Execution Profile

garnet-labs/garnet-runtime-review-demo

Kernel-recorded by the Garnet eBPF sensorpinned to commit a0aa1cf (merge ref)

Garnet Record (install under sensor)/record

run 30304296055

Network Egress

7 destinations · 7 flows · 4 processes
  • systemd
    • hosted-compute-agent[2018 · hosted-compute-agent]runner infrastructure
      • Runner.Listener
        • Runner.Worker
          • bash
            • node[2548 · node]step: 1. Install dependencies (the workload)
              • registry.npmjs.org104.16.3.34:443 (https) · tcp(detection: exec_from_unusual_dir)
              • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: credentials_files_access)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
          • node[2502 · node]runner infrastructure
            • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: credentials_files_access)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
            • github.com140.82.116.4:443 (https) · tcp(detection: credentials_files_access)(detection: interpreter_shell_spawn)
            • api.github.com140.82.116.5:443 (https) · tcp(detection: credentials_files_access)(detection: interpreter_shell_spawn)
            • release-assets.githubusercontent.com185.199.109.133:443 (https) · tcp(detection: credentials_files_access)(detection: interpreter_shell_spawn)
      • sudo
        • provjobd1535529067[2033 · provjobd1535529067]runner infrastructure
          • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: credentials_files_access)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
          • hosted-compute-watchdog-prod-iad-02.githubapp140.82.114.24:443 (https) · tcpalso recorded: glb-2a3c35-public-internal.githubapp.com
      • 140.82.113.24:443 (https) · tcp

Assertions

1 hit
ATTENTIONno_bad_egress_domain
Workload
Repositorygarnet-labs/garnet-runtime-review-demo
WorkflowGarnet Record (install under sensor)
Jobrecord
Profile UUID019fa558-e2a3-7bba-a030-3c7bbbc7add4
Refrefs/pull/3/merge
Timestamp
💡 How to read this
  • Runner.Worker
    • bash
      • curl
        • example.com
        • localhost(dns resolver)

Put the record on your pull requests

Garnet records what your code actually did when it ran — one step in your GitHub Actions workflow.