0:00
8:22
8:22

Perplexity Open-Sourced a Scanner Every Dev Should Know (Bumblebee)

Tech

In this video, I take a hands-on look at Bumblebee, Perplexity’s new open-source scanner for developer machines, and show how it helps answer one of the hardest supply chain security questions: “Do any dev laptops have a risky package, extension, or AI config sitting on disk right now?” I’ll run Bumblebee live to show how it scans local metadata without running package managers, executing project code, or triggering install scripts. It’s a fast, read-only developer endpoint inventory tool that outputs clean NDJSON so teams can pipe results into scripts, MDM, SIEM workflows, or incident response processes. 🔗 Relevant Links Perplexity Bumblebee - https://www.perplexity.ai/hub/blog/perplexity-is-open-sourcing-bumblebee Bumblebee Repo - https://github.com/perplexityai/bumblebee ❤️ More about us Radically better observability stack: https://betterstack.com/ Written tutorials: https://betterstack.com/community/ Example projects: https://github.com/BetterStackHQ 📱 Socials Twitter: https://twitter.com/betterstackhq Instagram: https://www.instagram.com/betterstackhq/ TikTok: https://www.tiktok.com/@betterstack LinkedIn: https://www.linkedin.com/company/betterstack 📌 Chapters: 0:00 The Dev Machine Supply Chain Problem 0:35 Why Developer Laptops Are Now an Attack Surface 1:25 Bumblebee Install and Self-Test 1:55 Running a Baseline Scan with Bumblebee 2:15 Reading Bumblebee NDJSON Output 3:00 Why Bumblebee Is Not Another SCA Tool 3:54 Baseline vs Project vs Deep Scan Profiles 4:55 What Bumblebee Scans: npm, PyPI, VS Code, Browsers, MCP 5:30 Bumblebee Pros: Fast, Safe, Open Source 6:05 Why Read-Only Scanning Matters During Incidents 7:20 Should Developers Use Bumblebee?

ADVERTISEMENT

Comments 20

Sign in to join the conversation

Sign in
babyberry
babyberry 3 weeks, 2 days ago

thank you for the best video

J
justin_brown 3 weeks, 2 days ago

Bruh fix your ugly powerline icons

A
andrea_hodges 3 weeks, 2 days ago

Why do I hear AI Slop writing??

D
danielleadams340 3 weeks, 2 days ago

Do you have any dictionary for all the acronyms?

R
robert_richardson 3 weeks, 2 days ago

could you make your script less ai for god sake

micheal_santiago
micheal_santiago 3 weeks, 2 days ago

Downloading anything from Perplexity is wild 😂

severin.geisel
severin.geisel 3 weeks, 2 days ago

Man you really needed that microphone. So much more professional sounding now.

D
davimiguel_silveira 3 weeks, 3 days ago

Supply Chain attack on bumblebee in 5 ... 4 .. 3..

C
christy_cooper 3 weeks, 3 days ago

" THIS will keep you safe. Just download and run it!" 😂

A
aimée.foucher 3 weeks, 3 days ago

live demo free handed

claude.renard
claude.renard 3 weeks, 3 days ago

Great deep dive!

J
john.jensen 3 weeks, 3 days ago

Hmmm, Nix, anyone?

kabir_khalsa
kabir_khalsa 3 weeks, 3 days ago

Folks, if in 2026 you're still doing development locally, directly on your machine... You're doing it wrong! Please use dev containers! Even for the small projects! Any project that has dependencies needed to be installed from a package manager, needs a dev container. The risk of compromising your whole machine is just too great!

H
hans-hinrichhendriks264 3 weeks, 3 days ago

1. requiring you to install it with go instead of publishing to homebrew is a PITA 2. there's no catalog bundle shipped with the binary, so you have to manually fetch the json files from the repo before you can match anything 3. no self-update for catalogs either...you have to remember to git pull or re-curl every time a new advisory drops, otherwise you're scanning against stale intel 4. catalog coverage is limited to the handful of named campaigns their team happens to write up. For comparison npm audit / pip-audit / bundle audit already consume the github advisory db and catch real cves across the board As it stands it's a barebones tool with limited value for a single laptop. The one thing it actually does that the audit tools don't is cover editor/browser extensions and mcp configs... for plain package cves the audit tools already win

G
graciela_morales 3 weeks, 3 days ago

I stopped watching after the ai slop script "No x, no x, just x" terrible, please stop that.

R
robert_richardson 3 weeks, 3 days ago

Not actually useful everything from perplexity is garbage

H
harryjames211 3 weeks, 3 days ago

That's pretty useful. I'm tackling the supply chain issues different ways but this helps solve an issue I had a few weeks back where I was asking myself "have I been pwned and I just don't know it?". When you have multiple projects on the go and plugins for IDEs auto-updating it is hard to know what you have installed locally. (Also don't take this the wrong way because the video is ultimately fine... But I can hear that AI wrote most of this script. Claude loves snappy short sentences and going on and on about "boring tech".)

R
rael.novaes 3 weeks, 3 days ago

Cool tool, nice presentation. It feels like you mention many things repeatedly, which reduces the quality of the video overall IMO.

S
suzanneshadow59 3 weeks, 3 days ago

Install some powerline fonts so the terminal doesn't look as ugly :D

L
laurie.morgan 3 weeks, 3 days ago

AI never sleeps 😴