
Apache scanned 230 repositories with AI in three days
The Apache Software Foundation ran full security scans across 230 of its repositories in a three-day window in August 2026, using Anthropic's Claude Mythos 5 via Project Glasswing. Findings reached the projects through the official disclosure path.
The Apache Software Foundation (ASF) ran full security scans across 230 of its repositories within three days in August 2026. The work was done by its ASF Security and ASF Tooling teams under the Responsible AI Initiative (RAI), using Anthropic's Claude Mythos 5 through the Project Glasswing security program. Findings reached the projects that own the code through the Foundation's official disclosure path, and remediation is under way.
Why the scans started
ASF Security analysed Mythos-based scans that Alpha-Omega ran on two ASF projects and found the reports specific and detailed. At the same time, the volume of AI-generated vulnerability reports reaching open source projects keeps growing, and telling useful reports from noise costs maintainer attention that projects rarely have to spare. The Foundation concluded it should run the analysis itself, with the projects and with enough context for the output to be worth reading.
What was already in place
Since early 2026 ASF Tooling has run an automated audit pipeline that evaluates code against the OWASP ASVS standard on Gofannon, its own agent platform. The pipeline has three tiers: a light tier filters high volume, a medium tier inventories what the code contains, and a heavy tier performs the analysis that needs real reasoning. The model per tier is chosen at runtime from an Opus, Sonnet and Haiku ensemble or a Mythos, Gemma and Qwen one. The team says giving models codebase context sharply cut false positives.
Threat models first
Before scanning, ASF Security invited projects to work through a threat model. 75 Project Management Committees (PMCs) covering more than 180 repositories signed up and described what matters, which boundaries must hold and which assumptions are already settled. Models built with a Threat Model skill contributed by Alpha-Omega were reviewed first, and scanning against a reviewed model cost roughly a fifth less.
Glasswing, disclosure and next steps
Anthropic's Project Glasswing gives selected organizations access to its most capable models for security research. Scans ran with the Glasswing harness in parallel sessions of Claude Code, and critical vulnerabilities came with a drafted, separately reviewed patch attached. Sensitive findings reach a project's security list first, and the PMC remediates on its own timeline. Next come incremental scans, more scan types and a self-serve mode with a token budget the Foundation manages.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.