Update openpolicyagent/opa Docker tag to v1.21.1 (main) - #1955
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #1955 +/- ##
=======================================
Coverage 88.94% 88.95%
=======================================
Files 111 111
Lines 12448 12448
=======================================
+ Hits 11072 11073 +1
+ Misses 1374 1373 -1
Partials 2 2 see 1 file with indirect coverage changes Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.20.2→1.21.1Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
open-policy-agent/opa (openpolicyagent/opa)
v1.21.1Compare Source
This release fixes a compiler regression introduced in OPA v1.21.0.
Fix
some … in/everyin comprehensions nested in object and set literals (#9280)A comprehension using
some … inoreveryin its body, nested inside an object or set literal, was wrongly treated as ground, so the compiler skipped rewriting it.some … inthen failed withrego_unsafe_var_error;everycaused a compiler panic:Array literals weren't affected, and neither were literals that contain some other non-ground term.
authored by @srenatus, reported by @tun0
v1.21.0Compare Source
This release contains a mix of new features and bug fixes. Notably:
Rules with general refs no longer collide in the recursion check (#6813)
Before, this was a recursion error:
Rules with a variable in their head are all stored at the ground prefix of their ref, so
p[x].foo.barandp[x].foo.bazlooked like dependencies of each other. The compiler isnow less conservative and compares the ref parts past the prefix. Genuine cycles are still
reported.
The IR and Wasm targets however still return an error: they plan one function per ground
path prefix, and cannot evaluate part of a function that is still being planned.
Authored by @sspaink, reported by @tsandall
Data and Query APIs can return rule labels in the response (#9211)
# METADATAlabelsfor evaluated rules were only available in decision logevents. The Data API (
GET/POST /v1/data) and Query API (GET/POST /v1/query) now accept arule_labelsquery parameter to include the samemerged labels in the response payload, under a
rule_labelskey.Authored by @srenatus
Behavior change: response gzip compression now bounds its buffer to
min_length(#9205)The server's gzip response compression (
server.encoding.gzip) buffered an entireincoming
Writecall before deciding whether to compress, so a single large write couldgrow the buffer well past
min_lengthbefore that decision was made. The handler is nowbuilt on
klauspost/compress/gzhttpinstead of a hand-rolled buffer and
gzip.Writerpool, which caps what it buffers tomin_length(floored at 512 bytes) before streaming the remainder through the chosenpath.
min_lengthandcompression_levelbehave the same as before; only gzip isnegotiated, not zstd.
Authored by @srenatus
YAML is now parsed against the 1.2 core schema (#5754, #6598)
OPA parsed YAML with a library pinned to go-yaml v2, which implements YAML 1.1. Under
1.1, the bare words
y,n,yes,no,onandoffresolve to booleans, so aGitHub Actions workflow loaded with
--datacame back withtruewhere it should havehad
on:{ "true": "push" }These words are now plain strings, as the YAML 1.2 core schema specifies.
trueandfalseare unaffected. This applies everywhere OPA reads YAML:--data, bundles,config files, and the
yaml.unmarshalbuiltin.If you were relying on
yes/no/on/offbeing read as booleans, quote the value anduse
true/falseinstead.Authored by @sspaink, reported by @scnewma and @johnc-c
Empty composite literals are now typed as empty (#7275)
The type checker used to give the empty object literal
{}the typeobject[any: any], the empty array literal[]the typearray[any], and theempty set literal
set()the typeset[any], i.e. the types of a collectionthat may hold anything. Every other literal is typed by its contents, so
referencing a key that isn't there is caught at compile time — but only for
non-empty literals:
Empty literals are now typed as what they are: an object with no properties, an
array with no items, and a set with no members. Both examples above now fail to
compile, and so does every other way of selecting from an empty literal,
including iterating one (
some x in []).Comparing an empty object or array literal against a value whose type says it
can't be empty (
{"foo": "bar"} == {}) is now a match error too, the same way{"foo": "bar"} == {"bar": "foo"}already was. Usecount(x) == 0to test acollection for emptiness without asserting its type. Sets are unaffected here:
set[string]describes any set of strings, the empty one included, so{"foo"} == set()still compiles.Authored by @sspaink, reported by @disaverio
Rule indexing improvements
The rule indexer now excludes rules from more kinds of expression, and builds a smaller
trie to do it with. See Use indexed statements
for what is indexed.
startswith,endswith,strings.any_prefix_matchandstrings.any_suffix_matchare indexed when the base strings are known at compile time.
(
data.groups.admins.members[input.subject]) is indexed by asking that object for thekey, where such a ruleset used to leave every rule a candidate.
x := input; x.foo == "a") are indexed thesame as
input.foo == "a", and a chain of assignments no longer drops the constraintat the end of it.
reached by several values no longer leaves the rest of the rule unindexed.
do. A
complete rules must not produce multiple outputserror now points at the firstof the conflicting definitions rather than the second, and partial evaluation names
and orders the generated locals of its support rules differently. What a policy
evaluates to is unaffected.
Changes
Runtime, SDK, Tooling
querystack-trace framing mode (#9128) authored by @johanfyllingrunner.CapturePrintOutputsetting never read (#9104) authored by @anderseknertifbody (#9109) authored by @sspaink, reported by @anderseknertDisableUndefinedOutputsetting (#9185) authored by @anderseknertCompiler, Topdown and Rego
GenericTransformer(#9148) authored by @anderseknertoutputVarsForExprEq(#8302) authored by @zanarellidev, reported by @johanfyllinginoperator against the collection's types (#5658) authored by @sspaink, reported by @anderseknertsemverbuilt-ins (#9004) authored by @sueun-devstrings.replace_n(#9216) authored by @andreaTPDocs, Website, Ecosystem
Miscellaneous
util.MapKeyshelper (#9158) authored by @anderseknerterrors.Ascall sites to useerrors.AsType(#9106) authored by @anderseknertand/orkeywords (#9115) authored by @johanfyllingConfiguration
📅 Schedule: (UTC)
* 0-3 * * *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.