NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #280 by repository stars
Last release today
01 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4337 releases · first in 2016
This is a security fix release for the fixes published in Golang 1.22.1.
This is a security fix release for the fixes published in Golang 1.22.1.
OPA servers using --authentication=tls would be affected: crafted malicious client
certificates could cause a panic in the server.
Also, crafted server certificates could panic OPA's HTTP clients, in bundle plugin,
status and decision logs; and http.send calls that verify TLS.
This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.
This is CVE-2024-24783 (https://pkg.go.dev/vuln/GO-2024-2598).
Note that there are other security fixes in this Golang release, but whether or not OPA is affected is harder to tell. An update is advised.
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
> * The minimum version of Go required to build the OPA module is 1.20
NOTES:
- The minimum version of Go required to build the OPA module is 1.20
This release contains a mix of improvements and bugfixes.
WithBundleParserOpts method to OCI downloader (#6571) authored by @slonka%!F(MISSING) in logs by skipping calls to the {Debug,Info,Warn,Error}f functions when there are no arguments (#6555) authored by @srenatusraise_error flag during input validation (#6553) authored by @ashutosh-narkarapplication/yaml instead of application/x-yaml as the former is now a recognized content type (#6565) authored by @anderseknertNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Removing deprecated fields and functions related to rego-v1 compatibility (#6542) authored by @johanfylling
This release contains a mix of new features and bugfixes.
--v1-compatible flag to all previously unsupported command line commands (#6520) authored by @johanfyllingsize_limit_bytes (#6514) authored by @anderseknert reported by @dolevfhttp.send cache entries periodically (#5320) authored by @rudrakhp reported by @lukyerNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
OPA can be run in 1.0 compatibility mode by using the new --v1-compatible flag. When this mode is enabled, the current release of OPA will behave as O
--v1-compatible flag. When this mode is enabled, the current release of OPA will behave as OPA v1.0 will eventually behave by default. This flag is currently supported on the build, check, fmt, eval and test commands (#6478) authored by @johanfyllingopa fmt where the assignment operator and term in the rule head of chain rules are removed from the re-written rule head (#6467) authored by @anderseknertdiff tool with an external golang library function (#6284) authored by @colinjlacyproviders.aws.sign_req builtin command (#6456) authored by @c2zwdjnlcgsprintf builtin command when used with the %T marker (#6487) authored by @lcarvaMakefile to allow custom GOFLAGS to be provided to the golang executable (#6458) authored by @cova-feNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
It also contains a mix of improvements, bugfixes and security fixes for third-party libraries.
This release adds tooling to help prepare existing policies for the upcoming OPA 1.0 release. It also contains a mix of improvements, bugfixes and security fixes for third-party libraries.
NOTES:
- All published OPA images now run with a non-root uid/gid. The
uid:gidis set to1000:1000for all images. As a result there is no longer a need for the-rootlessimage variant and hence it will not be published as part of future releases. This change is in line with container security best practices. OPA can still be run with root privileges by explicitly setting the user, either with the--userargument fordocker run, or by specifying thesecurityContextin the Kubernetes Pod specification.
The upcoming release of OPA 1.0, which will be released at a future date, will introduce breaking changes to the Rego language. Most notably:
import future.keywords into a module before use will be part of the Rego language by default, without the need to first import them.if keyword will be required before the body of a rule.contains keyword will be required when declaring a multi-value rule (partial set rule).This current release (0.59.0) introduces a new --rego-v1 flag to the opa fmt and opa check commands to facilitate the transition of existing policies to be compatible with the 1.0 syntax.
When used with opa fmt, the --rego-v1 flag will format the module(s) according to the new Rego syntax in OPA 1.0.
Formatted modules are compatible with both the current version of OPA and 1.0.
Modules using deprecated built-ins will terminate formatting with an error. Future versions of OPA will support rewriting applicable function calls with equivalent Rego compatible with 1.0.
When used with opa check, the --rego-v1 flag will check that the modules are compatible with both the current version of OPA and 1.0.
--rego-v1 flag to check cmd (#6429) authored by @johanfyllingopa fmt (#6297) authored by @johanfyllingrego.v1 import (#6375) (authored by @johanfylling)rego.v1) (#6356) authored by @ashutosh-narkarrego.v1 import (#6247) introduced in OPA 0.58.0, authored by @johanfyllingrule_head_refs capabilities feature flag (#6334) authored by @johanfyllingstrings.render_template to render templated strings (#6371) authored by @RDVasavadaNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a mix of performance improvements, bugfixes and security fixes for third-party libraries.
NOTES:
- All published OPA images now run with a non-root uid/gid. The
uid:gidis set to1000:1000for all images. As a result there is no longer a need for the-rootlessimage variant and hence it will not be published as part of future releases. This change is in line with container security best practices. OPA can still be run with root privileges by explicitly setting the user, either with the--userargument fordocker run, or by specifying thesecurityContextin the Kubernetes Pod specification.
This release contains a mix of performance improvements, bugfixes and security fixes for third-party libraries.
= true as it is implied (#6323) authored by @anderseknertv0.23.0 (#2266) authored by @ashutosh-narkarhttp_request_duration_seconds metric (#6238) authored by @AdrianArnautuwalk-ing (#6267) authored by @anderseknert/) or other special characters (#6264) authored by @dennisghub tool in GitHub workflows in favor of GitHub CLI tool (#6326) authored by @ashutosh-narkarThis is a bug fix release addressing the following security issues:
This is a bug fix release addressing the following security issues:
A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption.
Denial of service in otelhttp due to unbound cardinality metrics.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains an updated Rego syntax to allow general references in rule heads, and a mix of new features and bugfixes.
This release contains an updated Rego syntax to allow general references in rule heads, and a mix of new features and bugfixes.
In OPA 0.56.0, we introduced support for general references in rule heads as an experimental feature.
It has now graduated to a fully supported feature, and is no longer experimental.
A general reference is a reference with variables at arbitrary locations. In Rego, partial rules are used for generating sets and objects. In previous versions of OPA, variables were only allowed in the very last position in the rule's reference. Now, Rego has been expanded to allow rules to be declared with general references in their head, with variables at arbitrary locations. This allows for generating nested dynamic object structures:
package example
import future.keywords
# Converting a flat list of users to a mapping by "role" and then "id".
users_by_role[role][id] := user if {
some user in data.users
id := user.id
role := user.role
}
# Explicit "admin" key override to the above mapping.
users_by_role.admin[id] := user if {
some user in data.admins
id := user.id
}
# Leaf entries can be multi-value.
users_by_country[country] contains user.id if {
some user in data.users
country := user.country
}
See the documentation for more information.
Authored by @johanfylling.
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →