OpenAI and Trail of Bits launch "Patch the Planet" to audit open-source code with AI assistance
OpenAI is funding Trail of Bits engineers to triage and patch vulnerabilities in open-source projects using its security tools, starting with maintainer-led reviews and reusable workflows.
1 source · single source
- OpenAI and Trail of Bits launched "Patch the Planet," an initiative to help open-source maintainers find and patch bugs using AI-assisted security tools.
- Trail of Bits engineers will work directly with maintainers to review code issues, develop patches, and create reusable security workflows.
- The effort aims to reduce the burden on maintainers by having security engineers pre-filter findings before they reach maintainers.
- OpenAI’s Codex Security tools will support the process, though long-term scaling and sustainability remain unclear.
OpenAI announced "Patch the Planet," a joint initiative with Trail of Bits to help open-source maintainers identify and remediate security vulnerabilities. Under the program, security engineers from Trail of Bits will collaborate directly with open-source maintainers to review potential code issues, develop patches, and establish reusable workflows for ongoing security improvements.
The initiative frames Trail of Bits engineers as rapid-response "code EMTs" who triage findings before they reach maintainers, aiming to reduce the review burden on already stretched-thin teams. OpenAI’s security tools, including Codex Security, will assist in the process, though the announcement did not specify which projects or how many maintainers will initially participate.
OpenAI stated that the effort is designed to avoid adding to maintainers’ workloads by pre-filtering results and providing structured remediation paths. The company did not detail timelines for broader rollout or metrics for success, leaving the initiative’s long-term scalability and sustainability unclear.
The move comes amid growing concerns about AI’s dual-use potential in cybersecurity, including tools that can automate bug discovery and exploit generation. By contrast, OpenAI is positioning this effort as a defensive application of AI to strengthen open-source security rather than enable attacks.
- Jun 23, 2026 · Hugging Face
Hugging Face’s Transformers.js experiments with proposed Cross-Origin Storage API to reduce redundant model downloads
Trust79 - Jun 23, 2026 · TechCrunch — AI
Anthropic launches Claude Tag in research preview to capture enterprise context in Slack
Trust76 - Jun 23, 2026 · TechCrunch — AI
Fika Jobs raises $4M to build AI-powered video hiring platform
Trust79