NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #286 by repository stars
Last release today
05 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4342 releases · first in 2016
Nothing published for this version
Nothing published for this version
This release contains a mix of features and bugfixes.
This release contains a mix of features and bugfixes.
entrypoint annotation implies document scope (#6798)The entrypoint annotation's scope requirement
has changed from rule to document (https://github.com/open-policy-agent/opa/issues/6798).
Furthermore, if no scope annotation is declared for a METADATA block preceding a rule, the presence of an entrypoint
annotation with a true value will assign the block a document scope, where the rule scope is otherwise the default.
In practice, a rule entrypoint always point to the entire document and not a particular rule definition. The previous behavior was a bug, and one we've now addressed.
Authored by @anderseknert
copy method copy all values (#6949) authored by @anderseknertopa exec: This command never supported "pretty" formatting (--format=pretty or -f pretty), only json. Passing pretty is now invalid. (#6923) authored by @srenatus
Note that the flag is now unnecessary, but it's kept so existing calls like opa exec -fjson ... remain valid.This release includes a fix where OPA would accept UNC locations on Windows. Reading those could leak NTLM hashes.
The attack vector would include an adversary tricking the user in passing an UNC path to OPA, e.g. opa eval -d $FILE.
UNC paths are now forbidden. If this is an issue for you, please reach out on Slack or GitHub issues.
Reported by Shelly Raban Authored by @ashutosh-narkar
opa-config.yaml as name for config file (#6966) (#6959) authored by @anderseknerthttp.send in inter-query cache config docs (#6953) authored by @anderseknertOne column per quarter.
This is a bug fix release addressing the following issue:
This is a bug fix release addressing the following issue:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a mix of features, a new builtin function (strings.count), performance improvements, and bugfixes.
This release contains a mix of features, a new builtin function (strings.count), performance improvements, and bugfixes.
OPA now automatically rejects very large requests (#6868) authored by @philipaconrad.
Requests with a Content-Length larger than 128 MB uncompressed, and gzipped requests with payloads that decompress to
larger than 256 MB will be rejected, as part of hardening OPA against denial-of-service attacks. Previously, a large
enough request could cause an OPA instance to run out of memory in low-memory sidecar deployment scenarios, just from
attempting to read the request body into memory.
These changes allow improvements in memory usage for the OPA HTTP server, and help OPA deployments avoid some accidental out-of-memory situations.
For most users, no changes will be needed to continue using OPA. However, to control this behavior, two new configuration
keys are available: server.decoding.max_length and server.decoding.gzip.max_length. These control the max size in
bytes to allow for an incoming request payload, and the maximum size in bytes to allow for a decompressed gzip request payload, respectively.
Here's an example OPA configuration using the new keys:
# Set max request size to 64 MB and max gzip size (decompressed) to be 128 MB.
server:
decoding:
max_length: 67108864
gzip:
max_length: 134217728
strings.count builtin which returns the number of non-overlapping instances of a substring in a string (#6827) authored by @Manish-Giri--rego-v1 formatted module has rule name conflicting with keyword (#6833) authored by @johanfylling--follow-symlinks flag to the opa build command to allow users to build directories with symlinked files, and have the contents of those symlinked files included in the built bundle (#6800) authored by @tjonsexplain=fails query value (#6886) authored by @acamatciscorego_version and file_rego_versions attributes (#6885) authored by @ashutosh-narkarNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a mix of features, performance improvements, and bugfixes.
This release contains a mix of features, performance improvements, and bugfixes.
The opa test command now includes a new --var-values flag that enriches reporting of failed tests with the values and locations for variables in the failing expression.
E.g.:
FAILURES
--------------------------------------------------------------------------------
data.test.test_my_policy: FAIL (0ms)
test.rego:8:
x == y + z
| | |
| | 3
| y + z: 5
| y: 2
1
SUMMARY
--------------------------------------------------------------------------------
test.rego:
data.test.test_foo: FAIL (0ms)
--------------------------------------------------------------------------------
FAIL: 1/1
Authored by @johanfylling, reported by @grosser.
opa exec (#6538)The opa exec command now supports reading input documents from stdin with the --stdin-input (-I) flag.
E.g.:
$ echo '{"user": "alice"}' | opa exec --stdin-input --bundle my_bundle
Authored by @colinjlacy, reported by @humbertoc-silva.
every domain (#6790) authored by @johanfylling reported by @anakrishgo_memstats_gc_cpu_fraction (#6783) authored by @philipaconradan HTTP (#6786) authored by @jdbaldryNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
A new IsSetStmt statement has been added to the intermediate representation (IR). This is a breaking change for custom IR evaluators, which must inter…
This release contains a mix of features and bugfixes.
every domain is a collection type before evaluation (#6762) authored by @johanfylling reported by @anderseknertA new IsSetStmt statement has been added to the intermediate representation (IR). This is a breaking change for custom IR evaluators, which must interpret this statement in IR plans generated by this OPA version and later. No actions are required for Wasm users, as long as Wasm modules are built by this OPA version or later.
This is a bug fix release addressing the following issues:
This is a bug fix release addressing the following issues:
macos-latest was changed from amd64 to arm64 and as a result darwin/amd64 binary wasn't released (#6720) authored by @suzuki-shunsukeNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
build: Update WASM Rego test generation docker command to address CVE-2022-24765 in Git (#6703) authored by @ashutosh-narkar
NOTES:
- The minimum version of Go required to build the OPA module is 1.21
This release contains a mix of features, a new builtin function (json.marshal_with_options()), performance improvements, and bugfixes.
Previously if Discovery was enabled, other features like bundle downloading and status reporting could not be configured manually. The reason for this was to prevent OPAs being deployed that could not be controlled through discovery. It's possible that the system serving the discovered config is unaware of all options locally available in OPA. Hence, we relax the configuration check when discovery is enabled so that the bootstrap configuration can contain plugin configurations. In case of conflicts, the bootstrap configuration for plugins wins. These local configuration overrides from the bootstrap configuration are included in the Status API messages so that management systems can get visibility into the local overrides.
In general, the bootstrap configuration overrides the discovered configuration. Previously this was not the case for all
configuration fields. For example, if the discovered configuration changes the labels section, only labels that are
additional compared to the bootstrap configuration are used, all other changes are ignored. This implies labels in the
bootstrap configuration override those in the discovered configuration. But for fields such as default_decision, default_authorization_decision,
nd_builtin_cache, the discovered configuration would override the bootstrap configuration. Now the behavior is more consistent
for the entire configuration and helps to avoid accidental configuration errors. (#5722) authored by @ashutosh-narkar
rego_version attribute to the bundle manifestA new global rego_version attribute is added to the bundle manifest, to inform the OPA runtime about what Rego version (v0/v1) to
use while parsing/compiling contained Rego files. There is also a new file_rego_versions attribute which allows individual
files to override the global Rego version specified by rego_version.
When the version of the contained Rego is advertised by the bundle through this attribute, it is not required to run OPA with the
--v1-compatible (or future --v0-compatible) flag in order to correctly parse, compile and evaluate the bundle's modules.
A bundle's rego_version attribute takes precedence over any applied --v1-compatible/--v0-compatible flag. (#6578) authored by @johanfylling
opa build was provided an entrypoint from both a CLI flag, and via entrypoint metadata annotation. (#6661) authored by @philipaconraddeps command for policies with high dependency connectivity (#6685) authored by @johanfyllingv1 syntax (#6689) authored by @xico42rego.v1 in v0 support modules when applicable (#6450) authored by @johanfyllingjson.marshal_with_options() builtin for indented/"pretty-printed" and/or line-prefixed JSON (#6630) authored by @sean-r-williamsgo stanza of OPA's go.mod to go 1.21. OPA, used as Go dependency, requires at least go 1.21, and thus works with all officially supported Go versions (1.21.x and 1.22.x) (#6678) authored by @srenatusupload-artifact and download-artifact Github actions to the latest version (v4) (#6670) authored by @philipaconradNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a mix of features, performance improvements, and bugfixes.
This release contains a mix of features, performance improvements, and bugfixes.
--timeout flag to opa exec to prevent infinite hangs. (#6613) authored by @philipaconradcrypto.x509.parse_and_verify_certificates_with_options built-in function. (#5882) authored by @yogisinha reported by @IxDayDebugging OPA (#6637) authored by @setchyNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →