AI サービスが一時的に利用できないため、復旧後に翻訳を補完します。
Anthropic’s offering to help open-source projects track down security vulnerabilities with a new service called OSS Scanner. It says open-source projects that opt-in will get “thorough, periodic security scans by our strongest models at no cost.” That could mean open-source projects get alerted about possible security issues sooner, but the trade-off is that OSS Scanner’s reports don’t come with human review: > The outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage. This will enable faster and more frequent scanning, but means that it is possible reports will be incorrect or invalid. These reports will be generated by our strongest models (including Claude Mythos) to give open-source projects the largest defensive advantage. OSS Scanner is far from the first AI bug hunting helper out there. AI tools have helped find some major security flaws in open-source software over recent months, like the “Copy Fail” bug that impacted nearly every Linux distro in May. At the same time, some open-source projects are struggling to keep up with the sudden onslaught of AI-generated bug reports, including Linus Torvalds and even Google.