# Zed Moves Toward Secure-by-Default: Introducing Worktree Trust

DevFeed: [Zed Moves Toward Secure-by-Default: Introducing Worktree Trust](<https://devfeed.tech/articles/zed-moves-toward-secure-by-default-introducing-worktree-trust-13533.md>)

Original publisher: [Read original article](<https://zed.dev/blog/secure-by-default>)

Author: John Swanson, Kirill Bulatov

Published: 2025-12-17T00:00:00Z

Content type: release

Language: en

Sources: [Zed Industries - Blog](<https://devfeed.tech/sources/zed-industries-blog.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [configuration](<https://devfeed.tech/tags/configuration.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [release](<https://devfeed.tech/tags/release.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

Zed introduces a preview worktree trust mechanism to support secure-by-default behavior. Project settings will no longer automatically download or execute language servers or MCP servers without giving users an opportunity to review and trust the worktree.

## Source excerpt

We're introducing a new worktree trust mechanism while maintaining options for a low-friction experience you expect from Zed.