Launching an opt-in vulnerability-finding service for open-source software
anthropic.com
anthropic.com
1. It's opt-in, anyone that doesn't want to receive these reports, or has reasons to not want AI used on their project gets that by default.
2. It's free for OSS projects, many of us won't spend money for a hobby we work on in our spare time and give away.
3. The reports go back to the maintainer, and not to potential attackers.
I would like to see more locally run models in this space, breaking the dependency on SaaS vendors. Even though those local models can't be controlled and would therefore be used by attackers. At some point, we'll get past this wave of newly discovered issues that have been lurking in the code for years, and the scans should run like any other linter or dependency checking tool.