expression) is a pattern language for matching and extracting text, powerful and easy to get catastrophically wrong.
- Region — Region is a geographic cluster of availability zones.
- Registrar — Registrar is the company that sells you the domain and talks to the registry.
- Registry — Registry is a store for images or packages, such as Docker Hub, GHCR, or npm.
- Regression — Regression is a bug that came back after a change.
- Relay — Relay is Facebook's GraphQL client with a strict fragment and cache model.
- Release — Release is a GitHub object around a tag, with notes and downloadable assets.
- release please — release please is Google's Action that opens release PRs from conventional commits.
- Remix — Remix is a React framework that leans on web standards, nested routes, and progressive enhancement.
- Remote — Remote is a named copy of the repo on another machine, usually origin on GitHub.
- Render — Render is a simpler PaaS for web services, workers, and Postgres.
- Render props — Render props is a pattern that shares code by passing a function as a child.
- Repaint — Repaint is the browser redrawing pixels without changing layout, cheaper than reflow but still not free.
- Replica — Replica (read replica) is a copy of the database that serves reads so the primary can focus on writes.
- Repository — Repository (repo) is a Git project: the working files plus the .
- repository — repository is the object that loads and saves domain objects.
- repository pattern — repository pattern is hiding storage behind an interface so the domain does not import SQL.
- repro — repro (reproduction) is the smallest steps or repo that shows the bug.
- Request changes — Request changes is a review state that blocks merge until the author addresses the feedback.
- requestAnimationFrame — requestAnimationFrame (rAF) is scheduling work for the next frame so animation stays in sync with paint.
- requestIdleCallback — requestIdleCallback is running low-priority work when the browser is idle.
- Required status check — Required status check is a CI job that must pass before GitHub will merge the PR.
- rerere — rerere is Git remembering how you resolved a conflict so a later rebase can reuse it.
- Reset — Reset (git reset) is moving HEAD and optionally the index and working tree.
- resize — resize (CSS resize) is the CSS resize property: whether a textarea-like box may be resized.
- Resize Observer — Resize Observer is watching an element's size without listening to window resize.
- Resolve conflict — Resolve conflict is editing the conflict markers, then adding and committing (or continuing the rebase).
- Resolve conversation — Resolve conversation is marking a review thread done after the fix landed.
- Responsive design — Responsive design is layouts that adapt across phone, tablet, and desktop instead of shipping a separate mobile site.
- REST — REST (Representational State Transfer) is an API style that models nouns as URLs and uses GET, POST, PUT, PATCH, and DELETE instead of custom RPC verbs.
- REST API — REST API is an HTTP API that is resource-oriented.
- rest parameter — rest parameter is the .
- REST resource — REST resource is a noun the API exposes, identified by a URL.
- RESTful — RESTful is the adjective for an API that actually follows REST constraints rather than just returning JSON from random paths.
- Restore — Restore (git restore) is the modern command to discard or restore files in the working tree or index.
- Retrospective — Retrospective is the meeting where the team changes how it works, not just what it builds.
- retry — retry is doing the same call again after a failure.
- Reverse proxy — Reverse proxy is a server that accepts public traffic and forwards it to internal apps, adding TLS, caching, or routing.
- Revert — Revert is adding a new commit that undoes an older one, safe for shared history.
- Review — Review is comments, approvals, or change requests on a pull request.
- Reviewer — Reviewer is someone asked to look at a PR.
- revocation — revocation is telling clients a certificate is no longer trusted, via CRL or OCSP.
- Rewrite — Rewrite is replacing a system instead of evolving it.
- RFC — RFC (Request for Comments) is a design doc you circulate before a large change.
- right — right (CSS right) is the CSS right property: the inset from the right edge when the box is positioned.
- right to be forgotten — right to be forgotten is a deletion request you must actually honor in the systems that hold the person.
- Rollback — Rollback is returning production to the previous artifact when the new one misbehaves.
- Rollup — Rollup is a bundler favored for libraries because of clean ESM output and tree shaking.
- Route 53 — Route 53 is Amazon's DNS and traffic-routing service.
- RPC — RPC (Remote Procedure Call) is calling a function that runs on another machine as if it were local, used by gRPC, tRPC, and older SOAP stacks.
- RPO — RPO (Recovery Point Objective) is how much data you can afford to lose, measured in time.
- RSA — RSA is a public-key algorithm still used for signatures and some key exchange.
- RTO — RTO (Recovery Time Objective) is how long you can stay down before the business is in real trouble.
- Ruby — Ruby is a language optimized for programmer happiness, best known through Rails for conventional web apps.
- Runbook — Runbook is the checklist an on-call person follows for a known class of failure.
- Runner — Runner is the machine, GitHub-hosted or self-hosted, that executes a job.
- Rust — Rust is a systems language that aims for C-like speed with compile-time memory safety and no garbage collector pause.
- S3 — S3 (Simple Storage Service) is Amazon's object store.
- Safe method — Safe method is an HTTP method that should not change server state, mainly GET, HEAD, and OPTIONS.
- salt — salt is random per-password data mixed into a hash so two identical passwords do not match.
- SameSite — SameSite is a cookie attribute that limits when cookies travel on cross-site requests, a main CSRF defense.
- SAML — SAML (Security Assertion Markup Language) is an XML SSO standard still common in enterprise IT.
- Sass — Sass (SCSS) is a CSS preprocessor with variables, nesting, and mixins.
- SAST — SAST (Static Application Security Testing) is the vendor name for security-focused static analysis.
- SBOM — SBOM (Software Bill of Materials) is a list of what is in a build, so you can answer 'are we affected?
- SBOM CycloneDX — SBOM CycloneDX is a common SBOM format besides SPDX.
- SCA — SCA (Software Composition Analysis) is scanning dependencies for known CVEs.
- Scala — Scala is a JVM language that mixes object and functional styles, known from Spark and some high-scale backends.
- Schema — Schema is the shape of the data: tables, columns, types, and relations, or a JSON schema for documents.
- scoped package — scoped package is a package named @org/name, used for namespacing and private registries.
- scroll-behavior — scroll-behavior (CSS scroll-behavior) is the CSS scroll-behavior property: smooth or instant scrolling for the box.
- scroll-margin — scroll-margin (CSS scroll-margin) is the CSS scroll-margin property: extra snap or scroll padding around a target.
- Scrum — Scrum is a popular Agile wrapper with roles, sprints, and ceremonies.
- Secret — Secret (GitHub Secret) is an encrypted value injected into Actions, never to be echoed in logs.
- secret rotation — secret rotation is replacing a key or token on a schedule and after a leak.
- Secure cookie — Secure cookie is a cookie that the browser will only send over HTTPS.
- SECURITY.md — SECURITY.md is the file that says how to report a vulnerability privately.
- Seed — Seed is scripted sample or required rows loaded after migrations.
- Semantic HTML — Semantic HTML is using elements for their meaning (nav, main, button) so tools do not have to guess from divs.
- semantic-release — semantic-release is automation that versions and publishes from commit messages.
- semaphore — semaphore is a counter that limits how many threads may enter a section.
- SemVer — SemVer (Semantic Versioning) is version numbers MAJOR.
- semver range — semver range is a version constraint such as ^1.
- Sentry — Sentry is an error-tracking product that groups stack traces and tells you who is hurt.
- SEO — SEO (Search Engine Optimization) is making pages understandable and fast so search engines can rank and show them.
- sequential scan — sequential scan is reading every row.
- Server Component — Server Component (RSC) is a React component that renders on the server and does not ship its JS to the client.
- server hook — server hook is a hook on the receiving Git host.
- Serverless — Serverless is running functions or containers that scale to zero and you pay per use, such as AWS Lambda.
- service — service is the object that holds business rules, called by controllers or workers.
- Service mesh — Service mesh is a sidecar layer such as Istio or Linkerd that handles mTLS, retries, and traffic policy.
- Service worker — Service worker is a script the browser runs in the background to intercept fetches, cache files, and enable offline.
- Service worker skip waiting — Service worker skip waiting is the pattern that activates a new service worker immediately instead of waiting for every tab to close.
- Session — Session is server-side state tied to a visitor, often looked up from a cookie or token.
- sessionStorage — sessionStorage is like localStorage but scoped to a tab lifetime.
- Set — Set is a collection of unique values.
- SFTP — SFTP (SSH File Transfer Protocol) is file transfer over SSH, not the old FTP.
- SHA-1 — SHA-1 is a retired hash.
- SHA-256 — SHA-256 is a widely used cryptographic hash.
- Shadow DOM — Shadow DOM is an isolated DOM subtree used by web components so their CSS does not leak.
- shallow clone — shallow clone is cloning with limited history, common in CI to save time.
- shallow copy — shallow copy is copying only the top level of an object.
- Sharding — Sharding is splitting data across many databases by a key so no single box holds everything.
- shebang — shebang is the #! line that tells Unix which interpreter to run.
- Shim — Shim is a thin compatibility layer that makes one API look like another.
- side effect — side effect is any change a function makes besides its return value: network, DOM, or global state.
- sideEffects flag — sideEffects flag is the package.
- SIEM — SIEM (Security Information and Event Management) is a system that aggregates security logs and alerts.
- Signed commit — Signed commit is a commit whose author used GPG or SSH signing so GitHub can mark it Verified.
- sigstore — sigstore is a project for signing artifacts with short-lived OIDC-bound keys.
- single responsibility — single responsibility is a module should have one reason to change.
- singleton — singleton is one shared instance.
- SLA — SLA (Service Level Agreement) is the contractual promise, often with credits if you miss it.
- SLI — SLI (Service Level Indicator) is the raw measurement behind an SLO, such as the ratio of 2xx responses.
- SLO — SLO (Service Level Objective) is the target reliability number you actually try to hit, such as 99.
- SLSA — SLSA is a supply-chain security framework with levels of provenance.
- Slug — Slug is a URL-safe, usually lowercase title used in permalinks, such as tech-dictionary.
- Smoke test — Smoke test is a tiny suite that proves the build basically boots.
- SMTP — SMTP (Simple Mail Transfer Protocol) is the protocol servers use to send mail to each other.
- snapshot — snapshot is a point-in-time copy of a disk or database.
- Snapshot test — Snapshot test is comparing output to a saved file.
- SNI — SNI (Server Name Indication) is the TLS extension that tells a shared IP which hostname you wanted.
- SOAP — SOAP (Simple Object Access Protocol) is an older XML web-service protocol still found in banks and enterprise integrations.
- SOC — SOC (Security Operations Center) is the team and tools that watch for attacks.
- social engineering — social engineering is attacks that target people and process, not only packets.
- Soft reset — Soft reset is moving HEAD but leaving the index and working tree, so commits become staged changes.
- soft wrap — soft wrap is the editor wrapping long lines without inserting newlines.
- Solid — Solid (SolidJS) is a reactive UI library that updates the real DOM with fine-grained signals.
- SOLID — SOLID is five object-oriented design principles: single responsibility, open-closed, Liskov, interface segregation, dependency inversion.
- Solidity — Solidity is the main language for Ethereum smart contracts.
- sorting — sorting is ordering a list.
- Source map — Source map is a file that maps minified code back to your original lines for debugging.
- SPA — SPA (Single-Page Application) is an app that loads once and then changes views with client routing instead of full page reloads.
- Span — Span is one timed operation inside a trace, such as a DB query.
- sparse checkout — sparse checkout is checking out only some paths, used in huge monorepos.
- spear phishing — spear phishing is phishing aimed at one person or role with researched bait.
- Specificity — Specificity is the scoring of selectors that decides which rule beats another, before source order.
- SpiderMonkey — SpiderMonkey is Mozilla's JavaScript engine in Firefox.
- Spike — Spike is a time-boxed exploration to learn enough to estimate or choose.
- spread — spread is the ... syntax that expands arrays or objects into another literal or call.
- Spring — Spring (Spring Boot) is the main Java stack for production APIs and enterprise services.
- Sprint — Sprint is a short planned interval in Scrum, usually one or two weeks.
- SQL — SQL (Structured Query Language) is the standard language for asking relational databases to select, join, insert, update, and delete rows.
- SQL injection — SQL injection is smuggling SQL through unsanitized input so the database runs an attacker's command.
- SQLite — SQLite is a database in a single file, perfect for mobile, tests, and small apps.
- Squash — Squash is folding several commits into one, often when merging a PR.
- Squash and merge — Squash and merge is a GitHub merge style that lands the PR as one commit on the base.
- SRI — SRI (Subresource Integrity) is a hash on a <script> or <link> so a CDN cannot silently change the file.
- SSE — SSE (Server-Sent Events) is a one-way HTTP stream from server to browser, simpler than WebSockets for notifications.
- SSG — SSG (Static Site Generation) is rendering pages at build time into files a CDN can serve with almost no origin compute.
- SSH — SSH (Secure Shell) is the encrypted remote shell and file protocol you use to administer servers.
- SSH key — SSH key is the key pair you use to push over git@github.
- SSL — SSL (Secure Sockets Layer) is the predecessor of TLS.
- SSO — SSO (Single Sign-On) is one login that opens many apps, usually through SAML or OIDC.
- SSR — SSR (Server-Side Rendering) is building the HTML on the server for the first paint so crawlers and slow devices see content sooner.
- SSRF — SSRF (Server-Side Request Forgery) is tricking your server into fetching an internal URL the attacker cannot reach directly.
- stack — stack is the memory region for call frames and locals.
- stack overflow — stack overflow is too many nested calls.
- Staging area — Staging area (index) is the set of changes you have marked to go into the next commit.
- stale-while-revalidate — stale-while-revalidate is serving a cached response while fetching a fresh one in the background.
- Standup — Standup is a short daily sync.
- star — star is a bookmark on a repo.
- Stash — Stash is a temporary shelf for dirty work so you can change branches cleanly.
- State — State is data a component owns and that, when changed, causes a new render.
- stateless — stateless is a process that keeps no required local disk state, so you can scale it by adding instances.
- Static analysis — Static analysis is reading code without running it to find bugs and vulns.
- Status code — Status code is the three-digit number that tells a client whether the request worked, redirected, or failed.
- Step — Step is one command or action inside a job.
- sticky session — sticky session is routing a user back to the same instance.
- stored procedure — stored procedure is a routine that lives in the database.
- Story point — Story point is a relative size number some teams use instead of hours.
- structuredClone — structuredClone is the platform function that deep-clones most structured data.
- Stub — Stub is a fake that returns canned data without much behavior.
- STUN — STUN is a protocol that helps WebRTC discover the public address behind NAT.
- Submodule — Submodule is a Git repo nested inside another, pinned to a specific commit.
- Subnet — Subnet is a slice of a VPC, often public or private, in one availability zone.
- Subtree — Subtree is an alternative to submodules that copies another project into a folder of yours.
- sudo — sudo is running a command as root.
- Suggested change — Suggested change is a review snippet the author can commit in one click.
- supply chain attack — supply chain attack is compromising you through a dependency, a CI token, or a poisoned package.
- Suspense — Suspense is React's boundary that shows a fallback while a child is loading.
- Svelte — Svelte is a compiler that turns components into tight vanilla JS instead of shipping a large runtime.
- SvelteKit — SvelteKit is the official Svelte app framework with routing, SSR, and adapters for many hosts.
- Swagger — Swagger is the original tooling name people still use for OpenAPI docs and the Swagger UI.
- SWC — SWC is a Rust-based compiler used by Next.
- Swift — Swift is Apple's language for iOS, macOS, and related platforms, replacing most new Objective-C work.
- Switch — Switch (git switch) is the modern command to move HEAD to another branch.
- Symbol — Symbol is a unique immutable value often used as a hidden property key.
- symmetric encryption — symmetric encryption is the same key encrypts and decrypts, such as AES.
- syscall — syscall is a request from user code to the kernel, such as read or write.
- system prompt — system prompt is the hidden or leading instructions that set the model's role and rules.
- tab-size — tab-size (CSS tab-size) is the CSS tab-size property: how wide a tab character is in preformatted text.
- Tag — Tag is a name for a commit, used for releases such as v1.
- Tailwind — Tailwind is a utility-first CSS framework where you compose classes like flex, gap-4, and text-sm in markup.
- Tauri — Tauri is a lighter desktop wrapper that uses the OS webview and a Rust core.
- TCP — TCP (Transmission Control Protocol) is the reliable, ordered stream protocol under HTTPS and SSH.
- TDD — TDD (Test-Driven Development) is writing a failing test first, then the code, then refactoring.
- Tech debt — Tech debt is shortcuts that cost more later.
- temperature — temperature is a sampling knob: low is picky and repeatable, high is more random.
- temporal dead zone — temporal dead zone (TDZ) is the time between entering a scope and initializing a let or const, when access throws.
- Terraform — Terraform is HashiCorp's language for declaring cloud resources as code and planning diffs.
- text-align — text-align (CSS text-align) is the CSS text-align property: inline alignment: start, center, justify.
- text-decoration — text-decoration (CSS text-decoration) is the CSS text-decoration property: underline, overline, line-through, and their styles.
- text-transform — text-transform (CSS text-transform) is the CSS text-transform property: uppercase, lowercase, or capitalize, which is not a substitute for real casing.
- this — this is the call-site binding in a function.
- thread — thread is a scheduled path of execution inside a process that shares memory.
- Threat model — Threat model is a structured look at what you are protecting, who might attack it, and how.
- throttle — throttle is running a function at most once per interval, used on scroll handlers.
- throughput — throughput is how many successful operations you complete per unit time.
- thundering herd — thundering herd is many waiters waking at once for one event.
- timeout — timeout is giving up when a call takes too long.
- timing attack — timing attack is learning a secret from how long a comparison takes.
- TLS — TLS (Transport Layer Security) is the protocol that encrypts HTTP, mail, and many other sockets.
- TLS handshake — TLS handshake is the first packets that agree versions, keys, and the server certificate.
- Toil — Toil is manual, repetitive ops work that does not add lasting value.
- token — token (LLM token) is a chunk of text the model reads and writes, smaller than a word and billed as usage.
- TOML — TOML (Tom's Obvious Minimal Language) is a config format with clear types, used by Cargo, many CLIs, and some app configs.
- tool calling — tool calling (function calling) is letting a model request a structured tool, then you run it and return the result.
- top — top (CSS top) is the CSS top property: the inset from the top edge when the box is positioned.
- top-level await — top-level await is await at module scope, which delays the module's evaluation.
- TOTP — TOTP (Time-based One-Time Password) is the rotating six-digit codes in authenticator apps.
- Trace — Trace (distributed trace) is a request's path across services, stitched by a trace id.
- Transaction — Transaction is a group of writes that all commit or all roll back, keeping data consistent.
- transform — transform (CSS transform) is the CSS transform property: translate, rotate, scale, and skew, which can create a containing block.
- transformer — transformer is the neural architecture that uses attention so models can weigh tokens against each other.
- transition — transition (CSS transition) is the CSS transition property: animating property changes over time.
- transitive dependency — transitive dependency is a package you did not list, pulled in by something you did.
- Transpile — Transpile is rewriting source from a newer syntax to an older one, such as TS to JS.
- tree — tree (AST) is usually the abstract syntax tree a compiler walks.
- Tree shaking — Tree shaking is bundlers dropping unused exports so the shipped JS is smaller.
- tree-shaking hole — tree-shaking hole is a side-effectful import that stops the bundler from dropping unused code.
- trigger — trigger is a function the database runs on insert, update, or delete.
- tRPC — tRPC is end-to-end typesafe RPC for TypeScript apps that share types between client and server.
- Trunk-based development — Trunk-based development is a style where everyone merges to main in small slices, often behind feature flags.
- truthy — truthy is a value that becomes true in a boolean context, such as a non-empty string.
- TSX — TSX is JSX written in TypeScript files so component props can be checked.
- TTL — TTL (Time To Live) is how long a cached value or DNS record stays valid before it must be refreshed.
- TTL in DNS — TTL in DNS is how long resolvers may cache a record.
- Turbopack — Turbopack is Vercel's incremental bundler aimed at large Next.
- TURN — TURN is a relay used when two peers cannot connect directly.
- TXT record — TXT record is a DNS text record used for SPF, DKIM, verification, and random proofs.
- Type checker — Type checker is a tool that proves shapes, such as tsc or mypy, without running the program.
- TypedArray — TypedArray is array views over binary buffers, such as Uint8Array.
- TypeScript — TypeScript (TS) is a typed superset of JavaScript that compiles to JS so large apps can catch shape errors before they reach the browser.
- typosquatting — typosquatting is publishing a package whose name is one letter off a popular one.
- UDP — UDP (User Datagram Protocol) is the fire-and-forget packet protocol under DNS, QUIC, and games.
- Uncontrolled input — Uncontrolled input is an input that owns its value in the DOM, read through a ref.
- undefined — undefined is the value of a missing binding or property in JavaScript.
- Unicode — Unicode is the standard that gives every character a code point, including emoji.
- unicode-bidi — unicode-bidi (CSS unicode-bidi) is the CSS unicode-bidi property: how bidirectional text is isolated.
- Unique constraint — Unique constraint is a rule that no two rows may share the same value in a column or set of columns.
- Unit test — Unit test is a fast test of one function or module with collaborators faked.
- Unix — Unix is the older OS family Linux and macOS inherited ideas from.
- Upstream — Upstream is the remote you track for official updates, often the original repo you forked.
- URI — URI (Uniform Resource Identifier) is the broader family that includes URLs and names that identify a resource.
- URL — URL (Uniform Resource Locator) is the address of a resource, including scheme, host, path, query, and fragment.
- URLPattern — URLPattern is a platform API for matching URL paths, still landing across browsers.
- URLSearchParams — URLSearchParams is a helper for reading and writing query strings.
- URN — URN (Uniform Resource Name) is a URI that names a resource without saying where to download it.
- use case — use case is an application action, such as SubmitApplication, that orchestrates services.
- useEffect — useEffect is the React hook for synchronizing with something outside render.
- useMemo — useMemo is the React hook that caches a calculation between renders.
- User story — User story is a small piece of work written from a user's point of view.
- user-select — user-select (CSS user-select) is the CSS user-select property: whether the user can select the text.
- useRef — useRef is the React hook that holds a mutable box that does not trigger render.
- userland — userland is everything outside the kernel: your app, shells, and libraries.
- useState — useState is the React hook that holds a piece of local state.
- UTF-8 — UTF-8 is the dominant way to encode Unicode as bytes.
- V8 — V8 is Google's JavaScript engine, used in Chrome and Node.
- VACUUM — VACUUM is Postgres maintenance that reclaims dead tuples.
- vault — vault is a dedicated secret store such as HashiCorp Vault or a cloud secret manager.
- vector database — vector database is a store optimized for nearest-neighbor search over embeddings.
- Velocity — Velocity is story points finished per sprint.
- Vercel — Vercel is the host built around Next.
- Verified badge — Verified badge is GitHub's mark that the commit signature matches a trusted key.
- vertical scaling — vertical scaling is giving one machine more CPU or RAM.
- vibe coding — vibe coding is shipping software by steering models with tight specs and reviewing the output like a senior, not pasting blindly.
- view — view (SQL view) is a stored query that looks like a table.
- Viewport — Viewport is the visible browser area; the viewport meta tag tells mobile browsers how to scale the page.
- Virtual DOM — Virtual DOM is a JS tree libraries like React diff against the real DOM to apply fewer mutations.
- visibility — visibility (CSS visibility) is the CSS visibility property: whether a box is drawn, while still occupying space if hidden.
- Vite — Vite is a frontend build tool that serves ESM in dev and rolls a production bundle with Rollup or esbuild.
- VPC — VPC (Virtual Private Cloud) is your isolated network in a cloud account.
- VPN — VPN (Virtual Private Network) is an encrypted tunnel to another network, for privacy or for reaching internal tools.
- VS Code — VS Code (Visual Studio Code) is Microsoft's editor that became the default for web work and the base of Cursor and Codespaces.
- Vue — Vue is a progressive UI framework with a template-first style and a gentler learning curve than React for many teams.
- WAF — WAF (Web Application Firewall) is a filter in front of HTTP that blocks common attacks and bots.
- WAL — WAL (Write-Ahead Log) is the sequential log a database writes before changing pages, used for crash recovery and replicas.
- warm start — warm start is a reuse of an already-booted instance.
- WASM — WASM (WebAssembly) is a compact binary format that lets languages like Rust and C run near-native speed inside browsers and other hosts.
- watch — watch is subscribing to notifications from a repo.
- Waterfall — Waterfall is planning the whole project up front, then building in phases.
- WeakMap — WeakMap is a map whose object keys can be garbage-collected.
- WeakSet — WeakSet is a set of objects that does not keep them alive.
- Web app manifest — Web app manifest is the JSON file that names the app, icons, and start URL for install prompts.
- Web Components — Web Components is custom elements, shadow DOM, and templates: the browser-native component model.
- WebAssembly — WebAssembly (WASM) is the full name of the portable compilation target that sits beside JavaScript in modern browsers.
- WebAuthn — WebAuthn is the browser API for passkeys and hardware keys.
- Webhook — Webhook is your server receiving an HTTP POST when another system has an event, instead of you polling.
- Webhook secret — Webhook secret is the HMAC key GitHub uses so you can verify a webhook really came from them.
- webpack — webpack is the long-standing JS bundler with a large plugin ecosystem.
- WebRTC — WebRTC is browser APIs for real-time audio, video, and data with peer connections.
- WebSocket — WebSocket is a persistent bidirectional channel upgraded from HTTP, used for chat and live boards.
- white-space — white-space (CSS white-space) is the CSS white-space property: how spaces and wraps are handled, including nowrap and pre-wrap.
- width — width (CSS width) is the CSS width property: the horizontal size of the box, subject to box-sizing.
- will-change — will-change (CSS will-change) is the CSS will-change property: a hint that a property will animate.
- Windows — Windows is Microsoft's desktop and server OS, still the office default.
- wontfix — wontfix is a closed issue the project will not implement.
- word-spacing — word-spacing (CSS word-spacing) is the CSS word-spacing property: extra space between words.
- Workbox — Workbox is Google's library for writing service worker caching strategies.
- Worker — Worker is a process that pulls jobs from a queue and does the slow or retryable work.
- Workers — Workers (Cloudflare Workers) is V8 isolates at the edge that run JS on Cloudflare's network.
- Workflow — Workflow is a YAML file under .
- Working tree — Working tree is the files you see and edit, as opposed to the index and the object store.
- workspace — workspace (npm workspace) is multiple packages in one repo that share a lockfile.
- worktree — worktree (git worktree) is a second working directory attached to the same repo, used for parallel branches.
- writing-mode — writing-mode (CSS writing-mode) is the CSS writing-mode property: horizontal or vertical flow, needed for some scripts.
- WSL — WSL (Windows Subsystem for Linux) is Linux userland on Windows, how many Windows developers run Node and Docker.
- XML — XML (eXtensible Markup Language) is a tagged document format still used in RSS, SOAP, Android layouts, and office files.
- XMLHttpRequest — XMLHttpRequest (XHR) is the older AJAX API.
- XSS — XSS (Cross-Site Scripting) is injecting script into a page so it runs as that site, often by reflecting unsanitized HTML.
- YAGNI — YAGNI (You Aren't Gonna Need It) is do not build the abstraction for a future that has not arrived.
- YAML — YAML (YAML Ain't Markup Language) is an indentation-based config format used by CI, Kubernetes, and many app settings.
- yarn — yarn is another Node package manager.
- z-index — z-index is the stacking order of positioned elements; it only works inside a stacking context.
- Zero trust — Zero trust is authenticate and authorize every request, even inside the 'private' network.
- zero-day — zero-day is a vuln with no public fix yet.
- Zustand — Zustand is a small React store that replaced a lot of Redux boilerplate.