Code Review and Working with Existing Codebases Questions

Reviewing others' code and navigating unfamiliar systems: giving and receiving actionable review feedback, spotting correctness and design issues, and reading and understanding large or legacy codebases before changing them. Covers collaborative coding norms, incremental change in shared repositories, and verifying changes against existing behavior. The team-facing side of day-to-day engineering.

MediumTechnical
88 practiced

You are reviewing an Ansible playbook intended to be idempotent. Identify problems in this snippet and propose changes to make it idempotent and testable.

yaml
- hosts: web
  tasks:
    - name: install nginx
      command: apt-get install -y nginx
    - name: create conf
      copy:
        content: "server { listen 80; }"
        dest: /etc/nginx/sites-enabled/default
    - name: restart nginx
      service:
        name: nginx
        state: restarted

What would you change and why? How would you test the playbook in CI?

EasyTechnical
67 practiced

You are reviewing a short Bash script authored by an operations engineer. Identify bugs, anti-patterns, portability and safety concerns, and propose fixes. The script:

bash
#!/bin/bash
DIR=$1
if [ ! -d $DIR ]; then
  mkdir $DIR
fi
for file in $(ls $DIR); do
  sudo echo 'Processing' $file
  rm -rf $DIR/$file
done

What would you comment on in the PR, and how would you rewrite or patch this script to be safer and idempotent?

MediumTechnical
80 practiced

Technical coding: Given the following Python function used in a deployment script, write pytest unit tests that cover normal behavior and edge cases. Mock external API calls.

python
import requests

def get_latest_image(repo):
    r = requests.get(f'https://registry.example/api/{repo}/latest')
    r.raise_for_status()
    return r.json()['tag']

Provide at least three tests and explain why you chose them.

EasyTechnical
60 practiced

You find a change in a PR that appears to add API keys and database passwords as plain text constants in a repository. As the reviewer, what steps do you take immediately and what long-term code-review policies and automated checks would you recommend to prevent credentials from being committed? Include remediation for secrets already committed to history.

EasyBehavioral
73 practiced

Behavioral: Tell me about a time when you found a critical bug or security issue in infrastructure code during a code review. Use the STAR format: describe the Situation, the Task you had, the Actions you took as reviewer and with the team, and the Results (including any follow-up changes to process or automation).

Unlock Full Question Bank

Get access to all 31 Code Review and Working with Existing Codebases interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.