NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #280 by repository stars
Last release today
01 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4337 releases · first in 2016
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a security fix addressing CVE-2025-46569. It also includes a mix of new features, bugfixes, and dependency updates.
This release contains a security fix addressing CVE-2025-46569. It also includes a mix of new features, bugfixes, and dependency updates.
A vulnerability in the OPA server's Data API allows an attacker to craft the HTTP path in a way that injects Rego code into the query that is evaluated.
The evaluation result cannot be made to return any other data than what is generated by the requested path, but this path can be misdirected, and the injected Rego code can be crafted to make the query succeed or fail; opening up for oracle attacks or, given the right circumstances, erroneous policy decision results.
Furthermore, the injected code can be crafted to be computationally expensive, resulting in a Denial Of Service (DoS) attack.
Users are only impacted if all of the following apply:
or, if all of the following apply:
Note: With no Authorization Policy configured for restricting API access (the default configuration), the RESTful Data API provides access for managing Rego policies; and the RESTful Query API facilitates advanced queries. Full access to these APIs provides both simpler, and broader access than what the security issue describes here can facilitate. As such, OPA servers exposed to a network are not considered affected by the attack described here if they are knowingly not restricting access through an Authorization Policy.
This issue affects all versions of OPA prior to 1.4.0.
See the Security Advisory for more details.
Reported by @GamrayW, @HyouKash, @AdrienIT, authored by @johanfylling
rego_v1 feature to --v0-compatible capabilities (#7474) authored by @johanfyllinginternal/gqlparser/ast to Position fields (#7509) authored by @robmyersrobmyersPartialRun() (#7490) authored by @srenatus/docs/edge/ path (#7529) authored by @charlieegan3Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a mix of features, bugfixes, and dependency updates.
This release contains a mix of features, bugfixes, and dependency updates.
A new, optional, buffering mechanism has been added to decision logging. The default buffer is designed around making precise memory footprint guarantees, which can produce lock contention at high loads, negatively impacting query performance. The new event-based buffer is designed to reduce lock contention and improve performance at high loads, but sacrifices the memory footprint guarantees of the default buffer.
The new event-based buffer is enabled by setting the decision_logs.reporting.buffer_type configuration option to event.
For more details, see the decision log plugin README.
Reported by @mjungsbluth, authored by @sspaink
Distributed tracing through OpenTelemetry has been extended to support HTTP collectors (enabled by setting the distributed_tracing.type configuration option to http).
Additionally, configuration has been expanded with fine-grained batch span processor options.
Authored and reported by @sqyang94
kind usage instruction in Envoy tutorial (#7465) authored by @joostholslagNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a mix of features, performance improvements, and bugfixes.
This release contains a mix of features, performance improvements, and bugfixes.
Rego tests now support parameterization, allowing a single test rule to include multiple, hierarchical, named test cases. This feature is useful for data-driven testing, where a single test rule can be used for multiple test cases with different inputs and expected outputs.
package example_test
test_concat[note] if {
some note, tc in {
"empty + empty": {
"a": [],
"b": [],
"exp": [],
},
"empty + filled": {
"a": [],
"b": [1, 2],
"exp": [1, 2],
},
"filled + filled": {
"a": [1, 2],
"b": [3, 4],
"exp": [1, 2, 3], # Faulty expectation, this test case will fail
},
}
act := array.concat(tc.a, tc.b)
act == tc.exp
}
$ opa test example_test.rego
example_test.rego:
data.example_test.test_concat: FAIL (263.375µs)
empty + empty: PASS
empty + filled: PASS
filled + filled: FAIL
--------------------------------------------------------------------------------
FAIL: 1/1
See the documentation for more information.
Authored by @johanfylling, reported by @anderseknert
opa fmt 3x faster formatting (#7341) authored by @anderseknertBuildAnnotationSet to ast v0 (#7347) authored by @anderseknert[]byte (#7379) authored by @dennygursky--v0-compatible isn't respected for custom bundles (#7338) authored by @johanfyllingopa test --bench (#7205) authored by @anderseknertopa exec output (#7373) authored by @anderseknertv1 import (#7391) authored by @charlieegan3--v1-compatible mentions outside the v1 upgrade guide and v0 compatibility docs (#7337) authored by @johanfyllingmake test-short task (#7364) (authored by @anderseknert)TestIntraQueryCache_ClientError and TestInterQueryCache_ClientError (#7280) authored by @JuneezeeNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a mix of features, performance improvements, and bugfixes.
This release contains a mix of features, performance improvements, and bugfixes.
opa bench (#7291) authored by @anderseknertio.jwt token verification built-ins (#7274) authored by @johanfyllingnumbers.range built-in (#7269) authored by @anderseknertopa repl (#7301) authored by @anderseknert reported by @tsandall--v0-compatible for opa eval partial eval support modules (#7251) authored by @johanfyllinglinter-settings configuration name (#7244) authored by @Juneezeebuild(go): bump to 1.23.5 (authored by @srenatus). Addressing CVE-2024-45341 and CVE-2024-45336 vulnerabilities in the Go runtime.
This is a bug fix release addressing the following issues:
CVE-2024-45341 and CVE-2024-45336 vulnerabilities in the Go runtime.--v0-compatible flag.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
> * The minimum version of Go required to build the OPA module is 1.22
NOTES:
- The minimum version of Go required to build the OPA module is 1.22
We are excited to announce OPA 1.0, a milestone release consolidating an improved developer experience for the future of Policy as Code. The release makes new functionality designed to simplify policy writing and improve the language's consistency the default.
Below we highlight some key changes to the defaults in OPA 1.0:
if for all rule definitions and contains for multi-value rules is now mandatory, not just when using the rego.v1 import.every, in) are available without any imports.opa check --strict) are now the default. Duplicate imports and imports which shadow each other are no longer allowed.Read more about the OPA 1.0 announcement on the OPA blog.
Following are other changes that are included in OPA 1.0.
PRs #7172, #7190,
#7193, #7165,
#7168, #7191 &
#7222 together improve the memory performance of OPA. Key strategies
include reusing pointers and optimizing array and object operations, minimizing intermediate object creation, and using sync.Pool
to manage memory-heavy operations. These changes cumulatively greatly reduced the number of allocations and improved
evaluation speed by 10-20%. Additional benchmarks highlighted significant memory and speed improvements in custom
function evaluation.
Authored by @anderseknert.
PR #7180 adds an EvalHTTPRoundTrip EvalOption and query-level WithHTTPRoundTrip option.
Both use a new function type which converts an http.Transport configured by topdown to an http.RoundTripper.
This supports use cases requiring the customization of the http.send built in behavior.
Authored by @evankanderson.
units.parsePR #7147 extends the behaviour of extractNumAndUnit to support
scientific notation values. This means values such as 1e3KB can now be handled by this function.
Authored by @berdanA.
bundle_loading_duration_ns metricPR #7156 extends OPA’s Prometheus configuration to allow the setting of user defined buckets for metrics. This aids when debugging the loading of slow bundles.
Authored by @jwu730-1.
PR #7126 updates tests to improve performance. Topdown and storage/disk/
tests now run around 50% and 75% faster respectively.
Authored by @philipaconrad.
rego.v1 and future.keywords imports for v1 by @johanfylling in #7224--rego-v1 cmd flag to --v0-v1 by @johanfylling in #7225topdown/cache by @evankanderson in #7188to_number now rejects "Inf", "Infinity" and "NaN" values by @sikehish in #7203opa build: provide an option to preserve print statements for the "wasm" target (#7194) by @me-viper in #7195opa eval: Return error if illegal arguments passed with --unknowns flag by @kd-labs in #7149Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →