HomeSecurityAnthropic introduces OSS Scanner for open source projects

Anthropic introduces OSS Scanner for open source projects

Anthropic on October 8 launched OSS Scanner, a free service that offers periodic security checks on selected open source projects. The tool is part of the broader Anthropic Cyber ​​Mission initiative and aims to identify bugs in shared software before they affect applications and services that rely on it, according to the company's announcement.

Anthropic's OSS Scanner checks code

The new service is optional and aimed at maintainers of critical projects, who can sign up for recurring scans at no charge. Anthropic did not announce a specific schedule for their frequency, but describes the checks as periodic and designed to continuously search for vulnerabilities.

What does OSS Scanner offer?

Each report can include a reproducible example showing how a bug is exploited, a technical explanation, and a proposed fix when available. Anthropic's more detailed description states that findings are accompanied, where possible, by evidence of when the problem was introduced and a candidate code change.

Membership is not open without criteria. The company says that core maintainers can propose projects with a significant impact on infrastructure and user security, and each application is evaluated individually. To apply for membership, maintainers submit a code merge request to the OSS Scanner public repository, following the template described there.

The process requires project configuration files and a build file, and managers can optionally add threat model documentation. The repository also allows reports to be encrypted with an OpenPGP public key so that they are only received by the primary contact.

See also: Anthropic introduces 3-tier cybersecurity verification program

Circuit check for vulnerabilities

The project is imported and built initially in an isolated virtual environment with internet access to obtain the necessary dependencies. The environment is then moved to a network without internet connection for scanning. This distinction is described in the repository's technical guidelines.

Reports are sent to the designated handlers and are not made public by Anthropic, according to the repository. The company also clarifies that it does not enforce a specific 90-day waiting period for disclosure of findings. This approach leaves it up to maintainers to verify and manage each report.

The challenge of evaluating the findings

OSS Scanner is based entirely on artificial intelligence models: reports are delivered without prior human review or screening. Anthropic warns that some may be inaccurate or invalid, for example because the model misinterprets the severity or how a project is performing.

The company estimates that the true positive rate will be over 90%, but that is its own expectation and not an independently verified metric. In a separate audit described by Anthropic, experts reviewed 97 high or critical severity findings from 48 projects and determined that 85 met the criteria for the notification process; of the rest, 11 were duplicates of known issues and one was invalid.

This data does not constitute an independent assessment of the service, nor does it guarantee the accuracy of each project. Anthropic says that for projects that cannot handle the volume of reports, it will continue to push findings through coordinated vulnerability disclosure, after human review.

Critical infrastructure security

Separate action for critical infrastructure

The OSS Scanner was announced alongside the Critical Infrastructure Defense Program, but the two arms have different audiences. The latter focuses on organizations that protect enterprise systems and critical infrastructure. The eleven founding partners include CrowdStrike, Dragos, Nozomi Networks and Rockwell Automation, CyberScoop.

The distinction is important: the infrastructure program combines Anthropic models, company engineers, and threat research with partner expertise, while the scanner is intended for open source projects. The company has not presented the scanner as a certified product or published an independent audit of its performance.

See also: Google temporarily stops reporting vulnerabilities in OSS VRP

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

For development teams, access to more frequent checks can speed up problem detection, but the absence of human triage shifts a significant portion of the verification to the maintainers themselves. The quality of the documentation and the ability to safely reproduce the findings will determine whether the tool helps without disproportionately burdening small teams.

See also: Critical vulnerability in LMCache allows code execution

The service gives selected projects another way to spot errors, but it's not a substitute for human review. Participating maintainers will need to review each finding, confirm that it's a real risk, and only incorporate fixes after assessing their impact.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS