Open-source devs just got free security audits.

Anthropic dropped OSS Scanner – $ANTH-powered vulnerability scans for critical open-source repos. Zero cost.

How it works:

Core maintainers of important projects get full reports: the bug, reproduction steps, fixes when available. Then ongoing scans for new vulns.

Apply via GitHub. That's it.

Early results hit different:

97 high/critical findings vetted by pen testers
85 met disclosure criteria
11 were real dupes
Only 1 invalid

The bugs were always there. Now something's actually scanning.

If you maintain infra that matters, this is free alpha. Check the repo and apply.