Anthropic launches free security scans for open-source projects
Summarised from 2 outlets · Updated 9 Oct, 12:37 · Archive
Anthropic is offering open-source projects free security scans using its strongest AI models to find vulnerabilities.
Anthropic has launched OSS Scanner, a free service offering open-source projects regular security vulnerability checks. Projects that opt in will receive thorough, periodic scans using Anthropic's strongest AI models, including Claude Mythos, at no cost.
The trade-off is that OSS Scanner's outputs will be fully model-generated without human review or triage. This approach enables faster and more frequent scanning, but reports may be incorrect or invalid. The service was inspired by OSS-Fuzz, an open-source software scanner created by Google and the Open Source Security Foundation that has been available since 2016.
Anthropologic already offers a paid product called Claude Security for general code scanning and patching. Both Google and Anthropic rely heavily on open-source code projects that underpin the internet, often maintained by unpaid volunteers. Recent examples of critical vulnerabilities in open-source software include the XZ Utils backdoor, which could have given hackers administrative control over millions of systems.

How it is being reported
- Anthropic now offers a free vulnerability-finding service for open-source softwareAnthropic is offering open-source projects a new way to check for vulnerabilities with its OSS Scanner.Engadget · 9 Oct, 12:24
- Anthropic launches free AI security scans for open-source projectsAnthropic's offering to help open-source projects track down security vulnerabilities with a new service called OSS Scanner. It says open-source projects that opt-in will get "thorough, periodic security scans by our strongest models at no cost." That could mean open-source projects get alerted about possible security issues sooner, but the trade-off is that OSS Scanner's […]The Verge · 8 Oct, 22:53
In this story: Anthropic · Google · Open Source Security Foundation · Claude Mythos · Linus Torvalds
This summary was written by AI from the headlines and standfirsts above, and states as fact only what at least two outlets report. How we use AI · Report a problem
Comments (0)