Skip to content

Runtime: Anthropic throws open source a token gesture

+ Mistral's Big Boy model, and Atlassian centers its services around a new hub.

Runtime: Anthropic throws open source a token gesture
Photo by 123Duo3 / Unsplash

Welcome to Runtime! Today on Product Saturday: Anthropic releases a scanning tool for open source projects that solves one problem and creates another, Mistral unveils "le Chonk," and more.

Please forward this email to a friend or colleague! If it was forwarded to you, sign up here to get Runtime for free every week, or level up here.


Ship it

The gift that keeps giving: "Open" has been a bit of a dirty word inside Anthropic's offices this year, given how quickly open-weight models have been able to catch up to the performance of its heavily funded closed-weight models. But open-source software is a little different, and indeed makes up some of the most important parts of Anthropic's internal software stack.

The people who maintain some of the most vital open-source projects used across enterprise tech were already scrambling to keep up with an onslaught of vulnerabilities before the launch of powerful cybersecurity AI models from Anthropic and OpenAI this year, which made it much easier to find and exploit holes in software. This week Anthropic launched a new free service for open-source maintainers called OSS Scanner that it thinks can help

OSS Scanner is "an opt-in vulnerability scanner for the open-source ecosystem informed by our experience using Claude to find vulnerabilities during Project Glasswing," Anthropic said in a blog post. The company said it has been scanning most of the bigger open-source projects since the launch of Claude Mythos Preview, but "we remain bottlenecked on our human capacity to validate these findings" and send reports to project maintainers that scrub out the false positives.

The new scanner will allow project maintainers to receive a list of unverified vulnerabilities and sort through them, but that dump a lot of work on those under-resourced maintainers and Anthropic's move drew some criticism. After all, if Anthropic can't afford to verify every potential vulnerability identified by its models, how can they expect that open-source projects — which aren't nearly as rich as the members of The Secret Security Society — will be able to do that?


The Stack Summit: We're convening in London on November 4-5, for a series of exclusive workshops and fireside conversations on the rise of BYOC as a favoured enterprise SaaS deployment model; how many CDOs are consolidating their data estates with Apache Iceberg; how CISOs at FTSE 100 scale are handling supply chain risk (with GSK's CISO) and more. 

Ticket applications are subject to pre-vetting. Get in touch with ed@thestack.technology if you want to be in the room.

Learn more

Delivery, continued

Found the beef: Mistral is an important part of Europe's determination to forge a tech stack of its own, but its models have consistently lagged the performance of the ones cranked out by The Tense Two (and Google). But this week it released its best challenger yet to the AI frontier, which will surely slow down one of these days, with the launch of Mistral 4 Large.

The open-weight model, which in a fit of absolute inspiration the French company dubbed "le Chonk," delivers "performance competitive with the strongest open-source models globally, while significantly outperforming any open-weight model developed in the US or Europe," it said in a blog post. It costs $1.36 and $4.18 per million input and output tokens, respectively, which is well below Anthropic and OpenAI's pricing for its state-of-the-art models.

How do you talk to an agent?: "Personal AI agents are taking the world by storm," declared Sierra this week, which is presumably true if your world is confined to a zip code that starts with 94. There certainly are a lot of companies launching personal agents that will need to talk to each other to accomplish their tasks, and while we'll give it a few months before telling everyone to seek shelter from the storm, Sierra introduced a protocol for enabling that communication.

Developed in partnership with Meta and several other companies, Personal Agent Protocol was designed "to handle authentication, empower consumers and give companies visibility into what personal agents do through their websites, APIs or company agents," the company said. Agent identification and observability will be crucial to the long-term sustainability of enterprise AI, but there are already a lot of agent protocols.

Speaking of protocols: Atlassian's tools remain at the heart of countless enterprise IT shops more than 20 years after they first arrived. The Australian company released a protocol of its own this week called Agentic Multiplayer Protocol, and it was designed to put those tools at the heart of the agentic AI platform shift.

AMP "defines how agents take part in multiplayer work with an identity, scoped authority, shared context and tasks, and results you can review," Atlassian said in a blog post. The company also introduced "local EU AI inference" this week, "which restricts LLM processing exclusively to models hosted within the EU, so you can run your most sensitive workloads in a region you trust."


The rest of The Stack

Party at Torvalds': AI coding tools are the new "wonderful gateway drug" for bringing new people into software development, according to Linux creator Linus Torvalds. “If you just use it correctly, and if you treat it as a tool, I find that it makes programming much more enjoyable,” he said at Open Source Summit.

Linus Torvalds says AI is a great coding gateway drug but...
The Linux and Git creator said he enjoyed AI coding but added it had been disruptive to the Linux kernel.

Trusted computing: Microsoft made its Microsoft Execution Containers service generally available this week, giving customers an option for running untrusted code, such as swarms of AI agents, in a secure enclave. "Developers and IT administrators define the resources, like files and network destinations an agent can use and MXC uses the appropriate container to enforce those policies at runtime," the company said.

Microsoft takes MXC, its agent management layer, GA
Pick one of four OS-isolated session types

Check disk: Valkey has come a long way in a few short years as an open-source alternative to Redis, and plans for future versions involve working around an annoying bottleneck in enterprise tech at the moment. By spring of next year, the project wants to enable users to store data in solid-state drives rather than memory, which has become exorbitantly expensive with no end in sight.

Valkey: The road to 10.0
Maintainers and contributors discuss Valkey’s progress since it forked from Redis, and adding data tiering, durability, and more for 10.0.

Quote of the week

"We've got over 4,000 software engineers who are using open-weight models for what will be 80% of the AI that we're running. The remaining 20% will be frontier.” — Nutanix's Andrew Brinded, speaking at an event in London this week and perhaps predicting the future of enterprise AI.


We're also reading:

Deno is joining Cloudflare: With Bun deeply ensconced at Anthropic, two proposals for the future of Node.js have now teamed up with some big tech companies.

The era of Super Intelligence is here. AIForce is officially SIForce: You just knew it would be Benioff.


Thanks for reading — see you Tuesday!

Add The Stack on Google