Anthropic has launched OSS Scanner, a free opt-in vulnerability scanner that uses artificial intelligence to help secure open-source software. Projects that join receive thorough, periodic security scans from the company’s strongest models, including Claude Mythos, at no cost. The reports are fully model-generated and do not undergo human review or triage, allowing faster and more frequent scanning, though some findings may be incorrect. The service builds on Anthropic’s experience finding vulnerabilities with Claude during Project Glasswing. Core maintainers enroll by submitting a pull request to the OSS Scanner GitHub repository with a YAML configuration that includes the repository link, contact email and a Dockerfile for an offline build environment. Selection criteria are similar to Google’s OSS-Fuzz and focus on projects with critical impact on infrastructure and user security. Anthropic has already identified more than 29,000 candidate vulnerabilities across major projects.
Anthropic has launched OSS Scanner, a free opt-in vulnerability scanner that uses artificial intelligence to help secure open-source software. Projects that join receive thorough, periodic security scans from the company’s strongest models, including Claude Mythos, at no cost. The reports are fully model-generated and do not undergo human review or triage, allowing faster and more frequent scanning, though some findings may be incorrect. The service builds on Anthropic’s experience finding vulnerabilities with Claude during Project Glasswing. Core maintainers enroll by submitting a pull request to the OSS Scanner GitHub repository with a YAML configuration that includes the repository link, contact email and a Dockerfile for an offline build environment. Selection criteria are similar to Google’s OSS-Fuzz and focus on projects with critical impact on infrastructure and user security. Anthropic has already identified more than 29,000 candidate vulnerabilities across major projects.