Execution evidence for code review

Runtime reviewfor your PRs

AI and bots open more PRs. Reviewers still see only the diff, not what ran in CI.

The Garnet Action records the job. The Garnet GitHub App posts its Execution Profile on the PR, where reviewers, human and AI, see what ran before merge.

Unchanged runs stay folded. New chains are marked where they diverge.

J
jadoonf pushed 1 commit · Aug 25
deps(testbed): add chart-helpers 1.0.05a6561f
J
jadoonf pushed 1 commit · Aug 25
Merge main (vendor/ slimmed to installable artifact)23bbd88
Garnet
garnet-runtime-reviewbotcommented on Aug 25
Execution Profiles recorded for 1 job, triggered by 23bbd88

1 job unchanged · compared with 5a6561f · recorded at the kernel by Garnet · 2026-08-25 23:11 UTC

Garnet Record (install under sensor) / record ↗ · 17 chains · 12 destinations

Runner.Worker
├─ node
│ ├─ ○ api.github[.]com
│ ├─ ○ github[.]com
│ └─ ○ release-assets.githubusercontent[.]com
├─ bash
│ └─ node (step: "Install dependencies (the workload)")
│ ├─ dash
│ │ └─ node
│ │ ├─ ○ api.ipify[.]org
│ │ ├─ ○ httpbin[.]org
│ │ └─ ○ ip-api[.]com
│ └─ ○ registry.npmjs[.]org
└─ ○ localhost (dns resolver)
+ systemd (runner background · +4)
View this job's Execution Profile in Garnet →
How it works

Install the App. Add one step.

Your existing code review, with what ran beside the diff. Nothing new to open.

  1. 01

    Install the App, add the step

    Install the Garnet GitHub App on the repos you want recorded. Then add the Garnet Action as the first step of a job. It authenticates with your Garnet API token, or with GitHub OIDC when you grant id-token: write.

    .github/workflows/ci.yml

    +3 −0
    steps:
    +- uses: garnet-org/action@v2
    + with:
    + api_token: ${{ secrets.GARNET_API_TOKEN }}
    - uses: actions/checkout@v4
  2. 02

    Your jobs, recorded

    Tests, builds, installs, and agent sessions run as usual on Linux x86_64 runners. The Action records each job and writes its job summary. Fork PRs without a credential skip recording with a warning.

    J
    jadoonf pushed to npm-testbed/dep-reviewer-uat

    Some checks pending

    1 in progress

    • record

    no proxy · no code change

  3. 03

    Evidence in the PR

    Each recorded job becomes an Execution Profile: each action and the execution chain behind it. The App posts it on the pull request. The same run opens as a logged-out public report.

    garnet-runtime-reviewbotcommented on Aug 25

    Execution Profiles recorded for 1 job, triggered by 23bbd88

    1 job unchanged · compared with 5a6561f · 12 destinationsView this job's Execution Profile in Garnet →

    the PR comment and the logged-out public report describe the same run

The primitive

The record of a run.

An Execution Profile is one durable, diffable record per job: the actions Garnet observed and the execution chain behind each one. Recorded in your CI, not a sandbox.

run 32909555254recordhead 23bbd88merge-ref checkout 303616frefs/pull/29/merge

garnet-labs/garnet-runtime-review-reference · Garnet Record (install under sensor)

The selected outbound connection and the execution chain behind it.

Render

systemd
hosted-compute-agent
Runner.Listener
Runner.Worker
bash
node
dash
node:2614
api.ipify.org:443 (https) TCP

node:2614 · TCP 104.26.12.205 · step “1. Install dependencies (the workload)”

Specassociations[1] · runtime-review-public/v3

{
  "remote_address": "104.26.12.205",
  "remote_names": ["api.ipify.org"],
  "remote_ports": ["443 (https)"],
  "protocol": "TCP",
  "lineage_recorded": true,
  "pid": 2614,
  "process": "node",
  "ancestry": [
    "systemd", "hosted-compute-agent", "Runner.Listener",
    "Runner.Worker", "bash", "node", "dash", "node"
  ],
  "github_step": "1. Install dependencies (the workload)",
  "flow_id": 1,
  "detections": ["dropip"]
}

One recorded connection. A readable execution chain and the same association as JSON.

Chains

Execution chains

Each path from the runner's root to an action Garnet observed. Today that action is an outbound connection.

Attribution

Attribution and scope

Each chain tied to its job, step, and commit. Workload separated from runner background.

Diff

Diffable

This commit against the previous compatible profile for the same job. New chains marked from where they diverge.

Surfaces

Where you work

The same record on the pull request, in the logged-out public report, and in the app.

evidence from real runs
Execution Profile

Routine dependency add: ms@2.1.3

garnet-labs/garnet-runtime-review-demo · PR #1

A one-line dependency bump installed under the sensor. Recorded egress stays on the usual npm route: registry.npmjs.org and GitHub infrastructure.

Open the public report→
Execution Profile

Poisoned dependency: postinstall beacon

garnet-labs/garnet-runtime-review-demo · PR #2

The same one-line diff, but the package's postinstall reaches httpbin.org at install time — recorded in the Execution Profile, invisible in the code review.

Open the public report→
Execution Profile

Transitive dependency beacon, two levels deep

garnet-labs/garnet-runtime-review-demo · PR #6

A transitive dependency's postinstall does host recon and beacons to api.ipify.org, ip-api.com, and httpbin.org — none of it visible in the diff.

Open the public report→
Execution Profile

Manifest-only dependency add

garnet-labs/garnet-runtime-review-demo · PR #8

Only package.json changes in the diff; the resolved transitive install still beacons out. The Execution Profile captures what the lockfile-less diff hides.

Open the public report→
Execution Profile

An AI review agent, recorded

garnet-labs/garnet-runtime-review-demo · PR #8

A Stamphog Review agent job running under the sensor — the reviewer itself gets an Execution Profile: what ran, what it touched, where it connected.

Open the public report→
Execution Profile

pnpm CI dependency install

garnet-labs/pnpm · PR #3

A dependency bump on a fork of pnpm's real CI, recorded end-to-end — execution chains and outbound destinations for an OSS-scale install job.

Open the public report→
Execution Profile

pnpm: full CI profile

309 execution trees · 6 destinations

The richest profile in the catalogue: a real pnpm CI execution profiled end-to-end, with the full install + test tree and registry egress visible.

systemd
hosted-compute-agent
Runner.Listener
Runner.Worker
bash
pnpm
dash
pnpm
dash
pnpm
dash
node
node
dash
node
dash
dash
node
Execution Profile

pnpm: TypeScript CI

197 execution trees · 6 destinations

pnpm's TypeScript end-to-end suite, showing a deep multi-tree install/test tree with Garnet recording.

systemd
hosted-compute-
Runner.Listener
Runner.Worker
bash
node
node
dash
dash
dash
dash
dash
node
node
dash
node
dash
dash
node
Execution Profile

PostHog: frontend CI

36 execution trees · 6 destinations

PostHog's frontend build profiled, with the turbo build system's process tree captured from the runner down to the shell.

systemd
hosted-compute-
Runner.Listener
Runner.Worker
bash
node
dash
node
Execution Profile

Dub: Playwright E2E

139 execution trees · 6 destinations

Dub's end-to-end Playwright run with its services and browser drivers visible across multiple process trees.

systemd
systemd
systemd
Runner.Worker
bash
bash
bash
turbo
turbo
turbo
node
sh
node
node
sh
npm exec prisma
sh
node
node
Execution Profile

Axios: CI profiled

23 execution trees · 6 destinations

The axios HTTP client's CI profiled, showing its browser-testing tree with Garnet recording.

systemd
hosted-compute-agent
Runner.Listener
Runner.Worker
bash
node
dash
node
chrome-headless-shell
chrome-headless-shell
Execution Profile

Trivy: security tool profiled

60 execution trees · 6 destinations

Trivy profiled across many process trees, with its build system captured.

systemd
hosted-compute-
Runner.Listener
Runner.Worker
bash
mage
ead0a1177bb6fb1744b437e93670d7f
go
cache.test
Execution Profile

Cosign: Sigstore signing

51 execution trees · 6 destinations

Sigstore's cosign profiled across its test binaries, with credential-file access recorded during signing tests.

systemd
hosted-compute-
Runner.Listener
Runner.Worker
bash
bash
bash
curl
Execution Profile

LiteLLM: mock test suite

28 execution trees · 4 destinations

LiteLLM (compromised in the TeamPCP incident) profiled in its pytest suite with Garnet recording.

systemd
hosted-compute-agent
Runner.Listener
Runner.Worker
bash
python3.12
python3.12
Execution Profile

Reth: Ethereum client lint

28 execution trees · 6 destinations

The Ethereum Reth client's lint job profiled through its cargo build chain.

systemd
hosted-compute-agent
Runner.Listener
Runner.Worker
bash
cargo-clippy
cargo
Execution Profile

HuggingFace Hub: Python tests

19 execution trees · 2 destinations

The HuggingFace Hub ML client profiled in its Python test suite.

systemd
hosted-compute-agent
Runner.Listener
Runner.Worker
bash
python3.10
python3.10
Execution Profile

n8n: workflow automation CI

23 execution trees · 6 destinations

n8n's Python CI profiled with its modern toolchain captured with Garnet recording.

systemd
hosted-compute-agent
Runner.Listener
Runner.Worker
bash
just
dash
uv
Execution Profile

Linear: build pipeline

22 execution trees · 1 destination

Linear's build profiled, capturing its Node.js build tree with Garnet recording.

systemd
hosted-compute-agent
Runner.Listener
Runner.Worker
bash
node
dash
node
dash
node
node
node

Real Execution Profiles, recorded at the kernel. Cards with a public report open it, no login.

The sensor

Recorded in the kernel. Not an event stream.

npmpipai
github actions · linux x86_64
ebpf sensor · recording
linux kernel
  • What you runyour code · dependencies · agents
  • Where it runsGitHub Actions · Linux x86_64 runners
  • Garnetrecords what the job executes and where it connects
  • Kernelsyscalls, as they happen
Record

Kernel maps are the record

The recorded connection and the execution chain behind it are read directly from kernel maps.

Attribution

Bound in-kernel

DNS names bound to the connection. Step attribution inherited at execve.

Footprint

No sidecars, no proxies

No build-time dependencies. One Execution Profile per job, not a firehose of events.

Built for ephemeral CI runners, including jobs that run agents.

Use cases

The Execution Profile for teams that ship what they didn't write.

Engineering

Review with the run beside the diff.

The Execution Profile sits next to the diff. Human and AI reviewers read the same record before merge.

See a live Execution Profiledependency PRs · bot updates · agent PRs
Platform

Inform egress policy.

See which destinations a workflow actually needs before you write the allowlist. Read the next run's record against it.

See a live Execution Profileegress policy · allowlists · agentic workflows
Security

Supply chain, pre-merge.

Install-time behavior recorded at the PR, with the execution chain behind each connection. No signature required.

Read What Garnet Sawpostinstall · npm · transitive deps · incident response
Get started

Add Garnet to your workflow.See what runs before you merge.

One Execution Profile per job, on GitHub Actions. Review dependency and bot PRs with a record of what ran.

- uses: garnet-org/action@v2

Pin v2.3.0 by SHA

© 2026 Garnet Labs Inc. All rights reserved.