macOS
brew install bumblebeelocal Homebrew formula metadata
brew
Read-only developer endpoint scanner for supply-chain exposure. Version 0.1.2 via Homebrew; verified 2026-06-18. Also installable with debian: sudo apt install bumblebee.
install
brew install bumblebeelocal Homebrew formula metadata
sudo apt install bumblebeeDebian stable package indexes · bumblebee · source: deb.debian.org
nix profile install nixpkgs#bumblebeenixpkgs package indexes · pkgs/by-name/bu/bumblebee/package.nix · source: api.github.com
sudo pacman -S bumblebeeArch Linux sync databases · bumblebee · source: geo.mirror.pkgbuild.com
sudo zypper install bumblebeeopenSUSE Tumbleweed package metadata · bumblebee · source: download.opensuse.org
overview
Read-only developer endpoint scanner for supply-chain exposure
history
Bumblebee is a Perplexity AI endpoint inventory scanner for software supply-chain response. It is designed to answer which developer machines show on-disk evidence of a named package, extension, or version during an incident.
The public repository was created in May 2026. Its first tagged public release, v0.1.1, was published on May 22, 2026, and v0.1.2 followed in June with additional exposure catalog coverage.
The README emphasizes a deliberately narrow scope: a single static Go binary, read-only scanning, zero non-standard-library dependencies, and no package-manager execution. Instead of asking package managers what is installed, Bumblebee parses lockfiles, installed metadata, extension manifests, and selected developer-tool configuration files.
Bumblebee arrived in the context of 2020s supply-chain incidents where responders needed quick fleet-wide answers about vulnerable or compromised developer tooling. Its early visibility is stronger than most new CLI tools because it comes from Perplexity AI and addresses active developer-endpoint inventory needs.
Users run `bumblebee scan` with baseline, project, or deep profiles and receive NDJSON package and finding records. With an exposure catalog, it can suppress ordinary package records and emit only exact package-exposure matches for response workflows.
For package-history work, Bumblebee is significant as a scanner of package-manager residue rather than a package manager itself. It catalogs npm, pnpm, Yarn, Bun, PyPI, Go, RubyGems, Composer, Homebrew, editor extensions, browser extensions, MCP configs, and agent-skill lock files, making it a snapshot of what modern developer machines accumulate.
security posture
No matching local secret-handling manifest was found for bumblebee. Nucleus package metadata is still published here so future coverage has a stable package URL.
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
executables
| Command | Kind | Exposure | Note |
|---|---|---|---|
bumblebee | cli | global executable |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
https://github.com/perplexityai/bumblebee
install metadata
| Package key | brew:bumblebee |
|---|---|
| Version | 0.1.2 |
| Package manager | Homebrew |
| Package manager page | https://formulae.brew.sh/formula/bumblebee |
| Homepage | https://github.com/perplexityai/bumblebee |
| Repository | https://github.com/perplexityai/bumblebee |
| Upstream docs | https://github.com/perplexityai/bumblebee#readme |
| License | Apache-2.0 |
| Source archive | https://github.com/perplexityai/bumblebee/archive/refs/tags/v0.1.2.tar.gz |
| Last updated | 2026-06-18T18:21:49Z |
| Pulse | updated |
| Build dependencies | go |
| Bottle | available (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | not defined |
| Service | none declared |
registry facts
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | bumblebee |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
source database matches
Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.
bumblebee 3.2.1-32
NVIDIA Optimus support for Linux
https://launchpad.net/~bumblebee
sudo apt install bumblebeebumblebee-nvidia 3.2.1-32
NVIDIA Optimus support using the proprietary NVIDIA driver
https://launchpad.net/~bumblebee
sudo apt install bumblebee-nvidiabumblebee
nix profile install nixpkgs#bumblebeebumblebee 3.2.1-29ubuntu3
NVIDIA Optimus support for Linux
https://launchpad.net/~bumblebee
sudo apt install bumblebeebumblebee-nvidia 3.2.1-29ubuntu3
NVIDIA Optimus support using the proprietary NVIDIA driver
https://launchpad.net/~bumblebee
sudo apt install bumblebee-nvidiabumblebee 3.2.1-21
NVIDIA Optimus support for Linux through VirtualGL
http://www.bumblebee-project.org
sudo pacman -S bumblebeebumblebee 3.2.1-14.23
NVidia Optimus support for GNU/Linux aimed at stability
https://github.com/Bumblebee-Project/bumblebee
sudo zypper install bumblebeesource trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.