NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #280 by repository stars
Last release today
01 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4337 releases · first in 2016
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a number of fixes and enhancements.
This release contains a number of fixes and enhancements.
A new set of built-in functions are now available to validate, parse and verify GraphQL query and schema! Following are the new built-ins:
graphql.is_valid: Checks that a GraphQL query is valid against a given schema
graphql.parse: Returns AST objects for a given GraphQL query and schema
graphql.parse_and_verify: Returns a boolean indicating success or failure alongside the parsed ASTs for a given GraphQL query and schema
graphql.parse_query: Returns an AST object for a GraphQL query
graphql.parse_schema: Returns an AST object for a GraphQL schema
Built-in function declarations now support additional metadata to specify name and description for function arguments and return values. The metadata can be programmatically consumed by external tools such as IDE plugins. The built-in function documentation is created using the new built-in function metadata. Check out the new look of the Built-In Reference page!
Under the hood, a new file called builtins_metadata.json is generated via make generate which can be consumed by
external tools.
opa fmt location for non-key rules (#4695) (authored by @jaspervdj)capabilities.json while creating a new built-in functionrego.metadata.rule() built-in functionimport keyword (#4689) authored by @mmzeeman reported by @mmzeemanapiVersion: admission.k8s.io/v1) (authored by @vicmarbev)make test: Fix "too many open files" issue on Mac OSNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a number of fixes and enhancements.
This release contains a number of fixes and enhancements.
The rich metadata added in the v0.38.0 release can now be introspected from the policies themselves!
package example
# METADATA
# title: Edits by owner only
# description: |
# Only the owner is allowed to edit their data.
deny[{"allowed": false, "message": rego.metadata.rule().description}] {
input.user != input.owner
}
This snippet will evaluate to
[{
"allowed": false,
"message": "Only the owner is allowed to edit their data.\n"
}]
Both the rule's metadata can be accessed, via rego.metadata.rule(), and the
entire chain of metadata attached to the rule via the various scopes that different
metadata annotations can have, via rego.metadata.chain().
All the details can be found in the documentation of these new built-in functions.
It is now possible to mock functions in tests! Both built-in and non-built-in functions can be mocked:
package authz
import data.jwks.cert
import data.helpers.extract_token
allow {
[true, _, _] = io.jwt.decode_verify(extract_token(input.headers), {"cert": cert, "iss": "corp.issuer.com"})
}
test_allow {
allow
with input.headers as []
with data.jwks.cert as "mock-cert"
with io.jwt.decode_verify as [true, {}, {}] # mocked built-in
with extract_token as "my-jwt" # mocked non-built-in
}
For further information about policy testing with data and function mock, see the Policy Testing docs
All details about with can be found in its Policy Language section.
:=Remaining restrictions around the use of := in rules and functions have been lifted (#4555).
These constructs are now valid:
check_images(imgs) := x { # function
# ...
}
allow := x { # rule
# ...
}
response[key] := object { # partial object rule
# ...
}
In the wake of this, rules may now be "redeclared", i.e. you can use := for more than one rule body:
deny := x {
# body 1
}
deny := x {
# body 2
}
This was forbidden before, but didn't serve a real purpose: it would catch trivial-to-catch errors like
p := 1
p := 2 # redeclared
But it would do no good in more difficult to debug "multiple assignment" problems like
p := x {
some x in [1, 2, 3]
}
opa capabilities: Expose capabilities through CLI, and allow using versions when passing --capabilities v0.39.0 to the various commands (#4236) authored by @IoannisMatzaris <!-- FC -->opa eval: Don't use source locations when formatting partially evaluated output (#4609)opa inspect: Fixing an issue where some errors encountered by the inspect command aren't properly reportedopa fmt: Fix a bug with missing whitespace when formatting multiple with statements on one indented line (#4634)When configured to do so, OPA's bundle and discovery plugins will retrieve bundles from any OCI registry. Please see the Services Configuration section for details.
Note that at this point, it's best considered a "feature preview". Be aware of this:
Thanks to @carabasdaniel for starting the work on this!
net.cidr_merge (#4596), reported by @alexhu20http.send can now parse and cache YAML responses, analogous to JSON responsesevery over other constructions (#4603)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →