deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

Anthropic's disclosure ledger: 6,157 open-source bugs reported, 516 patched upstream

Anthropic's Frontier Red Team dashboard reports 6,157 vulnerabilities disclosed across 591 open-source projects, with only 516 patched upstream so far, shifting the bottleneck to maintainer capacity.

Anthropic's disclosure ledger: 6,157 open-source bugs reported, 516 patched upstream

What the ledger counts

Anthropic's Frontier Red Team dashboard, last updated on 2 October 2026, reports 6,157 vulnerabilities disclosed across 591 open-source projects, according to a dev.to analysis of the data. Of that set, 5,103 reports have been acknowledged by maintainers, and 516 are known to have been patched upstream — about 8.4% of the disclosed total. The dashboard itself adds a caveat: a released patch does not guarantee that the fix has been widely installed.

The programme is explicit about its scope and method. It began in February 2026 with an early snapshot of Claude Mythos Preview, relies on external security research firms to reproduce and assess findings, and publishes details only once a finding's disclosure window has closed. Findings still inside the window appear as commitment hashes, making their existence and date provable while their content stays withheld. Of the 584 identifiers the programme has issued, 219 are CVEs and 365 are GitHub Security Advisories — with the notes that one finding can carry both, and that maintainers sometimes ship a fix without publishing an advisory at all.

The funnel above the headline

The numbers that explain the patch rate sit upstream of it. Across the reporting window the dashboard covers, from 1 November 2025 to 2 October 2026, the programme logged 29,439 discovered findings, of which 6,123 became candidates for human triage. External firms reviewed 5,674 of those candidates and confirmed 92.7% of the triaged set as true positives. Another 4,824 findings went straight to maintainers without the independent check, at the maintainers' own request.

Anthropic is unusually frank about how weak some of these metrics are. As the dev.to piece highlights, the dashboard's About page says the true-positive rate includes real bugs that had already been reported elsewhere and real bugs a maintainer chose not to fix, and that a vendor can miscategorise a finding in either direction. The company names the patch count as the more reliable figure, while conceding that patches take a long time to create — and that some confirmed findings remain unsent because of capacity limits inside the programme itself.

The policy that shapes the curve

The disclosure policy sets the timelines that produce these numbers. Standard reports run on a 90-day deadline, with a 14-day extension available when a maintainer is engaged and making progress. Actively exploited critical vulnerabilities get a compressed seven-day target for a patch or mitigation, extendable by a further seven days at the maintainer's request. Once a patch exists, full technical detail waits another 45 days so downstream users have time to deploy.

Two clauses show where the leverage sits. When Anthropic and a maintainer disagree on severity, the company generally defers to the maintainer's assessment, with active exploitation as the stated exception. A maintainer who stays silent for 30 days triggers escalation to an external coordinator, with public disclosure following at the end of the applicable timeline. The policy also commits the programme to pacing its submissions to what maintainers can realistically absorb, rather than pushing large volumes of findings at a single project without an agreed rate.

Why it matters

Read in sequence — 6,157 disclosed, 5,103 acknowledged, 516 patched — the ledger shows where the constraint in AI-assisted security research has moved. Discovery now scales with compute; remediation still scales with people, and most open-source projects are run by volunteers or small teams who must understand, reproduce, fix, test and release each report that arrives. Patch rate, not finding rate, is the number a security team can act on, and it is bounded by the capacity of the projects receiving the reports.

The ledger is also notable as an act of transparency: a vendor publishing both ends of the pipeline, the discoveries and the patches, including its own unsent backlog. For maintainers, the practical signal is that coordinated, paced disclosure with explicit timelines is becoming the default for machine-discovered bugs. For teams that consume open source, the next gap to measure is the one the dashboard already flags — between a patch released and a patch actually installed.

  • #anthropic
  • #open-source
  • #security
  • #vulnerability-disclosure
  • #ai

Related posts