Mechanism remediation
A researcher follow-up reports that the relevant upload path was removed in the reviewed 3.14.0 sample; this conclusion is limited to that reviewed sample.
Risk event record · monitored
Public disclosures describe repository data handling in the ZCode client. Review the affected samples, remediation and follow-up evidence before using that client with private repositories or sensitive code. This notice is not a finding about every GLM API or other compatible tool.
Applies only to the ZCode client path. It does not block the GLM API, catalog listings, purchase links, or access through other clients as a brand-wide rule.
The evidence covers discrete version and platform samples and does not establish a continuous affected range or every operating system.
Two researcher reports describe repository snapshots, including .git metadata, in discrete older ZCode samples. A later researcher review reports that the relevant upload path was removed in a 3.14.0 sample. A published report of ZCode's response says Repo Wiki could trigger uploads, the issue was fixed, and data was destroyed after Wiki processing. CreditsPlan has not independently verified the disposition of previously uploaded data, so remediation of the mechanism is kept separate from historical-data disposition.
A researcher follow-up reports that the relevant upload path was removed in the reviewed 3.14.0 sample; this conclusion is limited to that reviewed sample.
A published report of the official response says data was destroyed after Repo Wiki processing, but CreditsPlan has not independently verified the disposition of previously uploaded data.
The researcher reported snapshot manifests containing repository content and .git metadata; a small public-repository sample was accepted while a larger private-repository sample remained pending.
The researcher reported whole-repository snapshot handling including .git; a small public-repository sample was accepted while a larger commercial-project sample remained pending/failed.
A researcher follow-up reports removal of the relevant upload path and a 404 from the former credential endpoint; this does not verify historical-data disposition.
Verified · Review due
Checked · researcher_disclosure_and_follow_up
Checked · researcher_disclosure
Checked · official_product_page
Checked · official_privacy_policy
Checked · secondary_report_of_official_response