An automated security report from Anthropic’s OSS Scanner is not the start of a 90-day countdown to publication. Our five-document review finds that the scanner-specific clock starts only after Anthropic notifies a participant of its own human validation. But that wording leaves an important question unresolved: how earlier-publication provisions in the linked disclosure policy apply.
Original analysis: We compared five supplied primary documents: Anthropic’s launch announcement, OSS Scanner overview and FAQ, enrollment README, service agreement, and linked coordinated vulnerability disclosure policy. Coordinated vulnerability disclosure, or CVD, is the process Anthropic uses to notify maintainers and coordinate public sharing of confirmed security findings. The comparison follows three states: unreviewed delivery, subsequent Anthropic validation, and ordinary CVD reporting after opt-out.
This is a saved-document comparison, not a scanner test or a new collection. The requested evidence cutoff was October 10, 2026, at 15:30 UTC; supplied snapshots were retrieved at 15:31:39.935 UTC. Previously recorded live checks corroborate core wording, but exact document versions at the cutoff remain unverified. The findings describe the checked rules, not a measured delivery sequence.
The fast track removes human triage, not responsibility
Anthropic introduced OSS Scanner on October 8 as a free, opt-in service for open-source projects. Its launch announcement describes a fast track that sends fully model-generated findings without human review or triage, while retaining the existing human-verified CVD route. Faster delivery therefore changes who checks a report before it reaches the project, rather than establishing that every suspected flaw is confirmed.
The pipeline still includes agents that double-check bugs, propose patches and analyze their underlying causes. Those automated steps are distinct from human review. The agreement warns that a report can miss vulnerabilities, mistake a non-vulnerability for a flaw, or misjudge severity. A proposed patch may also be incomplete or break functionality. A detailed report is not, by itself, a human-validated finding.
That distinction explains the initial disclosure treatment. The FAQ excludes unvalidated findings from any 90-day coordinated-disclosure period. The enrollment README goes further on publication: Anthropic says it will not make those model-generated, unreviewed findings public. Neither automated arrival nor the scanner’s internal double-checking starts the scanner-specific clock.
An inbox arrival is not permission to redistribute
No publication countdown does not mean no participant obligations. The service agreement requires the participant to review each report and any proposed patch before using it to change the project or sharing the report. It supplies no prescribed review procedure or completion deadline. That leaves the review method unspecified, but does not remove the requirement to check the material first.
The agreement also limits use to identifying, assessing and fixing vulnerabilities or other bugs in the enrolled project. It expressly permits sharing with authorized project maintainers—not unrestricted redistribution. Participants must take reasonable steps to keep reports confidential and secure until the vulnerability is fixed or publicly disclosed. Publication timing and permission to share are separate questions under these provisions.
Delivery settings add another distinction. Projects can configure a primary contact and additional email CCs; encrypted delivery goes only to the primary contact and cannot include CCs. These settings describe where Anthropic sends reports. They do not expressly broaden the agreement’s sharing permission. The treatment of outside consultants, external coordinators and other non-maintainer recipients remains unresolved, even if an address can be entered in the configuration.
Validation creates a clock—and a policy boundary
A report can move into a different state if Anthropic subsequently validates it manually through its CVD program. Both the FAQ and agreement tie the scanner-specific period to notification that this validation occurred. Anthropic may disclose starting 90 days after that notice, not after the original automated delivery. Maintainer validation alone is not identified as the trigger, and subsequent Anthropic validation is not guaranteed.
The linked CVD policy complicates that reading. Marked last updated March 6, 2026, it targets public sharing with defenders after 90 days or after a patch is released, whichever comes first. It also allows deviations, including a seven-day patch-or-mitigation target for actively exploited critical vulnerabilities. These are policy targets and exceptions, not a single unconditional publication schedule.
Public sharing also differs from publishing full technical details. The CVD policy generally waits 45 days after a patch becomes available before releasing those details, to allow downstream users to deploy the fix. That buffer can be shortened or extended for stated reasons. It is a separate stage, not evidence that every disclosure must wait 45 additional days.
Leaving the scanner does not erase received reports
Maintainers can pause reports by submitting a pull request that sets disabled: true, or withdraw by submitting one that deletes the project’s enrollment directory. The FAQ says opt-out stops automated unvalidated reports and returns the project to receiving only standard CVD reports. Leaving this optional route therefore does not mean Anthropic stops sending vulnerability reports through its ordinary human-reviewed process.
Nor does withdrawal wipe out duties attached to reports already received. The agreement expressly preserves its permitted-use, review, security/disclosure and liability provisions after termination. The documents specify neither pull-request processing latency nor treatment of queued reports. They also provide no cancellation or reset of an existing validation-notice period upon withdrawal. Enrollment status and existing report obligations are not interchangeable.
Reader comments
Newest comments first. Replies stay oldest first.