Anthropic releases OSS scanner using Claude AI exceeding 85% detection
Anthropic just dropped OSS Scanner, a free tool that uses its Claude AI to help open-source developers catch security bugs in their code.
Built using insights from Project Glasswing, the scanner now finds vulnerabilities with more than 85% success rate, from fewer than 20% early last year.
Core maintainers of eligible projects can enroll by submitting a pull request to Anthropic's GitHub repository.
Experts confirm most OSS scanner findings
Security experts put OSS Scanner through its paces and confirmed most of its findings were legitimate, though one false positive popped up.
The feedback has been great so far: PostgreSQL maintainer Noah Misch said several reports came with fixes the project could use nearly as they were, and OpenSSL Corporation's Anton Arapov said the reports, raw model output included, were as good as and sometimes better than those from people, especially when an exploit was attached.
Core maintainers of eligible projects can enroll by submitting a pull request to Anthropic's GitHub repository.