Industry change
Anthropic launches free opt-in vulnerability scanner for open source
- Published
- Source
- Anthropic Research
Summary
Anthropic has launched OSS Scanner, an opt-in service that periodically scans open-source projects for vulnerabilities using its strongest models at no cost. According to the company, it discovered over 29,000 candidate vulnerabilities in the past six months but could manually review only about 6,000, and it has sent nearly 5,000 unverified reports directly to maintainers who asked for them. The company notes that reports are fully model-generated without human review, so they may contain errors.
Why it matters for our work
The numbers show that even when AI finds issues at scale, human validation remains the bottleneck. Designing the division of labor between AI detection and human verification is becoming a core part of security work.
Translated from the Korean original. Summaries may be translated and edited. Commentary reflects our perspective; forecasts remain the source’s views.