

“The outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage,” Anthropic explained. “This will enable faster and more frequent scanning, but means that it is possible reports will be incorrect or invalid.”
When I saw the headline, I was wondering about this specifically. This may make this service not super useful.
My experience with AI security reviews is that they’re fantastic at finding faults, but they always find a list of things to complain about. If there are no real/serious faults they’ll start finding things that kind of have the same shape as a security issue, but really aren’t if you dig into them. I’ve regularly had an LLM generate a list of 10-15 issues ranging in severity from “nits” to “critical” where none of them were actual issues.
Periodic reviews seem like they could get annoying really quickly, becoming more of a maintenance burden than a help.

GPL (and copyleft generally) gets way more attention than it should. In the wild, MIT and similar permissive licenses are by far the most common. Linux is on GPL, but that may be a historical artifact as much as anything. I don’t know if Linus himself would choose it if he were making the choice today.
The wider FOSS community, in my experience, leans permissive rather than copyleft. The copyleft people are just loud.
EDIT: To be clear, when I say I don’t know what choice Linus would make today, I don’t mean that I’m skeptical he’d choose GPL. I literally just mean that I don’t know. He’s been quite clear that he’s not a principled believer in copyleft, but it does have real advantages for a project like the Linux kernel.