Execution Profile

garnet-labs/garnet-runtime-review-demo

Kernel-recorded by the Garnet eBPF sensorpinned to commit a77c140 (merge ref)

Garnet Record (install under sensor)/record

run 31130181149

Network Egress

7 destinations · 7 flows · 4 processes
recorded without an execution chain:no_bad_egress_domain
  • systemd
    • hosted-compute-agent[1836 · hosted-compute-agent]runner infrastructure
      • Runner.Listener
        • Runner.Worker
          • bash
            • node[2351 · node]step: 1. Install dependencies (the workload)
              • registry.npmjs.org104.16.6.34:443 (https) · tcp(detection: exec_from_unusual_dir)
              • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: credentials_files_access)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
          • node[2315 · node]runner infrastructure
            • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: credentials_files_access)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
            • github.com140.82.114.4:443 (https) · tcp(detection: credentials_files_access)(detection: interpreter_shell_spawn)
            • api.github.com140.82.114.5:443 (https) · tcp(detection: credentials_files_access)(detection: interpreter_shell_spawn)
            • release-assets.githubusercontent.com185.199.109.133:443 (https) · tcp(detection: credentials_files_access)(detection: interpreter_shell_spawn)
      • sudo
        • provjobd3379589150[1870 · provjobd3379589150]runner infrastructure
          • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: credentials_files_access)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
          • hosted-compute-watchdog-prod-iad-02.githubapp140.82.113.24:443 (https) · tcpalso recorded: glb-2a3c35-public-internal.githubapp.com
      • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: credentials_files_access)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
      • glb-2a3c35-public-internal.githubapp.com140.82.112.23:443 (https) · tcpalso recorded: hosted-compute-watchdog-prod-iad-02.githubapp

Assertions

1 hit
ATTENTIONno_bad_egress_domain
Workload
Repositorygarnet-labs/garnet-runtime-review-demo
WorkflowGarnet Record (install under sensor)
Jobrecord
Profile UUID019fd95a-c023-747e-ac1d-d7e4ed3d10f6
Refrefs/pull/22/merge
Timestamp
💡 How to read this
  • Runner.Worker
    • bash
      • curl
        • example.com
        • localhost(dns resolver)

Put the record on your pull requests

Garnet records what your code actually did when it ran — one step in your GitHub Actions workflow.