{"repo":"perplexityai/bumblebee","free":true,"listed":false,"github":"https://github.com/perplexityai/bumblebee","clone":"git clone https://github.com/perplexityai/bumblebee.git","description":"Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.","language":"Go","stars":4931,"topics":["golang","package-inventory","supply-chain-security"],"license":"Apache-2.0","category":"dev-tools","readme_excerpt":"bumblebee Bumblebee is a read-only inventory collector for package, extension, and developer-tool metadata on macOS and Linux developer endpoints. It answers a narrow supply-chain response question: when an advisory names a package, extension, or version, which developer machines show a match in their on-disk metadata right now? SBOMs help answer what shipped, and EDR helps answer what ran or touched the network, but supply-chain response often needs a different view: messy local state across lockfiles, package-manager metadata, extension manifests, and supported developer-tool configs. Bumblebee turns that scattered on-disk state into structured NDJSON component records and, when given an exposure catalog, flags exact matches for fast, read-only exposure checks when responders already know what they are looking for. Scope - Single static binary, Go 1.25+, zero non-stdlib dependencies. - Three scan profiles ( baseline , project , deep ) for different populations and cadences. - Reads only the lockfiles, package-manager install metadata, extension manifests, and supported MCP JSON configs listed in docs/inventory-sources.md. No package manager execution ( npm ls , pip show , go list , ...) and no source-file reads. MCP host configs can carry environment values and credentials in their env blocks; Bumblebee parses these configs for the server inventory it needs but does not emit those values in its records. Coverage Family Emitted ecosystem Sources --- --- --- npm npm package-l","default_branch":null,"files":null,"tree":[],"storefront":"/r/perplexityai","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/perplexityai/bumblebee/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}