NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #280 by repository stars
Last release today
01 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4337 releases · first in 2016
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release includes the security fixes present in the recent v0.43.1 release, which mitigate CVE-2022-36085 in OPA itself, and CVE-2022-27664 and CV…
This release contains a number of fixes, two new builtins, a few new features, and several performance improvements.
This release includes the security fixes present in the recent v0.43.1 release, which mitigate CVE-2022-36085 in OPA itself, and CVE-2022-27664 and CVE-2022-32190 in our Go build tooling.
See the Release Notes for v0.43.1 for more details.
Rego Set element addition operations did not scale linearly (#4999) in the past, and like the Object type before v0.43.0, experienced noticeable reallocation/memory movement overheads once the Set grew past 120k-150k elements in size.
This release introduces different handling of Set internals during element addition operations to avoid pathological reallocation behavior, and allows linear performance scaling up into the 500k key range and beyond.
union Built-in OptimizationThe Set union builtin allows applying the union operation to a set of sets.
However, as discovered in #4979, its implementation generated unnecessary intermediate copies, which resulted in poor performance; in many cases, worse than writing the equivalent operation in pure Rego.
This release improves the union builtin's implementation, such that only the
final result set is ever modified, reducing memory allocations and GC pressure.
The union builtin is now about 15-30% faster than the equivalent operation in
pure Rego.
strings.any_prefix_match and strings.any_suffix_matchThis release introduces two new builtins, optimized for bulk matching of string
prefixes and suffixes: strings.any_prefix_match, and
strings.any_suffix_match.
It works with sets and arrays of strings, allowing efficient matching of
collections of prefixes or suffixes against a target string.
See the built-in functions docs for all the details
This implementation fixes #4994 and was authored by @cube2222.
This release includes several bugfixes and improvements around bundle building:
This release has performance improvements and bugfixes for the disk storage system:
util.Roundtrip on Write for improved performance (#4708)The AST and Topdown module received a number of important bugfixes in this release:
object.union_n builtin (#5073)is_type return values. (#4943)units.parse*units.* builtin test assertionsfile.Sync() to eliminate test failures due to slow disk writesformat_int to say it rounds downsemver.compare (#5012) reported by @tetsuya28Update links to opa-kafka-plugin
Add OCI documentation (authored by @carabasdaniel)
Add article on using OPA for data filtering in Kafka
Ecosystem: Add some links to Rönd (authored by @ugho16)
Add community integration for Fiber (authored by @mstrYoda)
Add Spacelift Integration (authored by @theseanodell)
Fix broken link for Minio OPA integration (authored by @unautre)
Ecosystem Additions:
Dockerfile: Append root "/" to $PATH (#5003) authored by @matusf reported by @matusf
Add VNG Cloud to adopters (authored by @vinhph0906)
Dependency bumps, notably:
Dependency removals:
This is a security release fixing the following vulnerabilities:
This is a security release fixing the following vulnerabilities:
CVE-2022-36085: Respect unsafeBuiltinMap for 'with' replacements in the compiler
See https://github.com/open-policy-agent/opa/security/advisories/GHSA-f524-rf33-2jjr for all details.
CVE-2022-27664 and CVE-2022-32190.
Fixed by updating the Go version used in our builds to 1.18.6, see https://groups.google.com/g/golang-announce/c/x49AQzIVX-s. Note that CVE-2022-32190 is most likely not relevant for OPA's usage of net/url. But since these CVEs tend to come up in security assessment tooling regardless, it's better to get it out of the way.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →