NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #286 by repository stars
Last release today
09 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4354 releases · first in 2016
Nothing published for this version
Nothing published for this version
topdown.Tracer has been deprecated in favor of a newer interface topdown.QueryTracer.
Decision log masks can now mutate decision log events. Previously, the masks could only erase data in the events. With this change, users can implement masks that obfuscate or add information to the decision log events before they are emitted. Thanks to @dkiser for implementing this feature #2379)!
This release contains a new built-in function for parsing X.509 Certificate Signing Requests (crypto.x509.parse_certificate_request). Thanks to @vivekbagade for implementing this feature #2402!
This release adds support for aggregation and bit arithmetic operations for WebAssembly compiled policies. These functions no longer have to be provided by the host environment.
child_modules (#1772)Thanks to @Syn3rman for implementing an improvement to our release process to automatically tag external contributors (#2323)!
The coverage and profiling tracers no longer require variable values from the evaluator. This change improves perfomance significantly when coverage or profiling is enabled and policies inspect large data sets. Benchmarks show anywhere from 0.5x to over 30x speedup depending on the policy.
topdown.Tracer has been deprecated in favor of a newer interface
topdown.QueryTracer.topdown.BuiltinContext#Tracers has been deprecated in favor of
topdown.BuiltinContext#QueryTracers. The older Tracers field will be nil
starting this release, and eventually removed.One column per quarter.
compile: Change name of result var for wasm binary
format: Refactor wildcard names to rewrite early
docs/content small output correction on terraform page
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
format: Fix panic with else blocks and comments
Nothing published for this version
Nothing published for this version
This release fixes an issue in the Docker image build. The default ca-certificates were not being included becasue the Docker image is FROM scratch no
This release fixes an issue in the Docker image build. The default ca-certificates were not being included becasue the Docker image is FROM scratch now.
Nothing published for this version
Nothing published for this version
See opa build --help for details. This change is backwards incompatible. If you were previously relying on opa build to compile policies to wasm, you…
This release includes a number of features, optimizations, and bugfixes.
OPA now determines the latest stable release version using
https://telemetry.openpolicyagent.org. The only information provided to the
telemetry service is the version (e.g., 0.20.0), a UUIDv4 generated on
startup, and the build platform/architecture (e.g., darwin, amd64). This
feature is on by default in opa run however it can be easily disabled by
specifying --skip-version-check on the command-line. If you are inside the
REPL, type help to see the latest version information. If you are running OPA
as a server, OPA will log an INFO level message indicating if OPA is out of
date. Version checking is best-effort. Any errors that occur while communicating
with https://telemetry.openpolicyagent.org are only logged at DEBUG level. For
more information see https://openpolicyagent.org/docs/latest/privacy/.
opa build commandThe opa build command can now be used to package OPA policy and data files
into bundles
that can be easily distributed via HTTP. See opa build --help for details.
This change is backwards incompatible. If you were previously relying on opa build to compile policies to wasm, you can still do so:
# before v0.20.0
opa build -d policy.rego 'data.example.allow'
# v0.20.0 and newer
opa build policy.rego -e example/allow -t wasm
This release includes a number of new built-in functions:
graph.reachable for computing the transitive closure from edge sets. This
function allows users to write policies that traverse organization charts,
security groups, etc. (thanks to @jaspervdj-luminal!)io.jwt.verify_rs512 and other variants (rs/es/hs/ps, 384/512)
were added (thanks to @GBrawl!)uuid.rfc4122 for generating UUIDv4s (thanks to @reneklootwijk!)This release also includes a few fixes to existing built-in functions:
units.parse_bytes now supports units without the B or b suffix (thanks to @GBrawl!)io.jwt.verify_decode now supports floating-point nbf and exp claims (thanks to @GBrawl!)array.slice clamping logic fixed to prevent panic (#2320).The opa run command now supports a --diagnostic-addr flag that causes the
server to expose the /health and /metric endpoint on a different address.
This makes it easier to secure sidecar deployments in Kubernetes because the
main API endpoints can be served on localhost and the diagnostic endpoints can
be served on 0.0.0.0 so that the kubelet and other components can access them
(#2002). The envoy
tutorial has been updated to show this in action.
The AWS credential provided has been updated to support the standard
AWS_SESSION_TOKEN and AWS_SECURITY_TOKEN environment variables. These are
used when signing S3 bundle requests for an AWS IAM assumed role (thanks to
@kpiotrowski!)
This release includes a number of improvements for wasm compiled policies.
Go To Definition inside policies.
This feature uses the new opa oracle find-definition command.opa test command now includes location information on trace output.opa fmt command now preserves else block style when possible (thanks to @mikaelcabot!)This release includes several improvements to the website and documentation.
else statement (#2353)make deb target. The target requires dpkg-deb to be installed. Thanks to @keshto
for contributing this!openpolicyagent/opa) is back to using FROM scratch.An internal utility function that unmarshals JSON (util.UnmarshalJSON) has
been fixed to return an error if the input bytes contain garbage following a
valid JSON value. In the past, the util.UnmarshalJSON function would just
return the valid JSON value and ignore the garbage following it. This change
is backwards incompatible since clients that were previously transmitting bad
data will now receive an error, however, we think it's important to surface
errors rather than hide them (#2331).
The Go plugin/shared library loading feature that was deprecated in v0.14.0 has finally been removed completely. If you are interested in extending OPA, see the Extensions for how to do so at compile-time (#2049).
The github.com/open-policy-agent/opa/metrics#Counter interface has been
extended to require an Add(uint64) function. This change only affects users
that have implemented their own version of the
github.com/open-policy-agent/opa/metrics#Metrics interface (which is the
factory for counters.)
As mentioned above, the opa build command-line syntax has changed. We think
this is the right time to refresh the command and we are more confident that
the new syntax will remain stable going forward.
This release deprecates opa test -l flag. Since we now display the trace
with line information, this flag is no longer needed.
In the next release we plan to deprecate the ?watch and ?partial HTTP API
parameters. The ?watch feature is unused and introduces significant
complexity in the server implementation. The ?partial parameter lazily
invokes Partial Evaluation inline with policy invocation. This is useful for
development and debug purposes, however, it's not recommended for enforcement
points ot use (since PE optimization can introduce significant latency.) Users
should rely on the new opa build command to perform PE on their policies.
See opa build --help for more information.
plugins: Fix race between manager and plugin startup
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →