Apache Foundation Completes AI-Powered Security Scans Across 230 Repositories
The Apache Software Foundation (ASF) conducted full security scans across 230 of its code repositories during a three-day window in August 2026. The work was carried out jointly by the ASF Security and ASF Tooling teams under the Foundation's Responsible AI Initiative, using Anthropic's Claude Mythos 5 via a program called Project Glasswing. The effort was partly motivated by a rise in low-quality AI-generated vulnerability reports reaching open-source projects, prompting ASF to run its own rigorous, context-aware scans internally. Scanning was powered by an automated pipeline built on the Gofannon agent platform, evaluating code against the OWASP Application Security Verification Standard across three model tiers of increasing analytical depth. Findings are now being disclosed to the respective project teams through official ASF channels, with remediation already underway, and the initiative was made possible in part by a donation from Anthropic.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in