Runtime reviewfor your PRs
AI and bots open more PRs. Reviewers still see only the diff, not what ran in CI.
The Garnet Action records the job. The Garnet GitHub App posts its Execution Profile on the PR, where reviewers, human and AI, see what ran before merge.
Unchanged runs stay folded. New chains are marked where they diverge.
23bbd881 job unchanged · compared with 5a6561f · recorded at the kernel by Garnet · 2026-08-25 23:11 UTC
Garnet Record (install under sensor) / record ↗ · 17 chains · 12 destinations
Install the App. Add one step.
Your existing code review, with what ran beside the diff. Nothing new to open.
- 01
Install the App, add the step
Install the Garnet GitHub App on the repos you want recorded. Then add the Garnet Action as the first step of a job. It authenticates with your Garnet API token, or with GitHub OIDC when you grant id-token: write.
+3 −0.github/workflows/ci.yml
steps:+- uses: garnet-org/action@v2+ with:+ api_token: ${{ secrets.GARNET_API_TOKEN }}- uses: actions/checkout@v4 - 02
Your jobs, recorded
Tests, builds, installs, and agent sessions run as usual on Linux x86_64 runners. The Action records each job and writes its job summary. Fork PRs without a credential skip recording with a warning.
Jjadoonf pushed to npm-testbed/dep-reviewer-uatSome checks pending
1 in progress
- record
no proxy · no code change
- 03
Evidence in the PR
Each recorded job becomes an Execution Profile: each action and the execution chain behind it. The App posts it on the pull request. The same run opens as a logged-out public report.
garnet-runtime-reviewbotcommented on Aug 25Execution Profiles recorded for 1 job, triggered by 23bbd88
1 job unchanged · compared with 5a6561f · 12 destinationsView this job's Execution Profile in Garnet →the PR comment and the logged-out public report describe the same run
The record of a run.
An Execution Profile is one durable, diffable record per job: the actions Garnet observed and the execution chain behind each one. Recorded in your CI, not a sandbox.
garnet-labs/garnet-runtime-review-reference · Garnet Record (install under sensor)
The selected outbound connection and the execution chain behind it.
Render
node:2614 · TCP 104.26.12.205 · step “1. Install dependencies (the workload)”
Specassociations[1] · runtime-review-public/v3
{
"remote_address": "104.26.12.205",
"remote_names": ["api.ipify.org"],
"remote_ports": ["443 (https)"],
"protocol": "TCP",
"lineage_recorded": true,
"pid": 2614,
"process": "node",
"ancestry": [
"systemd", "hosted-compute-agent", "Runner.Listener",
"Runner.Worker", "bash", "node", "dash", "node"
],
"github_step": "1. Install dependencies (the workload)",
"flow_id": 1,
"detections": ["dropip"]
}One recorded connection. A readable execution chain and the same association as JSON.
Execution chains
Each path from the runner's root to an action Garnet observed. Today that action is an outbound connection.
Attribution and scope
Each chain tied to its job, step, and commit. Workload separated from runner background.
Diffable
This commit against the previous compatible profile for the same job. New chains marked from where they diverge.
Where you work
The same record on the pull request, in the logged-out public report, and in the app.
Real Execution Profiles, recorded at the kernel. Cards with a public report open it, no login.
Recorded in the kernel. Not an event stream.
- What you runyour code · dependencies · agents
- Where it runsGitHub Actions · Linux x86_64 runners
- Garnetrecords what the job executes and where it connects
- Kernelsyscalls, as they happen
Kernel maps are the record
The recorded connection and the execution chain behind it are read directly from kernel maps.
Bound in-kernel
DNS names bound to the connection. Step attribution inherited at execve.
No sidecars, no proxies
No build-time dependencies. One Execution Profile per job, not a firehose of events.
Built for ephemeral CI runners, including jobs that run agents.
The Execution Profile for teams that ship what they didn't write.
Review with the run beside the diff.
The Execution Profile sits next to the diff. Human and AI reviewers read the same record before merge.
See a live Execution Profiledependency PRs · bot updates · agent PRsInform egress policy.
See which destinations a workflow actually needs before you write the allowlist. Read the next run's record against it.
See a live Execution Profileegress policy · allowlists · agentic workflowsSupply chain, pre-merge.
Install-time behavior recorded at the PR, with the execution chain behind each connection. No signature required.
Read What Garnet Sawpostinstall · npm · transitive deps · incident responseAdd Garnet to your workflow.See what runs before you merge.
One Execution Profile per job, on GitHub Actions. Review dependency and bot PRs with a record of what ran.
- uses: garnet-org/action@v2