ZCode goes open source after community-reported security issues
ZCode says it has completed security fixes and apologized to users. It plans an ongoing vulnerability reporting and response process, with rewards based on issue severity.
TLDR
ZCode announced it has open-sourced the product following community reports of security issues. It says none of the code data referenced by the community is retained or has ever been used for model training. According to ZCode, a CAICT assessment confirmed that the zcode-prod Alibaba Cloud storage bucket was empty and that remediation was complete in the v3.14.0 client. Repo Wiki was removed, and the workflow for generating and uploading local repository snapshots was disabled. ZCode also says NSFOCUS confirmed deletion of the bucket and all its data objects. It welcomes further community review and plans rewards for reported issues based on severity.