NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #280 by repository stars
Last release today
01 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4337 releases · first in 2016
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release focuses on bugfixes and documentation improvements, as well as a few small performance improvements.
This release focuses on bugfixes and documentation improvements, as well as a few small performance improvements.
json.Encode to avoid extra allocation (authored by @anderseknert)opa inspect: Fix prefix error when inspecting bundle from root (#5503) authored by @harikannan512 reported by @HarshPathakhphttp.send to cache responses based on status code (#5617) authored by @ashutosh-narkargithub.com/pkg/errors dependency (authored by @Iceber)crypto.x509.parse_certificates docs (authored by @charlieegan3)Ecosystem:
Website:
Dependency bumps:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release rolls in security fixes from recent patch releases, along with a number of bugfixes, and a new builtin function.
This release rolls in security fixes from recent patch releases, along with a number of bugfixes, and a new builtin function.
opa evalA common frustration when writing policies in OPA is when an error happens,
causing a rule to unexpectedly return undefined. Using
--strict-builtin-errors would allow finding the first error encountered
during evaluation, but terminates execution immediately.
To improve the debugging experience, it is now possible to display all of
the errors encountered during normal evaluation of a policy, via the new
--show-builtin-errors option.
Consider the following error-filled policy, multi-error.rego:
package play
this_errors(number) := result {
result := number / 0
}
this_errors_too(number) := result {
result := number / 0
}
res1 := this_errors(1)
res2 := this_errors_too(1)
Using --strict-builtin-errors, we would only see the first divide by zero
error:
opa eval --strict-builtin-errors -d multi-error.rego data.play
1 error occurred: multi-error.rego:4: eval_builtin_error: div: divide by zero
Using --show-builtin-errors shows both divide by zero issues though:
opa eval --show-builtin-errors -d multi-error.rego data.play -f pretty
2 errors occurred:
multi-error.rego:4: eval_builtin_error: div: divide by zero
multi-error.rego:8: eval_builtin_error: div: divide by zero
By showing more errors up front, we hope this will improve the overall policy writing experience.
time.formatIt is now possible to format a time value from nanoseconds to a formatted timestamp string via a built-in function. The builtin accepts 3 argument formats, each allowing for different options:
time.parse_ns).See the documentation for all details.
Implemented by @burnerlee.
Previously, every time the evaluator looked up a rule in the index, OPA performed checks for grounded refs over the entire index before looking up the rule.
Now, OPA performs all groundedness checks once at index construction time, which keeps index lookup times much more consistent as the number of indexed rules scales up.
Policies with large numbers of index-ready rules can expect a small performance lift, proportional to the number of indexed rules.
AWS has recently developed an extension to SigV4 called Signature Version 4A (SigV4A) which enables signatures that are valid in more than one AWS Region. This new signature method is required for signing multi-region API requests, such as Amazon S3 Multi-Region Access Points (MRAP).
OPA now supports this new request signing method for bundle fetching, which
means that you can use an S3 MRAP as a bundle source. This is configured
via the new services[<your_service_name>].credentials.s3_signing.signature_version
field.
See the the documentation for more details.
Implemented by @jwineinger
NDBCache errors (authored by @srenatus)http.send in interquery cache (authored by @asleire)contains keyword (#5525) authored and reported by @philipaconradSomeDecl to visitor walks (#5480) authored by @srenatusLazyObject in visitor walks (#5479) authored by @srenatus reported by @benweintopa inspect: Fix path of data namespaces on windows (authored by @shm12)schemas annotations if --schema flag is used (authored by @johanfylling)Community page updates (authored by @anderseknert)
Update Hugo version, update deprecated Page fields (authored by @charlieegan3)
docs: Update TLS-based Authentication Example (#5521) authored by @charlieegan3 reported by @jjthom87
docs: Update opa eval flags to link to bundle docs (authored by @charlieegan3)
docs: Make SDK first option for Go integraton (authored by @anderseknert)
docs: Fix typo on Policy Language page. (authored by @mcdonagj)
docs/integrations: Update kubescape repo links (authored by @dwertent)
docs/oci: Corrected config section (authored by @ogazitt)
website/frontpage: Update Learn More links (authored by @pauly4it)
integrations.yaml: Ensure inventors listed in organizations (authored by @anderseknert)
integrations: Fix malformed inventors item (authored by @anderseknert)
Add Digraph to ADOPTERS.md (authored by @jamesphlewis)
ast/visit_test error message (authored by @boranx)opa inspect: Fix wrong windows bundle tar files path separator (authored by @shm12)Dependency bumps:
CI/Distribution fixes:
This is a bug fix release addressing a panic in opa test.
This is a bug fix release addressing a panic in opa test.
This is a bug fix release addressing an issue that prevented OPA from fetching bundles stored in S3 buckets.
This is a bug fix release addressing an issue that prevented OPA from fetching bundles stored in S3 buckets.
This is a second security fix to address CVE-2022-41717/GO-2022-1144.
This is a second security fix to address CVE-2022-41717/GO-2022-1144.
We previously believed that upgrading the Golang version and its stdlib would be sufficient to address the problem. It turns out we also need to bump the x/net dependency to v0.4.0., a version that hadn't existed when v0.46.2 was released.
This release bumps the golang.org/x/net dependency to v0.4.0, and contains no other changes over v0.46.2.
Note that the affected code is OPA's HTTP server. So if you're using OPA as a Golang library, or if your confident that your OPA's HTTP interface is protected by other means (as it should be -- not exposed to the public internet), you're OK.
This backwards incompatibility wasn't intended, and has now been fixed.
This is a bug fix release addressing two issues: one security issue, and one bug related to formatting backwards-compatibility.
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests.
Since we advise against running an OPA service exposed to the general public of the internet, potential attackers would be limited to people that are already capable of sending direct requests to the OPA service.
opa fmt and backwards compatibility (#5449)In v0.46.1, it was possible that opa fmt would format a rule in such a way that:
This backwards incompatibility wasn't intended, and has now been fixed.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a mix of bugfixes, optimizations, and new features.
This release contains a mix of bugfixes, optimizations, and new features.
object.keysIt is now possible to conveniently retrieve an object's keys via a built-in function.
Before, you had to resort to constructs like
import future.keywords.in
keys[k] {
_ = input[k]
}
allow if "my_key" in keys
Now, you can simply do
import future.keywords.in
allow if "my_key" in object.keys(input)
See the documentation for all details.
Implemented by @kevinswiber.
It is now possible to use a built-in function to prepare a request with a signature, so that it can be used with AWS endpoints that use request signing for authentication.
See this example:
req := {"method": "get", "url": "https://examplebucket.s3.amazonaws.com/data"}
aws_config := {
"aws_access_key": "MYAWSACCESSKEYGOESHERE",
"aws_secret_access_key": "MYAWSSECRETACCESSKEYGOESHERE",
"aws_service": "s3",
"aws_region": "us-east-1",
}
example_verify_resource {
resp := http.send(providers.aws.sign_req(req, aws_config, time.now_ns()))
# process response from AWS ...
}
See the documentation on the new built-in for all details.
Reported by @jicowan and implemented by @philipaconrad.
object.get and in operatorBefore, using object.get and in had come with a performance penalty that wasn't
to be expected just from the look of the calls: Since they have been implemented using
built-in functions (obvious for object.get, not obvious for "admin" in input.user.roles),
all of their operands had to be read from the store (if applicable) and converted into
AST types.
Now, we use shallow references ("lazy objects") for store reads in the evaluator.
In these two cases, this can bring huge performance improvements, when the object
argument of these two calls is a ref into the base document (like data.users):
object.get(data.roles, input.role, [])
{ "id": 12 } in data.users
opa eval: Added --strict to enable strict code checking in evaluation (#5182) authored by @Parsifal-Mopa fmt: Remove { true } block following else headopa fmt: Generate new wildcards for else and chained function heads in the parser (#5347). This fixes superfluous
introductions of _1 instead of _ in when formatting functions that use wildcard arguments, like f(_) := true.opa fmt: Fix assignment rewrite in else formatting (#5348)http.send: Fix interquery cache size calculation with concurrent requests (#5359) reported and authored by @asleirehttp.send: Remove socket query param for unix sockets (#5313) reported and authored by @michivisome with unused vars (#4238)x in data.foo and object.get(data.bar, ...) calls significantly.json.patch (#5328)time.parse_nsNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →