Releases: FairwindsOps/goldilocks
Release list
v4.16.1
Changelog
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
cosign verify-blob checksums.txt --bundle=checksums.txt.sigstore.json --key https://artifacts.fairwinds.com/cosign-p256.pubcosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4.16.1 --key https://artifacts.fairwinds.com/cosign-p256.pubv4.16.0
Changelog
- 7b4c069 feat: mark containers whose requests/limits already match the VPA recommendation (#321) (#878)
- de70ae1 feat: update dependencies (#879)
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
cosign verify-blob checksums.txt --bundle=checksums.txt.sigstore.json --key https://artifacts.fairwinds.com/cosign-p256.pubcosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4.16.0 --key https://artifacts.fairwinds.com/cosign-p256.pubv4.15.3
Changelog
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
cosign verify-blob checksums.txt --bundle=checksums.txt.sigstore.json --key https://artifacts.fairwinds.com/cosign-p256.pubcosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4.15.3 --key https://artifacts.fairwinds.com/cosign-p256.pubv4.15.2
Changelog
- 010694f Managed by Terraform
- 16e02e7 Managed by Terraform
- 3be8f9e Managed by Terraform
- 07b6882 fix goreleaser signing on release (#859)
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
cosign verify-blob checksums.txt --bundle=checksums.txt.sigstore.json --key https://artifacts.fairwinds.com/cosign-p256.pubcosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4.15.2 --key https://artifacts.fairwinds.com/cosign-p256.pubv4.15.1
Changelog
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
cosign verify-blob checksums.txt --bundle=checksums.txt.sigstore.json --key https://artifacts.fairwinds.com/cosign-p256.pubcosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4.15.1 --key https://artifacts.fairwinds.com/cosign-p256.pubv4.15.0
Changelog
- d668d78 INS-2242: Fix goldilocks vulnerabilities (#849)
- 41c6607 Managed by Terraform
- 6e94e03 Managed by Terraform
- 86aaec6 Managed by Terraform
- ab42299 add notice to include registry change and immutable images notice on the readme (#851)
- b4d579c fix: honor -stderrthreshold when -logtostderr is set (#850)
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
cosign verify-blob checksums.txt --signature=checksums.txt.sig --key https://artifacts.fairwinds.com/cosign-p256.pubcosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4.15.0 --key https://artifacts.fairwinds.com/cosign-p256.pubv4.14.18
Changelog
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.18_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.18_checksums.txt --signature=goldilocks_v4.14.18_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub
v4.14.10
Changelog
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.10_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.10_checksums.txt --signature=goldilocks_v4.14.10_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub
v4.14.9
Changelog
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.9_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.9_checksums.txt --signature=goldilocks_v4.14.9_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub
v4.14.8
Changelog
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.8_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.8_checksums.txt --signature=goldilocks_v4.14.8_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub