NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #286 by repository stars
Last release today
07 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4350 releases · first in 2016
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
fix release-vulnerability-check.yaml (authored by @sspaink)
This release contains a mix of new features, performance improvements, and bugfixes. Notably:
NewClient() to
Prepare()OPA now supports pluggable logging implementations via the logger plugin interface, which is based on Go's standard log/slog.Handler interface. This allows any slog.Handler implementation to be used as a logger plugin. Loggers can be configured via the server.logger_plugin configuration option and used for both runtime logging and decision logs. OPA includes a built-in file logger plugin (file_logger) that writes structured JSON logs with rotation support using lumberjack. Users can also implement and register custom logger plugins when building OPA.
Example configuration for server logging:
server:
logger_plugin: file_logger
plugins:
file_logger:
path: /var/log/opa/server.log
max_size_mb: 100
max_age_days: 28
max_backups: 3
compress: true
level: info
Example configuration for decision logs using the same plugin:
server:
logger_plugin: file_logger
decision_logs:
plugin: file_logger
plugins:
file_logger:
path: /var/log/opa/server.log
max_size_mb: 100
max_age_days: 28
max_backups: 3
compress: true
level: info
The HTTPAuthPlugin.NewClient() method is now called once per Client instance and cached rather than being called for
every request. Custom plugins that performed per-request operations in NewClient() (such as request counters,
per-request transport wrapping, or logging/metrics side effects) will now only execute those operations once. All
per-request authentication logic must be moved from NewClient() to Prepare(). All plugins included in OPA have been
updated and are unaffected by this change.
cert_reread_interval_seconds field.
Defaults to re-reading on every request for backwards compatibility.
The implementation also uses content hashing to detect changes and avoid re-parsing unchanged TLS certificates and
keys. (#8376) (authored by @srenatus)This is a patch release collecting two bug fixes and various dependency updates for Golang standard library and common package vulnerabilities.
This is a patch release collecting two bug fixes and various dependency updates for Golang standard library and common package vulnerabilities.
These bug fixes include a revert of the rule indexer tweaks shipped in 1.14.0, which had caused unexpected lookup failures for some users. (We expect to properly fix the issue in 1.15.0, but for now, a revert is the quicker choice.)
x in {...} (#8341)" (#8410)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a mix of new features, performance improvements, and bugfixes. Notably:
This release contains a mix of new features, performance improvements, and bugfixes. Notably:
x in {...} expressions--h2c with unix domain socket for opa runx in {...} expressions (#1841)With this change, the rule indexer will index expressions like:
allow if input.role in {"admin", "user"}
On lookup, the rule body will only be returned if input.role is either one of "admin" or "user".
The reverse case is also indexed:
allow if "admin" in input.roles
in which the searched collection is unknown.
Authored by @srenatus reported by @nischalsheth
--h2c with unix domain socket (UDS) (#8282) authored by @srenatus reported by @theJCregisteredTriggers (#8363) reported and authored by @szuecsResultValue[T]() helper method (#8320) authored by @srenatusast: Add index else == nil test, fix it (#8348) authored by @srenatus
ast: Add scaffolding to introspect and skip compiler stages (#8304) (authored by @srenatus)
ast: Ensure term values implement ast.StringLengther (#8374) authored by @charlieegan3
ast: Fix double-fix for refs["with-a"].dash as package (#8286) authored by @srenatus
ast: Optimized template-expression handling of values known to be defined (#8310) authored by @anderseknert
ast: Put rule indices into rule tree, change Values to []*Rule (#8298) authored by @srenatus
ast: Replace true expr when appending to empty body (#8299) authored by @anderseknert
ast: Return correct location of unsafe var in object (#7935) authored by @sspaink reported by @anderseknert
ast: Use StageID in WithStageAfterID, also for QueryCompiler (follow-up) (#8306) authored by @srenatus
compile: Add StringLength to lazy object (#8369) authored by @charlieegan3 reported by @robmyersrobmyers
parser: Add test to verify filename interning in Location (#8322) authored by @anderseknert
perf: Allocate less in array unification (#8351) authored by @anderseknert
perf: Various minor eval performance tweaks (#8290) authored by @anderseknert
perf: json.patch + interning improvements (#8289) authored by @anderseknert
topdown: Optimize bindings allocation with dynamic pre-sizing (#7266) authored by @alex60217101990
topdown: Preserve original package name with special characters in optimized builds (#8284) authored by @sspaink reported by @at50989
wasm: Updates (LLVM+tools) (#8295) authored by @srenatus
glob.match built-in documentation (#8252) authored by @sibasispadhi reported by @anderseknerthttp.send, regex, and glob built-ins (#6730) authored by @anivar reported by @rudrakhpjson.patch target description (#8271) authored by @anderseknertinterface{} -> any in golang snippets (#8373) authored by @srenatusBenchmarkFunctionArgumentCounts query (#8327) authored by @alex60217101990This release updates the version of Go used to build the OPA binaries and images to 1.25.7. That version of the Go standard library contains a fix for
This release updates the version of Go used to build the OPA binaries and images to 1.25.7. That version of the Go standard library contains a fix for GO-2026-4337.
This bug fix release addresses an issue found in the new array.flatten built-in function
This bug fix release addresses an issue found in the new array.flatten built-in function
array.flatten handling of single item arrays (
#8273) (#8272) authored by @anderseknertNothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →