FreshPorts -- security/bumblebee: Read-only supply-chain exposure scanner for developer endpoints


FreshPorts -- The Place For Ports [画像:notbug]As an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photos
All times are UTC [画像:Ukraine]
The recently imposed "must be logged in" restriction is a response to increased bot traffic on the site. This affects search, commits, and vuxml pages.
Search engines are not blocked. Try using "site:www.freshports.org" and your search terms.
After the ports freeze to fix some stuff, the freeze is over. I have some work to do before FreshPorts can start processing commits again before it can start processing again. I've created an issue for that.
Port details
bumblebee Read-only supply-chain exposure scanner for developer endpoints
0.1.1_5 security on this many watch lists=0 search for ports that depend on this port Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout 0.1.1_4Version of this port present on the latest quarterly branch.
Maintainer: kiwi@FreeBSD.org search for ports maintained by this maintainer
Port Added: 2026年05月25日 04:03:05
Last Update: 2026年09月03日 04:50:55
Commit Hash: dd09051
License: APACHE20
WWW:
https://github.com/perplexityai/bumblebee
Description:
Bumblebee is a read-only inventory collector for package, extension, and developer-tool metadata on developer endpoints, built to check exposure to known software supply-chain compromises. It answers a narrow supply-chain response question: when an advisory names a package, extension, or version, which developer machines show a match in their on-disk metadata right now? SBOMs help answer what shipped, and EDR helps answer what ran or touched the network, but supply-chain response often needs a different view: messy local state across lockfiles, package-manager metadata, extension manifests, and developer-tool configurations. Bumblebee turns that scattered on-disk state into structured NDJSON component records and, when given an exposure catalog, flags exact matches for fast, read-only exposure checks. Key properties: - Single static binary, zero non-stdlib dependencies - Three scan profiles (baseline, project, deep) for different populations - Reads lockfiles, package-manager install metadata, extension manifests, and MCP JSON configs — without executing any package manager - Emits NDJSON output suitable for log-ingest pipelines
Homepage cgit ¦ Codeberg ¦ GitHub ¦ GitLab ¦ SVNWeb - no subversion history for this port

Manual pages:
FreshPorts has no man page information for this port.
pkg-plist: as obtained via: make generate-plist
Expand this list (7 items)
Collapse this list.
  1. /usr/local/share/licenses/bumblebee-0.1.1_5/catalog.mk
  2. /usr/local/share/licenses/bumblebee-0.1.1_5/LICENSE
  3. /usr/local/share/licenses/bumblebee-0.1.1_5/APACHE20
  4. bin/bumblebee
  5. @owner
  6. @group
  7. @mode
Collapse this list.
USE_RC_SUBR (Service Scripts)
  • no SUBR information found for this port
Dependency lines:
  • bumblebee>0:security/bumblebee
To install the port:
cd /usr/ports/security/bumblebee/ && make install clean
To add the package, run one of these commands:
  • pkg install security/bumblebee
  • pkg install bumblebee
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.
PKGNAME: bumblebee
Flavors: there is no flavor information for this port.
distinfo:
TIMESTAMP = 1779677916 SHA256 (go/security_bumblebee/perplexityai-bumblebee-v0.1.1_GH0/v0.1.1.mod) = 9a0e32ee8b3e8ca297631170ac2c8589ddaf1718b4752ffeead357da683a9878 SIZE (go/security_bumblebee/perplexityai-bumblebee-v0.1.1_GH0/v0.1.1.mod) = 50

Expand this list (4 items)

Collapse this list.

SHA256 (go/security_bumblebee/perplexityai-bumblebee-v0.1.1_GH0/v0.1.1.zip) = bf92e82b2bfc2752dec5c0c9fdfbcf2e08dee0be273b8afc7ef187e6ab50b266 SIZE (go/security_bumblebee/perplexityai-bumblebee-v0.1.1_GH0/v0.1.1.zip) = 200337 SHA256 (go/security_bumblebee/perplexityai-bumblebee-v0.1.1_GH0/perplexityai-bumblebee-v0.1.1_GH0.tar.gz) = 559a5fa9ca48128fb113644e7800048b0b6c2ff3a33bc56fe5236582ba1686b0 SIZE (go/security_bumblebee/perplexityai-bumblebee-v0.1.1_GH0/perplexityai-bumblebee-v0.1.1_GH0.tar.gz) = 154198

Collapse this list.


Packages (timestamps in pop-ups are UTC):
bumblebee
ABIaarch64amd64armv6armv7i386powerpcpowerpc64powerpc64le
FreeBSD:13:latest-----n/an/an/a
FreeBSD:13:quarterly-----n/an/an/a
FreeBSD:14:latest0.1.1_40.1.1_4--0.1.1_4---
FreeBSD:14:quarterly0.1.1_40.1.1_4--0.1.1_4---
FreeBSD:15:latest0.1.1_40.1.1_4n/a-n/an/a--
FreeBSD:15:quarterly0.1.1_40.1.1_4n/a-n/an/a--
FreeBSD:16:latest0.1.1_40.1.1_4n/a-n/an/a--
Dependencies
NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
Build dependencies:
  1. go126 : lang/go126
Fetch dependencies:
  1. go126 : lang/go126
There are no ports dependent upon this port

Configuration Options:
No options to configure
Options name:
security_bumblebee
USES:
go:modules zip
FreshPorts was unable to extract/find any pkg message
Master Sites:
Expand this list (2 items)
Collapse this list.
  1. https://codeload.github.com/perplexityai/bumblebee/tar.gz/v0.1.1?dummy=/
  2. https://proxy.golang.org/github.com/perplexityai/bumblebee/@v/
Collapse this list.

Number of commits found: 6

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
0.1.1_5
03 Sep 2026 04:50:55
commit hash: dd0905142a9a35cdf8267e2706db9488b516ad01 commit hash: dd0905142a9a35cdf8267e2706db9488b516ad01 commit hash: dd0905142a9a35cdf8267e2706db9488b516ad01 commit hash: dd0905142a9a35cdf8267e2706db9488b516ad01 files touched by this commit
Adam Weinberger (adamw) search for other commits by this committer
many: Bump go ports for 1.26.8 and 1.27.1
0.1.1_4
19 Aug 2026 17:39:04
commit hash: 4867821cd65241b6e8c0faa3ed76d67514594442 commit hash: 4867821cd65241b6e8c0faa3ed76d67514594442 commit hash: 4867821cd65241b6e8c0faa3ed76d67514594442 commit hash: 4867821cd65241b6e8c0faa3ed76d67514594442 files touched by this commit
Dag-Erling Smørgrav (des) search for other commits by this committer
various: Bump go ports for go-1.25.14 / 1.26.7
0.1.1_3
14 Aug 2026 00:38:09
commit hash: 6d39dcf04e96d7cdbad58d1b7f27d25d8e3b75b8 commit hash: 6d39dcf04e96d7cdbad58d1b7f27d25d8e3b75b8 commit hash: 6d39dcf04e96d7cdbad58d1b7f27d25d8e3b75b8 commit hash: 6d39dcf04e96d7cdbad58d1b7f27d25d8e3b75b8 files touched by this commit
Dag-Erling Smørgrav (des) search for other commits by this committer
various: Bump go ports for go-1.25.13 / 1.26.6
0.1.1_2
10 Jul 2026 07:54:15
commit hash: 4ea354713284ca756537346a9ebc6df56184ed31 commit hash: 4ea354713284ca756537346a9ebc6df56184ed31 commit hash: 4ea354713284ca756537346a9ebc6df56184ed31 commit hash: 4ea354713284ca756537346a9ebc6df56184ed31 files touched by this commit
Dag-Erling Smørgrav (des) search for other commits by this committer
various: Bump go ports for go-1.25.12 / 1.26.5
0.1.1_1
03 Jun 2026 17:54:22
commit hash: dd8dc2a59ddc46a12ace1cc4f7a953de512853bd commit hash: dd8dc2a59ddc46a12ace1cc4f7a953de512853bd commit hash: dd8dc2a59ddc46a12ace1cc4f7a953de512853bd commit hash: dd8dc2a59ddc46a12ace1cc4f7a953de512853bd files touched by this commit
Dag-Erling Smørgrav (des) search for other commits by this committer
various: Bump go ports for go-1.25.11 / go-1.26.4
0.1.1
25 May 2026 03:59:57
commit hash: 214a20af56c5bf88ed4944acca07c37b0a482430 commit hash: 214a20af56c5bf88ed4944acca07c37b0a482430 commit hash: 214a20af56c5bf88ed4944acca07c37b0a482430 commit hash: 214a20af56c5bf88ed4944acca07c37b0a482430 files touched by this commit
Xavier Beaudouin (kiwi) search for other commits by this committer
security/bumblebee: new port
Read-only supply-chain exposure scanner for developer endpoints

Number of commits found: 6

Login
User Login
Create account

Servers and bandwidth provided by
New York Internet, iXsystems, and RootBSD

This site
What is FreshPorts?
About the authors
Issues
FAQ
How big is it?
Security Policy
Privacy
Blog
Contact

Search
Enter Keywords:
more...

Latest Vulnerabilities
electron42 Sep 03
libnjs Sep 03
nginx-full Sep 03
njs Sep 03
chromium Sep 02
jenkins Sep 02
jenkins-lts Sep 02
erlang Sep 01
erlang Sep 01

30 vulnerabilities affecting 415 ports have been reported in the past 14 days

* - modified, not new

All vulnerabilities

Last processed:
2026年09月03日 17:10:13 UTC


Ports
Home
Categories
Deleted ports
Sanity Test Failures
Newsfeeds

Statistics
Graphs
NEW Graphs (Javascript)

Calculated hourly:
Port count 35095
Broken 77
Ignore 190

Servers and bandwidth provided by
New York Internet, iXsystems, and RootBSD Valid HTML, CSS, and RSS. Copyright © 2000-2026 Dan Langille. All rights reserved.

AltStyle によって変換されたページ (->オリジナル) /