Signal

Anthropic launches OSS Scanner, a free opt-in vulnerability scanner for critical open-source projects; its AI-generated reports are sent without human review

First reported by Anthropic ·

The signal ●●●○ Compiled by AI from Anthropic, Techmeme, Unite.AI and Help Net Security
Why you might care

Open-source projects can now receive automated security vulnerability reports that include candidate patches, speeding up the remediation process.

What happened

Anthropic has launched OSS Scanner, a free, opt-in vulnerability scanning service for critical open-source projects. Leveraging its advanced AI models, the service aims to identify security flaws rapidly, addressing a bottleneck in human review capacity. The scanner has already identified over 29,000 candidate vulnerabilities in major software projects over the past six months. While Anthropic will continue its traditional coordinated vulnerability disclosure process for human-verified reports, OSS Scanner offers a fast-track option for projects willing to receive AI-generated reports without human review. This allows for quicker identification and patching of potential exploits, as the reports include self-contained reproducible steps, explanations, and proposed fixes. Initial validation shows that 88% of reported vulnerabilities met Anthropic's disclosure criteria.

What it means

Anthropic's OSS Scanner signifies a major advancement in AI's role in software security, moving from passive identification to proactive, albeit unverified, vulnerability reporting. The initiative directly confronts the scalability issues faced by security teams by automating the initial triage and reporting stages, allowing maintainers to act on potential threats much faster. This could fundamentally alter the security maintenance landscape for open-source software, which underpins much of the internet's infrastructure.

The opt-in nature and the explicit

AI-written summary. May contain errors.