Anthropic 免费帮开源项目扫漏洞:OSS Scanner 上线了
Anthropic's Free Vulnerability Scanning for Open Source: OSS Scanner Is Live
如果你维护一个被大量项目依赖、会处理不可信输入的开源仓库,Anthropic 2026-10-08 上线的 OSS Scanner 值得申请:用前沿模型做周期性漏洞扫描,费用为零。
官方公告:https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source 申请入口:https://red.anthropic.com/oss-scanner/ GitHub 仓库:https://github.com/anthropics/oss-scanner
申请方式:一个 PR
1. Fork anthropics/oss-scanner
2. 新建 projects/<你的项目名>/project.yaml
3. 填写必填字段 + 提 PR
project.yaml 必填字段:
- 仓库地址(URL)
- 公开的安全联系邮箱(用于接收漏洞报告)
- Dockerfile(供扫描器构建和分析项目)
可选但建议写:
threat_model.md:描述你的威胁模型,帮助扫描器聚焦高风险区域
提交前可运行本地验证:
python tools/validate.py
完整本地检查需要 Git、Docker、Python 3 + PyYAML。
申请条件:不是任意仓库都收
Anthropic 逐案审核,主要考量:
| 维度 | 说明 |
|---|---|
| 安全影响 | 对基础设施或用户安全影响程度 |
| 攻击暴露面 | 是否有远程可利用的攻击路径 |
| 依赖量 | 有多少下游项目依赖这个仓库 |
| 维护者身份 | 会验证申请人是否是核心维护者 |
官方定位是”对安全生态有高乘数效应”的项目,不是个人小工具。
扫描流程和边界
构建阶段:可以联网(安装依赖等)
扫描阶段:在禁网沙箱内运行,扫描器无法在分析过程中访问外部网络
报告生成:由 AI 模型直接生成,无人工预审
这是这个服务最需要注意的地方:
⚠️ 报告可能误报(False Positive),可能错误判断漏洞严重程度,AI 建议的补丁也可能破坏功能。维护者必须对所有发现进行人工复核,不能直接采纳。
报告的使用规则
- 报告含敏感漏洞信息,应当保密
- 用途限于修复本项目,不用于其他目的
- Anthropic 未说明中文支持情况(官方文档为英文)
它解决什么问题
开源安全审计一直是个资源问题:商业工具要付费,人工审计要时间,大多数项目的核心维护者精力有限。OSS Scanner 针对的是这个真实的资源缺口——用 AI 模型提供一个”基线”扫描层,让维护者不需要付费或等人工安排就能获得周期性的安全分析。
代价是扫描质量依赖模型能力,报告需要人工复核,无法替代专业的人工安全审计。这是一个”免费基线”而不是”完整解决方案”。
一句话说清楚
Anthropic OSS Scanner 是一个申请制的免费服务:高影响开源项目的核心维护者提 PR 申请后,Anthropic 的前沿模型会周期性地扫描代码漏洞。报告 AI 直出无人工预审,维护者需自己复核——这是工具,不是托底。
Anthropic,2026-10-08 上线。申请入口:https://red.anthropic.com/oss-scanner/ | GitHub: https://github.com/anthropics/oss-scanner
Anthropic’s Free Vulnerability Scanning for Open Source: OSS Scanner Is Live
If you maintain a widely-depended-on open-source project that handles untrusted input, Anthropic’s OSS Scanner — launched 2026-10-08 — is worth applying for: periodic AI-powered vulnerability scanning at no cost.
Announcement: https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source Apply: https://red.anthropic.com/oss-scanner/ GitHub: https://github.com/anthropics/oss-scanner
How to Apply: One PR
1. Fork anthropics/oss-scanner
2. Create projects/<your-project>/project.yaml
3. Fill in required fields + submit PR
Required fields in project.yaml:
- Repository URL
- Public security contact email (for receiving reports)
- Dockerfile (for the scanner to build and analyze the project)
Optional but recommended:
threat_model.md: describes your threat model to help the scanner focus on high-risk areas
Local validation before submitting:
python tools/validate.py
Full local checks require Git, Docker, Python 3 + PyYAML.
Who Qualifies
Anthropic reviews case by case, weighing:
- Security impact on infrastructure or end users
- Remote attack surface exposure
- Downstream dependency count
- Verification that the applicant is a core maintainer
The target is projects with a high security multiplier effect on the ecosystem, not personal utilities.
Scan Process and Boundaries
Build phase: network access allowed (for installing dependencies)
Scan phase: runs in a network-isolated sandbox
Report generation: AI-generated directly, no human pre-review
This is the most important thing to know:
⚠️ Reports may contain false positives, incorrect severity judgments, and patches that could break functionality. Maintainers must manually review every finding before acting on it.
Report Rules
- Reports contain sensitive vulnerability details and should be kept confidential
- Use is restricted to fixing the scanned project
- No information on Chinese language support (documentation is in English)
What Problem It Solves
Open-source security auditing has always been a resource problem: commercial tools cost money, manual audits take time, and most maintainers operate with limited capacity. OSS Scanner targets this gap — a free baseline scanning layer that doesn’t require budget or scheduling a human audit.
The trade-off: report quality depends on model capability, reports require human review, and this doesn’t replace professional security audits. It’s a “free baseline,” not a “complete solution.”
Anthropic, launched 2026-10-08. Apply at https://red.anthropic.com/oss-scanner/ | GitHub: https://github.com/anthropics/oss-scanner
关于本站 · 免责声明
🍄 Mushroom Research Blog 是非营利、免费公开的个人科技观察博客与公众号 XStack18,不接受商业合作、不代表任何企业或机构立场,也不谋求商业利益。我们以个人视角客观中立地记录和分析 AI、Web3 等领域的最新模型发布与技术动态——不止转述新闻标题或二手信息,而是给出有独立思考的深入分析,希望帮更多人获得有价值的一手科技认知。
⚠️ 文中介绍的开源代码与模型,仅供学习交流与技术借鉴。它们大多仍处于早期阶段,有待进一步研究和验证,请勿直接用于工作或生产环境;如需采用,请先自行充分测试,并核实其许可证与安全性。
Open-source code and models featured here are shared for learning and reference only. Most are early-stage and still need further study and verification — please don't use them directly in your work or in production. Test them thoroughly and check their licenses and security first.
- 本站文章均为作者基于公开信息的个人研究与观点整理,不代表文中提及的任何公司、产品、模型的官方立场,未与其构成商业关联或合作关系。
- 科技行业信息更新极快,我们尽力保证内容准确、及时,但不对完整性、实时性做绝对保证,具体请以相关企业/项目官方公告为准。
- 文中引用的第三方商标、产品名称、图片、数据等版权归原权利人所有,我们会尽量注明来源;如你认为存在版权疑问或侵权,请通过下方邮箱联系我们,收到通知后会尽快核实处理(更正、加注来源或删除)。
- 文章内容仅为技术科普与个人观点,不构成投资、法律或其他专业建议,据此进行任何决策的后果需自行判断和承担。
📮 侵权 / 勘误 / 合作咨询:[email protected]
💬 评论与讨论
使用 GitHub 账号登录后发表评论