Execution Profile

aleesikander/express

Kernel-recorded by the Garnet eBPF sensorpinned to commit f2a80b8 (merge ref)

ci/test

run 31188020427

Network Egress

6 destinations · 7 flows · 5 processes
recorded without an execution chain:no_bad_egress_domain
  • systemd
    • hosted-compute-agent
      • Runner.Listener
        • Runner.Worker
          • bash
            • node[2591 · node]step: 3. Install dependencies
              • registry.npmjs.org104.16.5.34:443 (https) · tcp
              • localhost127.0.0.53:53 (dns) · udp(dns resolver)
          • node[2674 · node]runner infrastructure
            • glb-db52c2cf8be544.github.com140.82.112.22:443 (https) · tcpalso recorded: results-receiver.actions.githubusercontent
            • productionresultssa19.blob.core.windows20.209.113.193:443 (https) · tcpalso recorded: blob.bn3prdstrz12a.trafficmanager.net, blob.bn3prdstrz12a.store.core.windows.net
            • localhost127.0.0.53:53 (dns) · udp(dns resolver)
      • sudo
        • provjobd834747615[1986 · provjobd834747615]runner infrastructure
          • glb-p4a577-public-internal.githubapp.com20.75.202.224:443 (https) · tcpalso recorded: hosted-compute-watchdog-prod-eus-01.githubapp
          • localhost127.0.0.53:53 (dns) · udp(dns resolver)
    • systemd-resolved[524 · systemd-resolved]runner infrastructure
      • 168.63.129.16:53 (dns) · udp
    • python3.12
      • python3.12[1341 · python3.12]runner infrastructure
        • 168.63.129.16:32526, 80 (http) · tcp

Assertions

2 hits
ATTENTIONno_bad_egress_domain
FAILno_code_injection_via_proc_memory
Workload
Repositoryaleesikander/express
Workflowci
Jobtest
Profile UUID019fdca5-4279-7b83-b362-0a8ade242e0e
Refrefs/pull/3/merge
Timestamp
💡 How to read this
  • Runner.Worker
    • bash
      • curl
        • example.com
        • localhost(dns resolver)

Put the record on your pull requests

Garnet records what your code actually did when it ran — one step in your GitHub Actions workflow.