# OSS Scanner

> Anthropic's free, opt-in service scans eligible open-source projects with Claude and emails maintainers vulnerability reports and proposed patches.

OSS Scanner is a free security scanning service from Anthropic's Frontier Red Team for eligible open-source projects. It uses Claude to find potential vulnerabilities, double-check findings, propose patches, and analyze root causes. Maintainers receive model-generated reports by email, followed by periodic rescans for new or previously missed vulnerabilities. Reports are sent without prior human review.

Core maintainers apply through a pull request to Anthropic's OSS Scanner repository, providing project configuration and a Dockerfile for offline auditing. Acceptance is reviewed case by case, prioritizing established projects with significant impact on infrastructure and user security. Maintainers can supply a threat model, request encrypted reports, or pause participation. Anthropic covers the scanning cost.

## Features
- Opt-in vulnerability scanning of open-source repositories
- Reports delivered directly from models without prior human review
- Agents that double-check bugs, propose patches, and perform root cause analysis
- Periodic rescans for new and previously missed vulnerabilities
- Optional threat model file to guide the scanner
- PGP-encrypted email reports
- Offline sandboxed scanning using a maintainer-provided Dockerfile
- Enrollment and opt-out via pull request config

## Integrations
GitHub, Docker

## Platforms
ANDROID, IOS, WEB, API

## Pricing
Free

## Links
- Website: https://red.anthropic.com/oss-scanner/
- Documentation: https://red.anthropic.com/oss-scanner/#faq
- Repository: https://github.com/anthropics/oss-scanner
- EveryDev.ai: https://www.everydev.ai/tools/oss-scanner
