Execution Profile

aleesikander/flask

Kernel-recorded by the Garnet eBPF sensorpinned to commit 3e4c008 (merge ref)

Garnet Flask Baseline/baseline

run 31116746143

Network Egress

9 destinations · 10 flows · 6 processes
  • systemd
    • hosted-compute-agent
      • Runner.Listener
        • Runner.Worker
          • node[2799 · node]runner infrastructure
            • releases.astral.sh104.26.13.77:443 (https) · tcp(detection: dynamic_linker_attacks)(detection: interpreter_shell_spawn)
            • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: dynamic_linker_attacks)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
            • raw.githubusercontent.com185.199.108.133:443 (https) · tcp(detection: dynamic_linker_attacks)(detection: interpreter_shell_spawn)
          • bash
            • uv[2823 · uv]step: 4. Install locked test dependencies
              • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: dynamic_linker_attacks)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
              • pypi.org151.101.0.223:443 (https) · tcp(detection: exec_from_unusual_dir)
            • python3.12[2863 · python3.12]step: 6. Controlled long-lived direct Python HTTPS request
              • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: dynamic_linker_attacks)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
              • example.com172.66.147.243:443 (https) · tcp(detection: exec_from_unusual_dir)
      • sudo
        • provjobd1127515438[2050 · provjobd1127515438]runner infrastructure
          • 140.82.114.23:443 (https) · tcp
    • systemd-resolved[556 · systemd-resolved]runner infrastructure
      • 168.63.129.16:53 (dns) · udp
    • python3.12
      • python3.12[1384 · python3.12]runner infrastructure
        • 168.63.129.16:32526, 80 (http) · tcp
        • 169.254.169.254:80 (http) · tcp(instance metadata)

Assertions

2 hits
ATTENTIONno_bad_egress_domain
FAILno_code_injection_via_proc_memory
Workload
Repositoryaleesikander/flask
WorkflowGarnet Flask Baseline
Jobbaseline
Profile UUID019fd7be-d4e5-7229-b515-7ffae9c4d5f7
Refrefs/pull/1/merge
Timestamp
💡 How to read this
  • Runner.Worker
    • bash
      • curl
        • example.com
        • localhost(dns resolver)

Put the record on your pull requests

Garnet records what your code actually did when it ran — one step in your GitHub Actions workflow.