AI news · October 9, 2026

Anthropic opens free OSS Scanner after finding 29,000 candidate bugs

securityopen-sourceanthropiccode

Anthropic's OSS Scanner found 29,000 candidate vulnerabilities in prior work and now offers free periodic scans to eligible projects, giving maintainers a faster first pass before human review.

candidate findings
29,000+
manually reviewed
6,000
scanner cost
$0
Made With Models illustration for this story

Anthropic launched OSS Scanner on Oct8 as an opt-in service for eligible open-source projects. It runs periodic scans with its strongest models at no cost; maintainers receive a reproducer, explanation, and possible patch. Anthropic says its previous work found more than 29,000 candidate vulnerabilities in six months, with about 6,000 manually reviewed.

The fast track sends model-generated reports without human triage, so it is not a substitute for a maintainer's review. In an early check of 97 high-severity findings across 48 projects, Anthropic says 85 met its disclosure bar and one was invalid; severity can still be wrong. Eligibility is aimed at projects with important security impact, and sign-up is a pull request to anthropics/oss-scanner.

What you can do with it

If you maintain an established open-source project with real security impact, read the eligibility rules and open the requested enrollment pull request. Use each report as a lead: reproduce it, check the severity, and review the patch before merging anything.

Our take

This is a useful free service for projects that can handle more reports, not a free security team. The honest value is speed: a maintainer may see a concrete reproducer earlier. The catch is that fast model output can still be wrong, so small projects may be overwhelmed rather than helped.

Source: Anthropic ↗ — Made With Models writes the brief; the reporting is theirs.