NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #280 by repository stars
Last release today
01 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4337 releases · first in 2016
Nothing published for this version
Nothing published for this version
cmd: Add back default cmd.RootCommand definition. (#7811) authored by @philipaconrad Fixing a breaking change to the go API introduced in OPA v1.7.0.
This release contains a mix of new features, performance improvements, and bugfixes. Notably:
io.jwt built-ins, including a new io.jwt.verify_eddsa built-in.Support for the EdDSA signing algorithm has been added to built-in functions in the io.jwt namespace.
This introduces the new io.jwt.verify_eddsa built-in function, and adds EdDSA support for the following built-ins:
This feature benefited greatly from the groundwork laid by @lestrrat in (#7638). 👏 🎉 🥳
Authored by @johanfylling reported by @aromeyer
cmd.RootCommand definition. (#7811) authored by @philipaconradopa exec parameters (#7850, #7840) authored by @srenatus--fail-non-empty and --stdin-input flags were dropped."", discern from unset (#7831) authored by @srenatus reported by @ManuelNowackConfinaleObject.Insert on existing key (#7820) authored by @anderseknertgithub.com/lestrrat-go/jwx/v3 (#7638) authored by @lestrratcount description (#7836) authored by @charlieegan3TestCertReloading less verbose (#7823) authored by @charlieegan3*-patch build targets (#7864) authored by @johanfyllingOne column per quarter.
This is a bug fix release addressing two issues for users that include OPA's CLI in their own application's CLI:
This is a bug fix release addressing two issues for users that include OPA's CLI in their own application's CLI:
cmd package (cmd.RootCommand)opa parse commandNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a mix of new features, performance improvements, and bugfixes. Notably:
This release contains a mix of new features, performance improvements, and bugfixes. Notably:
The OPA SDK/API has been improved to provide better extensibility an more points of integration for developers.
DefaultModuleLoader (#7794) authored by @srenatusQueryTracers, tracing.Options and Cancel from QueryContext (#7767) authored by @philipaconradTracingOpts into EvalContext (#7778) authored by @srenatusExtraDiscoveryOpts to runtime.Params (#7766) authored by @srenatushttp.Flusher (#7772) authored by @srenatusuint64 and float64 metrics in runBenchmark (#7761) authored by @srenatusAsBundle() (#7798) authored by @srenatusFactories() merge the factories (#7777) authored by @srenatusBatchDecisionID field to Decision Logs (#7791) authored by @philipaconradNote: While we have been working on the new website we have been showing the edge documentation contents (as contents and framework changes often must go hand in hand). Now that the website development pace has slowed and the functionality is more stable, we will be returning to showing the documentation content from the latest release instead. Please use the edge documentation site to review new changes. PR previews are also based on the latest branch commit. This change will be made to show the v1.7.0 release shortly after publishing.
/docs/envoy-authorization/ 404 (#7755 authored by @charlieegan3/data/versions.json (#7783) authored by @charlieegan3Benchmark fixes (#7765) authored by @anderseknert
Use Regal for linting Rego (#7752) authored by @anderseknert
Use shorthand form for types (#7757) authored by @anderseknert
.github: Use types for issues (#7751) authored by @charlieegan3
build: Add top-level token permissions for workflows (#7795) authored by @timothyklee
docs/build: Link checker fixes (#7743) authored by @charlieegan3
Dependency updates; notably:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
…by @anderseknert Note: This is a potentially breaking change for go API users directly interfacing with the OPA server's routing.
This release contains a mix of new features, performance improvements, and bugfixes. Notably:
We're continuing to modernize the OPA website with a new design and improved user experience.
Some highlights:
Authored by @sky3n3t and @charlieegan3
Previously, Rego references could not contain terms that conflict with Rego keywords such as package, if, else, not, etc.
in certain constructs:
package example
allow if {
input.package.source # not allowed (before v1.6.0)
input["package"].destination # allowed
}
The constraints for valid Rego references have been relaxed to allow keywords. The above example is now valid and will no longer cause a compilation error.
Authored by @johanfylling
By default, OPA will now run tests in parallel (defaulting to one parallel execution thread per available CPU core), significantly speeding up test execution time for large test suites. The performance boost is closely tied to the number of tests in your project and your selected parallelism level. For larger projects and default settings, 2-3x performance gains have been measured on a MacBook Pro.
Parallelism can be disabled to run tests sequentially by setting the --parallel flag to 1. E.g. opa test . --parallel=1.
Authored by @sspaink reported by @anderseknert
The builtin context, an internal construct of OPA's evaluation engine, was previously provided to every builtin function. As it turns out, only very few of them actually need it, for caching, cancellation, or lookups. Those builtins are still provided with a builtin context, but for calls to all other builtins, we save the memory required by it. The impact is tremendous: Even though the size of a single builtin context is only about 270 bytes, in an example application (Regal), this change brings about 360 MB of reduced memory usage!
Authored by @anderseknert
opa check --bundle report virtual/base doc conflicts (#7701) authored by @anderseknertopa check is used with the --bundle flag, an error will be reported if the provided json/yaml data has a conflicting overlap with the virtual documents generated by Rego rules. Such conflicts are ambiguous and can lead to unexpected evaluation results, and should be resolved.opa inspect with JSON format (#7459) authored by @johanfylling reported by @mostealth--v0-compatible flag (#7668) authored by @tsandall/) and OPA is served at some other path than root.0123) are now considered invalid at time of parsing and will generate an error. If you're impacted by this change, please update your policies to not have numbers with leading zeros. E.g. 0123 should be changed to 123.walk would get mutated (#7656) authored by @anderseknert reported by @robmyersrobmyersgoogle.golang.org/protobuf (#7655) authored by @sspainkconcat performance (#7702) authored by @anderseknertThis is a bug fix release addressing a regression to the walk built-in function, introduced in v1.5.0. See #7656 (authored by @anderseknert reported b
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a mix of new features, performance improvements, and bugfixes. Among others:
This release contains a mix of new features, performance improvements, and bugfixes. Among others:
object.get, walk and builtin-function evaluationThe OPA website has been modernized with a new design and improved user experience.
The new site is based on Docusaurus and React which makes it easier to build live functionality and add non-documentation resources. This lays the groundwork for even more improvements in the future!
Documentation for older OPA versions are still available in the version archive.
Authored by @charlieegan3
SomeDecl Location field when compiler resolves refs (#7543) authored by @johanfyllingcommit and timestamp (#7471) reported by @kastl-ars authored by @sspainkobject.get built-in function (#7593) authored by @anderseknertwalk built-in function (#7612) authored by @anderseknertRef.String() shortcut on single var term ref (#7595) authored by @anderseknertopaTest (#7560) authored by @sspainkany in place of interface{} (#7566) authored by @anderseknertThis is a bug fix release addressing the missing capabilities/v1.4.1.json in the v1.4.1 release.
This is a bug fix release addressing the missing capabilities/v1.4.1.json in the v1.4.1 release.
This is a security fix release for the fixes published in Go 1.24.1 and 1.24.2
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →