Execution Profile

garnet-labs/posthog

Kernel-recorded by the Garnet eBPF sensorpinned to commit 796020d (merge ref)

demo — install-time metadata reach/install

run 31131955242

Network Egress

8 destinations · 8 flows · 4 processes
recorded without an execution chain:no_bad_egress_domain
  • systemd
    • hosted-compute-agent[2010 · hosted-compute-agent]runner infrastructure
      • Runner.Listener
        • Runner.Worker
          • bash
            • node[2643 · node]step: 1. Read manifest and install pinned tarball
              • registry.npmjs.org104.16.9.34:443 (https) · tcp(detection: exec_from_unusual_dir)
              • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: credentials_files_access)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
          • node[2592 · node]runner infrastructure
            • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: credentials_files_access)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
            • github.com140.82.114.3:443 (https) · tcp(detection: credentials_files_access)(detection: interpreter_shell_spawn)
            • api.github.com140.82.114.5:443 (https) · tcp(detection: credentials_files_access)(detection: interpreter_shell_spawn)
            • release-assets.githubusercontent.com185.199.109.133:443 (https) · tcp(detection: credentials_files_access)(detection: interpreter_shell_spawn)
      • sudo
        • provjobd2720977271[2029 · provjobd2720977271]runner infrastructure
          • localhost127.0.0.53:53 (dns) · udp(dns resolver)(detection: credentials_files_access)(detection: exec_from_unusual_dir)(detection: interpreter_shell_spawn)
          • glb-2a3c35-public-internal.githubapp.com140.82.112.23:443 (https) · tcpalso recorded: hosted-compute-watchdog-prod-iad-02.githubapp
      • 140.82.113.23:443 (https) · tcp
      • 140.82.114.24:443 (https) · tcp

Assertions

1 hit
ATTENTIONno_bad_egress_domain
Workload
Repositorygarnet-labs/posthog
Workflowdemo — install-time metadata reach
Jobinstall
Profile UUID019fd974-8a50-7f7d-88a3-f072c7c6d778
Refrefs/pull/94/merge
Timestamp
💡 How to read this
  • Runner.Worker
    • bash
      • curl
        • example.com
        • localhost(dns resolver)

Put the record on your pull requests

Garnet records what your code actually did when it ran — one step in your GitHub Actions workflow.