📊 See open-source project rankings

📱 Get the AI Rank app

Anthropic OSS Scanner is a free, opt-in service that periodically checks eligible open-source projects for security vulnerabilities. Core maintainers apply through the official enrollment repository. Its reports are model-generated and arrive without human review, so a team needs capacity to reproduce and triage findings before signing up. Official announcement

For maintainers, the practical question is whether the project can build in a prepared environment and whether someone can act on incoming reports. Start with the eligibility FAQ and enrollment template, rather than treating this as a scanner you install into every pull request. This guide checks the official materials available on October 10, 2026; we have not enrolled a project or measured detection quality.

Who should apply?

Anthropic evaluates established projects with important infrastructure or user-security impact, considering exposure to remote attacks and how many users or projects depend on them. Acceptance is case by case, and the service verifies core-maintainer status. Explain your project's importance in the application. Eligibility criteria and scan frequency can change; applying does not guarantee acceptance or a fixed schedule. Eligibility FAQ

Our editorial recommendation is to assign a security contact and agree on a triage process first. A free service still takes maintainer time: a plausible report needs reproduction, a severity decision and a patch review.

Prepare the enrollment files

Use the current official project template. Create projects/<name>/project.yaml in a fork of the enrollment repository. Its key fields are:

Field What to prepare
repo The HTTPS Git repository to audit; the template supports a branch or tag suffix.
primary_contact A monitored security email address.
dockerfile A relative build-file path in your repository, unless you place a Dockerfile beside the enrollment YAML.
threat_model Optional path documenting security assumptions and audit scope.
disabled Optional pause control.

The template also documents optional CC and OpenPGP settings. Choose a public security alias: enrollment email addresses appear in the public repository. Do not put credentials or private vulnerability details in a public pull request. Contribution instructions

Make the audit environment usable offline

The build stage fetches dependencies; the subsequent audit has no Internet access. Prepare dependencies and test fixtures in the image, then check that tests work there. Define which inputs are untrusted, what is out of scope and how severity should be assessed. These are project-specific decisions, not a generic configuration to copy blindly. Build and threat-model guidance

From the enrollment repository, the official pre-submission checks are:

tools/validate.py
tools/check <name>

Replace <name> with your enrollment directory name. Follow the README's current prerequisites: Git, Docker, Python 3 and PyYAML for the normal check path. Run checks only for a project you trust: the build executes its Dockerfile with network access. We have verified these instructions against the documentation, not run your project's build. Official README

Open one project-enrollment pull request, complete its checklist, and follow the contributor agreement bot's instructions if this is your first contribution. Enrollment is subject to maintainer verification and approval. Contribution process

Handle reports as findings to investigate

The launch announcement describes reports with reproducers, explanations and candidate patches when available. They may be incorrect. Our recommended workflow is to reproduce in an isolated environment, inspect the claimed trust boundary and review the proposed fix with regression tests before merging. Report format and limitations

The FAQ says the unvalidated reports have no imposed 90-day disclosure period; a report later validated by a human under the separate coordinated-disclosure program may follow that program's policy. Check the current FAQ and terms before enrollment. Disclosure policy

For a separate code-review workflow, Alibaba Open Code Review on AI Rank provides a related project to investigate. AI Rank's October 10, 2026 project snapshot records 44,796 GitHub stars, a one-day gain of 320 and a seven-day gain of 1,489. These are attention signals, not vulnerability-detection scores, proof of adoption or evidence that this project replaces OSS Scanner. Dated project data

→ Project ranking: alibaba/open-code-review on AI Rank — daily GitHub star growth

📱 Follow it in the AI Rank app

Use the project profile to discover tooling, then evaluate its documented scope against your own review process. For OSS Scanner itself, the next step is the official eligibility FAQ and enrollment template. If your team cannot currently triage additional reports, prepare that capacity before applying.

Keep exploring: see which open-source AI projects are rising today in the open-source rankings on AI Rank.

Or 📱 get the AI Rank app to follow them on your phone.