Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# CI — supply-chain + secret + dependency-audit + build gates.
#
# Runs on push to main/refactor/v2 and every pull request.
# Runs on push to main and every pull request.
#
# Layered security model:
# - Socket (supply-chain + SAST) -> malicious-package / code-level gate
Expand All @@ -18,7 +18,7 @@ name: CI

on:
push:
branches: [main, refactor/v2]
branches: [main]
pull_request:

concurrency:
Expand Down
4 changes: 2 additions & 2 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,5 +43,5 @@ Prefixes, loosely [Conventional Commits](https://www.conventionalcommits.org/):

## Reporting security problems

A private reporting channel is not set up yet. If you have found something, open an issue that says you have a
security problem without the details, and a maintainer will get in touch to arrange a private conversation.
Use the private route described in [SECURITY.md](SECURITY.md) rather than a public issue. A public issue that
describes a vulnerability before it is fixed puts everyone running this tool at risk.
6 changes: 4 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,8 @@
A web interface for [Bumblebee](https://github.com/perplexityai/bumblebee), the open source supply chain
security scanner from Perplexity AI.

This is an unofficial interface for that scanner. It is not affiliated with or endorsed by Perplexity AI.

Bumblebee walks a filesystem, reads package metadata across a dozen ecosystems, and reports anything that
matches a published compromise. It is a CLI, which suits some people and not others. Bumblebee GUI wraps it in
a web app: point it at a directory, run a scan, watch progress stream in, and read the result as a table you
Expand Down Expand Up @@ -175,8 +177,8 @@ and removes the partial output.
| `deep` | Incident response | Explicit root paths, full home directory |

`deep` is the incident-response profile and refuses to run without an explicit root, because it will not guess
which paths matter. The scan form's max duration defaults to `10m`, which a deep scan of a whole home
directory can exceed.
which paths matter. The scan form leaves max duration empty by default, which sends no limit at all and keeps
the scanner's own behaviour. Set `30s`, `10m` or `2h` to cap a scan, or `0` for no limit.

## What has actually been tested

Expand Down
42 changes: 42 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
# Security policy

## Reporting a vulnerability

Use GitHub's private vulnerability reporting for this repository: open the **Security** tab and choose **Report a vulnerability**. The report stays private between you and the maintainer until a fix is published.

Please do not open a public issue for a vulnerability.

A useful report says:

- what the problem is, and where in the project it lives
- how to reproduce it, including the commit or image you tested
- what an attacker could do with it
- a suggested fix, if you have one

There is no bug bounty and no guaranteed response time. This is a small project maintained in spare time. Reports are read and answered as soon as possible.

## Supported versions

Only the latest commit on `main` is supported. There are no maintained release branches yet.

## Scope

In scope:

- the backend API and the frontend in this repository
- the Docker Compose setup and its default configuration
- the image builds and the bundled exposure catalogues

Out of scope:

- the upstream Bumblebee scanner and its catalogues. Report those to
[perplexityai/bumblebee](https://github.com/perplexityai/bumblebee/issues).
- a vulnerability in a dependency with no exploitable path through this project

## How this project runs

Bumblebee GUI is an unofficial interface to the Bumblebee scanner, not affiliated with Perplexity. It runs on the host that starts it. The API binds to loopback by default, and a directory is only scanned if it is mounted into the backend container, read-only, by whoever starts the stack. Nothing is sent anywhere except the upstream threat-intel downloads performed during the image build.

## Reporting something that is not a vulnerability

Misleading output is worth reporting as a normal issue: a scan that matches nothing and a scan whose catalogues are stale should not look alike, and a scan that stopped early should say so. If you find a case where the interface states more confidence than the data supports, open an issue.
Loading