ZCode Releases Open Source After Resolving Security Issues
Key point
ZCode has completed addressing security vulnerabilities reported by the community and open-sourced its code.
Details
ZCode has officially announced its transition to open source after resolving security issues reported by the community. It has released the source code for its desktop app, web workspace, backend, Agent CLI, and runtime via GitHub (zai-org/ZCode) to ensure transparency.
Security Response and Verification
- Data Protection Confirmation: Confirmed that the code data of concern to the community was not stored and has never been used for model training.
- External Audits: Underwent security assessments by the China Academy of Information and Communications Technology (CAICT) and NSFOCUS. CAICT confirmed that the zcode-prod Alibaba Cloud OSS bucket was empty, and NSFOCUS confirmed that the bucket and all data objects had been deleted.
- Feature Removal: Removed the Repo Wiki feature and the local repository snapshot generation and upload workflow from the ZCode v3.14.0 client.
Future Plans
Establish a continuous process for reporting and addressing security vulnerabilities, and operate a program to reward reported vulnerabilities. The full security assessment report will be released at a later date.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.