- Anthropic has launched OSS Scanner, a security vulnerability scanning service for open source projects. It said it provides regular scans free of charge to projects that choose to participate.
- The company explained that scanning frequently with its most powerful model can help projects learn of security problems earlier. This is the company's own claim, and the article does not independently confirm the actual effect.
- Reports are generated entirely by the model without human review or triage. The company directly acknowledged that, for this reason, reports may be inaccurate or invalid.
- May The Copy Fail vulnerability, which affected most Linux distributions, is one recent example of AI tools finding flaws in open source software. Meanwhile, some projects, including Linus Torvalds and Google, are struggling to keep up with the flood of AI-generated bug reports.
The line about a report that no person ever checks makes me pause. If wrong reports get mixed in, managers may end up spending more time sorting them out, so the work could actually grow. It might help to first consider how big the project is and how many people will review the reports.