Skip to content
ossscanner.org

FAQ

Frequently asked questions

Everything about scanning, reports, enrollment and how we handle your code.

Scanning

Which repositories can I scan?

Any public git repository reachable over HTTPS: GitHub, GitLab, Codeberg, Bitbucket, Gitea or Forgejo instances and self-hosted forges. Private repositories and links with credentials are not supported.

Which languages are supported?

The audit reads source as text, so it works for most languages: C, C++, Rust, Go, Java, Kotlin, C#, Python, JavaScript, TypeScript, PHP, Ruby, Swift, Scala, Elixir, Lua, shell and more. The deepest results are usually in C/C++ parsers, web backends and anything that handles untrusted input.

How long does a scan take?

A quick scan usually finishes in 3–10 minutes, depending on size and queue. Deep scans for enrolled projects read more code and can take 15–40 minutes.

Is there a size limit?

Very large repositories are partly audited: the scanner ranks files by risk and reads the riskiest ones within its budget. The report shows how many files and lines were actually read.

Can I scan a specific branch?

Yes. Click Branch under the input field, or paste a link to a branch such as …/tree/release-2.4.

Why are there limits per day?

Every scan costs real money in model usage. To keep the service free we cap scans per visitor and per repository and set a daily budget. If it runs out, try again the next day (UTC).

Reports and accuracy

How accurate are the findings?

Each finding survived an independent verifier agent that tried to disprove it, and the report shows how many candidates were rejected. Still, findings are model-generated and not reviewed by humans: severity can be inflated and the model can misread your threat model. Treat findings as strong leads.

The report says no vulnerabilities. Is my project secure?

No scanner can promise that. A clean report means the riskiest code we read didn't show bugs the verifier could defend. Fuzzing, review and enrolling for deep scans all add coverage.

Why can't I see the reproducer?

Reproducers are shown only after someone proves write access to the repository by committing a token file. This keeps ready-made exploits out of the hands of people who merely paste a link.

What do I do with SARIF?

Upload it to GitHub code scanning (github/codeql-action/upload-sarif) or any tool that reads SARIF 2.1.0. Findings then appear as alerts on the right lines.

How should I credit a fix?

It's optional, but a line such as “Reported-by: OSS Scanner (ossscanner.org), OSS-2026-XXXXXXXX” in the commit message helps us measure which findings were real.

Can I report a false positive?

Yes — use Valid, False positive or Known/duplicate under each finding. We use this feedback to tune prompts and thresholds.

Privacy and safety

Who can see my report?

Only people with the link. Report IDs are random and unguessable, pages are marked noindex and are not listed anywhere.

Do you keep my source code?

No. The clone is deleted when the scan ends. Reports keep short snippets of the affected lines, the threat model and metadata such as the commit hash.

Is the code sent to an AI provider?

Yes. Selected files are sent to Claude models via OpenRouter, which routes to Anthropic, Amazon Bedrock or Google Vertex. Only public code is scanned.

Will you publish my vulnerabilities?

Never. We don't publish findings, file public issues or set disclosure deadlines.

Enrollment

What does enrollment add?

Deep scans with the strongest model and a larger budget, automatic weekly rescans when new commits land, reports by email and a persistent threat model.

How do you know I'm a maintainer?

You commit a file named ossscanner-verify.txt containing a token we give you. Only people with write access can do that.

Can I pause or leave?

Yes, at any time from your management link: pause, resume or delete the project.

Anthropic OSS Scanner

Are you Anthropic?

No. ossscanner.org is an independent project, not affiliated with or endorsed by Anthropic. We use Claude models through a public API.

What is Anthropic's OSS Scanner?

A free, opt-in service launched on October 8, 2026 that scans critical open-source projects with Anthropic's strongest models, including Claude Mythos, and emails unreviewed reports to maintainers. Projects enroll with a pull request to github.com/anthropics/oss-scanner.

Can I use both?

Yes. Our threat model builder produces the same .oss-scanner/threat_model.md file Anthropic's scanner reads, and our guide generates the project.yaml for their pull request.