Releases: FairwindsOps/goldilocks
v4.14.18
Changelog
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.18_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.18_checksums.txt --signature=goldilocks_v4.14.18_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub
v4.14.10
Changelog
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.10_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.10_checksums.txt --signature=goldilocks_v4.14.10_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub
v4.14.9
Changelog
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.9_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.9_checksums.txt --signature=goldilocks_v4.14.9_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub
v4.14.8
Changelog
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.8_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.8_checksums.txt --signature=goldilocks_v4.14.8_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub
v4.14.7
Changelog
- 37bafdd INS-1565: Fix goldilocks vulnerabilities (#805)
- ea8d0e6 Update link to VPA Recommender documentation (#804)
- 789ce65 fix: update deps in CI and go (#803)
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.7_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.7_checksums.txt --signature=goldilocks_v4.14.7_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub
v4.14.6
Changelog
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.6_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.6_checksums.txt --signature=goldilocks_v4.14.6_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub
v4.14.5
Changelog
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.5_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.5_checksums.txt --signature=goldilocks_v4.14.5_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub
v4.14.4
Changelog
- d28372d INS-1305: fix CVE-2025-47907 (#785)
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.4_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.4_checksums.txt --signature=goldilocks_v4.14.4_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub
v4.14.3
Changelog
- aae7bc1 INS-1305: fix CVE-2025-47907 (#784)
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.3_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.3_checksums.txt --signature=goldilocks_v4.14.3_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub
v4.14.2
Changelog
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.2_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.2_checksums.txt --signature=goldilocks_v4.14.2_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub