{"slug": "runtime-anthropic-throws-open-source-a-token-gesture", "title": "Runtime: Anthropic throws open source a token gesture", "summary": "Anthropic launched OSS Scanner, a free opt-in vulnerability scanner for open-source maintainers informed by its use of Claude to find vulnerabilities during Project Glasswing, but the service delivers unverified vulnerability lists that critics say shift validation work onto under-resourced maintainers. Separately, Mistral released Mistral 4 Large, an open-weight model it calls \"le Chonk,\" claiming performance competitive with the strongest open-source models globally and pricing at $1.36 per unit.", "body_md": "*Welcome to Runtime! Today on Product Saturday: Anthropic releases a scanning tool for open source projects that solves one problem and creates another, Mistral unveils \"le Chonk,\" and more.*\n\n*Please forward this email to a friend or colleague! If it was forwarded to you,* __sign up here__ *to get Runtime for free every week, or* __level up here__*.*\n\n### Ship it\n\n**The gift that keeps giving**: \"Open\" has been a bit of a dirty word inside Anthropic's offices this year, given how quickly open-weight models have been able to catch up to the performance of its heavily funded closed-weight models. But open-source software is a little different, and indeed [__makes up some of the most important parts__](https://clickhouse.com/blog/how-anthropic-is-using-clickhouse-to-scale-observability-for-ai-era?ref=thestack.technology) of Anthropic's internal software stack.\n\nThe people who maintain some of the most vital open-source projects used across enterprise tech were already scrambling to keep up with an onslaught of vulnerabilities before the launch of powerful cybersecurity AI models from Anthropic and OpenAI this year, which made it much easier to find and exploit holes in software. This week Anthropic launched a new free service for open-source maintainers called OSS Scanner that it thinks can help\n\nOSS Scanner is \"an opt-in vulnerability scanner for the open-source ecosystem informed by our experience using Claude to find vulnerabilities during [__Project Glasswing__](https://www.anthropic.com/glasswing?ref=thestack.technology),\" Anthropic [__said in a blog post__](https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source?ref=thestack.technology). The company said it has been scanning most of the bigger open-source projects since the launch of Claude Mythos Preview, but \"we remain bottlenecked on our human capacity to validate these findings\" and send reports to project maintainers that scrub out the false positives.\n\nThe new scanner will allow project maintainers to receive a list of unverified vulnerabilities and sort through them, but that dump a lot of work on those under-resourced maintainers and [__Anthropic's move drew some criticism__](https://bsky.app/profile/evacide.bsky.social/post/3mxhhkydf322s?ref=thestack.technology). After all, if Anthropic can't afford to verify every potential vulnerability identified by its models, how can they expect that open-source projects — which aren't nearly as rich as [__the members of The Secret Security Society__](https://www.thestack.technology/cant-get-access-to-gpt-5-6-cyber-palo-alto-networks-will-take-your-money/) — will be able to do that?\n\n**The Stack Summit***: We're convening in London on November 4-5, for a series of exclusive workshops and fireside conversations on the rise of BYOC as a favoured enterprise SaaS deployment model; how many CDOs are consolidating their data estates with Apache Iceberg; how CISOs at FTSE 100 scale are handling supply chain risk (with GSK's CISO) and more.* \n\n*Ticket applications are subject to pre-vetting. Get in touch with* **ed@thestack.technology** *if you want to be in the room.*\n\n[Learn more](https://luma.com/tk18zqlb?ref=thestack.technology)\n\n### Delivery, continued\n\n**Found the beef**: Mistral is an important part of Europe's determination to forge a tech stack of its own, but its models have consistently lagged the performance of the ones cranked out by The Tense Two (and Google). But this week it released its best challenger yet to the AI frontier, which will surely slow down one of these days, with the launch of Mistral 4 Large.\n\nThe open-weight model, which in a fit of absolute inspiration the French company dubbed \"le Chonk,\" delivers \"performance competitive with the strongest open-source models globally, while significantly outperforming any open-weight model developed in the US or Europe,\" it [__said in a blog post__](https://mistral.ai/news/mistral-large-4/?ref=thestack.technology). It costs $1.36 and $4.18 per million input and output tokens, respectively, which is well below Anthropic and OpenAI's pricing for its state-of-the-art models.\n\n**How do you talk to an agent?**: \"Personal AI agents are taking the world by storm,\" [__declared Sierra this week__](https://sierra.ai/blog/introducing-personal-agent-protocol?ref=thestack.technology), which is presumably true if your world is confined to a zip code that starts with 94. There certainly are a lot of companies launching personal agents that will need to talk to each other to accomplish their tasks, and while we'll give it a few months before telling everyone to seek shelter from the storm, Sierra introduced a protocol for enabling that communication.\n\nDeveloped in partnership with Meta and several other companies, Personal Agent Protocol was designed \"to handle authentication, empower consumers and give companies visibility into what personal agents do through their websites, APIs or company agents,\" the company said. Agent identification and observability will be crucial to the long-term sustainability of enterprise AI, but there [__are already a lot of agent protocols__](https://www.thestack.technology/the-protocol-proliferation-problem-making-sense-of-the-open-agent-stack/).\n\n**Speaking of protocols**: Atlassian's tools remain at the heart of countless enterprise IT shops more than 20 years after they first arrived. The Australian company released a protocol of its own this week called Agentic Multiplayer Protocol, and it was designed to put those tools at the heart of the agentic AI platform shift.\n\nAMP \"defines how agents take part in multiplayer work with an identity, scoped authority, shared context and tasks, and results you can review,\" Atlassian [__said in a blog post__](https://www.atlassian.com/blog/company-news/team26-europe-ai-platform?ref=thestack.technology). The company also introduced \"local EU AI inference\" this week, \"which restricts LLM processing exclusively to models hosted within the EU, so you can run your most sensitive workloads in a region you trust.\"\n\n### The rest of The Stack\n\n**Party at Torvalds'**: AI coding tools are the new \"wonderful gateway drug\" for bringing new people into software development, according to Linux creator Linus Torvalds. “If you just use it correctly, and if you treat it as a tool, I find that it makes programming much more enjoyable,” he said at Open Source Summit.\n\n**Trusted computing**: Microsoft made its Microsoft Execution Containers service generally available this week, giving customers an option for running untrusted code, such as swarms of AI agents, in a secure enclave. \"Developers and IT administrators define the resources, like files and network destinations an agent can use and MXC uses the appropriate container to enforce those policies at runtime,\" the company said.\n\n**Check disk**: Valkey has come a long way in a few short years as an open-source alternative to Redis, and plans for future versions involve working around an annoying bottleneck in enterprise tech at the moment. By spring of next year, the project wants to enable users to store data in solid-state drives rather than memory, which has become exorbitantly expensive with no end in sight.\n\n### Quote of the week\n\n\"We've got over 4,000 software engineers who are using open-weight models for what will be 80% of the AI that we're running. The remaining 20% will be frontier.” — *Nutanix's Andrew Brinded,* __speaking at an event in London this week__ *and perhaps predicting the future of enterprise AI.*\n\n### We're also reading:\n\n__Deno is joining Cloudflare__**:** With Bun deeply ensconced at Anthropic, [__two proposals for the future of Node.js__](https://www.thestack.technology/bun-is-on-a-roll/) have now teamed up with some big tech companies.\n\n__The era of Super Intelligence is here. AIForce is officially SIForce__**:** You just knew it would be Benioff.\n\n*Thanks for reading — see you Tuesday!*", "url": "https://wpnews.pro/news/runtime-anthropic-throws-open-source-a-token-gesture", "canonical_source": "https://www.thestack.technology/runtime-anthropic-throws-open-source-a-token-gesture/", "published_at": "2026-10-10 15:00:00+00:00", "updated_at": "2026-10-10 15:16:36.736711+00:00", "lang": "en", "topics": ["ai-safety", "ai-products", "large-language-models", "ai-tools", "ai-startups"], "entities": ["Anthropic", "OSS Scanner", "Claude", "Project Glasswing", "Mistral", "Mistral 4 Large", "OpenAI", "Google"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/runtime-anthropic-throws-open-source-a-token-gesture", "markdown": "https://wpnews.pro/news/runtime-anthropic-throws-open-source-a-token-gesture.md", "text": "https://wpnews.pro/news/runtime-anthropic-throws-open-source-a-token-gesture.txt", "jsonld": "https://wpnews.pro/news/runtime-anthropic-throws-open-source-a-token-gesture.jsonld"}}