Sourced from github.com/open-policy-agent/opa's releases.
v1.18.1
This release fixes a memory leak introduced in OPA v1.17.0. It is advised to update if you notice excess memory usage when running OPA server.
Fixes
- ast: fix AnnotationSet memory leak via runtime.AddCleanup cycle (#8817) authored by
@srenatusreported by@keydonand@gorsr01v1.18.0
This release contains a mix of bugfixes and small features. Notably:
- A breaking fix to the outbound
User-Agentheader so it conforms to RFC 9110 (see below)- Container-aware resource limits: automatic
GOMAXPROCSis restored and automaticGOMEMLIMITis now supported- Several
opa fmtcorrectness fixes- Improvements to
opa test --coverage(ranges in report, inline rule head tracking, conjunction-expression coverage)Breaking: Fix User-Agent according to RFC9110 (#8792)
OPA's outbound HTTP requests (bundle, discovery, decision log, status,
http.send, AWS KMS/ECR) previously sentUser-Agent: Open Policy Agent/<version> (<os>, <arch>), which is not a valid RFC 9110User-Agentvalue because theproducttoken cannot contain spaces. The header is nowOpen-Policy-Agent/<version> (<os>, <arch>). Server-side log filters or WAF rules that exact-match the old string will need to be updated.Authored by
@sspaink, reported by@SpecLadRuntime, SDK, Tooling
- bundle: fix per-module rego version lookup (#8797) authored by
@sspaink, reported by@xubinzheng- bundle: improve determinism of
file_rego_versionspatterns with overlap (#8733) authored by@philipaconrad- cover: Track inline rule head in post trace walk (#6531) authored by
@charlieegan3, reported by@anderseknert- cover: Update report to include ranges (#8748) reported and authored by
@charlieegan3- cover: Add support for coverage of conjunction exprs (#8809) authored by
@charlieegan3- download/oci: Set Accept headers (#8720) authored by
@charlieegan3- fmt: preserve the multiline but single entry iterables (#8557) authored by
@unichronic, reported by@anderseknert- format: Fix dropped with-clause after comment in object value (#8765) authored by
@sspaink, reported by@srabraham- format: keep lone
withon the closing-bracket line of multi-line expressions (#8804) authored by@anneheartrecord, reported by@burnster- oracle: Fix find-definition on expressions inside
ast.Notnodes (#8731) authored by@johanfylling- runtime: Restore goautomaxprocs, add automemlimit (#8784) authored by
@charlieegan3Compiler, Topdown and Rego
- ast: Apply location to inner
ast.Notexpressions (#8717) authored by@johanfylling, reported by@anderseknert- ast: Clean up code for value comparisons (#8737) authored by
@anderseknert- ast: Fix PE regression for
future.keywords.notnegation insideevery(#8781) authored by@johanfylling- internal/edittree: Add recursive tree node recycling (#8693) authored by
@philipaconrad- internal: compile,planner: improve determinism of
plan/wasmbundle builds (#8732) authored by@philipaconrad- perf: avoid allocations in
object.get(#8729) authored by@anderseknert- topdown: Fix PE not namespacing vars in comprehensions nested inside
every(#8816) authored by@johanfylling- topdown: remove
dst.Compare(src)shortcut (#8739) authored by@srenatus
... (truncated)
Sourced from github.com/open-policy-agent/opa's changelog.
Change Log
All notable changes to this project will be documented in this file. This project adheres to Semantic Versioning.
Unreleased
1.18.0
This release contains a mix of bugfixes and small features. Notably:
- A breaking fix to the outbound
User-Agentheader so it conforms to RFC 9110 (see below)- Container-aware resource limits: automatic
GOMAXPROCSis restored and automaticGOMEMLIMITis now supported- Several
opa fmtcorrectness fixes- Improvements to
opa test --coverage(ranges in report, inline rule head tracking, conjunction-expression coverage)Breaking: Fix User-Agent according to RFC9110 (#8792)
OPA's outbound HTTP requests (bundle, discovery, decision log, status,
http.send, AWS KMS/ECR) previously sentUser-Agent: Open Policy Agent/<version> (<os>, <arch>), which is not a valid RFC 9110User-Agentvalue because theproducttoken cannot contain spaces. The header is nowOpen-Policy-Agent/<version> (<os>, <arch>). Server-side log filters or WAF rules that exact-match the old string will need to be updated.Authored by
@sspaink, reported by@SpecLadRuntime, SDK, Tooling
- bundle: fix per-module rego version lookup (#8797) authored by
@sspaink, reported by@xubinzheng- bundle: improve determinism of
file_rego_versionspatterns with overlap (#8733) authored by@philipaconrad- cover: Track inline rule head in post trace walk (#6531) authored by
@charlieegan3, reported by@anderseknert- cover: Update report to include ranges (#8748) reported and authored by
@charlieegan3- cover: Add support for coverage of conjunction exprs (#8809) authored by
@charlieegan3- download/oci: Set Accept headers (#8720) authored by
@charlieegan3- fmt: preserve the multiline but single entry iterables (#8557) authored by
@unichronic, reported by@anderseknert- format: Fix dropped with-clause after comment in object value (#8765) authored by
@sspaink, reported by@srabraham- format: keep lone
withon the closing-bracket line of multi-line expressions (#8804) authored by@anneheartrecord, reported by@burnster- oracle: Fix find-definition on expressions inside
ast.Notnodes (#8731) authored by@johanfylling- runtime: Restore goautomaxprocs, add automemlimit (#8784) authored by
@charlieegan3Compiler, Topdown and Rego
- ast: Apply location to inner
ast.Notexpressions (#8717) authored by@johanfylling, reported by@anderseknert- ast: Clean up code for value comparisons (#8737) authored by
@anderseknert- ast: Fix PE regression for
future.keywords.notnegation insideevery(#8781) authored by@johanfylling- internal/edittree: Add recursive tree node recycling (#8693) authored by
@philipaconrad- internal: compile,planner: improve determinism of
plan/wasmbundle builds (#8732) authored by@philipaconrad- perf: avoid allocations in
object.get(#8729) authored by@anderseknert- topdown: Fix PE not namespacing vars in comprehensions nested inside
every(#8816) authored by@johanfylling- topdown: remove
dst.Compare(src)shortcut (#8739) authored by@srenatus
... (truncated)
acc8bf9
Release v1.18.1713dc6a
ast: fix AnnotationSet memory leak via runtime.AddCleanup cyclecc2c5c6
Prepare v1.18 release (#8820)e72a98f
format: keep lone with on the closing-bracket line of
multi-line expression...03646dd
topdown: Fix PE not namespacing vars in comprehensions nested inside
every ...bf2bb52
benchmarks: split off script, emit markdown table02ce276
version: fix ill-formed User-Agent header (#8796)1fdbb77
build(deps): bump the dependencies group across 2 directories with 6
updates954196a
cover: Add support for coverage of conjunction exprs (#8809)dec8333
deduplicate change-detection output in pr CI checks (#8808)