NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #286 by repository stars
Last release today
08 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4352 releases · first in 2016
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release extends the HTTP server authorizer (--authorization=basic) to supply the HTTP message body in the input document. See the Authentication
This release extends the HTTP server authorizer (--authorization=basic) to supply the HTTP message body in the input document. See the Authentication and Authorization section in the security documentation for details.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a fix for running OPA under Docker with a non-default working directory (#2974).
This release contains a fix for running OPA under Docker with a non-default working directory (#2974).
Nothing published for this version
Nothing published for this version
The --insecure-addr flag (which was deprecated in v0.10.0) has been removed completely
This release contains a number of improvements and fixes. Importantly, this release includes a notable change to built-in function error handling. See the section below for details.
Previously, built-in function errors would cause policy evaluation to halt immediately. Going forward, by default, built-in function errors no longer halt evaluation. Instead, expressions are treated as false/undefined if any of the invoked built-in functions return errors.
This change resolves a common issue people face when passing unsanitized input values to built-in functions. For example, prior to this change the expression io.jwt.decode("GARBAGE") would halt evaluation of the entire policy because the string is not a valid encoding of a JSON Web Token (JWT). If the expression was io.jwt.decode(input.token) and the user passed an invalid string value for input.token the same error would occur. With this change, the same expression is simply undefined, i.e., there is no result. This means policies can use negation to test for invalid values. For example:
decision := {"allowed": allow, "denial_reason": reason}
default allow = false
allow {
io.jwt.verify_hs256(input.token, "secret")
[_, payload, _] := io.jwt.decode(input.token)
payload.role == "admin"
}
reason["invalid JWT supplied as input"] {
not io.jwt.decode(input.token)
}
If you require the old behaviour, enable "strict" built-in errors on the query:
| Caller | Example |
|---|---|
| HTTP | POST /v1/data/example/allow?strict-builtin-errors |
| Go (Library) | rego.New(rego.Query("data.example.allow"), rego.StrictBuiltinErrors(true)) |
| CLI | opa eval --strict-builtin-errors 'data.example.allow' |
If you have implemented custom built-in functions and require policy evaluation to halt on error in those built-in functions, modify your built-in functions to return the topdown.Halt error type.
This release includes a few new built-in functions:
base64url.encode_no_pad, hex.encode, and hex.decode for dealing with encoded data (#2849) authored by @johanneslarssonjson.patch for applying JSON patches to values inside of policies (#2839) authored by @jaspervdj-luminaljson.is_valid and yaml.is_valid for testing validity of encoded values (authored by @jaspervdj-luminal)There were also a few fixes to existing built-in functions:
http.send to override no-cache HTTP header when force_cache specified (#2841) authored by @anderseknertstrings.replace_n to replace overlapping patterns deterministically (#2822)units.parse_bytes when passed a zero-length string (#2901)This release adds new credential providers for management services:
In addition the following server features were added:
opa run (--shutdown-wait-period) (#2764) authored by @bcarlssonbundles[_].size_limit_bytes) to override default 1GiB limit (#2781)error while continuing to report decision and status log to console) (#2733) authored by @anderseknert--verification-key handling to accept PEM files (#2796)--capabilities flag in opa build command (#2848) authored by @srenatuswith statements from mutating original input document (#2813)This release also includes a number of improvements to the Wasm support in OPA. Importantly, OPA now integrates a Wasm runtime that can be used to execute Wasm compiled policies. The runtime is integrated into the existing "topdown" evaluator so that specific portions of the policy can be compiled to Wasm as a performance optimization. When the evaluator executes a policy using the Wasm runtime it emits a special Wasm trace event. The Wasm runtime support in OPA is currently considered experimental and will be iterated on in coming releases.
This release also extends the Wasm compiler in OPA to natively support the following built-in functions (in alphabetical order):
base64.encode, base64.decode, base64url.encode, and base64url.decodeglob.matchjson.marshal and json.unmarshalnet.cidr_contains, net.cidr_intersects, and net.cidr_overlapregex.match, regex.is_valid, and regex.find_all_string_submatch_nto_numberwalk--insecure-addr flag (which was deprecated in v0.10.0) has been removed completely (#763)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →