Topic · 1 stories

#supply-chain-security

Reporting, analysis and practical guides connected to supply-chain-security.

Latest in #supply-chain-security

Newest first
Open Source

Bumblebee: Perplexity's Read-Only Dev Endpoint Scanner

Bumblebee is Perplexity's open-source, read-only supply-chain scanner for macOS and Linux developer endpoints, written in Go with zero non-stdlib dependencies under Apache 2.0. It inventories npm, PyPI, Go, RubyGems, Composer and other package managers plus MCP configs, editor extensions, and browser extensions, emitting NDJSON findings against operator-supplied exposure catalogs. Its read-only design never invokes package managers, so it cannot trigger malicious postinstall scripts during a scan.

Jul 28, 2026 · 6 min read
Search TeqVolt

Find an article

Type a keyword or browse a section.