Industry change

Anthropic launches free opt-in vulnerability scanner for open source

Published
Source
Anthropic Research

Summary

Anthropic has launched OSS Scanner, an opt-in service that periodically scans open-source projects for vulnerabilities using its strongest models at no cost. According to the company, it discovered over 29,000 candidate vulnerabilities in the past six months but could manually review only about 6,000, and it has sent nearly 5,000 unverified reports directly to maintainers who asked for them. The company notes that reports are fully model-generated without human review, so they may contain errors.

Why it matters for our work

The numbers show that even when AI finds issues at scale, human validation remains the bottleneck. Designing the division of labor between AI detection and human verification is becoming a core part of security work.

Translated from the Korean original. Summaries may be translated and edited. Commentary reflects our perspective; forecasts remain the source’s views.

Read original (opens in a new tab)