Anthropic 免费帮开源项目扫漏洞:OSS Scanner 上线了

Anthropic's Free Vulnerability Scanning for Open Source: OSS Scanner Is Live

Tech-News #安全#开源#Anthropic#AI工具#漏洞扫描
🇨🇳 中文

如果你维护一个被大量项目依赖、会处理不可信输入的开源仓库,Anthropic 2026-10-08 上线的 OSS Scanner 值得申请:用前沿模型做周期性漏洞扫描,费用为零。

官方公告:https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source 申请入口:https://red.anthropic.com/oss-scanner/ GitHub 仓库:https://github.com/anthropics/oss-scanner


申请方式:一个 PR

1. Fork anthropics/oss-scanner
2. 新建 projects/<你的项目名>/project.yaml
3. 填写必填字段 + 提 PR

project.yaml 必填字段:

  • 仓库地址(URL)
  • 公开的安全联系邮箱(用于接收漏洞报告)
  • Dockerfile(供扫描器构建和分析项目)

可选但建议写:

  • threat_model.md:描述你的威胁模型,帮助扫描器聚焦高风险区域

提交前可运行本地验证:

python tools/validate.py

完整本地检查需要 Git、Docker、Python 3 + PyYAML。


申请条件:不是任意仓库都收

Anthropic 逐案审核,主要考量:

维度说明
安全影响对基础设施或用户安全影响程度
攻击暴露面是否有远程可利用的攻击路径
依赖量有多少下游项目依赖这个仓库
维护者身份会验证申请人是否是核心维护者

官方定位是”对安全生态有高乘数效应”的项目,不是个人小工具。


扫描流程和边界

构建阶段:可以联网(安装依赖等)

扫描阶段:在禁网沙箱内运行,扫描器无法在分析过程中访问外部网络

报告生成:由 AI 模型直接生成,无人工预审

这是这个服务最需要注意的地方:

⚠️ 报告可能误报(False Positive),可能错误判断漏洞严重程度,AI 建议的补丁也可能破坏功能。维护者必须对所有发现进行人工复核,不能直接采纳。


报告的使用规则

  • 报告含敏感漏洞信息,应当保密
  • 用途限于修复本项目,不用于其他目的
  • Anthropic 未说明中文支持情况(官方文档为英文)

它解决什么问题

开源安全审计一直是个资源问题:商业工具要付费,人工审计要时间,大多数项目的核心维护者精力有限。OSS Scanner 针对的是这个真实的资源缺口——用 AI 模型提供一个”基线”扫描层,让维护者不需要付费或等人工安排就能获得周期性的安全分析。

代价是扫描质量依赖模型能力,报告需要人工复核,无法替代专业的人工安全审计。这是一个”免费基线”而不是”完整解决方案”。


一句话说清楚

Anthropic OSS Scanner 是一个申请制的免费服务:高影响开源项目的核心维护者提 PR 申请后,Anthropic 的前沿模型会周期性地扫描代码漏洞。报告 AI 直出无人工预审,维护者需自己复核——这是工具,不是托底。


Anthropic,2026-10-08 上线。申请入口:https://red.anthropic.com/oss-scanner/ | GitHub: https://github.com/anthropics/oss-scanner


🇬🇧 English

Anthropic’s Free Vulnerability Scanning for Open Source: OSS Scanner Is Live

If you maintain a widely-depended-on open-source project that handles untrusted input, Anthropic’s OSS Scanner — launched 2026-10-08 — is worth applying for: periodic AI-powered vulnerability scanning at no cost.

Announcement: https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source Apply: https://red.anthropic.com/oss-scanner/ GitHub: https://github.com/anthropics/oss-scanner


How to Apply: One PR

1. Fork anthropics/oss-scanner
2. Create projects/<your-project>/project.yaml
3. Fill in required fields + submit PR

Required fields in project.yaml:

  • Repository URL
  • Public security contact email (for receiving reports)
  • Dockerfile (for the scanner to build and analyze the project)

Optional but recommended:

  • threat_model.md: describes your threat model to help the scanner focus on high-risk areas

Local validation before submitting:

python tools/validate.py

Full local checks require Git, Docker, Python 3 + PyYAML.


Who Qualifies

Anthropic reviews case by case, weighing:

  • Security impact on infrastructure or end users
  • Remote attack surface exposure
  • Downstream dependency count
  • Verification that the applicant is a core maintainer

The target is projects with a high security multiplier effect on the ecosystem, not personal utilities.


Scan Process and Boundaries

Build phase: network access allowed (for installing dependencies)

Scan phase: runs in a network-isolated sandbox

Report generation: AI-generated directly, no human pre-review

This is the most important thing to know:

⚠️ Reports may contain false positives, incorrect severity judgments, and patches that could break functionality. Maintainers must manually review every finding before acting on it.


Report Rules

  • Reports contain sensitive vulnerability details and should be kept confidential
  • Use is restricted to fixing the scanned project
  • No information on Chinese language support (documentation is in English)

What Problem It Solves

Open-source security auditing has always been a resource problem: commercial tools cost money, manual audits take time, and most maintainers operate with limited capacity. OSS Scanner targets this gap — a free baseline scanning layer that doesn’t require budget or scheduling a human audit.

The trade-off: report quality depends on model capability, reports require human review, and this doesn’t replace professional security audits. It’s a “free baseline,” not a “complete solution.”


Anthropic, launched 2026-10-08. Apply at https://red.anthropic.com/oss-scanner/ | GitHub: https://github.com/anthropics/oss-scanner

💬 评论与讨论

使用 GitHub 账号登录后发表评论

关于本站 · 免责声明

🍄 Mushroom Research Blog 是非营利、免费公开的个人科技观察博客与公众号 XStack18,不接受商业合作、不代表任何企业或机构立场,也不谋求商业利益。我们以个人视角客观中立地记录和分析 AI、Web3 等领域的最新模型发布与技术动态——不止转述新闻标题或二手信息,而是给出有独立思考的深入分析,希望帮更多人获得有价值的一手科技认知。

⚠️ 文中介绍的开源代码与模型,仅供学习交流与技术借鉴。它们大多仍处于早期阶段,有待进一步研究和验证,请勿直接用于工作或生产环境;如需采用,请先自行充分测试,并核实其许可证与安全性。
Open-source code and models featured here are shared for learning and reference only. Most are early-stage and still need further study and verification — please don't use them directly in your work or in production. Test them thoroughly and check their licenses and security first.

  1. 本站文章均为作者基于公开信息的个人研究与观点整理,不代表文中提及的任何公司、产品、模型的官方立场,未与其构成商业关联或合作关系。
  2. 科技行业信息更新极快,我们尽力保证内容准确、及时,但不对完整性、实时性做绝对保证,具体请以相关企业/项目官方公告为准。
  3. 文中引用的第三方商标、产品名称、图片、数据等版权归原权利人所有,我们会尽量注明来源;如你认为存在版权疑问或侵权,请通过下方邮箱联系我们,收到通知后会尽快核实处理(更正、加注来源或删除)。
  4. 文章内容仅为技术科普与个人观点,不构成投资、法律或其他专业建议,据此进行任何决策的后果需自行判断和承担。

📮 侵权 / 勘误 / 合作咨询:[email protected]