NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #280 by repository stars
Last release today
02 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4340 releases · first in 2016
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release includes a number of features, enhancements, and fixes. The default branch for the Git repository has also been updated to main.
This release includes a number of features, enhancements, and fixes. The default
branch for the Git repository has also been updated to main.
This release adds support for annotations. Annotations allow users to declare metadata on rules and packages. Currently, OPA supports one form of metadata: schema declarations. For example:
package example
# METADATA
# schemas:
# - input: schema.service
deny["service is missing required 'owner' label"] {
input.kind == "Service"
not input.metadata.labels.owner
}
# METADATA
# schemas:
# - input: schema.deployment
deny["deployment replica count too low for 'production' namespace"] {
input.kind == "Deployment"
input.metadata.namespace == "production"
object.get(input.spec, "replicas", 1) < 3
}
Users can include schema annotations in their policies to tell OPA about the
structure of external data loaded under input or data. By learning the
schema of base documents, OPA can surface mistakes in the policy at authoring
time (e.g., referring to a non-existent field in a JSON object or calling a
built-in function with an invalid value.) For more information on the
annotations and schema support see the Type
Checking page in the
documentation. In the future, annotations will be expanded to support other
kinds of metadata and additional tooling will be added to leverage them.
token authentication mode without a corresponding authorization policy. (#3380) authored by @kale-amrutaGET /v1/config endpoint that returns OPA's active configuration. This API is useful if you need to debug the running configuration in an OPA configured via Discovery. (#2020)?pretty option in the v0 API (#3332) authored by @clarshadplugins.Logger option when creating the plugin manager.opa refactor move subcommand was added to support package renaming use cases (#3290)opa check subcommand now supports a -s/--schema flag like the opa eval subcommand.time.diff function was added to support calculating differences between date/time values (#3348) authored by @andrehalandunits.parse_bytes function now supports floating-point values (#3297) authored by @andy-painehttp.send function no longer errors out on invalid Expires headers. (#3284)glob.match usage (#3293)opa eval subcommand now correctly returns the set of all variable bindings and expression values when the wasm target is enabled. Previously it returned only set of variable bindings. (#3281)glob.match function now handles the default delimiter correctly. (#3294)opa build subcommand no longer requires a capabilities file when the wasm target is enabled. If capabilities are not provided, OPA will use the capabilities for its own version. (#3270)opa build subcommand now dumps the IR emitted by the planner when --debug is specified.opa eval subcommand no longer panics when a policy fails to type check and the wasm target is enabled.false instead of either being true or undefined. (#3271)CancelErr to indicate cancellation errors (instead of BuiltinErr which it returned previously.)data (#3279) and (#3305)rego package no longer panics when the wasm target is enabled and undefined functions are encountered (#3251)make image target now uses the CI image for building the Go binary. This avoids platform-specific build issues by building the Go binary inside of Docker.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →