diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2d8731a..29dcf0e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,6 +1,6 @@ # CI — supply-chain + secret + dependency-audit + build gates. # -# Runs on push to main/refactor/v2 and every pull request. +# Runs on push to main and every pull request. # # Layered security model: # - Socket (supply-chain + SAST) -> malicious-package / code-level gate @@ -18,7 +18,7 @@ name: CI on: push: - branches: [main, refactor/v2] + branches: [main] pull_request: concurrency: diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index e484b25..0df6c5b 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -43,5 +43,5 @@ Prefixes, loosely [Conventional Commits](https://www.conventionalcommits.org/): ## Reporting security problems -A private reporting channel is not set up yet. If you have found something, open an issue that says you have a -security problem without the details, and a maintainer will get in touch to arrange a private conversation. +Use the private route described in [SECURITY.md](SECURITY.md) rather than a public issue. A public issue that +describes a vulnerability before it is fixed puts everyone running this tool at risk. diff --git a/README.md b/README.md index 1727540..54ad604 100644 --- a/README.md +++ b/README.md @@ -3,6 +3,8 @@ A web interface for [Bumblebee](https://github.com/perplexityai/bumblebee), the open source supply chain security scanner from Perplexity AI. +This is an unofficial interface for that scanner. It is not affiliated with or endorsed by Perplexity AI. + Bumblebee walks a filesystem, reads package metadata across a dozen ecosystems, and reports anything that matches a published compromise. It is a CLI, which suits some people and not others. Bumblebee GUI wraps it in a web app: point it at a directory, run a scan, watch progress stream in, and read the result as a table you @@ -175,8 +177,8 @@ and removes the partial output. | `deep` | Incident response | Explicit root paths, full home directory | `deep` is the incident-response profile and refuses to run without an explicit root, because it will not guess -which paths matter. The scan form's max duration defaults to `10m`, which a deep scan of a whole home -directory can exceed. +which paths matter. The scan form leaves max duration empty by default, which sends no limit at all and keeps +the scanner's own behaviour. Set `30s`, `10m` or `2h` to cap a scan, or `0` for no limit. ## What has actually been tested diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..1b562fc --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,42 @@ +# Security policy + +## Reporting a vulnerability + +Use GitHub's private vulnerability reporting for this repository: open the **Security** tab and choose **Report a vulnerability**. The report stays private between you and the maintainer until a fix is published. + +Please do not open a public issue for a vulnerability. + +A useful report says: + +- what the problem is, and where in the project it lives +- how to reproduce it, including the commit or image you tested +- what an attacker could do with it +- a suggested fix, if you have one + +There is no bug bounty and no guaranteed response time. This is a small project maintained in spare time. Reports are read and answered as soon as possible. + +## Supported versions + +Only the latest commit on `main` is supported. There are no maintained release branches yet. + +## Scope + +In scope: + +- the backend API and the frontend in this repository +- the Docker Compose setup and its default configuration +- the image builds and the bundled exposure catalogues + +Out of scope: + +- the upstream Bumblebee scanner and its catalogues. Report those to + [perplexityai/bumblebee](https://github.com/perplexityai/bumblebee/issues). +- a vulnerability in a dependency with no exploitable path through this project + +## How this project runs + +Bumblebee GUI is an unofficial interface to the Bumblebee scanner, not affiliated with Perplexity. It runs on the host that starts it. The API binds to loopback by default, and a directory is only scanned if it is mounted into the backend container, read-only, by whoever starts the stack. Nothing is sent anywhere except the upstream threat-intel downloads performed during the image build. + +## Reporting something that is not a vulnerability + +Misleading output is worth reporting as a normal issue: a scan that matches nothing and a scan whose catalogues are stale should not look alike, and a scan that stopped early should say so. If you find a case where the interface states more confidence than the data supports, open an issue.