LINKSGRAPH
Technology

Anthropic launches free OSS Scanner for open-source projects

Anthropic launches free OSS Scanner for open-source projects

The service will scan code regularly at maintainers’ request, while its initial reports will not be reviewed by specialists.

Anthropic has launched OSS Scanner, a free service that periodically searches open-source software for vulnerabilities. Projects can opt in, and scans will be run by the company’s most capable models, including Claude Mythos.

The service sends reports as soon as a scan is complete and does not have a person review them first. Anthropic warns that some findings may be incorrect. The company therefore expects participating projects to have maintainers who can assess the reports themselves and decide which issues need to be fixed.

Anthropic says it will continue its usual coordinated vulnerability disclosure process for projects that may struggle to handle unverified results. Under that process, specialists review findings before they are shared with maintainers.

To enroll a project in OSS Scanner, its core maintainers must submit a pull request to the service’s repository and add a project configuration. Anthropic will consider applications individually. Its criteria include whether a project has a critical impact on infrastructure and user security.

Anthropic says external security testers evaluated 97 high- and critical-severity findings from an early version across 48 projects. Eighty-five met the company’s disclosure standards, 11 of the remainder were duplicates or related to known issues, and one was invalid. These figures are Anthropic’s own account.

Read next

Montenegro detains Rybar founder Mikhail Zvinchuk and four others

Search LinksGraph