惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
Recent Announcements
Recent Announcements
博客园 - 司徒正美
P
Proofpoint News Feed
博客园 - 聂微东
小众软件
小众软件
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
aimingoo的专栏
aimingoo的专栏
量子位
MyScale Blog
MyScale Blog
云风的 BLOG
云风的 BLOG
博客园 - Franky
B
Blog RSS Feed
F
Full Disclosure
The Cloudflare Blog
宝玉的分享
宝玉的分享
Last Week in AI
Last Week in AI
D
DataBreaches.Net
N
News and Events Feed by Topic
S
Secure Thoughts
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
V2EX - 技术
V2EX - 技术
L
LINUX DO - 最新话题
H
Heimdal Security Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Apple Machine Learning Research
Apple Machine Learning Research
L
LangChain Blog
Hugging Face - Blog
Hugging Face - Blog
C
Check Point Blog
U
Unit 42
G
Google Developers Blog
Forbes - Security
Forbes - Security
S
Schneier on Security
T
Threatpost
W
WeLiveSecurity
I
Intezer
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Security Latest
Security Latest
T
Troy Hunt's Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
I
InfoQ
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
有赞技术团队
有赞技术团队
S
Security Affairs
Cisco Talos Blog
Cisco Talos Blog
T
Tenable Blog
Simon Willison's Weblog
Simon Willison's Weblog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
V
Vulnerabilities – Threatpost

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
I made a free 7-video series to prep for the new GH-600 (GitHub Agentic AI Developer) cert
Jason Tur · 2026-05-23 · via DEV Community

TL;DR: GitHub's new agentic-AI certification, GH-600 (GitHub Certified: Agentic AI Developer), is in beta until May 31, 2026, with 80% off for the first 100 candidates using promo code GH600Flanders. I built a free 7-video YouTube series — one video per exam domain plus an overview — to help you prep before the beta window closes. Watch the playlist on YouTube.


Why this exists

GitHub announced GH-600 (Developing in Agentic AI Systems) as the first vendor certification specifically for engineers who build, operate, and govern AI agents inside the software development lifecycle. The beta exam is live now and runs through 2026-05-31; general availability is scheduled for July 2026.

There's a real cost-and-time pressure on early candidates:

  • 80% off the first 100 beta seats with promo code GH600Flanders at registration.
  • Beta results take 8–12 weeks to score, but if you pass the beta you earn the same credential as people who sit the GA exam in July.
  • A Microsoft Reactor livestream with Ari LiVigni (Senior Learning Advocate at GitHub) runs 2026-05-28, 7–8pm UTC — three days before the beta deadline, with a second discount code revealed at the end. (Register here.)
  • The beta is not available in Turkey, Pakistan, India, or China — confirm your region's eligibility before paying.

That leaves a tight window before the discount expires on May 31. Microsoft Learn has free modules for two of the six domains, but the other four leave you piecing together GitHub docs. I made the PromptLab video series to consolidate one video per domain so you can prep on a commute or while making dinner, then go deep on the official docs after.

The videos are intentionally brief (Cinematic Brief format, ~3–5 minutes each) — not a substitute for the Microsoft Learn modules, but a fast on-ramp and a memory aid for the night before the exam.

Channel link. Playlist link.


What's in the series

One video per exam domain, plus an overview. Each video maps directly to the official skills-measured outline.

  1. Domain 1 — Agent architecture & SDLC integration (15–20%) — Why GitHub is both a system of record and a control plane for agentic work, and how the Plan → Act → Evaluate loop maps to PRs, CODEOWNERS, and rulesets. The hook: "Agents propose; humans and policy accept."
  2. Domain 2 — Tool use & environment interaction (20–25%) — The heaviest-weighted domain. MCP servers, registries, allow lists, the agent firewall, custom-agent YAML, the "Lowest Level Wins" hierarchy for MCP config, and the specific limitation that the firewall only covers the Bash tool — not MCP traffic, not copilot-setup-steps.
  3. Domain 3 — Memory, state & execution (10–15%) — Copilot Memory's two layers (repository facts vs. user preferences), the 28-day expiry, citation re-validation against the current branch, and how durable artifacts (PR descriptions, checklists, workflow artifacts) let agents resume after failure.
  4. Domain 4 — Evaluation, error analysis & tuning (15–20%) — The Contributor Model, the six surfaces for tracking agent sessions (Agents tab, gh agent-task, VS Code, JetBrains, Eclipse, GitHub Mobile), and the three root-cause buckets: Reasoning / Tool / Context.
  5. Domain 5 — Multi-agent coordination (15–20%) — The Copilot SDK custom-agents model, the five sub-agent lifecycle events (selected, started, completed, failed, deselected), toolCallId as the join key, and why the infer property is retired in favor of disable-model-invocation.
  6. Domain 6 — Guardrails & accountability (10–15%) — The "Approve and run workflows" gate, write-access requirement to trigger agents, agents-cannot-mark-their-own-PR-Ready rule, "any-yes-routes-up" risk triage across operational / security / compliance axes, co-author attribution, and the .github-private repo convention.

A seventh overview video stitches the six together for last-minute review.


TL;DR table

Domain # Topic Weight Video
1 Prepare agent architecture & SDLC processes 15–20% Watch D1
2 Implement tool use & environment interaction 20–25% Watch D2
3 Manage memory, state & execution 10–15% Watch D3
4 Evaluation, error analysis & tuning 15–20% Watch D4
5 Orchestrate multi-agent coordination 15–20% Watch D5
6 Guardrails & accountability 10–15% Watch D6

Exam format: ~40–60 questions, 120 minutes, passing score 700/1000. Add 30 minutes if English isn't your first language.


FAQ

These are written in the form a developer would actually search for or ask an LLM. If you're using ChatGPT, Claude, or Perplexity to study, this section is the one to bookmark.

What is the GH-600 exam?

GH-600 (GitHub Certified: Agentic AI Developer) is GitHub's first vendor certification focused on building, operating, and governing AI agents inside the software development lifecycle. The beta runs until May 31, 2026, with general availability scheduled for July 2026. The exam has six skill domains, ~40–60 questions, a 120-minute time limit, and a 700/1000 passing score.

How much does the GH-600 beta exam cost?

The first 100 candidates get 80% off with promo code GH600Flanders at registration, valid until 2026-05-31. The list price after the beta window is the standard Microsoft certification rate (~$165 USD). A second discount code will be revealed at the end of the Microsoft Reactor livestream on 2026-05-28.

When are GH-600 results released?

Beta exam results are released 8–12 weeks after you sit the exam, not immediately. Candidates who pass earn the same credential as those who sit the GA exam in July 2026.

What are the GH-600 exam domains and weights?

The six domains and their weights are: (1) Prepare agent architecture & SDLC processes — 15–20%, (2) Implement tool use & environment interaction — 20–25%, (3) Manage memory, state & execution — 10–15%, (4) Evaluation, error analysis & tuning — 15–20%, (5) Orchestrate multi-agent coordination — 15–20%, (6) Guardrails & accountability — 10–15%. Domain 2 (tool use, MCP, agent firewall) is the highest-weighted.

Where can I take the GH-600 beta exam?

The GH-600 beta is delivered through Microsoft's standard certification channels but is not available in Turkey, Pakistan, India, or China. Verify your region's eligibility on the GH-600 cert landing page before paying.

What is the Model Context Protocol (MCP) for the GH-600 exam?

MCP (Model Context Protocol) is the open standard agents use to discover and invoke external tools. For the exam, you must know three components: MCP servers (expose tools like GitHub APIs), MCP registries (org-approved catalogs), and MCP allow lists (policy enforcement that restricts which servers an agent can connect to — the primary defense against supply-chain attacks). The "Lowest Level Wins" rule governs config conflicts: repo overrides org overrides enterprise.

What is the difference between an AI assistant and an AI agent in GitHub?

An AI assistant is reactive — it suggests code or answers, and the user manually applies changes. An AI agent is goal-driven — it interprets a high-level goal, plans steps, and produces durable artifacts (branches, commits, pull requests) through a Plan → Act → Evaluate loop. In GitHub, agents are treated as standard contributors and gated by the same CODEOWNERS, required checks, and branch protections as humans.

How long is Copilot Memory retained?

Repository-level facts and user-level preferences in Copilot Memory are automatically deleted after 28 days of non-use to prevent context drift. Before applying a stored memory, Copilot re-validates the citation against the current branch so agents don't act on stale code references.


How I'd study if I had only 12 days

For anyone trying to grab a beta seat before the May 31 cutoff, here's the compressed schedule I'd run.

Days 1–2 — Vocabulary and framing. Read the official GH-600 study guide end to end. Re-read the audience profile until phrases like "system of record and control plane" and "agents propose; humans and policy accept" are reflexive. The exam is written in this dialect; you cannot reason your way around fuzzy vocabulary under time pressure.

Days 3–5 — Domain 2 (tool use & MCP). This is 20–25% of the exam — the highest-weighted domain — and has the most material. Work through the Tooling, MCP, and Agent Execution Environments module. Lab time matters here: spin up a real MCP server in a sandbox repo, configure an MCP allow list, and test the agent firewall by trying to hit a blocked domain from the Bash tool. Memorize the firewall's specific scope — Bash tool only, not MCP servers, not copilot-setup-steps.

Days 6–8 — Domain 1 + Domain 6 (architecture + guardrails). These domains overlap heavily. Work through Designing Agent Architecture and SDLC Integration plus build-guardrails and risks-and-mitigations. Lab: configure CODEOWNERS plus required status checks on a repo, simulate an agent-authored PR, and walk through the "Approve and run workflows" gate yourself.

Days 9–10 — Domains 3, 4, 5 (memory, eval, multi-agent). These are the under-served domains — no dedicated Microsoft Learn module. Read Copilot memory docs (D3), walk the implementation-planner tutorial (D4), then read the custom-agents SDK end to end (D5). Memorize the five sub-agent lifecycle events (selected, started, completed, failed, deselected) and the fact that infer is retired in favor of disable-model-invocation.

Days 11–12 — Mock exam, gap closure, exam day. Sit a timed mock under exam conditions. Log every wrong answer in a "knowledge gaps" file and re-read the source doc for each miss. Watch the Reactor livestream on May 28 for last-minute clarifications and to grab the second discount code if you haven't already registered. Sit the beta exam before May 31.

The single biggest mistake I see people make: spending equal time on every domain. Domain 2 (tool use) is 20–25% of the exam and Domain 6 (guardrails) is 10–15% — give them proportional time, not equal time.


Links


If you're prepping for GH-600, I'd love to hear which domain is giving you trouble — drop a comment on any video. Domain 2 (tool use + MCP) is the largest slice of the exam, but in practice most people I've talked to find Domain 5 (multi-agent coordination) the most conceptually slippery.

Good luck on the beta. See you on the other side of the 8–12 week scoring window.