Anthropic launches free AI security scans for open-source projects

Anthropic launches free AI security scans for open-source projects

Anthropic 推出针对开源项目的免费 AI 安全扫描服务。

The new OSS Scanner service offers vulnerability reports from Anthropic’s “strongest models,” including Mythos.

这项全新的 OSS Scanner 服务提供来自 Anthropic“最强模型”(包括 Mythos)的漏洞报告。

Anthropic’s offering to help open-source projects track down security vulnerabilities with a new service called OSS Scanner. It says open-source projects that opt-in will get “thorough, periodic security scans by our strongest models at no cost.” That could mean open-source projects get alerted about possible security issues sooner, but the trade-off is that OSS Scanner’s reports don’t come with human review:

Anthropic 推出了一项名为 OSS Scanner 的新服务,旨在帮助开源项目追踪安全漏洞。该公司表示,选择加入的开源项目将“免费获得由我们最强模型进行的全面、定期安全扫描”。这意味着开源项目可能会更早收到潜在安全问题的警报,但代价是 OSS Scanner 的报告不经过人工审核:

The outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage. This will enable faster and more frequent scanning, but means that it is possible reports will be incorrect or invalid. These reports will be generated by our strongest models (including Claude Mythos) to give open-source projects the largest defensive advantage.

此项可选漏洞扫描器的输出将完全由模型生成,无需人工审核或分类。这将实现更快、更频繁的扫描,但也意味着报告可能会出现错误或无效。这些报告将由我们最强的模型(包括 Claude Mythos)生成,以赋予开源项目最大的防御优势。

OSS Scanner is far from the first AI bug hunting helper out there. AI tools have helped find some major security flaws in open-source software over recent months, like the “Copy Fail” bug that impacted nearly every Linux distro in May. At the same time, some open-source projects are struggling to keep up with the sudden onslaught of AI-generated bug reports, including Linus Torvalds and even Google.

OSS Scanner 远非市面上首个 AI 漏洞搜寻助手。近几个月来,AI 工具已帮助发现了开源软件中的一些重大安全漏洞,例如 5 月份影响了几乎所有 Linux 发行版的“Copy Fail”漏洞。与此同时,一些开源项目正疲于应对 AI 生成的漏洞报告的突然激增,其中包括 Linus Torvalds 领导的项目,甚至连谷歌也面临同样的困扰。