notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photos
All times are UTC
Ukraine
The recently imposed "must be logged in" restriction is a response to increased bot traffic on the site. This affects search, commits, and vuxml pages.
Search engines are not blocked. Try using "site:www.freshports.org" and your search terms.
Port details
bumblebee Read-only supply-chain exposure scanner for developer endpoints
0.1.1 securitynew! on this many watch lists=0 search for ports that depend on this port Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout Package not present on quarterly.This port was created during this quarter. It will be in the next quarterly branch but not the current one.
Maintainer: kiwi@FreeBSD.org search for ports maintained by this maintainer
Port Added: 2026-05-25 04:03:05
Last Update: 2026-05-25 03:59:57
Commit Hash: 214a20a
License: APACHE20
WWW:
https://github.com/perplexityai/bumblebee
Description:
Bumblebee is a read-only inventory collector for package, extension, and developer-tool metadata on developer endpoints, built to check exposure to known software supply-chain compromises. It answers a narrow supply-chain response question: when an advisory names a package, extension, or version, which developer machines show a match in their on-disk metadata right now? SBOMs help answer what shipped, and EDR helps answer what ran or touched the network, but supply-chain response often needs a different view: messy local state across lockfiles, package-manager metadata, extension manifests, and developer-tool configurations. Bumblebee turns that scattered on-disk state into structured NDJSON component records and, when given an exposure catalog, flags exact matches for fast, read-only exposure checks. Key properties: - Single static binary, zero non-stdlib dependencies - Three scan profiles (baseline, project, deep) for different populations - Reads lockfiles, package-manager install metadata, extension manifests, and MCP JSON configs — without executing any package manager - Emits NDJSON output suitable for log-ingest pipelines
Homepage    cgit ¦ Codeberg ¦ GitHub ¦ GitLab ¦ SVNWeb - no subversion history for this port

Manual pages:
FreshPorts has no man page information for this port.
pkg-plist: as obtained via: make generate-plist
Expand this list (7 items)
Collapse this list.
  1. /usr/local/share/licenses/bumblebee-0.1.1/catalog.mk
  2. /usr/local/share/licenses/bumblebee-0.1.1/LICENSE
  3. /usr/local/share/licenses/bumblebee-0.1.1/APACHE20
  4. bin/bumblebee
  5. @owner
  6. @group
  7. @mode
Collapse this list.
USE_RC_SUBR (Service Scripts)
  • no SUBR information found for this port
Dependency lines:
  • bumblebee>0:security/bumblebee
To install the port:
cd /usr/ports/security/bumblebee/ && make install clean
To add the package, run one of these commands:
  • pkg install security/bumblebee
  • pkg install bumblebee
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.
PKGNAME: bumblebee
Flavors: there is no flavor information for this port.
distinfo:
TIMESTAMP = 1779677916 SHA256 (go/security_bumblebee/perplexityai-bumblebee-v0.1.1_GH0/v0.1.1.mod) = 9a0e32ee8b3e8ca297631170ac2c8589ddaf1718b4752ffeead357da683a9878 SIZE (go/security_bumblebee/perplexityai-bumblebee-v0.1.1_GH0/v0.1.1.mod) = 50

Expand this list (4 items)

Collapse this list.

SHA256 (go/security_bumblebee/perplexityai-bumblebee-v0.1.1_GH0/v0.1.1.zip) = bf92e82b2bfc2752dec5c0c9fdfbcf2e08dee0be273b8afc7ef187e6ab50b266 SIZE (go/security_bumblebee/perplexityai-bumblebee-v0.1.1_GH0/v0.1.1.zip) = 200337 SHA256 (go/security_bumblebee/perplexityai-bumblebee-v0.1.1_GH0/perplexityai-bumblebee-v0.1.1_GH0.tar.gz) = 559a5fa9ca48128fb113644e7800048b0b6c2ff3a33bc56fe5236582ba1686b0 SIZE (go/security_bumblebee/perplexityai-bumblebee-v0.1.1_GH0/perplexityai-bumblebee-v0.1.1_GH0.tar.gz) = 154198

Collapse this list.


Packages (timestamps in pop-ups are UTC):
bumblebee
ABIaarch64amd64armv6armv7i386powerpcpowerpc64powerpc64le
FreeBSD:13:latest-----n/an/an/a
FreeBSD:13:quarterly-----n/an/an/a
FreeBSD:14:latest-0.1.1--0.1.1---
FreeBSD:14:quarterly--------
FreeBSD:15:latest0.1.10.1.1n/a-n/an/a--
FreeBSD:15:quarterly--n/a-n/an/a--
FreeBSD:16:latest-0.1.1n/a-n/an/a--
Dependencies
NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
Build dependencies:
  1. go125 : lang/go125
Fetch dependencies:
  1. go125 : lang/go125
There are no ports dependent upon this port

Configuration Options:
No options to configure
Options name:
security_bumblebee
USES:
go:modules zip
FreshPorts was unable to extract/find any pkg message
Master Sites:
Expand this list (2 items)
Collapse this list.
  1. https://codeload.github.com/perplexityai/bumblebee/tar.gz/v0.1.1?dummy=/
  2. https://proxy.golang.org/github.com/perplexityai/bumblebee/@v/
Collapse this list.

Number of commits found: 1

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
0.1.1
25 May 2026 03:59:57
commit hash: 214a20af56c5bf88ed4944acca07c37b0a482430commit hash: 214a20af56c5bf88ed4944acca07c37b0a482430commit hash: 214a20af56c5bf88ed4944acca07c37b0a482430commit hash: 214a20af56c5bf88ed4944acca07c37b0a482430 files touched by this commit
Xavier Beaudouin (kiwi) search for other commits by this committer
security/bumblebee: new port

Read-only supply-chain exposure scanner for developer endpoints

Number of commits found: 1