Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
[eclipse.org-committers] Eclipse Foundation joins Project Glasswing: enroll for priority security reviews

Dear Committers,

I am pleased to announce that the Eclipse Foundation is now officially part of Anthropic's Project Glasswing. Through this partnership, the Eclipse Foundation Security Team has access to Claude Mythos 5, which we are using to strengthen the security of Eclipse projects.

Some background: thanks to our partnership with Alpha-Omega, the Security Team has had access to Mythos in its preview version since Glasswing's debut. Over the last quarter, we used it to scan all Eclipse Foundation projects, and many of you have already received reports from us through the standard vulnerability-reporting process.

We are now taking this work to the next stage with a new campaign with Mythos 5 running through the end of October 2026.

What this means for your project:
  • Reviews combine automated and AI-assisted analysis with human validation by the Security Team.
  • All Eclipse Foundation projects will eventually be reviewed, whether or not they enroll. Enrollment is a prioritization mechanism, not a permission or opt-out mechanism.
  • If we validate a credible finding, a private vulnerability report will normally be your first notification that a review has taken place. The finding is then handled through the Eclipse Foundation's coordinated vulnerability-management process, and we work with you on validation, remediation, release, and disclosure.
  • If a review produces no credible findings, we will notify the project once the review is complete.
Get prioritized

We cannot offer Glasswing seats to the community, but we would like to prioritize projects that are ready to engage more closely with us throughout the process. If your project team is prepared to collaborate on validation and remediation, your repositories are actively maintained, and your project security team includes active Committers who can act on reports, we encourage you to enroll.

To enroll, follow these instructions and open a merge request in:
https://gitlab.eclipse.org/eclipsefdn/security/ai-scan-enrollment 

Enrollment is not first come, first served and does not guarantee a particular review date. Scheduling depends on program priorities and available capacity. Please note that the enrollment repository and its merge requests are public: do not use them to report vulnerabilities or include sensitive information.

Questions about the program can be sent to security@xxxxxxxxxxxxxxxxxxxxxx or discussed publicly in the Eclipse CSI GitHub Discussions: https://github.com/orgs/eclipse-csi/discussions

Thank you for your continued commitment to the security of the Eclipse ecosystem.

Kind regards,

Mikaël Barbero 
Head of Security | Eclipse Foundation

Back to the top