Skip to content

Anthropic launches Claude Security for automated vulnerability detection in GitHub repositories

Bottom line: With Claude Security, Anthropic offers a beta feature for enterprise customers that automatically scans GitHub repositories and proposes patches directly for approval.

Anthropic has introduced Claude Security, a new feature that automatically scans GitHub repositories for security vulnerabilities and proposes matching patches directly for approval. For CISOs, this represents a possible automation of a process step that has so far required manual code reviews or separate SAST tools.

Claude Security is a new feature from Anthropic that runs within Claude Code on the web. It scans entire GitHub repositories for security vulnerabilities and delivers not just a list of findings, but concrete patch proposals ready for approval. The entire workflow – from the initial scan to the finished fix – takes place without additional integration into existing toolchains. The feature is currently available as a public beta for Anthropic’s enterprise customers.

For security leaders, this shifts part of classic vulnerability analysis into an AI-supported, semi-automated workflow. Unlike traditional SAST or SCA tools, which primarily deliver findings, Claude Security directly generates fix proposals as pull requests or comparable approval objects. This potentially shortens the time between discovering and remediating a vulnerability, but also shifts responsibility: who reviews and approves automatically generated patches before they enter production code? This question directly affects existing code review and change management processes.

From a governance perspective, it is relevant that during the beta phase the feature gains access to repository contents, which raises questions about data processing, source code confidentiality, and contractual arrangements with Anthropic that need to be clarified before productive use. Since this is a public beta, CISOs should, before broad rollout within the organization, examine which repositories are included on a trial basis, how generated patches are integrated into existing review gates, and what liability and traceability questions arise from automatically proposed code changes.


Source: www.security-insider.de · Published August 4, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: