Anthropic OSS Scanner: free AI security scans hit your deps
Anthropic's OSS Scanner sends free AI security scans to open-source maintainers with no human review. Patches will land faster. Update your dependencies faster too.
Anthropic now runs free AI security scans for open-source projects, and the reports go to maintainers without a human checking them first. The service is called OSS Scanner, and it launched on October 8 as part of a wider Anthropic Cyber Mission. You will probably never enroll a project. But the libraries your store and your apps run on will, and that changes how fast you need to ship updates.
What actually happened: OSS Scanner and the Cyber Mission
Per Anthropic's announcement and the OSS Scanner page:
- Opt-in and free. Core maintainers enroll by opening a pull request on GitHub that adds a
project.yamlfile. The file gives the repo to clone, a primary contact, and a Dockerfile that builds the project so the agent can run offline. - Model-generated, no human review. Each report includes a proof of concept, an explanation, and a suggested fix where one is available. Anthropic says some reports will be wrong, for example with an incorrect severity rating.
- No 90-day clock on raw findings. Unvalidated reports carry no coordinated disclosure deadline. If Anthropic later validates a finding through its normal process, a 90-day period can start.
- Selective. Anthropic will pick projects with criteria similar to Google's OSS-Fuzz: established code that handles untrusted input or has many dependents.
Help Net Security reports that penetration testers reviewed 97 high and critical findings from an early version across 48 projects. 85 met Anthropic's disclosure criteria, 11 were real but duplicates, and one was invalid. Anthropic's own page only states that it expects a true-positive rate above 90%.
The same mission includes a Critical Infrastructure Defense Program. It gives Claude models and on-site engineers to 11 founding partners that secure power, water, and transport systems, including CrowdStrike, Dragos, Palo Alto Networks, and Rockwell Automation.
Why it matters for your business
More bugs found means more patches shipped. When a model scans a popular parsing library every week, fixes come out faster. That is good news only if you install them. A Shopify app, a Next.js storefront, or a Python script that runs payroll exports all pull in hundreds of open-source packages. If you update those quarterly, you will run known-vulnerable code for months.
The gap between fix and exploit gets shorter. A public patch tells attackers where the bug was. The same AI tools that find bugs can read a diff. Plan for days between release and exploit, not months.
Automate the boring part. Turn on Dependabot or Renovate. Group minor updates into one weekly pull request. Run your tests on every one. Merge security updates first. This takes an afternoon to set up, and it is the cheapest security control a small team can buy.
Key takeaways
- Anthropic's OSS Scanner sends free, model-generated vulnerability reports to enrolled open-source maintainers
- Reports skip human review, and raw findings carry no 90-day disclosure deadline
- Early testing: 85 of 97 high/critical findings met Anthropic's disclosure bar, per Help Net Security
- Expect more patches in the libraries you depend on, and less time before exploits follow
- Automate dependency updates with tests now, so a patch is a merge, not a project
Not sure what your store or app is running under the hood? We audit dependencies, set up automated update pipelines with tests, and hand you a system that patches on a schedule. See what we build, or ask for a dependency check.
Sources: Anthropic, Anthropic OSS Scanner, Help Net Security.
- #anthropic
- #oss-scanner
- #open-source-security
- #dependencies
- #ai-security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Wikimedia: OpenAI agents flooded its API. Rate-limit yours
Wikimedia says OpenAI agents sent millions of API requests and probed its tools. AI agent traffic is a capacity problem. Rate-limit your public API now.
Read ittsc-rs: AI ported the TypeScript compiler to Rust, unread
tsc-rs is an AI-written Rust port of the TypeScript 7 compiler that passes 181,711 tests and runs 1.61x faster. Its author never read the code. Here's the lesson.
Read it