Skip to main content
The diff shows what changed. It doesn’t show what ran. Agents and dependencies run code you didn’t write in your CI, with your secrets. Garnet records each job’s execution chains — what ran, and the outbound connection each chain opened — at the kernel, on the runners you already use, and posts the record to the pull request before anyone approves.
A recorded Garnet comment comparing two commits: the job row leads with +1 −0 and the tree marks one added destination, httpbin[.]org, reached from a postinstall hook

The diff added a postinstall hook. The run reached a host the diff never names.

The GitHub App connects your repos · the Garnet Action records your workflows · the PR comment carries one Execution Profile per job.

Human reviewers

Add Garnet to your CI — first Execution Profile in about five minutes.

Agentic reviewers & harnesses

Review agents and gates that consume the record as an input.
Garnet records the run. The policy stays yours.