Skip to content

fix(deps): update module github.com/open-policy-agent/opa to v1.21.1 (9.4) - #8220

Open
elastic-renovate-prod[bot] wants to merge 1 commit into
9.4from
renovate/9.4-github.com-open-policy-agent-opa-1.x
Open

elastic-renovate-prod[bot] wants to merge 1 commit into
9.4from
renovate/9.4-github.com-open-policy-agent-opa-1.x

Conversation

@elastic-renovate-prod

@elastic-renovate-prod elastic-renovate-prod Bot commented Aug 28, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
github.com/open-policy-agent/opa v1.19.1 → v1.21.1 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

open-policy-agent/opa (github.com/open-policy-agent/opa)

v1.21.1

Compare Source

This release fixes a compiler regression introduced in OPA v1.21.0.

Fix some … in/every in comprehensions nested in object and set literals (#​9280)

A comprehension using some … in or every in its body, nested inside an object or set literal, was wrongly treated as ground, so the compiler skipped rewriting it. some … in then failed with rego_unsafe_var_error; every caused a compiler panic:

package example

p := {"k": [r.a | some r in input.xs]}           # rego_unsafe_var_error: var r is unsafe

q := {[1 | every x in input.xs { x > 0 }]}       # panic

Array literals weren't affected, and neither were literals that contain some other non-ground term.

authored by @​srenatus, reported by @​tun0

v1.21.0

Compare Source

This release contains a mix of new features and bug fixes. Notably:

  • Improved rule indexing
  • Improved rule recursion check
  • YAML is parsed against the 1.2 core schema (breaking change)
Rules with general refs no longer collide in the recursion check (#​6813)

Before, this was a recursion error:

package play

p[x].foo.bar if {
	x := "a"
	not p[x].foo.baz
}

p[x].foo.baz if {
	x := "a"
	false
}

Rules with a variable in their head are all stored at the ground prefix of their ref, so
p[x].foo.bar and p[x].foo.baz looked like dependencies of each other. The compiler is
now less conservative and compares the ref parts past the prefix. Genuine cycles are still
reported.

The IR and Wasm targets however still return an error: they plan one function per ground
path prefix, and cannot evaluate part of a function that is still being planned.

Authored by @​sspaink, reported by @​tsandall

Data and Query APIs can return rule labels in the response (#​9211)

# METADATA labels for evaluated rules were only available in decision log
events. The Data API (GET/POST /v1/data) and Query API (GET/POST /v1/query) now accept a rule_labels query parameter to include the same
merged labels in the response payload, under a rule_labels key.

Authored by @​srenatus

Behavior change: response gzip compression now bounds its buffer to min_length (#​9205)

The server's gzip response compression (server.encoding.gzip) buffered an entire
incoming Write call before deciding whether to compress, so a single large write could
grow the buffer well past min_length before that decision was made. The handler is now
built on klauspost/compress/gzhttp
instead of a hand-rolled buffer and gzip.Writer pool, which caps what it buffers to
min_length (floored at 512 bytes) before streaming the remainder through the chosen
path. min_length and compression_level behave the same as before; only gzip is
negotiated, not zstd.

Authored by @​srenatus

YAML is now parsed against the 1.2 core schema (#​5754, #​6598)

OPA parsed YAML with a library pinned to go-yaml v2, which implements YAML 1.1. Under
1.1, the bare words y, n, yes, no, on and off resolve to booleans, so a
GitHub Actions workflow loaded with --data came back with true where it should have
had on:

on: push
{ "true": "push" }

These words are now plain strings, as the YAML 1.2 core schema specifies. true and
false are unaffected. This applies everywhere OPA reads YAML: --data, bundles,
config files, and the yaml.unmarshal builtin.

If you were relying on yes/no/on/off being read as booleans, quote the value and
use true/false instead.

Authored by @​sspaink, reported by @​scnewma and @​johnc-c

Empty composite literals are now typed as empty (#​7275)

The type checker used to give the empty object literal {} the type
object[any: any], the empty array literal [] the type array[any], and the
empty set literal set() the type set[any], i.e. the types of a collection
that may hold anything. Every other literal is typed by its contents, so
referencing a key that isn't there is caught at compile time — but only for
non-empty literals:

obj := {"foo": "bar"}
obj.bar # rego_type_error: undefined ref: obj.bar

obj := {}
obj.bar # compiles

Empty literals are now typed as what they are: an object with no properties, an
array with no items, and a set with no members. Both examples above now fail to
compile, and so does every other way of selecting from an empty literal,
including iterating one (some x in []).

Comparing an empty object or array literal against a value whose type says it
can't be empty ({"foo": "bar"} == {}) is now a match error too, the same way
{"foo": "bar"} == {"bar": "foo"} already was. Use count(x) == 0 to test a
collection for emptiness without asserting its type. Sets are unaffected here:
set[string] describes any set of strings, the empty one included, so
{"foo"} == set() still compiles.

Authored by @​sspaink, reported by @​disaverio

Rule indexing improvements

The rule indexer now excludes rules from more kinds of expression, and builds a smaller
trie to do it with. See Use indexed statements
for what is indexed.

  • startswith, endswith, strings.any_prefix_match and strings.any_suffix_match
    are indexed when the base strings are known at compile time.
  • A reference that reads a key out of the object at its ground prefix in base data
    (data.groups.admins.members[input.subject]) is indexed by asking that object for the
    key, where such a ruleset used to leave every rule a candidate.
  • References rooted at a local variable (x := input; x.foo == "a") are indexed the
    same as input.foo == "a", and a chain of assignments no longer drops the constraint
    at the end of it.
  • A rule's path through the trie stops at the last level it constrains, and a reference
    reached by several values no longer leaves the rest of the rule unindexed.
  • Candidates come back in declaration order, which the indexer documented but did not
    do. A complete rules must not produce multiple outputs error now points at the first
    of the conflicting definitions rather than the second, and partial evaluation names
    and orders the generated locals of its support rules differently. What a policy
    evaluates to is unaffected.
Changes
Runtime, SDK, Tooling
Compiler, Topdown and Rego
Docs, Website, Ecosystem
Miscellaneous
  • ast: Add util.MapKeys helper (#​9158) authored by @​anderseknert
  • ast: Enable more gocritic linters (#​9154) authored by @​anderseknert
  • ast: Enable unparam linter (#​9223) authored by @​anderseknert
  • ast: More niceties, less allocs, less code (#​9228) authored by @​anderseknert
  • ast: Pin BenchmarkObjectConstruction shuffle seed (#​9222) authored by @​srenatus
  • ast: Update remaining errors.As call sites to use errors.AsType (#​9106) authored by @​anderseknert
  • ast: Use modern Go in place of custom compare code (#​9151) authored by @​anderseknert
  • ast: Where have all the allocs gone? (#​9137) authored by @​anderseknert
  • build: Add bench-nightly, a three-arm benchlab experiment runner (#​9118) authored by @​srenatus
  • build: Pin pigeon in build/tools instead of go run pkg@​version (#​9160) authored by @​sspaink
  • bundle: Avoid allocation in getdepth (#​9199) authored by @​srenatus
  • bundle: Remove unused writeModules helper (#​9199) authored by @​srenatus
  • bundle: Reuse encoder buffer while hashing (#​9199) authored by @​srenatus
  • bundle: deep-copy bundle data natively instead of via JSON round-trip (#​9199) authored by @​srenatus
  • check: Avoid allocating in checkExprEq (#​9150) authored by @​anderseknert
  • ci: Publish benchmark trend on a schedule instead of per-push (#​9119) authored by @​srenatus
  • ci: Run the nightly benchlab experiment (#​9118) authored by @​srenatus
  • cmd: Stop binding a fixed port in the run tests (#​9240) authored by @​srenatus
  • github: Drop python from the CodeQL language matrix (#​9097) authored by @​sspaink
  • nightly: Fix go get smoke test (#​9245) authored by @​srenatus
  • perf: Cheaper custom function calls (#​9167) authored by @​anderseknert
  • perf: Fix linear runtime for Array.set due to rehashing (#​9161) authored by @​tsandall
  • perf: General performance improvements in compiler (#​9170) authored by @​anderseknert
  • style: Some more functional niceties (#​9152) authored by @​anderseknert
  • test/e2e: Wait for diagnostic listeners before running tests (#​9134) authored by @​sspaink
  • tests: Expanded testing for and/or keywords (#​9115) authored by @​johanfylling
  • topdown: Fix BulkStartsWith benchmark input generation (#​9222) authored by @​srenatus
  • topdown: Enable more revive linters (#​9181) authored by @​anderseknert
  • topdown: Fix flaky TestRegexBuiltinCache (#​9254) authored by @​sspaink
  • topdown: Fix linter issues (#​9231) authored by @​srenatus
  • util: Add RoundTripFast (#​9199) authored by @​srenatus
  • util: Decode RoundTrip's fallback into a fresh value (#​9206) authored by @​srenatus
  • workflows: Check the nightly go-get job for retractions via the proxy (#​9240) authored by @​srenatus
  • workflows: Remove benchmarks from nightly (#​9182) authored by @​srenatus
  • workflows: Run Regal's do.rq in the nightly compatibility check (#​9209) authored by @​sspaink
  • workflows: Use OCP@​main in nightly (#​9171) authored by @​srenatus
  • Collapse v0 shim packages into a single file each (#​8976) authored by @​sspaink, reported by @​anderseknert
  • Makefile: Add a benchlab target (#​9222) authored by @​srenatus
  • Remove retired go report (#​9112) authored by @​sspaink
  • Dependency updates:
    • build(go): Bump to 1.27.1 (#​9136) authored by @​srenatus
    • build(deps): Bump github.com/dgraph-io/badger/v4 from 4.9.5 to 4.9.6
    • build(deps): Bump github.com/gobwas/glob to v1.0.0 (#​9114) authored by @​sspaink, reported by @​ghmer
    • build(deps): Bump github.com/huandu/go-sqlbuilder from 1.42.1 to 1.43.0
    • build(deps): Bump github.com/lestrrat-go/jwx/v3 from 3.1.1 to 3.3.0
    • build(deps): Bump github.com/olekukonko/tablewriter from 1.1.4 to 1.1.5
    • build(deps): Bump github.com/prometheus/client_model from 0.6.2 to 0.6.3
    • build(deps): Bump github.com/santhosh-tekuri/jsonschema/v6 from 6.0.2 to 6.0.3
    • build(deps): Bump github.com/sirupsen/logrus from 1.9.4 to 1.10.2
    • build(deps): Bump github.com/vektah/gqlparser/v2 from 2.5.36 to 2.5.37
    • build(deps): Bump go.opentelemetry.io/contrib/bridges/prometheus from 0.69.0 to 0.71.0
    • build(deps): Bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp from 0.69.0 to 0.71.0
    • build(deps): Bump go.opentelemetry.io/otel from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlptrace from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/sdk from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/sdk/metric from 1.44.0 to 1.46.0
    • build(deps): Bump go.yaml.in/yaml/v3 from 3.0.4 to 3.0.5
    • build(deps): Bump golang.org/x/sync from 0.22.0 to 0.23.0
    • build(deps): Bump golang.org/x/term from 0.45.0 to 0.46.0
    • build(deps): Bump golang.org/x/text from 0.40.0 to 0.42.0
    • build(deps): Bump golang.org/x/time from 0.15.0 to 0.16.0
    • build(deps): Bump google.golang.org/grpc from 1.82.1 to 1.83.2
    • build(deps): Bump google.golang.org/protobuf from 1.36.11 to 1.36.12
    • build(deps): Drop sigs.k8s.io/yaml (was 1.6.0)

v1.20.2

Compare Source

This release includes a bug fix for a parser regression introduced in v1.20.0, and dependency updates.

Fix stale parse errors on statements starting with { (#​9140)

When the and/or keywords added in v1.20.0 are imported, a statement that starts with { is
first read as an explicit operand body, and re-read as a term (a comprehension, for example) if no
and or or follows. Errors recorded during the abandoned first attempt stayed in the parser's
term cache and were reported against the successful re-read, rejecting policies that parse fine:

package example

import future.keywords

xs := [1, 2, 3]

allow if {
	{
	y |
		some y in xs # rego_parse_error: unexpected some keyword
	} == {1, 2, 3}
}

The term cache is now restored along with the rest of the parser state when the operand-body guess
is abandoned. Only policies importing and or or — directly or via import future.keywords —
were affected; policies that don't import them parse unchanged.

Authored by @​sspaink

Miscellaneous
  • build(go): Bump to 1.27.1 (3652eeb) authored by @​srenatus
  • Dependency updates; notably:
    • build(deps): Bump github.com/dgraph-io/badger/v4 from 4.9.5 to 4.9.6
    • build(deps): Bump github.com/lestrrat-go/jwx/v3 from 3.1.1 to 3.2.0
    • build(deps): Bump github.com/santhosh-tekuri/jsonschema/v6 from 6.0.2 to 6.0.3
    • build(deps): Bump github.com/sirupsen/logrus from 1.9.4 to 1.10.2
    • build(deps): Bump go.opentelemetry.io/contrib/bridges/prometheus from 0.69.0 to 0.71.0
    • build(deps): Bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp from 0.69.0 to 0.71.0
    • build(deps): Bump go.opentelemetry.io/otel from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlptrace from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/sdk from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/sdk/metric from 1.44.0 to 1.46.0
    • build(deps): Bump go.opentelemetry.io/otel/trace from 1.44.0 to 1.46.0
    • build(deps): Bump go.yaml.in/yaml/v3 from 3.0.4 to 3.0.5
    • build(deps): Bump golang.org/x/text from 0.40.0 to 0.41.0
    • build(deps): Bump google.golang.org/grpc from 1.82.1 to 1.83.2
    • build(deps): Bump google.golang.org/protobuf from 1.36.11 to 1.36.12

v1.20.1

Compare Source

This release includes a bug fix for a regression introduced in v1.20.0 in
comparing a number to some float values.
Thanks @​kmadan for reporting the issue and submitting a fix!

v1.20.0

Compare Source

This release contains a mix of new features and bug fixes. Notably:

  • New Rego keywords: and and or, for combining conditions inside a single rule body
  • allow_net now restricts remote JSON Schema $ref fetching from json.match_schema and json.verify_schema
  • Coverage reports can now explain why a range is not covered
  • Much faster partial evaluation for dynamically composed policies
New Rego keywords: and and or (#​7602)

Rego gains two keywords for combining conditions inside a single rule body — a long-standing
request, and one of the larger additions to the language in some time. and and or let control
flow that previously had to be split across helper rules stay where it is read.

Before, a rule body that needed to succeed on one of several conditions meant extracting a rule:

package example

allow if {
	input.method == "GET"
	admin_or_public_owner
}

admin_or_public_owner if input.user.admin

admin_or_public_owner if {
	input.user.owner
	input.resource.public
}

Now:

package example

import future.keywords.and
import future.keywords.or

# the and groups first, so this reads as:

# an admin, or an owner of a public resource
allow if {
	input.method == "GET"
	input.user.admin or input.user.owner and input.resource.public
}

Both keywords are opt-in future keywords:
import future.keywords.and, import future.keywords.or, or import future.keywords for both.

An and/or expression either succeeds or fails; it never produces a value. So you can't assign
one to a variable, pass one to a function, or use one as the head of a comprehension.

Operands can read variables from the rule body around them, but can't create new ones for the rest
of the rule to use — wrap an operand in braces to give it a body of its own, and any variables it
creates stay inside those braces. Only as much is evaluated as needed: if the left side settles the
outcome, the right side is skipped. And when both sides of an or succeed, you still get a single
result; evaluation doesn't split in two.

Further reading:

Try the new keywords in the Rego Playground, or in your
editor with the VS Code extension
or the IntelliJ IDEA plugin — see
Editor and IDE Support for others.

Authored by @​johanfylling

Behavior change: allow_net applies to remote JSON Schema $refs (#​8979)

The allow_net
capability restricts which hosts remote JSON Schema $refs may be fetched from, but it was only
wired up on the compile-time type-checking path. Policies using neither -s schemas nor
# METADATA schemas:
annotations never reached it, and an unset allowlist permitted every host — so
json.match_schema
and json.verify_schema,
which compile schemas at evaluation time, fetched $refs from anywhere. Their schema argument can
come from input, so the host was not necessarily under the policy author's control.

The allowlist now travels with the schema loader and is checked per caller at any nesting depth.
Every redirect hop is checked too, matching http.send, and the inter-query cache key includes the
allowlist so a permissive caller cannot populate the cache for a restrictive one.

Authored by @​sspaink, reported by @​charlesdaniels

Coverage reports explain why a range is not covered (#​8937)

Coverage reports showed that a
range was uncovered, but not why: ranges skipped by rule indexing
or early exit looked identical to dead code.

Not-covered ranges are now tagged with a Kind — index_excluded or early_exit — determined
by re-evaluating with each optimization disabled and diffing the extra coverage data. Both
supplementary passes run by default when --coverage is set; the new --coverage-runs flag on
opa eval and opa test selects which of them to run, and an empty list disables them.

Authored by @​charlieegan3

Runtime, SDK, Tooling
Compiler, Topdown and Rego

Configuration

📅 Schedule: Branch creation - Between 01:00 AM and 01:59 AM, Monday through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from a6e3a28 to 14b5aba Compare August 29, 2026 18:50
@elastic-renovate-prod elastic-renovate-prod Bot changed the title fix(deps): update module github.com/open-policy-agent/opa to v1.20.1 (9.4) fix(deps): update module github.com/open-policy-agent/opa to v1.20.0 (9.4) Aug 29, 2026
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from 14b5aba to cac0aa5 Compare August 30, 2026 10:58
@elastic-renovate-prod elastic-renovate-prod Bot changed the title fix(deps): update module github.com/open-policy-agent/opa to v1.20.0 (9.4) fix(deps): update module github.com/open-policy-agent/opa to v1.20.1 (9.4) Aug 30, 2026
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from cac0aa5 to 2bcf1d3 Compare September 5, 2026 22:56
@elastic-renovate-prod elastic-renovate-prod Bot changed the title fix(deps): update module github.com/open-policy-agent/opa to v1.20.1 (9.4) fix(deps): update module github.com/open-policy-agent/opa to v1.20.2 (9.4) Sep 5, 2026
@mergify

mergify Bot commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

This pull request is now in conflicts. Could you fix it? 🙏
To fixup this pull request, you can check out it locally. See documentation: https://help.github.com/articles/checking-out-pull-requests-locally/

git fetch upstream
git checkout -b renovate/9.4-github.com-open-policy-agent-opa-1.x upstream/renovate/9.4-github.com-open-policy-agent-opa-1.x
git merge upstream/9.4
git push upstream renovate/9.4-github.com-open-policy-agent-opa-1.x

@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from 2bcf1d3 to 4f3c508 Compare September 6, 2026 06:52
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from 4f3c508 to e5c396f Compare September 16, 2026 16:01
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from e5c396f to cd6943a Compare September 16, 2026 16:02
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from cd6943a to 82f3d7b Compare September 16, 2026 16:18
@elastic-renovate-prod

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated

Details:

Package Change
github.com/gobwas/glob v0.2.3 -> v1.0.0

@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from 71770b7 to c0ae90a Compare September 29, 2026 16:32
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from c0ae90a to 65bdde8 Compare September 29, 2026 16:33
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from 65bdde8 to 00df191 Compare September 29, 2026 16:34
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from 00df191 to 5e4b527 Compare September 29, 2026 16:49
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from 5e4b527 to 44f19ba Compare September 29, 2026 16:52
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from 44f19ba to 37a04b2 Compare September 29, 2026 16:57
@mergify

mergify Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

This pull request is now in conflicts. Could you fix it? 🙏
To fixup this pull request, you can check out it locally. See documentation: https://help.github.com/articles/checking-out-pull-requests-locally/

git fetch upstream
git checkout -b renovate/9.4-github.com-open-policy-agent-opa-1.x upstream/renovate/9.4-github.com-open-policy-agent-opa-1.x
git merge upstream/9.4
git push upstream renovate/9.4-github.com-open-policy-agent-opa-1.x

@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from 37a04b2 to c479b6a Compare September 29, 2026 18:50
@mergify

mergify Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

This pull request is now in conflicts. Could you fix it? 🙏
To fixup this pull request, you can check out it locally. See documentation: https://help.github.com/articles/checking-out-pull-requests-locally/

git fetch upstream
git checkout -b renovate/9.4-github.com-open-policy-agent-opa-1.x upstream/renovate/9.4-github.com-open-policy-agent-opa-1.x
git merge upstream/9.4
git push upstream renovate/9.4-github.com-open-policy-agent-opa-1.x

@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from c479b6a to cb2c8db Compare September 30, 2026 18:59
@mergify

mergify Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

This pull request is now in conflicts. Could you fix it? 🙏
To fixup this pull request, you can check out it locally. See documentation: https://help.github.com/articles/checking-out-pull-requests-locally/

git fetch upstream
git checkout -b renovate/9.4-github.com-open-policy-agent-opa-1.x upstream/renovate/9.4-github.com-open-policy-agent-opa-1.x
git merge upstream/9.4
git push upstream renovate/9.4-github.com-open-policy-agent-opa-1.x

@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from cb2c8db to 8dd3ede Compare October 1, 2026 10:51
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from 8dd3ede to 94325ee Compare October 1, 2026 22:54
@elastic-renovate-prod elastic-renovate-prod Bot changed the title fix(deps): update module github.com/open-policy-agent/opa to v1.21.0 (9.4) fix(deps): update module github.com/open-policy-agent/opa to v1.21.1 (9.4) Oct 1, 2026
@mergify

mergify Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

This pull request is now in conflicts. Could you fix it? 🙏
To fixup this pull request, you can check out it locally. See documentation: https://help.github.com/articles/checking-out-pull-requests-locally/

git fetch upstream
git checkout -b renovate/9.4-github.com-open-policy-agent-opa-1.x upstream/renovate/9.4-github.com-open-policy-agent-opa-1.x
git merge upstream/9.4
git push upstream renovate/9.4-github.com-open-policy-agent-opa-1.x

@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.4-github.com-open-policy-agent-opa-1.x branch from 94325ee to efc9bd3 Compare October 2, 2026 18:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants