NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #286 by repository stars
Last release today
05 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4342 releases · first in 2016
This release contains a mix of new features, performance improvements, and bugfixes. Notably:
This release contains a mix of new features, performance improvements, and bugfixes. Notably:
--fail-on-empty flag for opa testIS NOT NULL query statements in the Compile APIStarting with this release, OPA will ship non-static arm64 executables for linux and darwin. Furthermore, the openpolicyagent/opa:latest docker image is a multi-platform image with arm64 support.
opa test --fail-on-empty to allow making bad -r or empty folders fail (#7943) reported and authored by @grosserwith keyword (#7942) authored by @sspainkReadMaybeCompressedBody (#7966) authored by @anderseknertundeclared error when printing nested comprehension (#7647) authored by @schmitd reported by @charlesdanielseval.Time term (#7968) authored by @anderseknertsplit built-in calls (#7962) authored by @anderseknertCLI Reference to Operations in TOC (#8001) authored by @johanfyllingGracefulShutdownPeriod (#7991) authored by @rMaxiQphttp.DefaultTransport fix to init() (#7955) authored by @srenatusvendor/ (#7975) authored by @srenatusopa test did not run any testsWith the new --fail-on-empty flag, accidentally running opa test in a directory without any tests or
with a -r that did not match any test names, can be caught by making the test fail instead.
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a mix of new features, performance improvements, and bugfixes. Notably:
This release contains a mix of new features, performance improvements, and bugfixes. Notably:
Compile API extensions with support for SQL filter generation previously exclusive to EOPA has been ported into OPA.
With OPA running with this policy, we'll compile the query data.filters.include into SQL filters:
package filters
# METADATA
# scope: document
# compile:
# unknowns: [input.fruits]
include if input.fruits.name == input.favorite
POST /v1/compile/filters/include HTTP/1.1
Content-Type: application/json
Accept: application/vnd.opa.sql.postgresql+json
{
"input": {
"favorite": "pineapple"
}
}
HTTP/1.1 200 OK
Content-Type: application/vnd.opa.sql.postgresql+json
{
"result": {
"query": "WHERE fruits.name = E'pineapple'"
}
}
See the documentation for more details.
Authored by @srenatus and @philipaconrad
OPA's rule indexer is a means by which OPA can optimize evaluation performance. Briefly, the indexer can in some cases determine that a rule won't successfully evaluate before it's evaluated based on the query input. The indexer previously only considered terms in certain compound expressions, ignoring single terms; e.g. an expression containing a sole "naked" ref. This has now changed!
Given a policy with an allow rule containing two "naked" refs: input.foo and input.bar:
package example
allow if {
input.foo
input.bar
}
and the input document:
{
"foo": 1
}
before this improvement, when evaluating the query data.example.allow, we get the trace log:
query:1 Enter data.example.allow = _
query:1 | Eval data.example.allow = _
query:1 | Index data.example.allow (matched 1 rule, early exit)
policy.rego:3 | Enter data.example.allow
policy.rego:5 | | Eval input.foo
policy.rego:6 | | Eval input.bar
policy.rego:6 | | Fail input.bar
policy.rego:5 | | Redo input.foo
query:1 | Fail data.example.allow = _
Here, we can see that the allow rule is evaluated, but fails on the input.bar expression, as it's referencing an undefined value.
With the improvement to the indexer, we instead get:
query:1 Enter data.example.allow = _
query:1 | Eval data.example.allow = _
query:1 | Index data.example.allow (matched 0 rules, early exit)
query:1 | Fail data.example.allow = _
Where we can see that the allow rule was never evaluated, since the input doesn't meet the conditions established by the indexer; i.e. both input.foo and input.bar must have defined values.
Authored by @srenatus
opa run when loading bundles in watch-mode (--watch) (#7870) authored by @sspaink reported by @johanfyllingnumbers.range_step built-in error message (#7882) authored by @charlieegan3every and not examples (#7901) authored by @charlieegan3io.jwt and time built-ins (#7892) authored by @charlieegan3regex and string built-ins (#7890) authored by @charlieegan3Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →