📡 Breaking news
0/0
Analyzing latest trends...
AI Text-to-Speech.

Z.ai Open-Sources ZCode Assistant Following Cloud Repository Exfiltration Controversy.

Z.ai Open-Sources ZCode Assistant Following Cloud Repository Exfiltration Controversy.
Z.ai Open-Sources ZCode Assistant Under Apache 2.0 License Following Repository Data Scraping Controversy

AI developer Z.ai, creator of the General Language Model (GLM) architecture, has officially released the source code for its ZCode programming assistant under the open-source Apache 2.0 license. The decision follows intense community scrutiny after cybersecurity researchers discovered that ZCode was silently exfiltrating entire project repositories to external cloud servers during background operations.

Technical Discovery, Open-Source Release, and Codebase Transparency

The open-source release reveals technical details about ZCode’s application architecture, alongside lingering questions regarding developer transparency:

  • Application Tech Stack: The open-sourced codebase shows that ZCode is built using TypeScript packaged into a desktop client via the Electron framework.

  • Abbreviated Commit History: Despite releasing the repository under the permissive Apache 2.0 license, developers noted that the public ZCode repository contains only two initial commits. The complete development history, incremental revisions, and prior internal implementations remain unexposed.

  • Background Repository Uploads: The security controversy emerged when network analysis showed ZCode uploading entire local source code repositories to Z.ai cloud infrastructure without explicit user authorization or prominent opt-in prompts.

Third-Party Security Audits and Remediation Patch

In response to privacy concerns, Z.ai initiated third-party technical verifications and issued software updates:

  • External Technical Audits: Z.ai engaged the China Academy of Information and Communications Technology (CAICT) and cybersecurity firm NSFOCUS to audit backend server telemetry and data handling practices.

  • Audit Findings on Repository Processing: According to Z.ai and the auditing entities, the exfiltrated repository data was processed strictly to generate automated "Repo Wiki" documentation features. The company stated that uploaded code artifacts were purged from backend servers immediately after processing.

  • Feature Deprecation in Version 3.14.0: Z.ai formally released ZCode Version 3.14.0, which completely removes the automatic repository uploading mechanism and decouples backend documentation generation from local workspace environments.

 

 

Source: @zcode_ai 

💬 AI Content Assistant

Ask me anything about this article. No data is stored for your question.

Comments