Anthropic launches free AI scanning of open-source projects — The Verge
Anthropic has launched OSS Scanner, a free service for finding vulnerabilities in open-source projects. Projects that voluntarily connect to the service will be able to regularly receive detailed reports on potential security issues, The Verge reports.
Reports without human review
Anthropic said that scans will be conducted by its most powerful models, including Claude Mythos. At the same time, OSS Scanner results will be generated entirely by the models, without human review or initial screening of reports.
According to the company, this approach makes it possible to conduct checks faster and more frequently. However, Anthropic warns that some reports may be erroneous or invalid.
More current news is available on the UA.News Telegram channel Telegram.
AI for finding bugs
Artificial intelligence-based tools have already helped identify serious security flaws in open-source software. In particular, The Verge mentions the Copy Fail bug, which affected nearly all Linux distributions in May.
At the same time, some open-source projects are trying to cope with a sharp increase in AI-generated vulnerability reports. According to the publication, Linus Torvalds and Google have faced this problem, among others.