Anthropic OSS Scanner Uses AI to Find Vulnerabilities in Opted-In Open-Source Projects
Anthropic has launched OSS Scanner , a free opt-in vulnerability-finding service for eligible open-source projects. The program periodically uses Anthropic's frontier-model capabilities to examine enrolled codebases, then provides maintainers with model-generated reports that can include a reproducer, an explanation of the issue and a suggested patch. For businesses that depend on open-source…
Anthropic has introduced OSS Scanner, a free opt-in vulnerability-finding service for eligible open-source projects. The service uses Anthropic's powerful models to scan codebases and deliver model-generated reports to maintainers, containing a reproducible example of the vulnerability, an explanation, potential impact, and a suggested patch.
The service is funded by the Defender Advantage Fund (0xDAF) and aims to complement existing security practices, not replace them. Projects are assessed based on criteria similar to Google's OSS-Fuzz program, focusing on those with critical infrastructure or security implications.
OSS Scanner scans enrolled projects periodically, generating reports that include a reproducible example, explanation, and suggested patch when possible. These reports are entirely model-generated, with no human review or triage before delivery. While this can provide valuable insights, maintainers must validate the findings and assess their accuracy before acting. Anthropic will use Coordinated Vulnerability Disclosure for projects that require or prefer validated reports.
The launch is significant as open-source maintainers often support software used far beyond their own organizations. By providing a recurring source of potential findings, OSS Scanner can strengthen security for important upstream projects. However, developers should not solely rely on automated reports and should continue using existing dependency monitoring, patch management, and internal security testing.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 4 other outlets
- Anthropic launches OSS Scanner, a free opt-in vulnerability scanner for critical open-source projects; its AI-generated reports are sent without human review (Anthropic) anthropic.com
- Anthropic launches critical infrastructure program and free OSS Scanner for open source siliconangle.com
- Anthropic launches free AI security scans for open-source projects theverge.com
- Anthropic launches the Critical Infrastructure Defense Program to provide AI models, threat research, and on-site support, starting with CrowdStrike and others (Sam Sabin/Axios) axios.com