OSS Scanner Agreement
This OSS Scanner Agreement (the "Agreement") governs your (“Participant”) access to and use of the OSS Scanner (the “Service”). Participant’s use of the Service is also subject to Anthropic's Consumer Terms of Service, as they apply to the Service (the "Terms"), which are incorporated into this Agreement by reference. If the Terms conflict with this Agreement, this Agreement controls.
1. Generally. Participant will provide Anthropic with the source code from a submitted open-source project approved in writing by Anthropic for the Service (each, a “Project”). Anthropic may approve a Project or withdraw its approval, in its sole discretion. Anthropic will scan that source code for security vulnerabilities and provide Participant with a report of the results (each, a "Report"). A Report is intended to include a description of a suspected vulnerability, a reproducer, and a proposed patch. The Service, each Report, and any associated materials are Anthropic’s confidential material and are provided “as is”. Participant uses the Service and Reports at its own risk.
2. Requirements.
a. Participation. By submitting a Project, Participant represents that (a) Participant is the lead maintainer of the Project, or is authorized by the Project’s lead maintainer to enroll the Project, and (b) if Participant maintains the Project in Participant’s formal capacity as an employee of a specific organization or entity that serves as the lead maintainer of the Project, Participant has permission from the organization or entity to enroll the Project in the Service. Anthropic may verify Participant’s authorization to enroll the Project, including by contacting the Project lead maintainers through other channels, and may remove a Project if Anthropic is unable to verify such information.
b. Project. Anthropic accepts established projects with a critical impact on infrastructure and user security and decides each request case by case. Factors include exposure to remote attacks (for example, libraries that process untrusted input) and the number of users or dependent projects. Anthropic may decline a Project that has already been submitted.
3. Permitted Use of Reports. Participant may only use Reports to identify, assess, and fix security vulnerabilities and other bugs in the Project (the “Permitted Use”). Participant may share Reports with individuals who are authorized maintainers of the Project. Participant may not use a Report for any other purpose, including to attack, exploit, or gain access to any third party computer system or code repository.
4. Disclaimer.
a. Nature of Reports. Each Report is generated by artificial intelligence models. Reports may be incomplete and inaccurate. Without limiting the foregoing, a Report may fail to identify vulnerabilities, may describe vulnerabilities as issues that are not vulnerabilities, may misjudge the severity of an issue, and may propose patches that are incomplete or that impair or break functionality.
b. Disclaimer. THE SERVICE AND ALL REPORTS ARE PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, ANTHROPIC DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING ANY WARRANTIES OF ACCURACY, COMPLETENESS, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. WITHOUT LIMITING THE FOREGOING, ANTHROPIC DOES NOT WARRANT THAT ANY REPORT WILL IDENTIFY ALL VULNERABILITIES OR THAT ANY PROPOSED PATCH WILL BE COMPLETE, WILL FUNCTION AS INTENDED, OR WILL NOT IMPAIR FUNCTIONALITY. NO ADVICE OR INFORMATION, WHETHER ORAL OR WRITTEN, OBTAINED FROM ANTHROPIC OR THROUGH THE SERVICE WILL CREATE ANY WARRANTY NOT EXPRESSLY STATED IN THIS AGREEMENT.
c. Participant's Responsibility. Participant is responsible for reviewing each Report, and any patch proposed in it, before making changes to the Project in reliance on a Report or sharing that Report.
5. Security. Reports may include sensitive information, including descriptions of unpatched vulnerabilities. Participant will take reasonable steps to keep them confidential and secure until the vulnerability is fixed or publicly disclosed. If Anthropic manually validates a Report under its Coordinated Vulnerability Disclosure Policy and notifies Participant, Anthropic may disclose the vulnerability under that policy starting 90 days after that notice. Anthropic may in the future apply a disclosure period to some Reports by giving Participant reasonable advance notice.
6. No fees. The Service is provided at no cost.
7. Limitation of Liability. To the fullest extent permitted by law, Anthropic is not liable for any use of a Report or of the Service, including any use outside the Permitted Use, or for any loss arising from reliance on a Report or on a proposed patch. Anthropic's total liability arising from this Agreement or the Service will not exceed $1,000.
8. Term. This Agreement will remain in full force and effect while your Project is enrolled. Participant may pause or end enrollment at any time. Anthropic may modify, suspend, or end the Service, or any enrollment, at any time and for any reason. Sections 3, 4, 5, and 7 survive after this Agreement ends.