Perplexity's recent open-source Bumblebee is quite practical—read-only scanning without touching the production environment. The supply chain risk assessment finally has a handy tool.

View Original
CoinNetwork
Perplexity open-source read-only dependency scanning tool Bumblebee, blocks developers' terminal supply chain backdoors
Perplexity AI announces the open-source security scanning tool Bumblebee, a read-only asset collector for macOS/Linux that quickly inventories local dependencies, package management metadata, editor plugins, and AI tool configurations, using read-only parsing to ensure safety. It offers baseline, project, and deep three configurations, supporting extraction of dependency information from over ten ecosystems including npm, pypi, and go modules. It is open-sourced on GitHub under Apache 2.0, version v0.1.1, helping enterprise security teams assess risk exposure during supply chain attacks.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned