NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #280 by repository stars
Last release today
01 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4337 releases · first in 2016
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
This release contains a mix of new features, bugfixes and a new builtin function.
This release contains a mix of new features, bugfixes and a new builtin function.
A new experimental feature in OPA is support for general refs in rule heads. Where a general ref is a reference with variables at arbitrary locations.
package example
import future.keywords
# Converting a flat list of users to a mapping by "role" and then "id".
users_by_role[role][id] := user if {
some user in data.users
id := user.id
role := user.role
}
# Explicit "admin" key override to the above mapping.
users_by_role.admin[id] := user if {
some user in data.admins
id := user.id
}
# Leaf entries can be multi-value.
users_by_country[country] contains user.id if {
some user in data.users
country := user.country
}
General refs are currently not supported by the OPA planner, making this feature unsupported for Wasm and IR.
Note: this feature is disabled by default, and needs to be enabled by setting the EXPERIMENTAL_GENERAL_RULE_REFS environment variable (once the feature is complete - supports Wasm and IR - this requirement will be dropped).
Authored by @johanfylling.
numbers.range_stepSimilar to the numbers.range built-in function, numbers.range_step returns an array of numbers in a given range. The new built-in function also allows you to control the step between each entry.
See the documentation on the new built-in for all the details.
Authored by @sspaink.
The OPA Ecosystem of related integrations has been refreshed and moved to a more prominent location on the website.
If you're interested to add any new integrations you've been working on, please see the docs here (updates to existing integrations are very welcome too!).
opa test -z fail with failing tests (#6126) authored by @fdaguinopa test --ignore when used together with --bundle (#6185) authored by @joaobrandt--fail-non-empty flag to opa exec (#6153) authored by @Ronnie-personalopa_no_oci flag to build without containerd (#6159) authored by @slonkaSince its introduction in 0.34.0, the --exit-zero-on-skipped option always made the opa test command return an exit code 0. When used, it now returns the exit code 0 only if no failed tests were found.
Test runs on existing projects using --exit-zero-on-skipped will fail if any failed tests were inhibited by this behavior.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Make rootless deprecation messages more explicit as all published OPA images now run with non-root uid/gid (#6091) authored by @charlieegan3
NOTES:
All published OPA images now run with a non-root uid/gid. The
uid:gidis set to1000:1000for all images. As a result there is no longer a need for the-rootlessimage variant and hence it will be not be published as part of future releases. This change is in line with container security best practices. OPA can still be run with root privileges by explicitly setting the user, either with the--userargument fordocker run, or by specifying thesecurityContextin the Kubernetes Pod specification.The minimum version of Go required to build the OPA module is 1.19
This release contains a mix of new features, bugfixes and a new builtin function.
default keyword on functionsPreviously if a function was defined with a default value, OPA would ignore it. Now the default function is honored
if all functions with the same name are undefined. For example,
package example
default clamp_positive(x) := 0
clamp_positive(x) = x {
x > 0
}
$ opa eval -d example.rego 'data.example.clamp_positive(1)' -f pretty
1
$ opa eval -d example.rego 'data.example.clamp_positive(-1)' -f pretty
0
The value of a default function follows the same conditions as that of a default rule. In addition, a default
function satisfies the following properties:
NOTE:
defaultfunctions used to be previously ignored. If existing policies containdefaultfunctions, ensure that they conform to the properties mentioned above. Otherwise, those policies will fail to evaluate.
Authored by @ashutosh-narkar.
crypto.parse_private_keys returns zero or more private keys from the given encoded string containing DER certificate data.
If the input contains a list of one or more concatenated PEM blocks, then the built-in will output the parsed private keys
represented as objects.
See the documentation on the new built-in for all the details.
Authored by @volck.
discard output format to opa eval which discards the result while still showing the output of eval flags like --profile (#6103) authored by @26tanishabanikWithRoots compiler option that allows callers to set the roots to include in the output bundle manifest (#6088) authored by @kubajEcosystem:
Website:
CRLF line terminations in the patch output (#6069) authored by @johanfyllingNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release focuses on bug fixes, but also includes some improvements to the SDK and commandline.
This release focuses on bug fixes, but also includes some improvements to the SDK and commandline.
Note: This will be the last OPA release to support building with Golang 1.18. (Golang 1.21 is expected to be released in August. Keeping the support for 1.18 is blocking OPA from upgrading OpenTelemetry.)
lazyObj when compared against other object type (6060) (authored by @johanfylling)fmt panic in comprehension with comments (#5798) authored by @Trolloldem reported by @Djoustobject.union_n where nested objects were mutated (#5975) authored by @qshu-splunkobject.subset method failing to correctly compare array relationships (5968) authored by @DCRUNNNhttp.send (#5997) authored by @ashutosh-narkartime.format and time.parse_ns (#5945) authored by @tjons--schema flag to opa test (#5923) authored by @renatoscpersistence_directory config (#6042) authored by @blacksailstzdata is not found on filesystem (6038) authored by @charlieegan3Store implementation in SDK (5962) authored by @srenatus/v1/config API result (6056) authored by @srenatusThis is a bug fix release addressing the following issues:
This is a bug fix release addressing the following issues:
WWW-Authenticate header of a 401 Unauthorized response. Errors were returned when downloading a public image as it was assumed that authorization is not necessary for public repositories. This fix addresses this issue by challenging any 401 Unauthorized responses by passing it to the docker.Authorizer (#5902) authored by @DerGutopa fmt: Fix panic encountered while processing policies with comprehensions written on multiple lines with comments in these lines (#5798) authored by @TrolloldemNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
False positive finding of CVE-2022-3517 addressed by removing the dead code (#5941) authored by @testwill
This release contains some enhancements, bugfixes, and a new builtin function.
opa eval: Update OPA eval's --profile-sort flag description to highlight the valid options to sort the profile results (#5924) authored by @ecbenezraopa fmt: Fix cases in which invalid code was generated due to parentheses being improperly handled (#5537) authored by @Trolloldemloader package that provide ability to register handlers for certain file extensions. This feature is currently EXPERIMENTAL (#5940) authored by @srenatuscrypto.x509.parse_keypair: Returns a key pair from a pair of PEM or base64 encoded strings of data. See the documentation on the new built-in for all the details. (#5853) authored by @volck.io.jwt.decode_verify: Fix issue where token verification succeeded in case where iss constraint was required but JWT did not contain it (#5850) authored by @AleksanderBrzozowskihttp.send: Add a new option to the http.send input object which allows policy authors to specify a retry count for executing a HTTP request. Retries are performed with an exponential backoff delay (#5891) authored by @ashutosh-narkar_ matching only scalars in rule indexing for arrays (#5916) authored by @jaspervdjNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains some enhancements, bugfixes, and a new builtin function.
This release contains some enhancements, bugfixes, and a new builtin function.
Previously OPA did not allow any updates to the labels provided in the boot configuration via the discovered (ie. service) config. This was done to avoid breaking the discovery configuration. But there are use cases where labels can serve as a convenient way to pass information that could be used in policies, status updates or decision logs. This change allows additional labels to be configured in the service config which are then made available during runtime.
See the Discovery documentation for more details.
Authored by @mjungsbluth.
crypto.hmac.equal provides a convenient way to compare hashes generated by the MD5, SHA-1, SHA-256 and SHA-512 hashing algorithms.
Below is a real world example of how this built-in function can be utilized. Imagine our server is registered as a
GitHub webhook which subscribes to certain events on GitHub.com. Now we want to limit requests to those coming from GitHub.
One of the ways to do that is to first set up a secret token and validate the information. Once we create the token on GitHub,
we'll set up an environment variable that stores this token and makes it available to OPA via the opa.runtime built-in.
In the case of GitHub webhooks the validation is done by comparing the hash signature received in the X-Hub-Signature-256
header and calculating a hash using the secret token and payload body. The check_signature rule implements this logic.
package example
import input.attributes.request.http as http_request
allow {
http_request.method == "POST"
input.parsed_path = ["workflows", "github", "webhooks"]
check_signature
}
check_signature {
secret_key := opa.runtime().env.GITHUB_SECRET_KEY
hash_body := crypto.hmac.sha256(http_request.raw_body, secret_key)
expected_signature := concat("", ["sha256=", hash_body])
header_signature = http_request.headers["X-Hub-Signature-256"]
crypto.hmac.equal(header_signature, expected_signature)
}
See the documentation on the new built-in for all the details.
Authored by @sandokandias.
Previously the OCI Downloader had support for only three types of authentication methods, namely Client TLS Certificates,
Basic Authentication and Bearer Token. This change adds support for other authentication methods such as AWS Signature,
GCP Metadata Token. See the documentation
for more details.
Authored by @DerGut.
The number of EVAL/REDO counts in the profile result are sometimes difficult to understand. This is mainly due to the fact that the compiler rewrites expressions and assigns the same location to each generated expression and the profiler keys the counters by the location. To provide more clarity, the profile output now includes the number of generated expressions for each given expression thereby helping to better understand the result and also how the evaluation works.
Here is an example of the updated profiler output with the new NUM GEN EXPR column:
+----------+----------+----------+--------------+-------------+
| TIME | NUM EVAL | NUM REDO | NUM GEN EXPR | LOCATION |
+----------+----------+----------+--------------+-------------+
| 20.291µs | 3 | 3 | 3 | test.rego:7 |
| 1µs | 1 | 1 | 1 | test.rego:6 |
| 2.333µs | 1 | 1 | 1 | test.rego:5 |
| 6.333µs | 1 | 1 | 1 | test.rego:4 |
| 84.75µs | 1 | 1 | 1 | data |
+----------+----------+----------+--------------+-------------+
See the Profiling documentation for more details.
Authored by @ashutosh-narkar.
Ecosystem:
Website:
MISCELLANEOUS section to improve content navigation (#4614) authored by @lakhanjindamNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →