| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| goldilocks_4.14.7_checksums.txt | 2025-10-31 | 620 Bytes | |
| goldilocks_4.14.7_darwin_amd64.tar.gz | 2025-10-31 | 15.1 MB | |
| goldilocks_4.14.7_darwin_arm64.tar.gz | 2025-10-31 | 13.9 MB | |
| goldilocks_4.14.7_linux_amd64.tar.gz | 2025-10-31 | 14.9 MB | |
| goldilocks_4.14.7_linux_arm64.tar.gz | 2025-10-31 | 13.3 MB | |
| goldilocks_4.14.7_linux_armv6.tar.gz | 2025-10-31 | 14.0 MB | |
| goldilocks_4.14.7_linux_armv7.tar.gz | 2025-10-31 | 14.0 MB | |
| README.md | 2025-10-31 | 671 Bytes | |
| v4.14.7 source code.tar.gz | 2025-10-31 | 1.1 MB | |
| v4.14.7 source code.zip | 2025-10-31 | 1.1 MB | |
| Totals: 10 Items | 87.4 MB | 2 | |
Changelog
- [37bafd] INS-1565: Fix goldilocks vulnerabilities (#805)
- [ea8d0e] Update link to VPA Recommender documentation (#804)
- [789ce6] fix: update deps in CI and go (#803)
You can verify the signatures of both the checksums.txt file and the published docker images using cosign.
sha256sum -c goldilocks_v4.14.7_checksums.txt --ignore-missing
cosign verify-blob goldilocks_v4.14.7_checksums.txt --signature=goldilocks_v4.14.7_checksums.txt.sig --key https://artifacts.fairwinds.com/cosign.pub
cosign verify us-docker.pkg.dev/fairwinds-ops/oss/goldilocks:v4 --key https://artifacts.fairwinds.com/cosign.pub