NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #280 by repository stars
Last release today
01 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4337 releases · first in 2016
Use Trivy for vulnerability scans in code and container images (authored by @JAORMX)
This release contains a number of fixes and enhancements.
object.subsetThis function checks if a collection is a subset of another collection. It works on objects, sets, and arrays.
If both arguments are objects, then the operation is recursive, e.g. {"c": {"x": {10, 15, 20}}
is considered a subset of {"a": "b", "c": {"x": {10, 15, 20, 25}, "y": "z"}.
See the built-in functions docs for all the details
This implementation fixes #4358 and was authored by @charlesdaniels.
These new keywords let you increase the expressiveness of your policy code:
Before
package authz
allow { not denied } # `denied` left out for presentation purposes
deny[msg] {
count(violations) > 0
msg := sprintf("there are %d violations", [count(violations)])
}
After
package authz
import future.keywords
allow if not denied # one expression only => no { ... } needed!
deny contains msg if {
count(violations) > 0
msg := sprintf("there are %d violations", [count(violations)])
}
Note that rule bodies containing only one expression can be abbreviated when using if.
To use the new keywords, use import future.keywords.contains and import future.keywords.if; or
import all of them at once via import future.keywords. When these future imports are present, the
pretty printer (opa fmt) will introduce contains and if where applicable.
if is allowed in all places to separate the rule head from the body, like
response[key] = value if { key := "open", y := "sesame" }
but not for partial set rules, unless also using contains:
deny[msg] if msg := "forbidden" # INVALID
deny contains msg if msg := "forbidden" # VALID
bundle_failed_load_counter metric for bundles without revisions (#4822) reported and authored by @jkbschmidsystem.authz policy now properly supports the interquery caching of http.send calls (#4829), reported by @HarshPathakhpopa bench: Passing --e2e makes the benchmark measure the performance of a query including the server's HTTP handlers and their processing.opa fmt: Output list and diff changes with --fail flag (#4710) (authored by @davidkuridza)repl: Add a WithCapabilities function (authored by @jaspervdj)opa version) on Windows. Fixes #4646.count, object.filter, and object.remove built-in functions (#4767)startswith and endswith (authored by @whme)Note that website changes like these become effective immediately and are not tied to a release. We still use our release notes to record the nice fixes contributed by our community.
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →