Anthropic offers free AI security scans for open-source projects
AI company Anthropic has launched OSS Scanner, a new free service designed to help open-source projects identify security vulnerabilities.

AI firm Anthropic has launched a new free service called OSS Scanner, aimed at assisting open-source projects in detecting security vulnerabilities. Projects that opt-in will receive comprehensive, periodic security scans conducted by Anthropic's most capable AI models at no charge.
The service intends to expedite the identification of potential security issues within open-source communities. OSS Scanner utilizes AI to pinpoint vulnerabilities, enabling faster and more frequent scanning. However, the company notes that the outputs from these scans are generated entirely by AI models, without human review or triage.
The absence of human oversight may result in incorrect or invalid reports. Anthropic states this trade-off allows for quicker and more frequent scanning. The company has not specified the frequency of these scans or the exact types of vulnerabilities it aims to flag.
The launch of OSS Scanner comes at a time when the security of open-source software is a significant concern in the technology sector. Many critical software infrastructures rely on open-source components, and vulnerabilities within them can have widespread implications.