Execution Profile

aleesikander/express

Kernel-recorded by the Garnet eBPF sensorpinned to commit ae755f7 (merge ref)

ci/test

run 31199046721

Network Egress

5 destinations · 6 flows · 5 processes
recorded without an execution chain:no_bad_egress_domain
  • systemd
    • hosted-compute-agent
      • Runner.Listener
        • Runner.Worker[2045 · Runner.Worker]runner infrastructure
          • bash
            • node[2594 · node]step: 3. Install dependencies
              • registry.npmjs.org104.16.0.34:443 (https) · tcp
              • localhost127.0.0.53:53 (dns) · udp(dns resolver)
          • localhost127.0.0.53:53 (dns) · udp(dns resolver)
      • sudo
        • provjobd972501930[1985 · provjobd972501930]runner infrastructure
          • hosted-compute-watchdog-prod-eus-01.githubapp20.75.202.224:443 (https) · tcpalso recorded: glb-p4a577-public-internal.githubapp.com
          • localhost127.0.0.53:53 (dns) · udp(dns resolver)
    • python3.12
      • python3.12[1403 · python3.12]runner infrastructure
        • 168.63.129.16:32526, 80 (http) · tcp
        • 169.254.169.254:80 (http) · tcp(instance metadata)
    • systemd-resolved[600 · systemd-resolved]runner infrastructure
      • 168.63.129.16:53 (dns) · udp

Assertions

2 hits
ATTENTIONno_bad_egress_domain
FAILno_code_injection_via_proc_memory
Workload
Repositoryaleesikander/express
Workflowci
Jobtest
Profile UUID019fdd1f-6dc5-71c3-835a-bf6840e8fab4
Refrefs/pull/4/merge
Timestamp
💡 How to read this
  • Runner.Worker
    • bash
      • curl
        • example.com
        • localhost(dns resolver)

Put the record on your pull requests

Garnet records what your code actually did when it ran — one step in your GitHub Actions workflow.