ZCode open-sourced after an unauthorized data-upload controversy
Reports say an older ZCode build uploaded repository data without clear consent. Zhipu apologized; the newly opened code shows broad telemetry, but not enough to prove the old behavior line for line.
What happened
Chinese technology media and community posts reported that an older ZCode version uploaded repository-related user data without clear permission. Zhipu subsequently apologized, said the issue had been fixed and promised to open the product’s source code and arrange a third-party audit. TechWeb also reported that one affected company sent a formal letter seeking accountability.
The sequence matters. The controversy surfaced on September 18, the apology followed on September 19, and the repository was opened on September 21 after the initially discussed deadline slipped.
What the public code shows
The current repository enables telemetry and initializes broad desktop monitoring for performance, exceptions, API calls, resource loads, clicks, long tasks, crashes and RPC activity. It also contains redaction code intended to remove click text and snapshots and sanitize paths, URLs, secrets and email addresses.
Separately, its Git snapshot logic can read the active branch, Git user name, dirty status, changed filenames and recent commit summaries for agent context. That is sensitive repository metadata, even when it is not the same thing as uploading complete source files.
What is verified, and what is not
The public reporting, apology and later open-source release make the old-version data-upload incident a real trust issue, not launch-week speculation. However, the code now on GitHub is not a forensic copy of the closed build implicated in the reports. It does not, by itself, prove that the current open-source version uploads users’ complete source code.
The unresolved questions are whether the promised third-party audit will be published, exactly what the old client sent, how consent was presented and whether telemetry can be disabled cleanly. Until those answers exist, the correct label is developing, not cleared.
Why we missed it
Our first pass watched GitHub stars, forks and Hacker News. It did not watch Chinese media, community reports, privacy keywords, company responses or changes around repository telemetry. That made the feed fast at spotting popularity and weak at spotting risk. This story should have led the ZCode coverage from the start.