NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #3465 most downloaded on crates.io
Cedar is a language for defining permissions as policies, which describe who should have access to what.
Last release 21 days ago
15 Sep 2026
Ships fairly regularly
a new release about every 4 weeks
Nearly every release is documented
notes for 56 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
80 releases · first in 2023
One column per quarter.
Calling add_template with a PolicyId that is an existing link will now error. (#671, backport of #456)
Cedar Language Version: 2.1
add_template with a PolicyId that is an existing link will now error. (#671, backport of #456)PolicySet::link to not mutate internal state when failing to link a static
policy. With this fix it is possible to create a link with a policy id
after previously failing to create that link with the same id from a static
policy. (#669, backport of #412)i64::MIN can now be properly converted to the JSON policy format. (#672, backport of #601)Template::from_json errors when there are slots in template conditions. (#672, backport of #626)Policy::to_json does not error on policies containing special identifiers such as principal, then, and true. (#672, backport of #628)Reverted accidental breaking change to schema format introduced in the 2.3.2 release. Attribute types in schema files may now contain unexpected keys…
Cedar Language Version: 2.1
Issue #370 related to how the validator handles template-linked policies. The validator will now produce the same result for an equivalent static and
Cedar Language Version: 2.1
EntityUid's impl of FromStr is no longer marked as deprecated.
Cedar Language Version: 2.1
Unknown fields for partial evaluation.EntityUid's impl of FromStr is no longer marked as deprecated. (#319)if,
resulting in a panic on some inputs.Request::principal(), Request::action(), and Request::resource() will
now return None if the entities are unspecified (i.e., constructed by passing
None to Request::new()). (#339)Uses of deprecated __expr escapes from integration tests.
Cedar Language Version: 2.1
EntityTypeName.
basename to get the basename (without namespaces).namespace_components to get the namespace as an iterator over its components.namespace to get the namespace as a single string.RecordAttrDoesNotExist error
message now contains a list of attributes that do exist.Record, the error message will indicated the affected entity type or action.permit(principal, action, resource) when {{"foo": 5} has bar}; would validate.
Now it will not, since we know {"foo": 5} has bar is False, and the
validator will return an error for a policy that can never fire.__expr escapes from integration tests.Fixed parsing of small negative decimal literals.
Cedar Language Version: 2.1
Re-export cedar_policy_core::EntitiesError.
Cedar Language Version: 2.1
cedar_policy_core::entities::EntitiesError.memberOf lists in
schemas. An action without an explicit namespace in a memberOf now
correctly uses the default namespace. (#151)Improve error messages for some validation errors
Cedar Language Version: 2.1
"type" field will generate an error
stating that "type" is a required field instead of an inscrutable error
complaining about the untagged enum SchemaType."type" field corresponding to one of the
builtin types but missing a required field for that type will generate an
error stating that a required field is missing instead of claiming that it
could not find "common types" definition for that builtin type.partial-eval feature flag.Panic in PolicySet::link() that could occur when the function was called with a policy id corresponding to a static policy.
Cedar Language Version: 2.1
PolicySet::link() that could occur when the function was called
with a policy id corresponding to a static policy. (#203)Cedar Language Version: 2.1.0
PolicySet::link() that could occur when the function was called
with a policy id corresponding to a static policy. (#203)…function names). The risk that this may be a breaking change for some Cedar users was accepted due to the potential security ramifications; see discus…
Cedar Language Version: 2.1
EntityTypeName::from_str() and
EntityNamespace::from_str(), as well as in some fields of the Cedar JSON
schema format (e.g., namespace declarations, entity type names), Cedar JSON
entities format (e.g., entity type names, extension function names) and the
Cedar JSON policy format used by Policy::from_json() (e.g., entity type names,
extension function names). The risk that this may be a breaking change for some
Cedar users was accepted due to the potential security ramifications; see
discussion in the RFC.Nothing published for this version
Nothing published for this version
Entities::write_to_json function to api.rs.
Cedar Language Version: 2.0
Entities::write_to_json function to api.rs.Cedar Language Version: 2.0.0
Entities::write_to_json function to api.rs.Nothing published for this version
Schema::action_entities to provide access to action entities defined in a schema.
Cedar Language Version: 2.0
Schema::action_entities to provide access to action entities defined in a schema.cedar-policy-core dependency.Cargo.toml due to having both license and license-file metadata entries.Nothing published for this version
Update Cargo.toml metadata to correctly represent this crate as Apache-2.0 licensed.
Cedar Language Version: 2.0
Cargo.toml metadata to correctly represent this crate as Apache-2.0 licensed.Cedar Language Version: 2.0.0
Cargo.toml metadata to correctly represent this crate as Apache-2.0 licensed.Cedar Language Version: 2.0
Cedar Language Version: 2.0
Cedar Language Version: 2.0
Cedar Language Version: 2.0
Initial release of cedar-policy.
Cedar Language Version: 2.0
cedar-policy.Your coding agent can read these notes before it upgrades. Set up the MCP server →