0:00
8:22
8:22

Perplexity Open-Sourced a Scanner Every Dev Should Know (Bumblebee)

Tech

In this video, I take a hands-on look at Bumblebee, Perplexity’s new open-source scanner for developer machines, and show how it helps answer one of the hardest supply chain security questions: “Do any dev laptops have a risky package, extension, or AI config sitting on disk right now?” I’ll run Bumblebee live to show how it scans local metadata without running package managers, executing project code, or triggering install scripts. It’s a fast, read-only developer endpoint inventory tool that outputs clean NDJSON so teams can pipe results into scripts, MDM, SIEM workflows, or incident response processes. 🔗 Relevant Links Perplexity Bumblebee - https://www.perplexity.ai/hub/blog/perplexity-is-open-sourcing-bumblebee Bumblebee Repo - https://github.com/perplexityai/bumblebee ❤️ More about us Radically better observability stack: https://betterstack.com/ Written tutorials: https://betterstack.com/community/ Example projects: https://github.com/BetterStackHQ 📱 Socials Twitter: https://twitter.com/betterstackhq Instagram: https://www.instagram.com/betterstackhq/ TikTok: https://www.tiktok.com/@betterstack LinkedIn: https://www.linkedin.com/company/betterstack 📌 Chapters: 0:00 The Dev Machine Supply Chain Problem 0:35 Why Developer Laptops Are Now an Attack Surface 1:25 Bumblebee Install and Self-Test 1:55 Running a Baseline Scan with Bumblebee 2:15 Reading Bumblebee NDJSON Output 3:00 Why Bumblebee Is Not Another SCA Tool 3:54 Baseline vs Project vs Deep Scan Profiles 4:55 What Bumblebee Scans: npm, PyPI, VS Code, Browsers, MCP 5:30 Bumblebee Pros: Fast, Safe, Open Source 6:05 Why Read-Only Scanning Matters During Incidents 7:20 Should Developers Use Bumblebee?

ADVERTISEMENT
Comments 20 hans-hinrichhendriks264: 1. requiring you to install it with go instead of publishin…