Skip to content

ci(deps): bump github.com/open-policy-agent/opa from 1.19.1 to 1.20.1 - #250

Merged
sonupreetam merged 1 commit into
mainfrom
dependabot/go_modules/github.com/open-policy-agent/opa-1.20.1
Sep 4, 2026
Merged

ci(deps): bump github.com/open-policy-agent/opa from 1.19.1 to 1.20.1#250
sonupreetam merged 1 commit into
mainfrom
dependabot/go_modules/github.com/open-policy-agent/opa-1.20.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 4, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/open-policy-agent/opa from 1.19.1 to 1.20.1.

Release notes

Sourced from github.com/open-policy-agent/opa's releases.

v1.20.1

This release includes a bug fix for a regression introduced in v1.20.0 in comparing a number to some float values. Thanks @​kmadan for reporting the issue and submitting a fix!

v1.20.0

This release contains a mix of new features and bug fixes. Notably:

  • New Rego keywords: and and or, for combining conditions inside a single rule body
  • allow_net now restricts remote JSON Schema $ref fetching from json.match_schema and json.verify_schema
  • Coverage reports can now explain why a range is not covered
  • Much faster partial evaluation for dynamically composed policies

New Rego keywords: and and or (#7602)

Rego gains two keywords for combining conditions inside a single rule body — a long-standing request, and one of the larger additions to the language in some time. and and or let control flow that previously had to be split across helper rules stay where it is read.

Before, a rule body that needed to succeed on one of several conditions meant extracting a rule:

package example
allow if {
input.method == "GET"
admin_or_public_owner
}
admin_or_public_owner if input.user.admin
admin_or_public_owner if {
input.user.owner
input.resource.public
}

Now:

package example
import future.keywords.and
import future.keywords.or
the and groups first, so this reads as:
an admin, or an owner of a public resource
allow if {
input.method == "GET"
</tr></table>

... (truncated)

Changelog

Sourced from github.com/open-policy-agent/opa's changelog.

1.20.1

This release includes a bug fix for a regression introduced in v1.20.0 in comparing a number to some float values. Thanks @​kmadan for reporting the issue and submitting a fix!

1.20.0

This release contains a mix of new features and bug fixes. Notably:

  • New Rego keywords: and and or, for combining conditions inside a single rule body
  • allow_net now restricts remote JSON Schema $ref fetching from json.match_schema and json.verify_schema
  • Coverage reports can now explain why a range is not covered
  • Much faster partial evaluation for dynamically composed policies

New Rego keywords: and and or (#7602)

Rego gains two keywords for combining conditions inside a single rule body — a long-standing request, and one of the larger additions to the language in some time. and and or let control flow that previously had to be split across helper rules stay where it is read.

Before, a rule body that needed to succeed on one of several conditions meant extracting a rule:

package example
allow if {
input.method == "GET"
admin_or_public_owner
}
admin_or_public_owner if input.user.admin
admin_or_public_owner if {
input.user.owner
input.resource.public
}

Now:

package example
import future.keywords.and
import future.keywords.or
the and groups first, so this reads as:
an admin, or an owner of a public resource
allow if {
</tr></table>

... (truncated)

Commits
  • 72f30d6 Prepare v1.20.1 release
  • ceb4bf2 ast: fix panic comparing a decimal zero with a non-integral number (#9099)
  • 328ca09 Prepare v1.20.0 release (#9095)
  • ce7ab30 Add Scanara to the OPA ecosystem page. (#9094)
  • cbc0993 ast: Index rules with and/or expressions (#9063)
  • 54bf329 fix loading absolute paths on Windows (#9055)
  • 48310c6 format: Honor line breaks before explicit and/or operand bodies (#9086)
  • a3953de build/release: Create new release tool (#8959)
  • ec9536c format: converge object comprehension layout (#9076)
  • 255adec ast: Fix future.keywords wildcard import not including the not keyword (#...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa) from 1.19.1 to 1.20.1.
- [Release notes](https://github.com/open-policy-agent/opa/releases)
- [Changelog](https://github.com/open-policy-agent/opa/blob/main/CHANGELOG.md)
- [Commits](open-policy-agent/opa@v1.19.1...v1.20.1)

---
updated-dependencies:
- dependency-name: github.com/open-policy-agent/opa
  dependency-version: 1.20.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 4, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 4, 2026 01:54
@github-actions

github-actions Bot commented Sep 4, 2026

Copy link
Copy Markdown

CRAP Load Analysis

No Go code changes detected in this PR. No CRAP impact.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automatically approved: risk=medium, review=success, ownership=third-party, release_age=162h.

@github-actions

github-actions Bot commented Sep 4, 2026

Copy link
Copy Markdown

🤖 Standardized Dependabot Review Summary 🤖

This PR was processed by the organization's reusable CI pipeline.

Criterion Status Detail
Dependencies Review success View logs
Calculated Risk medium github.com/open-policy-agent/opa v1.20.1
Release Age 162h Released 162 hours ago
Ownership third-party External dependency
Dependency Usage 7 repos Informational only — does not affect approval

Auto-approval: ✅ Approved


Maintainer check list:

  1. Ensure the PR passed all CI tests (required status checks).
  2. Investigate failures for Major updates or any manual review requirement.
  3. Don't overlook breaking changes and changelog information.
  4. If the scorecard value is low, consider to contribute to make it higher. Everybody wins!
  5. Be diligent. When in doubt, ask another maintainer for additional review.

@sonupreetam sonupreetam left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@sonupreetam
sonupreetam merged commit a048bea into main Sep 4, 2026
15 checks passed
@sonupreetam
sonupreetam deleted the dependabot/go_modules/github.com/open-policy-agent/opa-1.20.1 branch September 4, 2026 08:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants