Back to feed
Dev.to
Dev.to
6/29/2026
The original title is: "Perplexity Bumblebee Review: The Supply Chain Scanner Your Dev Machine Needs"

The original title is: "Perplexity Bumblebee Review: The Supply Chain Scanner Your Dev Machine Needs"

Original: Perplexity Bumblebee Review: The Supply Chain Scanner Your Dev Machine Needs

Short summary

Bumblebee is an open-source supply chain scanner from Perplexity that detects compromised packages, extensions, and MCP configs across 10 ecosystems without executing code. It fills a gap traditional scanners miss: what's actually installed on a developer's machine right now, including Claude Code and IDE configs. The tool is lightweight (Go binary, zero dependencies) and safe for rapid fleet audits when supply chain advisories hit.

  • Scans 10 ecosystems (npm, PyPI, Go, RubyGems, Composer, Homebrew, MCP, VS Code, browser extensions) in seconds without executing package managers
  • Specifically designed for AI developer environments: detects compromised MCP servers and Claude Code configs that traditional scanners ignore
  • Open-source (Apache 2.0), built in Go with zero external dependencies; 4k+ GitHub stars as of v0.1.1

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more