AI NewsOpen sourceAnnouncement

Anthropic launched OSS Scanner, free security scans for open-source projects

Anthropic launched OSS Scanner, an opt-in service that scans enrolled open-source repositories for security vulnerabilities with its strongest models and emails reports to maintainers at no cost.

AI News

Editorial2 min read

LinkedInX
Anthropic Cyber Mission announcement header

Image: Anthropic

Why it mattersMaintainers of critical libraries can enrol one project by opening a pull request and receive machine-generated vulnerability reports, which shifts the triage work rather than removing it and will produce false positives teams need to budget for.

A maintainer of a widely used library can now ask one of the strongest frontier models to look for security bugs in it, on a repeating schedule, and send the findings in by email.

Anthropic announced the Anthropic Cyber Mission and said OSS Scanner is one of the first two efforts under it. The service is opt-in, free, and starts from a public pull request against the anthropics/oss-scanner repository.

How a maintainer joins

Anthropic says the core maintainers of a project enrol by opening a pull request that adds a projects/<project>/project.yaml file. The config names the git repository, a primary contact email, and a Dockerfile that builds the project and installs its dependencies inside a container that then runs without network access. Optional fields include extra email addresses to CC, a GPG public key for encrypted reports, and a threat model file that tells the scanner what to treat as adversarial and how to format findings. Anthropic says it will manually confirm each enrolment is from a real maintainer before accepting it.

What the scanner sends to maintainers

Anthropic says the pipeline includes agents to double-check bugs, propose patches, and perform root-cause analysis before the bundle is emailed. Projects then receive regular rescans whose frequency depends on how many projects are in the pipeline and how widely used each one is. The OSS Scanner track skips human review before sending, so each report lands with the maintainer as soon as a model produces it. Anthropic says it will not apply any coordinated disclosure window to these reports because they may contain false positives.

Anthropic places the service alongside its longer-running Coordinated Vulnerability Disclosure process, which it says had produced more than 6,000 human-reviewed reports by October 2026. The claim that OSS Scanner uses the company's strongest models is Anthropic's own, and the project borrows its eligibility criteria from OSS-Fuzz.

The eligibility bar explicitly favours projects that process untrusted input and that many other projects depend on. Anthropic says it recognises many maintainers are already overwhelmed by low-quality AI-generated reports, and that OSS Scanner is built for projects that already keep up with verified high and critical vulnerability reports and now want more coverage.

The reports come straight from the model, so a maintainer who turns the service on inherits the AI-generated-report problem Anthropic names on its page, with the volume now attached to one vendor and the vendor's name on each report. Two upsides come with that shift: a named counterparty a maintainer can push back on, and candidate patches that arrive attached to each report.

Source

SourceAnthropic

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX