Skip to content

Update openpolicyagent/opa Docker tag to v1.21.1 (main) - #1955

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/main-openpolicyagent-opa-1.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/main-openpolicyagent-opa-1.x

Conversation

@renovate

@renovate renovate Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
openpolicyagent/opa (source) stage minor 1.20.2 → 1.21.1

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

open-policy-agent/opa (openpolicyagent/opa)

v1.21.1

Compare Source

This release fixes a compiler regression introduced in OPA v1.21.0.

Fix some … in/every in comprehensions nested in object and set literals (#​9280)

A comprehension using some … in or every in its body, nested inside an object or set literal, was wrongly treated as ground, so the compiler skipped rewriting it. some … in then failed with rego_unsafe_var_error; every caused a compiler panic:

package example

p := {"k": [r.a | some r in input.xs]}           # rego_unsafe_var_error: var r is unsafe

q := {[1 | every x in input.xs { x > 0 }]}       # panic

Array literals weren't affected, and neither were literals that contain some other non-ground term.

authored by @​srenatus, reported by @​tun0

v1.21.0

Compare Source

This release contains a mix of new features and bug fixes. Notably:

  • Improved rule indexing
  • Improved rule recursion check
  • YAML is parsed against the 1.2 core schema (breaking change)
Rules with general refs no longer collide in the recursion check (#​6813)

Before, this was a recursion error:

package play

p[x].foo.bar if {
	x := "a"
	not p[x].foo.baz
}

p[x].foo.baz if {
	x := "a"
	false
}

Rules with a variable in their head are all stored at the ground prefix of their ref, so
p[x].foo.bar and p[x].foo.baz looked like dependencies of each other. The compiler is
now less conservative and compares the ref parts past the prefix. Genuine cycles are still
reported.

The IR and Wasm targets however still return an error: they plan one function per ground
path prefix, and cannot evaluate part of a function that is still being planned.

Authored by @​sspaink, reported by @​tsandall

Data and Query APIs can return rule labels in the response (#​9211)

# METADATA labels for evaluated rules were only available in decision log
events. The Data API (GET/POST /v1/data) and Query API (GET/POST /v1/query) now accept a rule_labels query parameter to include the same
merged labels in the response payload, under a rule_labels key.

Authored by @​srenatus

Behavior change: response gzip compression now bounds its buffer to min_length (#​9205)

The server's gzip response compression (server.encoding.gzip) buffered an entire
incoming Write call before deciding whether to compress, so a single large write could
grow the buffer well past min_length before that decision was made. The handler is now
built on klauspost/compress/gzhttp
instead of a hand-rolled buffer and gzip.Writer pool, which caps what it buffers to
min_length (floored at 512 bytes) before streaming the remainder through the chosen
path. min_length and compression_level behave the same as before; only gzip is
negotiated, not zstd.

Authored by @​srenatus

YAML is now parsed against the 1.2 core schema (#​5754, #​6598)

OPA parsed YAML with a library pinned to go-yaml v2, which implements YAML 1.1. Under
1.1, the bare words y, n, yes, no, on and off resolve to booleans, so a
GitHub Actions workflow loaded with --data came back with true where it should have
had on:

on: push
{ "true": "push" }

These words are now plain strings, as the YAML 1.2 core schema specifies. true and
false are unaffected. This applies everywhere OPA reads YAML: --data, bundles,
config files, and the yaml.unmarshal builtin.

If you were relying on yes/no/on/off being read as booleans, quote the value and
use true/false instead.

Authored by @​sspaink, reported by @​scnewma and @​johnc-c

Empty composite literals are now typed as empty (#​7275)

The type checker used to give the empty object literal {} the type
object[any: any], the empty array literal [] the type array[any], and the
empty set literal set() the type set[any], i.e. the types of a collection
that may hold anything. Every other literal is typed by its contents, so
referencing a key that isn't there is caught at compile time — but only for
non-empty literals:

obj := {"foo": "bar"}
obj.bar # rego_type_error: undefined ref: obj.bar

obj := {}
obj.bar # compiles

Empty literals are now typed as what they are: an object with no properties, an
array with no items, and a set with no members. Both examples above now fail to
compile, and so does every other way of selecting from an empty literal,
including iterating one (some x in []).

Comparing an empty object or array literal against a value whose type says it
can't be empty ({"foo": "bar"} == {}) is now a match error too, the same way
{"foo": "bar"} == {"bar": "foo"} already was. Use count(x) == 0 to test a
collection for emptiness without asserting its type. Sets are unaffected here:
set[string] describes any set of strings, the empty one included, so
{"foo"} == set() still compiles.

Authored by @​sspaink, reported by @​disaverio

Rule indexing improvements

The rule indexer now excludes rules from more kinds of expression, and builds a smaller
trie to do it with. See Use indexed statements
for what is indexed.

  • startswith, endswith, strings.any_prefix_match and strings.any_suffix_match
    are indexed when the base strings are known at compile time.
  • A reference that reads a key out of the object at its ground prefix in base data
    (data.groups.admins.members[input.subject]) is indexed by asking that object for the
    key, where such a ruleset used to leave every rule a candidate.
  • References rooted at a local variable (x := input; x.foo == "a") are indexed the
    same as input.foo == "a", and a chain of assignments no longer drops the constraint
    at the end of it.
  • A rule's path through the trie stops at the last level it constrains, and a reference
    reached by several values no longer leaves the rest of the rule unindexed.
  • Candidates come back in declaration order, which the indexer documented but did not
    do. A complete rules must not produce multiple outputs error now points at the first
    of the conflicting definitions rather than the second, and partial evaluation names
    and orders the generated locals of its support rules differently. What a policy
    evaluates to is unaffected.
Changes
Runtime, SDK, Tooling
Compiler, Topdown and Rego
Docs, Website, Ecosystem
Miscellaneous
  • ast: Add util.MapKeys helper (#​9158) authored by @​anderseknert
  • ast: Enable more gocritic linters (#​9154) authored by @​anderseknert
  • ast: Enable unparam linter (#​9223) authored by @​anderseknert
  • ast: More niceties, less allocs, less code (#​9228) authored by @​anderseknert
  • ast: Pin BenchmarkObjectConstruction shuffle seed (#​9222) authored by @​srenatus
  • ast: Update remaining errors.As call sites to use errors.AsType (#​9106) authored by @​anderseknert
  • ast: Use modern Go in place of custom compare code (#​9151) authored by @​anderseknert
  • ast: Where have all the allocs gone? (#​9137) authored by @​anderseknert
  • build: Add bench-nightly, a three-arm benchlab experiment runner (#​9118) authored by @​srenatus
  • build: Pin pigeon in build/tools instead of go run pkg@​version (#​9160) authored by @​sspaink
  • bundle: Avoid allocation in getdepth (#​9199) authored by @​srenatus
  • bundle: Remove unused writeModules helper (#​9199) authored by @​srenatus
  • bundle: Reuse encoder buffer while hashing (#​9199) authored by @​srenatus
  • bundle: deep-copy bundle data natively instead of via JSON round-trip (#​9199) authored by @​srenatus
  • check: Avoid allocating in checkExprEq (#​9150) authored by @​anderseknert
  • ci: Publish benchmark trend on a schedule instead of per-push (#​9119) authored by @​srenatus
  • ci: Run the nightly benchlab experiment (#​9118) authored by @​srenatus
  • cmd: Stop binding a fixed port in the run tests (#​9240) authored by @​srenatus
  • github: Drop python from the CodeQL language matrix (#​9097) authored by @​sspaink
  • nightly: Fix go get smoke test (#​9245) authored by @​srenatus
  • perf: Cheaper custom function calls (#​9167) authored by @​anderseknert
  • perf: Fix linear runtime for Array.set due to rehashing (#​9161) authored by @​tsandall
  • perf: General performance improvements in compiler (#​9170) authored by @​anderseknert
  • style: Some more functional niceties (#​9152) authored by @​anderseknert
  • test/e2e: Wait for diagnostic listeners before running tests (#​9134) authored by @​sspaink
  • tests: Expanded testing for and/or keywords (#​9115) authored by @​johanfylling
  • topdown: Fix BulkStartsWith benchmark input generation (#​9222) authored by @​srenatus
  • topdown: Enable more revive linters (#​9181) authored by @​anderseknert
  • topdown: Fix flaky TestRegexBuiltinCache (#​9254) authored by @​sspaink
  • topdown: Fix linter issues (#​9231) authored by @​srenatus
  • util: Add RoundTripFast (#​9199) authored by @​srenatus
  • util: Decode RoundTrip's fallback into a fresh value (#​9206) authored by @​srenatus
  • workflows: Check the nightly go-get job for retractions via the proxy (#​9240) authored by @​srenatus
  • workflows: Remove benchmarks from nightly (#​9182) authored by @​srenatus
  • workflows: Run Regal's do.rq in the nightly compatibility check (#​9209) authored by @​sspaink
  • workflows: Use OCP@​main in nightly (#​9171) authored by @​srenatus
  • Collapse v0 shim packages into a single file each (#​8976) authored by @​sspaink, reported by @​anderseknert
  • Makefile: Add a benchlab target (#​9222) authored by @​srenatus
  • Remove retired go report (#​9112) authored by @​sspaink
  • Dependency updates:
    • build(go): Bump to 1.27.1 (#​9136) authored by @​srenatus
    • build(deps): Bump github.com/dgraph-io/badger/v4 from 4.9.5 to 4.9.6
    • build(deps): Bump github.com/gobwas/glob to v1.0.0 (#​9114) authored by @​sspaink, reported by @​ghmer
    • build(deps): Bump github.com/huandu/go-sqlbuilder from 1.42.1 to 1.43.0
    • build(deps): Bump github.com/lestrrat-go/jwx/v3 from 3.1.1 to 3.3.0
    • build(deps): Bump github.com/olekukonko/tablewriter from 1.1.4 to 1.1.5
    • build(deps): Bump github.com/prometheus/client_model from 0.6.2 to 0.6.3
    • build(deps): Bump github.com/santhosh-tekuri/jsonschema/v6 from 6.0.2 to 6.0.3
    • build(deps): Bump github.com/sirupsen/logrus from 1.9.4 to 1.10.2
    • build(deps): Bump github.com/vektah/gqlparser/v2 from 2.5.36 to 2.5.37
    • build(deps): Bump go.opentelemetry.io/contrib/bridges/prometheus from 0.69.0 to 0.71.0
    • build(deps): Bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp from 0.69.0 to 0.71.0
    • build(deps): Bump go.opentelemetry.io/otel from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlptrace from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/sdk from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/sdk/metric from 1.44.0 to 1.46.0
    • build(deps): Bump go.yaml.in/yaml/v3 from 3.0.4 to 3.0.5
    • build(deps): Bump golang.org/x/sync from 0.22.0 to 0.23.0
    • build(deps): Bump golang.org/x/term from 0.45.0 to 0.46.0
    • build(deps): Bump golang.org/x/text from 0.40.0 to 0.42.0
    • build(deps): Bump golang.org/x/time from 0.15.0 to 0.16.0
    • build(deps): Bump google.golang.org/grpc from 1.82.1 to 1.83.2
    • build(deps): Bump google.golang.org/protobuf from 1.36.11 to 1.36.12
    • build(deps): Drop sigs.k8s.io/yaml (was 1.6.0)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate
renovate Bot requested a review from a team as a code owner October 4, 2026 00:43
@renovate renovate Bot added the v3.x Issues and Pull Requests related to the major version v3 label Oct 4, 2026
@codecov

codecov Bot commented Oct 4, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 88.95%. Comparing base (17a4971) to head (52b8be4).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1955   +/-   ##
=======================================
  Coverage   88.94%   88.95%           
=======================================
  Files         111      111           
  Lines       12448    12448           
=======================================
+ Hits        11072    11073    +1     
+ Misses       1374     1373    -1     
  Partials        2        2           

see 1 file with indirect coverage changes


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 17a4971...52b8be4. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

v3.x Issues and Pull Requests related to the major version v3

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants