From ef6c632f21f5cc25804043afd1296f1203b85011 Mon Sep 17 00:00:00 2001 From: ruangraung Date: Tue, 22 Sep 2026 21:17:13 +0700 Subject: [PATCH] docs: state the unofficial status, the real scan default, and the security route The README described the max duration default as 10m. The form leaves it empty since the change that removed the cap, so the sentence now describes what the form does. The README also states plainly that this is an unofficial interface, and CONTRIBUTING points at SECURITY.md instead of describing a reporting channel that was never set up. SECURITY.md is new. It names GitHub private vulnerability reporting, states what is in scope, and says what a useful report contains. The CI triggers no longer list refactor/v2, which was deleted with the other merged branches. --- .github/workflows/ci.yml | 4 ++-- CONTRIBUTING.md | 4 ++-- README.md | 6 ++++-- SECURITY.md | 42 ++++++++++++++++++++++++++++++++++++++++ 4 files changed, 50 insertions(+), 6 deletions(-) create mode 100644 SECURITY.md diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2d8731a..29dcf0e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,6 +1,6 @@ # CI — supply-chain + secret + dependency-audit + build gates. # -# Runs on push to main/refactor/v2 and every pull request. +# Runs on push to main and every pull request. # # Layered security model: # - Socket (supply-chain + SAST) -> malicious-package / code-level gate @@ -18,7 +18,7 @@ name: CI on: push: - branches: [main, refactor/v2] + branches: [main] pull_request: concurrency: diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index e484b25..0df6c5b 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -43,5 +43,5 @@ Prefixes, loosely [Conventional Commits](https://www.conventionalcommits.org/): ## Reporting security problems -A private reporting channel is not set up yet. If you have found something, open an issue that says you have a -security problem without the details, and a maintainer will get in touch to arrange a private conversation. +Use the private route described in [SECURITY.md](SECURITY.md) rather than a public issue. A public issue that +describes a vulnerability before it is fixed puts everyone running this tool at risk. diff --git a/README.md b/README.md index 1727540..54ad604 100644 --- a/README.md +++ b/README.md @@ -3,6 +3,8 @@ A web interface for [Bumblebee](https://github.com/perplexityai/bumblebee), the open source supply chain security scanner from Perplexity AI. +This is an unofficial interface for that scanner. It is not affiliated with or endorsed by Perplexity AI. + Bumblebee walks a filesystem, reads package metadata across a dozen ecosystems, and reports anything that matches a published compromise. It is a CLI, which suits some people and not others. Bumblebee GUI wraps it in a web app: point it at a directory, run a scan, watch progress stream in, and read the result as a table you @@ -175,8 +177,8 @@ and removes the partial output. | `deep` | Incident response | Explicit root paths, full home directory | `deep` is the incident-response profile and refuses to run without an explicit root, because it will not guess -which paths matter. The scan form's max duration defaults to `10m`, which a deep scan of a whole home -directory can exceed. +which paths matter. The scan form leaves max duration empty by default, which sends no limit at all and keeps +the scanner's own behaviour. Set `30s`, `10m` or `2h` to cap a scan, or `0` for no limit. ## What has actually been tested diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..1b562fc --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,42 @@ +# Security policy + +## Reporting a vulnerability + +Use GitHub's private vulnerability reporting for this repository: open the **Security** tab and choose **Report a vulnerability**. The report stays private between you and the maintainer until a fix is published. + +Please do not open a public issue for a vulnerability. + +A useful report says: + +- what the problem is, and where in the project it lives +- how to reproduce it, including the commit or image you tested +- what an attacker could do with it +- a suggested fix, if you have one + +There is no bug bounty and no guaranteed response time. This is a small project maintained in spare time. Reports are read and answered as soon as possible. + +## Supported versions + +Only the latest commit on `main` is supported. There are no maintained release branches yet. + +## Scope + +In scope: + +- the backend API and the frontend in this repository +- the Docker Compose setup and its default configuration +- the image builds and the bundled exposure catalogues + +Out of scope: + +- the upstream Bumblebee scanner and its catalogues. Report those to + [perplexityai/bumblebee](https://github.com/perplexityai/bumblebee/issues). +- a vulnerability in a dependency with no exploitable path through this project + +## How this project runs + +Bumblebee GUI is an unofficial interface to the Bumblebee scanner, not affiliated with Perplexity. It runs on the host that starts it. The API binds to loopback by default, and a directory is only scanned if it is mounted into the backend container, read-only, by whoever starts the stack. Nothing is sent anywhere except the upstream threat-intel downloads performed during the image build. + +## Reporting something that is not a vulnerability + +Misleading output is worth reporting as a normal issue: a scan that matches nothing and a scan whose catalogues are stale should not look alike, and a scan that stopped early should say so. If you find a case where the interface states more confidence than the data supports, open an issue.