Open-source devs just got free security audits.
Anthropic dropped OSS Scanner – $ANTH-powered vulnerability scans for critical open-source repos. Zero cost.
How it works:
Core maintainers of important projects get full reports: the bug, reproduction steps, fixes when available. Then ongoing scans for new vulns.
Apply via GitHub. That's it.
Early results hit different:
97 high/critical findings vetted by pen testers
85 met disclosure criteria
11 were real dupes
Only 1 invalid
The bugs were always there. Now something's actually scanning.
If you maintain infra that matters, this is free alpha. Check the repo and apply.
Anthropic dropped OSS Scanner – $ANTH-powered vulnerability scans for critical open-source repos. Zero cost.
How it works:
Core maintainers of important projects get full reports: the bug, reproduction steps, fixes when available. Then ongoing scans for new vulns.
Apply via GitHub. That's it.
Early results hit different:
97 high/critical findings vetted by pen testers
85 met disclosure criteria
11 were real dupes
Only 1 invalid
The bugs were always there. Now something's actually scanning.
If you maintain infra that matters, this is free alpha. Check the repo and apply.