Commit 25f3310
authored
fix(deps): update module github.com/open-policy-agent/opa to v1.18.1 (8.19) (#7089)
This PR contains the following updates:
| Package | Change | Age | Confidence |
|---|---|---|---|
|
[github.com/open-policy-agent/opa](https://redirect.github.com/open-policy-agent/opa)
| `v1.17.1` -> `v1.18.1` |
[](https://docs.renovatebot.com/merge-confidence/)
|
[](https://docs.renovatebot.com/merge-confidence/)
|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.
---
### Release Notes
<details>
<summary>open-policy-agent/opa
(github.com/open-policy-agent/opa)</summary>
###
[`v1.18.1`](https://redirect.github.com/open-policy-agent/opa/releases/tag/v1.18.1)
[Compare
Source](https://redirect.github.com/open-policy-agent/opa/compare/v1.18.0...v1.18.1)
This release fixes a memory leak introduced in OPA v1.17.0. It is
advised to update if you notice excess memory usage when running OPA
server.
##### Fixes
- ast: fix AnnotationSet memory leak via runtime.AddCleanup cycle
([#​8817](https://redirect.github.com/open-policy-agent/opa/issues/8817))
authored by [@​srenatus](https://redirect.github.com/srenatus)
reported by [@​keydon](https://redirect.github.com/keydon) and
[@​gorsr01](https://redirect.github.com/gorsr01)
###
[`v1.18.0`](https://redirect.github.com/open-policy-agent/opa/releases/tag/v1.18.0)
[Compare
Source](https://redirect.github.com/open-policy-agent/opa/compare/v1.17.1...v1.18.0)
This release contains a mix of bugfixes and small features. Notably:
- A breaking fix to the outbound `User-Agent` header so it conforms to
RFC 9110 (see below)
- Container-aware resource limits: automatic `GOMAXPROCS` is restored
and automatic `GOMEMLIMIT` is now supported
- Several `opa fmt` correctness fixes
- Improvements to `opa test --coverage` (ranges in report, inline rule
head tracking, conjunction-expression coverage)
##### Breaking: Fix User-Agent according to RFC9110
([#​8792](https://redirect.github.com/open-policy-agent/opa/issues/8792))
OPA's outbound HTTP requests (bundle, discovery, decision log, status,
`http.send`, AWS KMS/ECR)
previously sent `User-Agent: Open Policy Agent/<version> (<os>,
<arch>)`, which is not a valid
RFC 9110 `User-Agent` value because the `product` token cannot contain
spaces. The header is now
`Open-Policy-Agent/<version> (<os>, <arch>)`. Server-side log filters or
WAF rules that
exact-match the old string will need to be updated.
Authored by [@​sspaink](https://redirect.github.com/sspaink),
reported by [@​SpecLad](https://redirect.github.com/SpecLad)
##### Runtime, SDK, Tooling
- bundle: fix per-module rego version lookup
([#​8797](https://redirect.github.com/open-policy-agent/opa/issues/8797))
authored by [@​sspaink](https://redirect.github.com/sspaink),
reported by [@​xubinzheng](https://redirect.github.com/xubinzheng)
- bundle: improve determinism of `file_rego_versions` patterns with
overlap
([#​8733](https://redirect.github.com/open-policy-agent/opa/pull/8733))
authored by
[@​philipaconrad](https://redirect.github.com/philipaconrad)
- cover: Track inline rule head in post trace walk
([#​6531](https://redirect.github.com/open-policy-agent/opa/issues/6531))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3),
reported by
[@​anderseknert](https://redirect.github.com/anderseknert)
- cover: Update report to include ranges
([#​8748](https://redirect.github.com/open-policy-agent/opa/issues/8748))
reported and authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- cover: Add support for coverage of conjunction exprs
([#​8809](https://redirect.github.com/open-policy-agent/opa/pull/8809))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- download/oci: Set Accept headers
([#​8720](https://redirect.github.com/open-policy-agent/opa/pull/8720))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- fmt: preserve the multiline but single entry iterables
([#​8557](https://redirect.github.com/open-policy-agent/opa/issues/8557))
authored by
[@​unichronic](https://redirect.github.com/unichronic), reported
by [@​anderseknert](https://redirect.github.com/anderseknert)
- format: Fix dropped with-clause after comment in object value
([#​8765](https://redirect.github.com/open-policy-agent/opa/issues/8765))
authored by [@​sspaink](https://redirect.github.com/sspaink),
reported by [@​srabraham](https://redirect.github.com/srabraham)
- format: keep lone `with` on the closing-bracket line of multi-line
expressions
([#​8804](https://redirect.github.com/open-policy-agent/opa/issues/8804))
authored by
[@​anneheartrecord](https://redirect.github.com/anneheartrecord),
reported by [@​burnster](https://redirect.github.com/burnster)
- oracle: Fix find-definition on expressions inside `ast.Not` nodes
([#​8731](https://redirect.github.com/open-policy-agent/opa/pull/8731))
authored by
[@​johanfylling](https://redirect.github.com/johanfylling)
- runtime: Restore goautomaxprocs, add automemlimit
([#​8784](https://redirect.github.com/open-policy-agent/opa/pull/8784))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
##### Compiler, Topdown and Rego
- ast: Apply location to inner `ast.Not` expressions
([#​8717](https://redirect.github.com/open-policy-agent/opa/issues/8717))
authored by
[@​johanfylling](https://redirect.github.com/johanfylling),
reported by
[@​anderseknert](https://redirect.github.com/anderseknert)
- ast: Clean up code for value comparisons
([#​8737](https://redirect.github.com/open-policy-agent/opa/pull/8737))
authored by
[@​anderseknert](https://redirect.github.com/anderseknert)
- ast: Fix PE regression for `future.keywords.not` negation inside
`every`
([#​8781](https://redirect.github.com/open-policy-agent/opa/pull/8781))
authored by
[@​johanfylling](https://redirect.github.com/johanfylling)
- internal/edittree: Add recursive tree node recycling
([#​8693](https://redirect.github.com/open-policy-agent/opa/pull/8693))
authored by
[@​philipaconrad](https://redirect.github.com/philipaconrad)
- internal: compile,planner: improve determinism of `plan`/`wasm` bundle
builds
([#​8732](https://redirect.github.com/open-policy-agent/opa/pull/8732))
authored by
[@​philipaconrad](https://redirect.github.com/philipaconrad)
- perf: avoid allocations in `object.get`
([#​8729](https://redirect.github.com/open-policy-agent/opa/pull/8729))
authored by
[@​anderseknert](https://redirect.github.com/anderseknert)
- topdown: Fix PE not namespacing vars in comprehensions nested inside
`every`
([#​8816](https://redirect.github.com/open-policy-agent/opa/pull/8816))
authored by
[@​johanfylling](https://redirect.github.com/johanfylling)
- topdown: remove `dst.Compare(src)` shortcut
([#​8739](https://redirect.github.com/open-policy-agent/opa/pull/8739))
authored by [@​srenatus](https://redirect.github.com/srenatus)
- topdown: skip strconv.ParseInt in format\_int base-10 fast path
([#​8801](https://redirect.github.com/open-policy-agent/opa/pull/8801))
authored by [@​srenatus](https://redirect.github.com/srenatus)
##### Docs, Website, Ecosystem
- docs/chore: Remove broken links
([#​8714](https://redirect.github.com/open-policy-agent/opa/issues/8714))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3),
reported by
[@​github-actions](https://redirect.github.com/github-actions)
- docs: PoC for kapa.ai
([#​8125](https://redirect.github.com/open-policy-agent/opa/issues/8125))
reported and authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- docs(ecosystem): update OPA MCP entry with video, blog, and
distribution links
([#​8712](https://redirect.github.com/open-policy-agent/opa/pull/8712))
authored by [@​OrygnsCode](https://redirect.github.com/OrygnsCode)
- docs/contributing: add formatting
([#​8740](https://redirect.github.com/open-policy-agent/opa/pull/8740))
authored by [@​mmzzuu](https://redirect.github.com/mmzzuu)
- docs: Add SDK references for evaluating IR plans
([#​8783](https://redirect.github.com/open-policy-agent/opa/pull/8783))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- docs: Add depkeep to enterprise support
([#​8685](https://redirect.github.com/open-policy-agent/opa/pull/8685))
authored by [@​pkuzco](https://redirect.github.com/pkuzco)
- docs: Add notes about use of GOMEMLIMIT
([#​8771](https://redirect.github.com/open-policy-agent/opa/pull/8771))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- docs: Add we/our/us check to spell check
([#​8787](https://redirect.github.com/open-policy-agent/opa/pull/8787))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- docs: Update built-in index page titles
([#​8728](https://redirect.github.com/open-policy-agent/opa/pull/8728))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- docs: Update documentation to be more consistent and sound more like
reference docs
([#​8786](https://redirect.github.com/open-policy-agent/opa/pull/8786))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- docs: Update regal docs for 0.41.1 release
([#​8730](https://redirect.github.com/open-policy-agent/opa/pull/8730))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- docs: Update to agents.md regarding security dependences 'fixes'
([#​8754](https://redirect.github.com/open-policy-agent/opa/pull/8754))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- docs: clarify environment variable substitution behaviour
([#​8713](https://redirect.github.com/open-policy-agent/opa/pull/8713))
authored by [@​taurelius](https://redirect.github.com/taurelius)
- docs: remove duplicated word in Rego style guide
([#​8800](https://redirect.github.com/open-policy-agent/opa/pull/8800))
authored by [@​s3onghyun](https://redirect.github.com/s3onghyun)
- website: Add .md alternate content types for llms
([#​8725](https://redirect.github.com/open-policy-agent/opa/pull/8725))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- website: Add support page disclaimer and sort by date added
([#​8736](https://redirect.github.com/open-policy-agent/opa/pull/8736))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- website: Fix build from missing dateAdded
([#​8764](https://redirect.github.com/open-policy-agent/opa/pull/8764))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- website: Update docusaurus
([#​8756](https://redirect.github.com/open-policy-agent/opa/pull/8756))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- website: Update homepage AI example to tool calls
([#​8755](https://redirect.github.com/open-policy-agent/opa/pull/8755))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- website: Various updates to node and website deps
([#​8768](https://redirect.github.com/open-policy-agent/opa/pull/8768))
authored by
[@​charlieegan3](https://redirect.github.com/charlieegan3)
- website: add ossrisk to ecosystem
([#​8780](https://redirect.github.com/open-policy-agent/opa/pull/8780))
authored by [@​pkuzco](https://redirect.github.com/pkuzco)
##### Miscellaneous
- benchmarks: smaller tweaks
([#​8759](https://redirect.github.com/open-policy-agent/opa/pull/8759))
authored by [@​srenatus](https://redirect.github.com/srenatus)
- benchmarks: split off script, emit markdown table
([#​8812](https://redirect.github.com/open-policy-agent/opa/pull/8812))
authored by [@​srenatus](https://redirect.github.com/srenatus)
- benchmarks: use details+summary comments for benchlab results
([#​8811](https://redirect.github.com/open-policy-agent/opa/pull/8811))
authored by [@​srenatus](https://redirect.github.com/srenatus)
- capabilities: Integrate 1.17.1 patch release
([#​8798](https://redirect.github.com/open-policy-agent/opa/pull/8798))
authored by [@​sspaink](https://redirect.github.com/sspaink)
- chore: tidy go.mod to remove untagged versions
([#​8791](https://redirect.github.com/open-policy-agent/opa/pull/8791))
authored by [@​thaJeztah](https://redirect.github.com/thaJeztah)
- e2e: Add proto schemas for the IR plan and bundle manifest
([#​8766](https://redirect.github.com/open-policy-agent/opa/issues/8766))
reported and authored by
[@​sspaink](https://redirect.github.com/sspaink)
- gha: deduplicate change-detection output in pr CI checks
([#​8808](https://redirect.github.com/open-policy-agent/opa/pull/8808))
authored by [@​sspaink](https://redirect.github.com/sspaink)
- nightly: use regal\@​main
([#​8735](https://redirect.github.com/open-policy-agent/opa/pull/8735))
authored by [@​srenatus](https://redirect.github.com/srenatus)
- workflow: remove tests from docker (edge) image build
([#​8721](https://redirect.github.com/open-policy-agent/opa/pull/8721))
authored by [@​srenatus](https://redirect.github.com/srenatus)
- workflows: bring back docker edge tags for post-merge
([#​8718](https://redirect.github.com/open-policy-agent/opa/pull/8718))
authored by [@​srenatus](https://redirect.github.com/srenatus)
- workflows: use `go-version-file` with `actions/setup-go`
([#​8751](https://redirect.github.com/open-policy-agent/opa/pull/8751))
authored by [@​srenatus](https://redirect.github.com/srenatus)
- Dependency updates; notably:
- build(deps): Add github.com/KimMachineGun/automemlimit v0.7.5
- build(deps): Add go.uber.org/automaxprocs v1.6.0
- build(deps): Bump github.com/dgraph-io/badger/v4 from v4.9.1 to v4.9.2
- build(deps): Bump github.com/vektah/gqlparser/v2 from v2.5.33 to
v2.5.34
- build(deps): Bump go.opentelemetry.io/contrib/bridges/prometheus from
v0.68.0 to v0.69.0
- build(deps): Bump
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp from
v0.68.0 to v0.69.0
- build(deps): Bump go.opentelemetry.io/otel from v1.43.0 to v1.44.0
- build(deps): Bump
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc from
v1.43.0 to v1.44.0
- build(deps): Bump
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp from
v1.43.0 to v1.44.0
- build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlptrace
from v1.43.0 to v1.44.0
- build(deps): Bump
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc from
v1.43.0 to v1.44.0
- build(deps): Bump
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp from
v1.43.0 to v1.44.0
- build(deps): Bump go.opentelemetry.io/otel/sdk from v1.43.0 to v1.44.0
- build(deps): Bump go.opentelemetry.io/otel/sdk/metric from v1.43.0 to
v1.44.0
- build(deps): Bump go.opentelemetry.io/otel/trace from v1.43.0 to
v1.44.0
- build(deps): Bump golang.org/x/sync from v0.20.0 to v0.21.0
- build(deps): Bump golang.org/x/text from v0.37.0 to v0.38.0
- build(deps): Bump google.golang.org/grpc from v1.81.0 to v1.81.1
- build(deps): Bump gopkg.in/ini.v1 from v1.67.2 to v1.67.3
- build(deps): Bump oras.land/oras-go/v2 from v2.6.0 to v2.6.1
- build(deps): bump golang.org/x/crypto to v0.52.0 and golang.org/x/net
to v0.55.0
([#​8745](https://redirect.github.com/open-policy-agent/opa/pull/8745))
authored by [@​BGebken](https://redirect.github.com/BGebken)
- build: bump go 1.26.3 -> 1.26.4
([#​8726](https://redirect.github.com/open-policy-agent/opa/pull/8726))
authored by [@​srenatus](https://redirect.github.com/srenatus)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - Between 01:00 AM and 01:59 AM, Monday
through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MC42Mi4xIiwidXBkYXRlZEluVmVyIjoiNDEuMTczLjEiLCJ0YXJnZXRCcmFuY2giOiI4LjE5IiwibGFiZWxzIjpbIlRlYW06U2VjdXJpdHktQ2xvdWQgU2VydmljZXMiLCJiYWNrcG9ydC1za2lwIiwiZGVwZW5kZW5jaWVzIiwicmVub3ZhdGUiLCJyZW5vdmF0ZS1hdXRvLWFwcHJvdmUiXX0=-->
Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>1 parent 2d2cb45 commit 25f3310
2 files changed
Lines changed: 9 additions & 9 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
69 | 69 | | |
70 | 70 | | |
71 | 71 | | |
72 | | - | |
| 72 | + | |
73 | 73 | | |
74 | 74 | | |
75 | 75 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
390 | 390 | | |
391 | 391 | | |
392 | 392 | | |
393 | | - | |
394 | | - | |
| 393 | + | |
| 394 | + | |
395 | 395 | | |
396 | 396 | | |
397 | 397 | | |
| |||
1063 | 1063 | | |
1064 | 1064 | | |
1065 | 1065 | | |
1066 | | - | |
1067 | | - | |
| 1066 | + | |
| 1067 | + | |
1068 | 1068 | | |
1069 | 1069 | | |
1070 | 1070 | | |
| |||
1135 | 1135 | | |
1136 | 1136 | | |
1137 | 1137 | | |
1138 | | - | |
1139 | | - | |
| 1138 | + | |
| 1139 | + | |
1140 | 1140 | | |
1141 | 1141 | | |
1142 | 1142 | | |
| |||
1426 | 1426 | | |
1427 | 1427 | | |
1428 | 1428 | | |
1429 | | - | |
1430 | | - | |
| 1429 | + | |
| 1430 | + | |
1431 | 1431 | | |
1432 | 1432 | | |
1433 | 1433 | | |
| |||
0 commit comments