Skip to content

Vulnerability Scanner Launches for Open-Source Software

Anthropic Introduces Free OSS Scanner for Open-Source Vulnerabilities

  • Anthropic launched OSS Scanner, a free service to identify vulnerabilities in open-source software.
  • The service utilizes models like Claude Mythos and has identified over 29,000 potential vulnerabilities in six months.
  • Penetration testers found that out of 97 critical findings across 48 projects, 85 (88%) met coordinated vulnerability disclosure quality standards.
  • OSS Scanner generates reports without human review, aiming to speed up the vulnerability reporting process for developers.
  • Project maintainers can apply for the service via GitHub, with selection criteria similar to OSS-Fuzz.

OSS Scanner is designed to enhance security audits for open-source projects by providing automated reports on identified vulnerabilities. This initiative aims to address the growing demand from developers for comprehensive vulnerability assessments.

With over half of critical findings verified as meeting quality requirements, OSS Scanner represents a significant advancement in open-source software security efforts.(Source)

Share