Free and periodic scanning
Anthropic has announced a service called OSS Scanner to help open-source projects find security vulnerabilities. Projects that join the program will receive thorough, periodic security scans at no cost, carried out by the company's strongest models.
No human review
The most notable aspect of the service is that its reports are entirely model-generated. Anthropic says the outputs will not go through human review or triage. This allows for faster and more frequent scanning, but it also means reports may be incorrect or invalid.
What it means for open source
Open-source projects often rely on volunteer contributions for security work due to limited resources. Automated, free scanning could help surface potential issues earlier. Still, because there is no human verification, the results should be treated with care.



