Anthropic said it is launching OSS Scanner, a free, opt-in service that scans open-source code for security flaws. Eligible projects can enrol, judged case by case on OSS-Fuzz-style criteria, such as critical impact on infrastructure and user security. Google's OSS-Fuzz feeds code odd inputs to trigger crashes. Anthropic said each OSS Scanner report adds a reproducer (a test that triggers the flaw), an explanation, and a patch when available. Some findings chained into remote code execution without a login. The Verge covered the launch on 8 October.
Anthropic said it found over 29,000 possible flaws in six months but reviewed only about 6,000 by hand. Scanner reports get no human review, so some may be wrong. In an early test, 85 of 97 critical and high-severity findings met Anthropic's bar. Eleven were real but repeated known issues, and one was invalid. The sources do not say how many projects have joined or how often scans will run.
Finding bugs is no longer the slow step; checking them is. Anton Arapov of OpenSSL Corporation said a report with a real exploit can be verified right away. Ask your key open-source suppliers: do they take part, who checks the reports, and how fast do they ship patches?