trampolim.net
PT EN

Trampolim · Technology weekly

The Week in Tech

Issue 22Week of September 28 to October 2, 20266 stories
Business

Z.ai apologizes, opens ZCode source and erases commit history

After delaying release for security reasons, Chinese lab releases GLM-5.3 under open-source license. The decision to reset version history raises transparency questions.

Z.ai apologizes, opens ZCode source and erases commit history
Mercado · September 28 to October 2, 2026

Chinese lab Z.ai, spun off from Tsinghua University research, published the source code of ZCode under an open license last month and simultaneously wiped the entire commit history from the repository. The company also issued a public apology without detailing the specific reason for removing the history.

The move comes weeks after Z.ai claimed its GLM-5.3 model approaches Anthropic Mythos in its ability to find software vulnerabilities. At the time, the lab announced it would delay the release for a two-week security review, becoming the first Chinese lab to publicly postpone a model based on security concerns.

The Chinese regulatory environment has intensified recently. China's cybersecurity regulator published an updated version of its AI security framework last week, which includes specific warnings about shutdown resistance, evaluator deception and sandbox escape.

The decision to open ZCode's source is consistent with Z.ai's stated strategy of betting on transparency as a competitive differentiator. However, erasing the commit history contradicts that narrative, as it eliminates change traceability and makes independent auditing of the model's development impossible.

For organizations considering adopting open models in production, especially for offensive or defensive security tasks, a repository without history is a warning sign. Without access to the version log, it is impossible to verify whether security fixes were applied, whether vulnerabilities were introduced in intermediate revisions, or whether the current code matches what was audited.

The paper understands that opening the code is a positive step for the AI ecosystem, but erasing the commit history compromises the practical usefulness of the initiative. Transparency is not limited to an open license; it includes traceability. Operators evaluating ZCode for internal use should demand access to the full repository or consider the model as non-auditable — which, for security applications, makes production use unviable.

Book a call