Execution Profile

garnet-labs/posthog

Kernel-recorded by the Garnet eBPF sensorpinned to commit 0bd8906 (merge ref)

demo — install-time metadata reach/install

run 31131775657

Network Egress

9 destinations · 9 flows · 5 processes
recorded without an execution chain:no_bad_egress_domain
  • systemd
    • hosted-compute-agent[2001 · hosted-compute-agent]runner infrastructure
      • Runner.Listener
        • Runner.Worker
          • bash
            • node[2581 · node]step: 1. Read manifest and install pinned tarball
              • dash
                • node
                  • node[2600 · node]
                    • example.com104.20.23.154:443 (https) · tcp(detection: exec_from_unusual_dir)
                    • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: credentials_files_access)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
                    • 169.254.169.254:80 (http) · tcp(instance metadata)(detection: exec_from_unusual_dir)
              • registry.npmjs.org104.16.7.34:443 (https) · tcp(detection: exec_from_unusual_dir)
              • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: credentials_files_access)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
          • node[2531 · node]runner infrastructure
            • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: credentials_files_access)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
            • github.com140.82.114.4:443 (https) · tcp(detection: credentials_files_access)(detection: interpreter_shell_spawn)
            • api.github.com140.82.114.6:443 (https) · tcp(detection: credentials_files_access)(detection: interpreter_shell_spawn)
            • release-assets.githubusercontent.com185.199.109.133:443 (https) · tcp(detection: credentials_files_access)(detection: interpreter_shell_spawn)
      • sudo
        • provjobd4045566184[2041 · provjobd4045566184]runner infrastructure
          • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: credentials_files_access)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
          • glb-2a3c35-public-internal.githubapp.com140.82.114.24:443 (https) · tcpalso recorded: hosted-compute-watchdog-prod-iad-01.githubapp
      • 140.82.113.24:443 (https) · tcp
      • glb-2a3c35-public-internal.githubapp.com140.82.114.24:443 (https) · tcpalso recorded: hosted-compute-watchdog-prod-iad-01.githubapp

Assertions

1 hit
ATTENTIONno_bad_egress_domain
Workload
Repositorygarnet-labs/posthog
Workflowdemo — install-time metadata reach
Jobinstall
Profile UUID019fd971-db1a-7dad-882e-0c245ddb782f
Refrefs/pull/92/merge
Timestamp
💡 How to read this
  • Runner.Worker
    • bash
      • curl
        • example.com
        • localhost(dns resolver)

Put the record on your pull requests

Garnet records what your code actually did when it ran — one step in your GitHub Actions workflow.