AI news · October 9, 2026
Anthropic opens free OSS Scanner after finding 29,000 candidate bugs
Anthropic's OSS Scanner found 29,000 candidate vulnerabilities in prior work and now offers free periodic scans to eligible projects, giving maintainers a faster first pass before human review.
- candidate findings
- 29,000+
- manually reviewed
- 6,000
- scanner cost
- $0

Anthropic launched OSS Scanner on Oct8 as an opt-in service for eligible open-source projects. It runs periodic scans with its strongest models at no cost; maintainers receive a reproducer, explanation, and possible patch. Anthropic says its previous work found more than 29,000 candidate vulnerabilities in six months, with about 6,000 manually reviewed.
The fast track sends model-generated reports without human triage, so it is not a substitute for a maintainer's review. In an early check of 97 high-severity findings across 48 projects, Anthropic says 85 met its disclosure bar and one was invalid; severity can still be wrong. Eligibility is aimed at projects with important security impact, and sign-up is a pull request to anthropics/oss-scanner.
What you can do with it
If you maintain an established open-source project with real security impact, read the eligibility rules and open the requested enrollment pull request. Use each report as a lead: reproduce it, check the severity, and review the patch before merging anything.
Our take
This is a useful free service for projects that can handle more reports, not a free security team. The honest value is speed: a maintainer may see a concrete reproducer earlier. The catch is that fast model output can still be wrong, so small projects may be overwhelmed rather than helped.
Links Try it Launch post Eligibility and FAQ
Source: Anthropic ↗ — Made With Models writes the brief; the reporting is theirs.