Perplexity Open-Sources Bumblebee: A Read-Only Supply-Chain Scanner for Developer Endpoints
Perplexity just open-sourced Bumblebee, the supply-chain scanner it built to lock down its own developer endpoints. Here's why your infrastructure team should care.

Why it matters
Perplexity is shipping a developer security tool as open source, signaling both its confidence in internal security practices and a strategic move to set industry standards for supply-chain scanning in AI infrastructure.
The key facts
12 to knowTool: Bumblebee — read-only supply-chain inventory scanner
Supported platforms: macOS and Linux
Scope: npm, PyPI, Go modules, MCP configs, editor extensions, browser extensions
Key differentiator: Non-invasive (no package manager invocation, no code execution)
Original use case: Protecting developer systems behind Perplexity's Comet and Computer products
Status: Open-sourced (public release)
Perplexity open-sources Bumblebee security tool
Read-only inventory scanner for macOS and Linux
Scans npm, PyPI, Go modules, MCP configs, editor extensions, browser extensions
No package manager invocation or code execution required
Originally built for internal use protecting Comet and Computer products
Published May 23, 2026
Go to the source
MarkTechPostmarktechpost.com
Publisher excerpt: Perplexity has open-sourced Bumblebee, an internal security tool it uses to protect the developer systems behind its search product, Comet, and Computer. Bumblebee is a read-only inventory collector for macOS and Linux developer endpoints. It scans npm, PyPI, Go modules, MCP configs, editor…
