-
Notifications
You must be signed in to change notification settings - Fork 10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(deps): update module github.com/open-policy-agent/opa to v0.61.0 - autoclosed #118
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.50.0
Update module github.com/open-policy-agent/opa to v0.50.1
Mar 16, 2023
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
2 times, most recently
from
March 21, 2023 15:18
edf7f3e
to
0c4d9c9
Compare
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.50.1
Update module github.com/open-policy-agent/opa to v0.50.2
Mar 21, 2023
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.50.2
Update module github.com/open-policy-agent/opa to v0.51.0
Mar 31, 2023
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
from
March 31, 2023 15:21
0c4d9c9
to
b48d1b7
Compare
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
from
April 27, 2023 21:18
b48d1b7
to
47f0e6c
Compare
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.51.0
Update module github.com/open-policy-agent/opa to v0.52.0
Apr 27, 2023
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
from
May 28, 2023 11:08
47f0e6c
to
98babda
Compare
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.52.0
Update module github.com/open-policy-agent/opa to v0.53.0
May 28, 2023
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
from
June 6, 2023 09:11
98babda
to
9252ffe
Compare
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.53.0
Update module github.com/open-policy-agent/opa to v0.53.1
Jun 6, 2023
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
from
June 29, 2023 20:43
9252ffe
to
2714657
Compare
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.53.1
Update module github.com/open-policy-agent/opa to v0.54.0
Jun 29, 2023
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.54.0
Update module github.com/open-policy-agent/opa to v0.55.0
Jul 27, 2023
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
from
July 27, 2023 21:23
2714657
to
295b94d
Compare
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
from
August 31, 2023 15:22
295b94d
to
8e1818b
Compare
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.55.0
Update module github.com/open-policy-agent/opa to v0.56.0
Aug 31, 2023
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.56.0
Update module github.com/open-policy-agent/opa to v0.57.0
Sep 28, 2023
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
from
September 28, 2023 14:46
8e1818b
to
73afb51
Compare
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.57.0
Update module github.com/open-policy-agent/opa to v0.57.1
Oct 18, 2023
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
from
October 18, 2023 10:50
73afb51
to
32e2d48
Compare
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
from
October 27, 2023 01:44
32e2d48
to
df5e562
Compare
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.57.1
Update module github.com/open-policy-agent/opa to v0.58.0
Oct 27, 2023
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
from
November 30, 2023 16:41
df5e562
to
c7657a6
Compare
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.58.0
Update module github.com/open-policy-agent/opa to v0.59.0
Nov 30, 2023
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
2 times, most recently
from
December 21, 2023 01:53
d0c0d89
to
3b0e891
Compare
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.59.0
Update module github.com/open-policy-agent/opa to v0.60.0
Dec 21, 2023
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
from
January 25, 2024 14:28
3b0e891
to
ed2bc92
Compare
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.60.0
Update module github.com/open-policy-agent/opa to v0.61.0
Jan 25, 2024
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
from
February 5, 2024 06:59
ed2bc92
to
2f41c5d
Compare
renovate
bot
force-pushed
the
renovate/github.com-open-policy-agent-opa-0.x
branch
from
February 5, 2024 07:43
2f41c5d
to
9ef21b8
Compare
renovate
bot
changed the title
Update module github.com/open-policy-agent/opa to v0.61.0
fix(deps): update module github.com/open-policy-agent/opa to v0.61.0
Feb 5, 2024
renovate
bot
changed the title
fix(deps): update module github.com/open-policy-agent/opa to v0.61.0
fix(deps): update module github.com/open-policy-agent/opa to v0.61.0 - autoclosed
Feb 5, 2024
renovate
bot
deleted the
renovate/github.com-open-policy-agent-opa-0.x
branch
February 5, 2024 07:58
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.49.2
->v0.61.0
Release Notes
open-policy-agent/opa (github.com/open-policy-agent/opa)
v0.61.0
Compare Source
This release contains a mix of new features and bugfixes.
Runtime, SDK
--v1-compatible
flag to all previously unsupported command line commands (#6520) authored by @johanfyllingsize_limit_bytes
(#6514) authored by @anderseknert reported by @dolevfTopdown
http.send
cache entries periodically (#5320) authored by @rudrakhp reported by @lukyerDocs
Miscellaneous
v0.60.0
Compare Source
v0.60.0
Runtime, Tooling, SDK
--v1-compatible
flag. When this mode is enabled, the current release of OPA will behave as OPAv1.0
will eventually behave by default. This flag is currently supported on thebuild
,check
,fmt
,eval
andtest
commands (#6478) authored by @johanfyllingopa fmt
where the assignment operator and term in the rule head of chain rules are removed from the re-written rule head (#6467) authored by @anderseknertdiff
tool with an external golang library function (#6284) authored by @colinjlacyTopdown and Rego
providers.aws.sign_req
builtin command (#6456) authored by @c2zwdjnlcgDocs
sprintf
builtin command when used with the%T
marker (#6487) authored by @lcarvaWebsite + Ecosystem
Miscellaneous
Makefile
to allow customGOFLAGS
to be provided to the golang executable (#6458) authored by @cova-fev0.59.0
Compare Source
v0.59.0
This release adds tooling to help prepare existing policies for the upcoming OPA 1.0 release.
It also contains a mix of improvements, bugfixes and security fixes for third-party libraries.
Rego v1
The upcoming release of OPA 1.0, which will be released at a future date, will introduce breaking changes to the Rego language. Most notably:
import future.keywords
into a module before use will be part of the Rego language by default, without the need to first import them.if
keyword will be required before the body of a rule.contains
keyword will be required when declaring a multi-value rule (partial set rule).This current release (
0.59.0
) introduces a new--rego-v1
flag to theopa fmt
andopa check
commands to facilitate the transition of existing policies to be compatible with the 1.0 syntax.When used with
opa fmt
, the--rego-v1
flag will format the module(s) according to the new Rego syntax in OPA 1.0.Formatted modules are compatible with both the current version of OPA and 1.0.
Modules using deprecated built-ins will terminate formatting with an error. Future versions of OPA will support rewriting applicable function calls with equivalent Rego compatible with 1.0.
When used with
opa check
, the--rego-v1
flag will check that the modules are compatible with both the current version of OPA and 1.0.Relevant Changes
--rego-v1
flag tocheck
cmd (#6429) authored by @johanfyllingopa fmt
(#6297) authored by @johanfyllingrego.v1
import (#6375) (authored by @johanfylling)rego.v1
) (#6356) authored by @ashutosh-narkarrego.v1
import (#6247) introduced in OPA 0.58.0, authored by @johanfyllingRuntime, Tooling, SDK
rule_head_refs
capabilities feature flag (#6334) authored by @johanfyllingTopdown and Rego
strings.render_template
to render templated strings (#6371) authored by @RDVasavadaMiscellaneous
v0.58.0
Compare Source
This release contains a mix of performance improvements, bugfixes and security fixes for third-party libraries.
Runtime, Tooling, SDK
= true
as it is implied (#6323) authored by @anderseknertv0.23.0
(#2266) authored by @ashutosh-narkarhttp_request_duration_seconds
metric (#6238) authored by @AdrianArnautuTopdown and Rego
walk
-ing (#6267) authored by @anderseknertDocs
/
) or other special characters (#6264) authored by @dennisgWebsite + Ecosystem
Miscellaneous
hub
tool in GitHub workflows in favor of GitHub CLI tool (#6326) authored by @ashutosh-narkarv0.57.1
Compare Source
This is a bug fix release addressing the following security issues:
Golang security fix GO-2023-2102
OpenTelemetry-Go Contrib security fix CVE-2023-45142
v0.57.0
Compare Source
This release contains an updated Rego syntax to allow general references in rule heads, and a mix of new features and bugfixes.
Support for General References in Rule Heads
In OPA
0.56.0
, we introduced support for general references in rule heads as an experimental feature.It has now graduated to a fully supported feature, and is no longer experimental.
A general reference is a reference with variables at arbitrary locations.
In Rego, partial rules are used for generating sets and objects.
In previous versions of OPA, variables were only allowed in the very last position in the rule's reference.
Now, Rego has been expanded to allow rules to be declared with general references in their head, with variables at arbitrary locations.
This allows for generating nested dynamic object structures:
See the documentation for more information.
Authored by @johanfylling.
Runtime, Tooling, SDK
Topdown and Rego
Miscellaneous
Breaking Changes
GO SDK: the
ast.JSONOptions
struct has changed location toast.json.Options
.v0.56.0
Compare Source
This release contains a mix of new features, bugfixes and a new builtin function.
Support for General References in Rule Heads (Experimental)
A new experimental feature in OPA is support for general refs in rule heads. Where a general ref is a reference with variables at arbitrary locations.
General refs are currently not supported by the OPA planner, making this feature unsupported for Wasm and IR.
Note: this feature is disabled by default, and needs to be enabled by setting the
EXPERIMENTAL_GENERAL_RULE_REFS
environment variable (once the feature is complete - supports Wasm and IR - this requirement will be dropped).Authored by @johanfylling.
New Built-In Function:
numbers.range_step
Similar to the
numbers.range
built-in function,numbers.range_step
returns an array of numbers in a given range. The new built-in function also allows you to control the step between each entry.See the documentation on the new built-in
for all the details.
Authored by @sspaink.
New Ecosystem page on The Website
The OPA Ecosystem of related integrations has been refreshed and moved to a more prominent location on the website.
If you're interested to add any new integrations you've been working on, please see the docs here (updates to existing integrations are very welcome too!).
Runtime, Tooling, SDK
opa test -z
fail with failing tests (#6126) authored by @fdaguinopa test
--ignore
when used together with--bundle
(#6185) authored by @joaobrandt--fail-non-empty
flag toopa exec
(#6153) authored by @Ronnie-personalopa_no_oci
flag to build without containerd (#6159) authored by @slonkaTopdown and Rego
Miscellaneous
Breaking changes
Since its introduction in 0.34.0, the
--exit-zero-on-skipped
option always made theopa test
command return an exit code 0. When used, it now returns the exit code 0 only if no failed tests were found.Test runs on existing projects using
--exit-zero-on-skipped
will fail if any failed tests were inhibited by this behavior.v0.55.0
Compare Source
This release contains a mix of new features, bugfixes and a new builtin function.
Honor
default
keyword on functionsPreviously if a function was defined with a
default
value, OPA would ignore it. Now thedefault
function is honoredif all functions with the same name are undefined. For example,
The value of a
default
function follows the same conditions as that of adefault
rule. In addition, adefault
function satisfies the following properties:
Authored by @ashutosh-narkar.
New Built-In Function: crypto.parse_private_keys
crypto.parse_private_keys
returns zero or more private keys from the given encoded string containing DER certificate data.If the input contains a list of one or more concatenated PEM blocks, then the built-in will output the parsed private keys
represented as objects.
See the documentation on the new built-in
for all the details.
Authored by @volck.
Runtime, Tooling, SDK
discard
output format toopa eval
which discards the result while still showing the output of eval flags like--profile
(#6103) authored by @26tanishabanikTopdown and Rego
WithRoots
compiler option that allows callers to set the roots to include in the output bundle manifest (#6088) authored by @kubajDocs
Website + Ecosystem
Ecosystem:
Website:
Miscellaneous
CRLF
line terminations in the patch output (#6069) authored by @johanfyllingv0.54.0
Compare Source
This release focuses on bug fixes, but also includes some improvements to the SDK and commandline.
Note: This will be the last OPA release to support building with Golang 1.18. (Golang 1.21 is expected to be released in August. Keeping the support for 1.18 is blocking OPA from upgrading OpenTelemetry.)
Topdown and Rego
lazyObj
when compared against other object type (6060) (authored by @johanfylling)fmt
panic in comprehension with comments (#5798) authored by @Trolloldem reported by @Djoustobject.union_n
where nested objects were mutated (#5975) authored by @qshu-splunkobject.subset
method failing to correctly compare array relationships (5968) authored by @DCRUNNNhttp.send
(#5997) authored by @ashutosh-narkartime.format
andtime.parse_ns
(#5945) authored by @tjonsRuntime, Tooling, SDK
--schema
flag toopa test
(#5923) authored by @renatoscpersistence_directory
config (#6042) authored by @blacksailstzdata
is not found on filesystem (6038) authored by @charlieegan3Store
implementation in SDK (5962) authored by @srenatus/v1/config
API result (6056) authored by @srenatusMiscellaneous
v0.53.1
Compare Source
This is a bug fix release addressing the following issues:
Runtime, Tooling, SDK
WWW-Authenticate
header of a401 Unauthorized
response. Errors were returned when downloading a public image as it was assumed that authorization is not necessary for public repositories. This fix addresses this issue by challenging any401 Unauthorized
responses by passing it to the docker.Authorizer (#5902) authored by @DerGutopa fmt
: Fix panic encountered while processing policies with comprehensions written on multiple lines with comments in these lines (#5798) authored by @TrolloldemTopdown and Rego
object.subset
: Fix an issue inobject.subset
related to incorrect results being generated when arrays are provided as an input (#5968) authored by @DCRUNNNv0.53.0
Compare Source
This release contains some enhancements, bugfixes, and a new builtin function.
Runtime, Tooling, SDK
opa eval
: Update OPA eval's--profile-sort
flag description to highlight the valid options to sort the profile results (#5924) authored by @ecbenezraopa fmt
: Fix cases in which invalid code was generated due to parentheses being improperly handled (#5537) authored by @Trolloldemloader
package that provide ability to register handlers for certain file extensions. This feature is currently EXPERIMENTAL (#5940) authored by @srenatusTopdown and Rego
crypto.x509.parse_keypair
: Returns a key pair from a pair of PEM or base64 encoded strings of data. See the documentation on the new built-in for all the details. (#5853) authored by @volck.io.jwt.decode_verify
: Fix issue where token verification succeeded in case whereiss
constraint was required but JWT did not contain it (#5850) authored by @AleksanderBrzozowskihttp.send
: Add a new option to thehttp.send
input object which allows policy authors to specify a retry count for executing a HTTP request. Retries are performed with an exponential backoff delay (#5891) authored by @ashutosh-narkar_
matching only scalars in rule indexing for arrays (#5916) authored by @jaspervdjMiscellaneous
v0.52.0
Compare Source
This release contains some enhancements, bugfixes, and a new builtin function.
Allow Adding Labels via Discovery
Previously OPA did not allow any updates to the labels provided in the boot configuration via the discovered (ie. service)
config. This was done to avoid breaking the discovery configuration. But there are use cases where labels can serve as a convenient
way to pass information that could be used in policies, status updates or decision logs. This change allows
additional labels to be configured in the service config which are then made available during runtime.
See the Discovery documentation for more details.
Authored by @mjungsbluth.
New Built-In Function: crypto.hmac.equal
crypto.hmac.equal
provides a convenieConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.