Execution Profile

aleesikander/flask

Kernel-recorded by the Garnet eBPF sensorpinned to commit 455f09a (merge ref)

Garnet Flask Baseline/baseline

run 31114534286

Network Egress

5 destinations · 6 flows · 4 processes
  • systemd
    • hosted-compute-agent
      • Runner.ListenerRunner.Worker
        • node[2819 · node]runner infrastructure
          • releases.astral.sh104.26.12.77:443 (https) · tcp(detection: dynamic_linker_attacks)(detection: interpreter_shell_spawn)
          • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: code_modification_through_procfs)(detection: dynamic_linker_attacks)(detection: interpreter_shell_spawn)
          • raw.githubusercontent.com185.199.111.133:443 (https) · tcp(detection: dynamic_linker_attacks)(detection: interpreter_shell_spawn)
      • sudo
        • provjobd2240395158[2183 · provjobd2240395158]runner infrastructure
          • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: code_modification_through_procfs)(detection: dynamic_linker_attacks)(detection: interpreter_shell_spawn)
          • glb-p4a577-public-internal.githubapp.com20.75.202.224:443 (https) · tcp(detection: code_modification_through_procfs)also recorded: hosted-compute-watchdog-prod-eus-02.githubapp
    • systemd-resolved[535 · systemd-resolved]runner infrastructure
      • 168.63.129.16:53 (dns) · udp
    • python3.12
      • python3.12[1754 · python3.12]runner infrastructure
        • 168.63.129.16:32526, 80 (http) · tcp

Assertions

2 hits
ATTENTIONno_bad_egress_domain
FAILno_code_injection_via_proc_memory
Workload
Repositoryaleesikander/flask
WorkflowGarnet Flask Baseline
Jobbaseline
Profile UUID019fd7a0-b99b-7295-82b5-e116ab50e7ff
Refrefs/pull/1/merge
Timestamp
💡 How to read this
  • Runner.Worker
    • bash
      • curl
        • example.com
        • localhost(dns resolver)

Put the record on your pull requests

Garnet records what your code actually did when it ran — one step in your GitHub Actions workflow.