Releases: open-policy-agent/regal
Release list
v0.42.0
Regal v0.42.0 is here! Bringing a number of improvements to both the linter, language server and debug adapter.
42 is the magic constant of the smallest non-trivial magic cube, a 3×3×3 cube with entries of 1 through 27, where every row, column, corridor, and diagonal passing through the center sums to forty-two.
Language Server
Find References and Rename
This release brings initial support for finding references and renaming symbols in the workspace. This first version
is limited to function arguments and some bindings, but we plan to expand this in future releases.
rename.mov
References are checked across the whole workspace, and renames work even when for example, a function is incrementally defined in several different files.
Thanks @SeanLedford for your work on this!
New future.keywords completion provider
The language server will now suggest future.keywords in completions for import lines — notably the new import future.keywords.not for now, with a few more to follow soon in OPA.
Debug Adapter
Evaluate
Regal's debug adapter protocol (DAP) implementation now supports evaluating variables and expressions inside of stack frames in debugging sessions! This also allows setting up watch expressions in clients like VS Code.
Make sure to download the latest version of the OPA VS Code extension to try it out. More clients hopefully supported soon!
Various Improvements
- Add
--aggregateflag toregal new rulecommand to create aggregate rules. Thanks @mvanhorn! - Allocate less memory while linting with this one simple trick
- Make common rule name provider provide suggestions for default rules
- Make
input.jsoncompletion provider provide suggestion for imports - Have boolean value completion provider provide suggestions in many more locations
- Add inline docs to
importprovider - Add label details to built-in function completion provider
- Bump OPA dependency to v1.18.2
Bugs Fixed
- Override return type of
object.subsetwhile waiting for the next OPA release to fix this. Thanks @mvanhorn! - Fix wrong end location of reported for unresolved functions
- Fix wrong end location reported by rule-shadows-builtin
Documentation
- Update defunct styra.com links to point to archived copies until we find a better home for them
- Documentation added for how GitHub Copilot breaks autocomplete in VS Code and a recommendation not to use it.
Changelog
- 22365a3: docs: Document Copilot breaking language servers in VS Code (#2021) (@anderseknert)
- b842742: docs: Archive some styra.com references (#2022) (@charlieegan3)
- a2539ef: roast: adjust
nottest locations (#2023) (@srenatus) - 81d6485: feat: add --aggregate flag to
regal new rule(#341) (#1966) (@mvanhorn) - 75ce34c: lsp: first implementation of find references and rename (#2029) (@anderseknert)
- efa9106: perf: remove a million allocations with this one simple trick (#2024) (@anderseknert)
- c64b3a3: build(deps): bump the dependencies group with 3 updates (#2027) (@dependabot[bot])
- b3594a4: docs: Small updates to address some inconsistencies (#2030) (@charlieegan3)
- dd92373: [lsp] Update find references and rename request to support "some" variables (#2031) (@SeanLedford)
- a107bea: build(deps): bump markdown-it and markdownlint-cli in /build (#2032) (@dependabot[bot])
- 656cb56: [feature] Extending find references variable support (#2035) (@SeanLedford)
- c78887b: build(deps): bump the dependencies group across 1 directory with 4 updates (#2037) (@dependabot[bot])
- 4e5e4a2: build(deps): bump the dependencies group with 5 updates (#2043) (@dependabot[bot])
- 9b380f4: build(deps): bump golang.org/x/net from 0.53.0 to 0.55.0 in /build/lsp (#2041) (@dependabot[bot])
- ce12d08: OPA v1.18.2 (#2040) (@anderseknert)
- 4f5d1dc: fix: override object.subset return type to boolean (#2048) (@mvanhorn)
- 75fd9d3: build(deps): bump golang.org/x/crypto from 0.50.0 to 0.52.0 in /build/ws (#2044) (@dependabot[bot])
- c2328a5: build(deps): bump the dependencies group with 4 updates (#2049) (@dependabot[bot])
- 758630a: Fix wrong end location of reported unresolved functions (#2053) (@anderseknert)
- 9a74766: Fix wrong end location reported by rule-shadows-builtin (#2054) (@anderseknert)
- 2bb3592: dap: Implement Evaluate feature (#2051) (@anderseknert)
- 76ed1f0: Raise test timeout threshold to 3 seconds (#2058) (@anderseknert)
- d7aaf8f: Use new inmem.NewFromASTObject to set up Regal store (#2056) (@anderseknert)
- 98fc359: Add import future.keywords completion provider (#2055) (@anderseknert)
- bcdaa1d: Various completion provider improvements (#2057) (@anderseknert)
v0.41.1
We've been getting a new version of Regal for an exciting summer of high performance Rego development.
This release brings automatic Rego test generation, as well as squashing a bunch of issues under the hood with sweeping enhancements to the core language server code.
NOTE this is the same code as that of v0.41.0 — just that the combination of a release deployment issue and immutable releases just had that one end up without any downloadable artifacts. That is now corrected!
New Feature: Automatic Test Generation
A first pass at automatic test generation has landed in the language server (#1982), thanks to @SeanLedford! With a new code action available when working in a policy file, Regal can generate a test stub based on the current state of the workspace. This uses the values found in input.json to populate the with statements in the generated test.
Language Server Improvements
This release includes significant internal improvements to the language server.
Completion performance has seen a major improvement: for clients like VS Code that support a default replacement range, the completion payload is now roughly half the size it was before, and clients generally do no longer need to send continuous requests to the server for more suggestions once you start typing (#1992).
The folding range provider has been rewritten in Rego (#1979), and now additionally honours client capabilities like lineFoldingOnly and rangeLimit.
The handling of input.json and input.yaml files has been overhauled (#2002). These files are now tracked as first-class workspace state: they are parsed and cached when saved, and the server now requests update notifications for them from the client, rather than re-parsing the file on each evaluation, or debug sessions started.
OPA v1.17.0
Regal has been updated to OPA v1.17.0 (#2014). This OPA release notably introduces future.keywords.not, which improves the semantics of the not keyword by wrapping composite-expression negation in an implicit body. Thanks @johanfylling for making sure this also works in Regal now!
Regal's RoAST representation (and docs) have been updated to support the new ast.Not form introduced alongside this feature (#1985).
RoAST module.comments Representation
The RoAST representation of module.comments has changed (#1987). Comments are now represented as plain locations rather than base64-encoded text, allowing Regal to retrieve the original text from the source file directly with less bytes to transfer and parse. Note: this is a breaking change for custom rules that reference input.comments directly. Users should instead prefer to reference data.regal.ast.comments_decoded, which provides comment locations in the usual form and which will remain stable even through future format changes.
Bug Fixes
- Addressed a panic in
regal fixcaused by fixes being applied in non-deterministic order;opa-fmtcould reduce line count such thatuse-assignment-operatorwould then access out-of-bounds row numbers (#2003) as reported by @erazemk - The
unassigned-return-valuerule now correctly flags namespaced builtins likejson.match_schema(...)in addition to flat builtins likelower(...)(#2005) — thanks @mvanhorn for the fix and @anderseknert for the report - Nicer formatting of
withsequences (#1969) regal/ast: metadatalabelsfield is now recognized as a valid metadata key, aligned with OPA v1.17.0 (#1983, #1988) — thanks @srenatus- Regal fix now works regardless of local git state (#2011). Thanks @seiyab for the report in #2006
New Contributors
- @mvanhorn added pre-commit hooks for
regal fixin #1976 - @sspaink added support for recursive JSON schemas in OPA, and later applied that fix in our schemas #1967
All changes
- Use OPA main until next OPA release by @anderseknert in #1968
- Update ast.json else to use "#/$defs/rule" by @sspaink in #1967
- Nicer formatting of
withtest sequences by @anderseknert in #1969 - Various code quality improvements by @anderseknert in #1970
- Move initialize handler to Rego router by @anderseknert in #1977
- build(deps): bump the dependencies group with 2 updates by @dependabot[bot] in #1975
- feat(pre-commit): add regal-fix hooks for auto-fixing rules by @mvanhorn in #1976
- Cleanup by @anderseknert in #1978
- Move folding range provider to Rego handlers by @anderseknert in #1979
- build(deps): bump github/codeql-action from 4.35.2 to 4.35.3 in the dependencies group by @dependabot[bot] in #1981
- regal/ast: add 'id' to valid metadata keys by @srenatus in #1983
- Introduce passthrough handler type by @anderseknert in #1984
- roast: Add support for
ast.Notby @johanfylling in #1985 - regal/ast: update metadata fields by @srenatus in #1988
- Breaking: new RoAST representation of module.comments by @anderseknert in #1987
- New framework for testing language server handlers by @anderseknert in #1992
- Move location of LSP storage helpers by @anderseknert in #1993
- build(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.1 by @dependabot[bot] in #2001
- build(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.1 in /e2e/testbuild by @dependabot[bot] in #2000
- Improved handling of input.(json|yaml) files by @anderseknert in #2002
- build(deps): bump brace-expansion from 5.0.5 to 5.0.6 in /build by @dependabot[bot] in #1997
- build(deps): bump the dependencies group across 1 directory with 2 updates by @dependabot[bot] in #1998
- fixer: Apply linter fixes in deterministic order by @charlieegan3 in #2003
- [feature] First Pass at Automatic Test Generation in Regal by @SeanLedford in #1982
- fix(rules): unassigned-return-value now covers namespaced builtins by @mvanhorn in #2005
- [bugfix] Remove the settings.json change that was introduced in a recent PR by @SeanLedford in #2010
- lsp: Introduce workspace abstraction by @anderseknert in #2009
- cmd: Remove git validation from fix command by @charlieegan3 in #2011
- Extract file polling into waitForFile helper by @charlieegan3 in #2013
- deps: Update opa to 1.17.0 by @charlieegan3 in #2014
- Use logger in Rego router by @anderseknert in #2012
- build: Add capabilities verification to build check by @charlieegan3 in #2015
- build(deps): bump github.com/containerd/containerd/v2 from 2.2.3 to 2.2.4 in /e2e/testbuild by @dependabot[bot] in #2007
- build(deps): bump the dependencies group with 3 updates by @dependabot[bot] in #2008
- Unify common aggregation and aggregated data by @anderseknert in #2016
- build(deps): bump github/codeql-action from 4.36.0 to 4.36.1 in the dependencies group by @dependabot[bot] in #2017
- debug: Determine abs debugging path for input.json by @charlieegan3 in #2018
- Use common aggregate data in circular-import by @anderseknert in #2019
Full Changelog: v0.40.0...v0.41.0
v0.41.0
We've been getting a new version of Regal for an exciting summer of high performance Rego development.
This release brings automatic Rego test generation, as well as squashing a bunch of issues under the hood with sweeping enhancements to the core language server code.
NOTE the combination of a release deployment issue and immutable releases had this release end up without any downloadable artifacts. This has been corrected in v0.41.1.
New Feature: Automatic Test Generation
A first pass at automatic test generation has landed in the language server (#1982), thanks to @SeanLedford! With a new code action available when working in a policy file, Regal can generate a test stub based on the current state of the workspace. This uses the values found in input.json to populate the with statements in the generated test.
Language Server Improvements
This release includes significant internal improvements to the language server.
Completion performance has seen a major improvement: for clients like VS Code that support a default replacement range, the completion payload is now roughly half the size it was before, and clients generally do no longer need to send continuous requests to the server for more suggestions once you start typing (#1992).
The folding range provider has been rewritten in Rego (#1979), and now additionally honours client capabilities like lineFoldingOnly and rangeLimit.
The handling of input.json and input.yaml files has been overhauled (#2002). These files are now tracked as first-class workspace state: they are parsed and cached when saved, and the server now requests update notifications for them from the client, rather than re-parsing the file on each evaluation, or debug sessions started.
OPA v1.17.0
Regal has been updated to OPA v1.17.0 (#2014). This OPA release notably introduces future.keywords.not, which improves the semantics of the not keyword by wrapping composite-expression negation in an implicit body. Thanks @johanfylling for making sure this also works in Regal now!
Regal's RoAST representation (and docs) have been updated to support the new ast.Not form introduced alongside this feature (#1985).
RoAST module.comments Representation
The RoAST representation of module.comments has changed (#1987). Comments are now represented as plain locations rather than base64-encoded text, allowing Regal to retrieve the original text from the source file directly with less bytes to transfer and parse. Note: this is a breaking change for custom rules that reference input.comments directly. Users should instead prefer to reference data.regal.ast.comments_decoded, which provides comment locations in the usual form and which will remain stable even through future format changes.
Bug Fixes
- Addressed a panic in
regal fixcaused by fixes being applied in non-deterministic order;opa-fmtcould reduce line count such thatuse-assignment-operatorwould then access out-of-bounds row numbers (#2003) as reported by @erazemk - The
unassigned-return-valuerule now correctly flags namespaced builtins likejson.match_schema(...)in addition to flat builtins likelower(...)(#2005) — thanks @mvanhorn for the fix and @anderseknert for the report - Nicer formatting of
withsequences (#1969) regal/ast: metadatalabelsfield is now recognized as a valid metadata key, aligned with OPA v1.17.0 (#1983, #1988) — thanks @srenatus- Regal fix now works regardless of local git state (#2011). Thanks @seiyab for the report in #2006
New Contributors
- @mvanhorn added pre-commit hooks for
regal fixin #1976 - @sspaink added support for recursive JSON schemas in OPA, and later applied that fix in our schemas #1967
All changes
- Use OPA main until next OPA release by @anderseknert in #1968
- Update ast.json else to use "#/$defs/rule" by @sspaink in #1967
- Nicer formatting of
withtest sequences by @anderseknert in #1969 - Various code quality improvements by @anderseknert in #1970
- Move initialize handler to Rego router by @anderseknert in #1977
- build(deps): bump the dependencies group with 2 updates by @dependabot[bot] in #1975
- feat(pre-commit): add regal-fix hooks for auto-fixing rules by @mvanhorn in #1976
- Cleanup by @anderseknert in #1978
- Move folding range provider to Rego handlers by @anderseknert in #1979
- build(deps): bump github/codeql-action from 4.35.2 to 4.35.3 in the dependencies group by @dependabot[bot] in #1981
- regal/ast: add 'id' to valid metadata keys by @srenatus in #1983
- Introduce passthrough handler type by @anderseknert in #1984
- roast: Add support for
ast.Notby @johanfylling in #1985 - regal/ast: update metadata fields by @srenatus in #1988
- Breaking: new RoAST representation of module.comments by @anderseknert in #1987
- New framework for testing language server handlers by @anderseknert in #1992
- Move location of LSP storage helpers by @anderseknert in #1993
- build(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.1 by @dependabot[bot] in #2001
- build(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.1 in /e2e/testbuild by @dependabot[bot] in #2000
- Improved handling of input.(json|yaml) files by @anderseknert in #2002
- build(deps): bump brace-expansion from 5.0.5 to 5.0.6 in /build by @dependabot[bot] in #1997
- build(deps): bump the dependencies group across 1 directory with 2 updates by @dependabot[bot] in #1998
- fixer: Apply linter fixes in deterministic order by @charlieegan3 in #2003
- [feature] First Pass at Automatic Test Generation in Regal by @SeanLedford in #1982
- fix(rules): unassigned-return-value now covers namespaced builtins by @mvanhorn in #2005
- [bugfix] Remove the settings.json change that was introduced in a recent PR by @SeanLedford in #2010
- lsp: Introduce workspace abstraction by @anderseknert in #2009
- cmd: Remove git validation from fix command by @charlieegan3 in #2011
- Extract file polling into waitForFile helper by @charlieegan3 in #2013
- deps: Update opa to 1.17.0 by @charlieegan3 in #2014
- Use logger in Rego router by @anderseknert in #2012
- build: Add capabilities verification to build check by @charlieegan3 in #2015
- build(deps): bump github.com/containerd/containerd/v2 from 2.2.3 to 2.2.4 in /e2e/testbuild by @dependabot[bot] in #2007
- build(deps): bump the dependencies group with 3 updates by @dependabot[bot] in #2008
- Unify common aggregation and aggregated data by @anderseknert in #2016
- build(deps): bump github/codeql-action from 4.36.0 to 4.36.1 in the dependencies group by @dependabot[bot] in #2017
- debug: Determine abs debugging path for input.json by @charlieegan3 in #2018
- Use common aggregate data in circular-import by @anderseknert in #2019
Full Changelog: v0.40.0...v0.41.0
v0.40.0
Today we celebrate Regal who turns v0.40.0 just in time for the GitHub download tracker to report 1 million total downloads. Quite the milestone! Thank you all for the encouragement, support and contributions during these past 3 years. Together we're redefining the policy development experience, and we have a lot more of that planned for the future. Stay tuned!
This release includes 2 new linter rules, and many new features and improvements to both the linter and language server.
Linter
New Rule: invalid-regexp
Category: bugs
The new invalid-regexp rule scans regular expressions found in policies and reports invalid patterns that would otherwise fail at runtime.
Avoid
package policy
invalid if regexp.match("[a-z", "test")Prefer
package policy
valid if regexp.match("[a-z]", "test")New Rule: superfluous-object-get
Category: idiomatic
The superfluous-object-get rule flags calls to object.get where using the built-in function provides no benefit compared to using a reference directly, and without the call.
Avoid
package policy
superfluous if {
# the default value (`""`) isn't used in the expression,
# so object.get provides no benefit here
object.get(input, ["user", "department"], "") == "engineering"
}Prefer
package policy
much_better if {
input.user.department == "engineering"
}More cases of superfluous object.get will be added to this rule as we encounter them.
Improvements
- The
naming-conventionrule now accepts a list of allowed names in addition to regex patterns - The
non-loop-expressionrule now identifies more types of expressions that could be moved out of iteration - All rules now contain a
related_resourcesitem in their metadata pointing to the docs for the rule - The
regal new rulecommand now generates aRelated Resourcessection in the new rule's documentation template
(thanks @mvanhorn!)
Bugs Fixed
- Fixed two false positives reported in the
non-loop-expressionrule - The server now exits with an error if the
--profileflag is used without--format json(thanks @mvanhorn!)
Language Server
Evaluate and Debug Actions
Any input.json or input.yaml file found in the workspace will be used for input during evaluation and debugging sessions, but this wasn't obvious without reading the docs. The Evaluate and Debug code lenses / commands will now present a dialog option asking to create an input.json file in the project workspace in case one isn't found. This file is populated with dummy JSON data based on references to input found in the policy, and should be edited by the user to provide more relevant data.
Many thanks to @SeanLedford for this great work!
Hover Provider Improvements
The hover provider showing tooltips for built-in functions and keywords has been rewritten in Rego, and additionally saw a few improvements land as part of that process:
- Links to examples for built-in functions now point to the correct location in the OPA docs
- The
printfunction now shows up in hover results as well - Hover provider now less resource intensive, and all information rendered just in time for display
Inlay Hints Improvements
The inlay hint provider (that provides names of function arguments to be displayed at call sites) has also been rewritten in Rego, and the server now implements also the inlayHint/resolve handler, which improves performance by only calculating inlay hint details when the client requests them for display.
Additionally, the inlay hint provider now properly takes the range of the active editor view into account, and will only spend resources calculating hints for code that the user can actually can see.
Semantic Tokens in Comprehensions and every Expressions
The language server's semantic token provider (providing context-based syntax highlighting) now provides semantic tokens inside of comprehensions and every expressions in addition to previously supported contexts. Additionally, most of the semantic token logic is now implemented entirely in Rego.
Improved Language Server Initialization
This release contains a number of fixes and improvements related to the language server's initialization routine, which should now be both more robust and faster.
Bugs Fixed
- Two potential nil dereferences identified and fixed
- Fix a potential out of bounds panic in slice access
- The bundled web server now shows a link to Regal's editor integration documentation on its index page
Finally
Extra thanks goes out to @charlieegan3 this release, who worked tirelessly to fix some really complex race conditions and concurrency issues in the language server. A thankless job, but extremely important, and he pulled it off like a true Viking!
Changelog
- 691afe1: Replace some Styra references (#1904) (@anderseknert)
- 975ae72: build(deps): bump github.com/go-git/go-git/v5 in the dependencies group (#1903) (@dependabot[bot])
- c85d88f: build(deps): bump go.opentelemetry.io/otel/sdk in /build/lsp (#1906) (@dependabot[bot])
- 5ff449b: build(deps): bump the dependencies group with 3 updates (#1907) (@dependabot[bot])
- 9900522: lsp: Wait for client to send initialized at boot (#1909) (@charlieegan3)
- d661b5a: build(deps): bump github/codeql-action in the dependencies group (#1912) (@dependabot[bot])
- fd85e2d: Allow naming-convention rule to take list of names (not only a pattern) (#1911) (@anderseknert)
- 299d3fc: Semantic Token Support for Comprehensions and Constructs (#1883) (@SeanLedford)
- 422a9ef: build(deps): bump github/codeql-action in the dependencies group (#1915) (@dependabot[bot])
- 02a9dc8: Fail with error when --profile used without JSON format (#1918) (@mvanhorn)
- 1716e13: lsp/webserver: Add links to the index page (#1914) (@charlieegan3)
- 1ab360f: lsp/testing: Nested test implementation (#1913) (@charlieegan3)
- 53e5bf2: build(deps): bump google.golang.org/grpc in /e2e/testbuild (#1916) (@dependabot[bot])
- 45841bf: build(deps): bump smol-toml and markdownlint-cli in /build (#1919) (@dependabot[bot])
- 371bf1f: build(deps): bump picomatch from 4.0.3 to 4.0.4 in /build (#1920) (@dependabot[bot])
- 62852fc: build(deps): bump the dependencies group across 1 directory with 4 updates (#1921) (@dependabot[bot])
- d32408d: build(deps): bump github.com/go-git/go-git/v5 in /e2e/testbuild (#1922) (@dependabot[bot])
- 8b9bcf0: build(deps): bump github.com/go-git/go-git/v5 from 5.17.0 to 5.17.1 (#1923) (@dependabot[bot])
- f2251f2: [create-pull-request] automated change (#1908) (@github-actions[bot])
- 820d3f0: OPA v1.15.1 (#1925) (@anderseknert)
- a155b62: Add popup prompt for creating input.json if it doesnt exist when Evaluate is run (#1929) (@SeanLedford)
- 27067af: build(deps): bump the dependencies group with 2 updates (#1931) (@dependabot[bot])
- 2179ae4: Fix non-loop-expression false positives (#1930) (@anderseknert)
- 33282ba: Rule: superflous-object-get (#1932) (@anderseknert)
- 6fd115a: Include rule docs links in metadata (#1935) (@anderseknert)
- 6a364fb: Fix aggregate test loop initialization (#1936) (@charlieegan3)
- 61ab730: Rule: invalid-regexp (#1937) (@anderseknert)
- 752ca7e: Cover more
non-loop-expressions (#1938) (@anderseknert) - cb9a9c8: Add convenience functions for working with lines and uints (#1944) (@anderseknert)
- 85171b8: build(deps): bump go.opentelemetry.io/otel/sdk in /e2e/testbuild (#1942) (@dependabot[bot])
- 7fd6d66: [feature] Create input.json Skeleton if User Would Like When One Doesn't Exist (#1934) (@SeanLedford)
- e4e326b: OPA v1.15.2 (#1945) (@anderseknert)
- e8f1469: build(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp (#1941) (@dependabot[bot])
- 7a1235c: Fix potential nil deref in language server (#1947) (@anderseknert)
- d6d2bf0: Fix index out of bounds in parital inlay hint (#1948) (@anderseknert)
- 0a0f1f8: build(deps): bump the dependencies group with 2 updates (#1946) (@dependabot[bot])
- d0e99b5: Rewrite hover provider in Rego (#1951) (@anderseknert)
- cc35d48: Fix possible nil deref in ogre (#1954) (@anderseknert)
- 44ceabe: Rewrite inlay hint provider in Rego (#1953) (@anderseknert)
- 5c62c72: testing: Improve lsp shutdown logic & address test race conditions (#1943) (@charlieegan3)
- 1...
v0.39.0
We're happy to announce Regal v0.39.0, featuring 3 new linter rules, many language server improvements, and much faster linting!
New Rule: use-array-flatten
Category: idiomatic
The use-array-flatten rule recommends using array.flatten instead of nested array.concatenation (#1873).
Avoid
package policy
flat1 := array.concat(arr1, array.concat(arr2, arr3))
flat2 := array.concat(arr1, array.concat(arr2, array.concat(arr3, arr4)))Prefer
package policy
flat1 := array.flatten([arr1, arr2, arr3])
flat2 := array.flatten([arr1, arr2, arr3, arr4])New Rule: use-object-union-n
Category: idiomatic
The use-object-union-n rule recommends using object.union_n over nested calls to object.union (#1873).
Avoid
package policy
obj := object.union(obj1, object.union(obj2, obj3))Prefer
package policy
obj := object.union_n([obj1, obj2, obj3])New Rule: equals-over-count
Category: performance
The new optional equals-over-count rule suggests using direct equality comparisons rather than count when checking collection membership or emptiness (#1878). This is a micro-optimization and not a general recommendation. Must be manually enabled.
Performance
This release brings an approximate 25% reduction in linting time through aggregate remodeling and Rego prepare stage optimizations (#1838). Additional performance work includes Rego refactoring (#1857, #1884), AST transform improvements (#1892), and various micro-optimizations (#1866, #1879).
Language Server Improvements
The language server now includes a semantic token framework for improved syntax highlighting (#1845, #1865, #1870),
code actions for the constant-condition and redundant-existence-check fixers (#1830).
and an opaTestProvider feature for test discovery (#1888, #1889, #1898),
Completion performance is improved with a completionItem/resolve handler (#1831),
and server capabilities are now properly exposed and consistent with the clients (#1867, #1880).
Note: Semantic token support is feature flagged and will be available in the next release.
Compiler Explorer
Regal now supports the VSCode-based OPA Explorer extension, providing a rich GUI to compare compiler stages directly in VS Code (#1862) - thanks @srenatus! A new "Format stages" option has also been added to the compiler explorer (#1854) - thanks @johanfylling!
Experimental: rq Engine Support
Initial support for the rq engine has been added (#1872) - thanks @charlesdaniels!
Various Improvements
- Improved
redundant-existence-checkrule (#1897, fixes #1805) - Disabled
zero-arity-functionrule asopa-fmtnow covers that (#1885)
Bug Fixes
- Fix nil dereference on compiler errors in explorer (#1837)
- Fix broken links to fixer page (#1852)
- Fix false positive in
use-some-for-output-vars(#1886) - Fix broken
input.jsoncompletion provider (#1891)
Dependency Updates
Regal has been upgraded to use OPA v1.14.0 and Go 1.26.
Documentation
- Added mise as an alternative installation method (#1849) - thanks @jylenhof!
- Updated installation documentation (#1861)
- Updated note about eval and debug roots (#1894)
- Show release badge when using pre-release versions (#1899)
New Contributors
- @jylenhof made their first contribution in #1849
- @charlesdaniels made their first contribution in #1872
v0.38.1
This patch release fixes several bugs including some found in the recent v0.38.0 release, as well some other improvements.
Bug Fixes
- Fix for
prefer-equals-comparisonfixer failing to parse policies with multiple "=" in expressions (#1824, fixes #1818 reported by @gusega) - Fix for incorrect fixable violation count display in lint output (#1825, fixes #1813 reported by @gusega)
- Fix for false positive in
prefer-equals-comparisonrule with comprehension term vars (#1828, fixes #1826 reported by @SeanLedford) - bundle: Surface configured rule notices as messages in lint output (#1827, fixes #1795 reported by @ghmer)
Improvements
- Code action for
prefer-equals-comparisonfixer now available in the language server (#1810) - New option for
prefer-value-in-headrule to count interpolated strings as scalars (#1817) - Minor performance improvement for
any_set_item, used for selecting items from sets (#1815)
Changelog
- f1c5f74: bundle: Improve performance of any_set_item (#1815) (@charlieegan3)
- 9300420: Implemented Code action for prefer-equals-comparison fixer (#1810) (@SeanLedford)
- 28121f0: build(deps): bump github/codeql-action in the dependencies group (#1823) (@dependabot[bot])
- 54cdcb6: Add
prefer-value-in-headoption to count interpolated string as scalar (#1817) (@anderseknert) - e68184d: Fix false positivie in prefer-equals-comparison (#1828) (@anderseknert)
- 593e221: fix: Prefer-Equals-Comparison Edge Case With Multiple "=" (#1824) (@SeanLedford)
- 3dc28bb: bundle: Surface configured rule notices (#1827) (@charlieegan3)
- aac9618: Updated lint reporter to track fixable violation count separate from fixable violation Set (#1825) (@SeanLedford)
- fd6dd4d: Updated example for prefer-equals-comparison edge case to not include false positive (#1829) (@SeanLedford)
v0.38.0
Happy New Year from the Regal maintainers!
Feature: String Interpolation Support
v0.38.0 of your favorite Rego linter, debugger and language server brings full support for OPA's new string interpolation feature. This means not only that Regal lints code found inside interpolated strings, but that you'll have access to all your favorite language server features within them too — like code completions, tooltips on hover, or document highlighting. You can even use the debugger to step through interpolated expressions! If you haven't yet tried it out, grab OPA v1.12.2, Regal v0.38.0 and enjoy an absolutely awesome addition to the Rego language!
In addition to this, we have a number of fun new features and performance improvements.
New Rule: disallow-rego-v1
Category: custom
This optional new rule flags the use of import rego.v1 in Rego policies (#1778). Since OPA v1.0 (December 2024), this import is a no-op and no longer needed. The rule helps users maintain clean code by preventing this outdated import from appearing in new policies. Teams standardizing on OPA 1.0+ can enable this rule to enforce modern Rego standards.
package example
import rego.v1 # <-- Happy 2026! Time to stop doing this!Authored by @SeanLedford.
New Fixers
@SeanLedford has also done some great work to help expand Regal's auto-fixing capabilities by having regal fixers added for three more rules.
See (#1790) and (#1794) for more details.
Performance
The fixer saw a 12% performance improvement by reusing the linter, reducing allocations from 2.3M to 2.0M operations (#1783). Additional optimizations include:
- faster file filtering by avoiding recompiled ignore patterns (#1758),
- better built-in function handling by registering Regal's functions globally only once (#1788),
- and more efficient AST location serialization (#1758)
To track ongoing performance work, a new post-merge benchmark-recording workflow was added (#1793).
LSP: New Ignore Code Action
The language server now supports a code action to quickly add regal ignore configuration for specific rules directly from the editor (#1777).
Changelog
- ac35695: Various performance improvements (#1758) (@anderseknert)
- 48cd03d: docs: Add custom head for regal index page (#1761) (@charlieegan3)
- 728ae28: build(deps): bump golangci/golangci-lint-action (#1762) (@dependabot[bot])
- 92cf6ca: explorer: allow hiding stages without an effect (+misc) (#1760) (@srenatus)
- c000994: docs: Correct sidebar labels (#1763) (@charlieegan3)
- bf0b621: build(deps): bump github.com/containerd/containerd/v2 in /e2e/testbuild (#1753) (@dependabot[bot])
- 18e7a89: build(deps): bump github.com/containerd/containerd/v2 (#1754) (@dependabot[bot])
- ccab7bd: Rename: encoding/util -> encoding/write (#1764) (@anderseknert)
- 54f7625: build: run windows in matrix with other jobs (#1770) (@charlieegan3)
- 5c9e6f0: update: Update version checking logic (#1772) (@charlieegan3)
- 5034776: build: Add badge update to readme script (#1773) (@charlieegan3)
- 95e8220: Added OPA installation as a Regal prerequisite, and fixed golangci-lint link. (#1774) (@SeanLedford)
- 149f71d: build(deps): bump js-yaml from 4.1.0 to 4.1.1 in /build (#1775) (@dependabot[bot])
- b8f8b7f: Enable more golangci-lint linters (@anderseknert)
- e092627: build: Update mac runner (@charlieegan3)
- 877884c: lsp: Add code action and command to ignore rule (#1777) (@charlieegan3)
- ece9ca2: build(deps): bump the dependencies group with 5 updates (@dependabot[bot])
- bd37bbd: build(deps): bump golang.org/x/crypto in /build/lsp (@dependabot[bot])
- 17cc429: build(deps): bump golang.org/x/crypto in /e2e/testbuild (@dependabot[bot])
- 415b05f: build(deps): bump golang.org/x/crypto from 0.43.0 to 0.45.0 (@dependabot[bot])
- e1bb975: Improve fixer performance (@anderseknert)
- 1b083ff: Added Rule: Disallow import rego.v1 (#1778) (@SeanLedford)
- 9e43c50: Optimize and improve code for built-in functions (@anderseknert)
- 64ce2aa: build(deps): bump glob and markdownlint-cli in /build (#1779) (@dependabot[bot])
- 48fddeb: build(deps): bump github/codeql-action in the dependencies group (#1787) (@dependabot[bot])
- bc41f63: pkg/linter: use errgroup, set limits + context on it (@srenatus)
- f22c2aa: Add fixer for prefer-equals-comparison rule (#1790) (@SeanLedford)
- cf88eb9: Fixers for redundant-existence-check and constant-condition rules (#1794) (@SeanLedford)
- 36401a2: build(deps): bump the dependencies group across 1 directory with 7 updates (#1796) (@dependabot[bot])
- ecb23d3: version: Add OPA version to version output (#1798) (@charlieegan3)
- 94ce038: build(deps): bump golang.org/x/crypto from 0.43.0 to 0.45.0 in /build/ws (#1791) (@dependabot[bot])
- 9ce1ddd: workflows: add post-merge benchmark-recording workflow (@srenatus)
- e111443: workflows/benchmark: fix golang setup (@srenatus)
- 4bb2d5a: docs: Update messy rule docs (@charlieegan3)
- dec83ea: docs: Updates from opa website link scanner (@charlieegan3)
- 8f544a6: fix typo in fix.go help message (#1807) (@gusega)
- 941b02e: build(deps): bump the dependencies group with 3 updates (#1804) (@dependabot[bot])
- 9f09e6e: build(deps): bump the dependencies group with 4 updates (#1808) (@dependabot[bot])
- 476ef89: OPA v1.12.2 and full string interpolation support (#1811) (@anderseknert)
- a9843ab: Move
chained-rule-bodytocustomcategory (#1812) (@anderseknert)
v0.37.0
Regal v0.37.0
This release features a new linter rule, several new language server features, and many improvements and fixes. The two major OPA versions bumped since the last release additionally contains several performance improvements that were contributed as part of developing Regal!
New Rule: prefer-equals-comparison
The prefer-equals-comparison linter rule recommends using the == operator for equality comparison over the unification operator =. The rule helps improve code clarity by using operators for their intended purposes: := for assignment, == for equality comparison, and = for unification. The linter identifies when = is used for comparison by checking if both sides of the operator are "unassignable".
Avoid
input.request.method = "GET"Prefer
input.request.method == "GET"There are some certainly valid use cases for the unification operator! But simple equality comparison is not one. For more information, see the documentation for the rule. As an amusing aside, this fixes one of the first issues created in the project!
Language server: Document highlighting to help show where function args are referenced
Document highlighting is one of the more subtle features of the LSP specification, but a really helpful one when implemented well. The experimental first implementation that shipped with Regal v0.36.0 is no longer experimental, and has also been extended to highlight usage of function argument variables inside of a function head or body.
Language server: Selection ranges
Selection ranges provide smart selection of code that can expand and shrink based on knowledge of the code rather than simple text properties, like hyphens or whitespace. This makes moving code around extremely fast, and without leaving the keyboard. Consult the language server docs for how to enable this in your editor
Improvements
- The pointless-reassignment rule would previously only flag reassignment at the top level of a rule body. Now it flags pointless reassignments also in nested bodies, like comprehensions,
everystatements, and so on.
- All completion providers are now implemented purely in Rego
- Remove the go-semver dependency in favor of a custom, much faster implementation
- Build: Reduce permissions granted in update-caps top-level workflow, by @timothyklee
- Docs: Update language server page to demonstrate recently added features
- Docs: Add kakoune LSP configuration example
Windows compatibility improvements
In this release we have fixed various Windows bugs (Language Server Init, Goto Definition, Error Popups) in #1740, #1737, #1736, following #1633, and #1642 last release. Reported and verified by geirs73.
These fixes have also made it possible to run our test suites on Windows runners to catch issues sooner in future. A huge thanks to @charlieegan3 for his tireless work on this!
Bugs fixed
- Fix false positive in use-some-for-output-vars triggered by nested variables in rule ref heads, like
rule[input[i]].allow if .... - Fix false positive in redundant-existence-check when a
notcheck made an existence check necessary, reported by @gusega - Fix false positive in narrow-argument rule, which would incorrectly flag some arrays passed as arguments
- Ensure that the language server
InitOptionsis never nil and don't cause issues with clients that don't provide those
Dependency Updates:
Go modules:
github.com/open-policy-agent/opa:v1.8.0→v1.10.1github.com/arl/statsviz:v0.7.1→v0.7.2github.com/go-git/go-git/v5:v5.16.2→v5.16.3github.com/olekukonko/tablewriter:v0.0.5→v1.1.0github.com/spf13/cobra:v1.9.1→v1.10.1github.com/spf13/pflag:v1.0.7→v1.0.10- Removed:
github.com/coreos/go-semver:v0.3.1
GitHub Actions:
open-policy-agent/setup-opa:v2.2.0→v2.3.0actions/cache:v4.2.4→v4.3.0actions/upload-artifact:v4.6.2→v5.0.0golangci/golangci-lint-action:v2.4.0→v2.5.0actions/setup-go:v5.5.0→v6.0.0
Support
If you encounter any issues with this release, please either file an issue, or let us know in the #opa-regal channel in the OPA Slack!
Changelog
- 244459c: docs: Remove some old references (#1689) (@anderseknert)
- 4212b5c: build(deps): bump the dependencies group with 2 updates (#1690) (@dependabot[bot])
- e149c6d: build: reduce update-caps top-level workflow permission to read (#1691) (@timothyklee)
- 819bbec: lsp: Fix missing initial root (#1692) (@charlieegan3)
- be8b020: docs: Update style guide links to new repo (#1693) (@charlieegan3)
- ceb890b: Builtin function completion in Rego (#1694) (@anderseknert)
- d36555e: Package ref import suggestions in Rego (#1698) (@anderseknert)
- 4e44131: build(deps): bump the dependencies group with 2 updates (#1703) (@dependabot[bot])
- 14166e9: Avoid multi-line highlighting of issues (#1702) (@anderseknert)
- 1685bb8: Move completion handler into Rego router (#1699) (@anderseknert)
- 0da5eaa: build(deps): bump the dependencies group with 2 updates (#1708) (@dependabot[bot])
- e792757: Bump OPA -> v1.9.0, golangci-lint 2.5.0 (#1709) (@anderseknert)
- 3092d1d: docs: Address some broken links from OPA report (#1704) (@charlieegan3)
- bebfd06: util: use Partial2 for IsAnyError (@srenatus)
- f22a570: Fix false positive in
redundant-existence-check(#1716) (@anderseknert) - 2703715: Various fixes (#1715) (@anderseknert)
- 87981f2: build(deps): bump the dependencies group with 2 updates (#1713) (@dependabot[bot])
- a6487b6: lsp: document highlighting supporting function args (#1718) (@anderseknert)
- fe8cbd3: Rule: prefer-equals-comparison (#1726) (@anderseknert)
- f3722ea: Fix false positive in narrow-argument (#1724) (@anderseknert)
- 73b8c65: Improve pointless-reassignment to cover nested cases (#1727) (@anderseknert)
- 9cf180c: lsp: Implement selection ranges and linked editing range (#1722) (@anderseknert)
- bf632d0: build(deps): bump the dependencies group with 2 updates (#1725) (@dependabot[bot])
- a373ae3: lsp: Use filename path for current buffer for defns (#1732) (@charlieegan3)
- d758eaf: lsp: Refactor range utilities (#1729) (@anderseknert)
- 13de8a9: Fix incorrect behavior in pointless-import (#1733) (@anderseknert)
- fb560c1: Fix false positive in use-some-for-output-vars (#1731) (@anderseknert)
- 70449b7: Various small fixes (#1736) (@anderseknert)
- 2594719: windows: Better use of slash paths (#1737) (@charlieegan3)
- 499125f: Get FindClosestMatchingRoot working on windows (#1740) (@charlieegan3)
- 3715085: OPA v1.10.0 (#1742) (@anderseknert)
- 781f809: deps: stick to github.com/vektah/gqlparser/v2@v2.5.30 (#1744) (@srenatus)
- bbb03db: Use generic client identifier in tests (#1741) (@charlieegan3)
- c42ce08: build(deps): bump github/codeql-action in the dependencies group ...
v0.36.1
This is Regal v0.36! The first Regal release since becoming a part of the OPA project last month. This release mostly delivers a number of new language server features as well as wider improvements under the hood and to the developer experience.
A note for users getting Regal via Homebrew
Since Regal was made an official formula, our recommendation has been to use that as your source for Regal. This is the first release distributed only via that formula, so if you still rely on the old styrainc/regal one, make sure to have that removed and brew install regal instead.
A note about Regal's documentation
Our documentation is now displayed as part of the main OPA website!
https://www.openpolicyagent.org/projects/regal
From this release, links generated from Regal in output to rules will point to this location. You might find links to the old location as we get things updated. Please feel free to open any issues for link problems you find just so we don't miss anything.
Get contextual documentation when calling built-in functions
Following PR #1654, the Regal language server will now offer signatureHelp to compatible clients. This shows the current argument type and description in the help text for built-in functions. This is in addition to the other general function documentation displayed here.
Quickly see related fields in when editing METADATA
PR #1657 implements support for the documentHighlight request from clients. This is currently only used to show signal other related METADATA keys when working with Rego metadata.
In future, this same functionality could be used to highlight other related items currently in the viewport.
Jump directly from ignore directives to documentation
documentLink is another request from clients which allow the server to respond with link ranges. We have used this to make regal ignore directives clickable, helping users quickly learn what they mean when encountered in policies PR #1657.
Get live diagnostics from custom rules as you type
PR #1631 ensures that users of custom linter rules are also able to access these for live diagnostics in language server clients. Previously these were not evaluated in the server, only in the Regal CLI.
Notable Refactors & Development Changes
- Rego Language Server Routing: PR #1675 makes some notable changes to how Rego is used within the Regal’s language server. The Language Server Protocol (LSP), which Regal implements to support LSP clients, is based on JSON message passing. This lends itself to Rego evaluation which is JSON in, JSON out. This PR updates the handling of different LSP messages sent from clients to route them in Rego, handling Rego backed rules first, and falling back to Golang implementations that still remain otherwise. This sets the direction for more Rego LSP functionality in the language server in future.
- Development bundle loading from disk: PR #1646 gives those working on Regal in development the option of using the current source for the Regal bundle without rebuilding the binary. This improves the experience when working on Rego based language server functionality by reducing the time of a feedback loop. Set
REGAL_BUNDLE_PATHto use this feature.
Changelog
- 1f1044f: build: Remove tap key (#1687) (@charlieegan3)
- build(deps): bump github/codeql-action from 3.29.0 to 3.29.1 in the dependencies group by @dependabot[bot] in #1616
- Add Regal bundle compilation benchmark by @anderseknert in #1618
- Remove quotes from keywords in refs by @anderseknert in #1619
- lsp: Skip loading files on disk when in cache by @charlieegan3 in #1620
- build(deps): bump the dependencies group with 2 updates by @dependabot[bot] in #1621
- automated: update capabilities by @github-actions[bot] in #1622
- add experimental lsp package for websocket communication by @srenatus in #1623
- internal/io: add FindInputPath when the content isn't needed by @srenatus in #1624
- build(deps): bump github/codeql-action from 3.29.2 to 3.29.3 in the dependencies group by @dependabot[bot] in #1626
- lsp/completions: Handle hyphenated package names by @charlieegan3 in #1625
- lsp: fix didOpen templating race by @charlieegan3 in #1627
- build/lsp: add web client demo by @srenatus in #1629
- lsp: Fix stale diagnostics after deletion by @charlieegan3 in #1628
- Some doc updates by @anderseknert in #1632
- lsp: Add support for custom rules by @charlieegan3 in #1631
- Vendor roast dependency by @anderseknert in #1634
- lsp: Address windows goto definition URI issue by @charlieegan3 in #1633
- Fix
regal new ruleissues + refactor io code by @anderseknert in #1636 - lsp: Use full text replacement for Intellij fmt by @charlieegan3 in #1637
- test: refactor e2e test, add new regal command runner by @anderseknert in #1640
- build(deps): bump github/codeql-action from 3.29.3 to 3.29.5 in the dependencies group by @dependabot[bot] in #1641
- Fix missing source.explore code action by @anderseknert in #1643
- lsp: Present filename relative to root in errors by @charlieegan3 in #1638
- refactor: Improve code quality throughout the codebase by @anderseknert in #1642
- lsp/uri: Refactor URI handling by @charlieegan3 in #1644
- Tidying up more code by @anderseknert in #1645
- Provide development option to load bundle from disk by @anderseknert in #1646
- lsp/eval: Ensure filenames use URI in print output by @charlieegan3 in #1647
- Rewrite more completion providers in Rego. Resolve schemas at runtime. by @anderseknert in #1652
- lsp: Add signature help by @charlieegan3 in #1654
- lsp: Fix server signature race in test by @charlieegan3 in #1655
- build(deps): bump the dependencies group with 5 updates by @dependabot[bot] in #1639
- build(deps): bump the dependencies group with 3 updates by @dependabot[bot] in #1653
- docs: update README badges for OPA 1.7.1 release by @charlieegan3 in #1656
- New LSP features and internal improvements by @anderseknert in #1657
- lsp/documenthighlight: Add tests by @charlieegan3 in #1659
- Add tests for textDocument/documentLink handler by @anderseknert in #1658
- Styra URLs -> OPA URLs by @anderseknert in #1662
- docs: Update README re: move to open-policy-agent by @charlieegan3 in #1664
- internal/io: explicitly disable lazy loading of regal bundle by @srenatus in #1666
- build(deps): bump the dependencies group across 1 directory with 4 updates by @dependabot[bot] in #1663
- Enable pprof endpoint only with env var set by @anderseknert in #1667
- docs: Remove update workflow & minor adjustments by @charlieegan3 in https://gi...
v0.35.1
We're happy to release v0.35.1, the mid-summer release of Regal for the 🏖️ ! This release updates to OPA v1.6.0 bringing a number of performance improvements as well as other improvements and bug fixes.
Improved Schema Loading
This PR replaces Regal's custom schema loader with one that matches OPA's behavior, enabling the same schemas to work across opa check, opa eval, and other OPA commands. PR #1605
Performance Improvements
- Thanks to a PR in OPA, Regal's memory use is now much reduced due to a change conditionally supplying built-in contexts only when needed.
- This PR optimizes Rego evaluation by directly mapping source data to ast.Value objects instead of going through intermediate map[string]any or JSON representations, eliminating ~2.9 million allocations in benchmarks. PR #1606
- Regal contributors will be happy with open-policy-agent/opa#7442 which makes running Regal's tests around 2.5x as fast!
Code Actions Rewrite
Code actions are LSP features that provide automated fixes or refactoring suggestions (like "quick fix" options), and this PR implements them for Regal with server-side filtering to reduce data transfer and ensure consistent editor behavior. This is also now implemented in Rego! PR #1604
Docs
- PR #1584 refactors a number of Regal's pages including breaking down the previously large README into separate files. Browse the new structure on the Regal Website.
- The Code Lens documentation has been updated to better explain supported configurations. Thanks @Shinzu for the report here. #1596
Changelog
- 92d1ba9: deps: Update OPA to v1.6.0 (#1617) (@charlieegan3)
- 2bbe76e: [create-pull-request] automated change (#1582) (@github-actions[bot])
- 6e5e6bb: e2e: add frankenstein test build (@srenatus)
- 5bf607d: build(deps): bump github/codeql-action in the dependencies group (#1585) (@dependabot[bot])
- 6f45a9f: build(deps): bump brace-expansion from 2.0.1 to 2.0.2 in /build (#1587) (@dependabot[bot])
- e85b878: docs: Update config cli docs (#1584) (@charlieegan3)
- 30c73fe: build(deps): bump github/codeql-action in the dependencies group (#1595) (@dependabot[bot])
- b8f3e8f: fix: improve snippets suggestion condition (#1597) (@anderseknert)
- eb48984: Fix issue with handling big numbers (#1599) (@anderseknert)
- 1ee1cf4: fix: Correct end location in unresolved-reference (#1600) (@anderseknert)
- e50c9af: Bump Roast -> v0.12.0 (#1601) (@anderseknert)
- 981d8d2: docs: Update Evaluation Code Lens docs (#1602) (@charlieegan3)
- 3577efe: lsp/completion/input: don't suggest 'input' following dot (#1603) (@srenatus)
- 02d1546: lsp: Code Action feature rewritten in Rego (#1604) (@anderseknert)
- 25b1072: More robust loading of schemas (#1605) (@anderseknert)
- 112dc87: perf: avoid JSON/map roundtrips in ast.Value transforms (#1606) (@anderseknert)
- d87fd2f: docs: Tone down "obsolete" description for use-rego-v1 (#1610) (@anderseknert)
- a939219: lsp: Roll over load file failures (#1611) (@charlieegan3)
- 1d771ca: interning: bump opa+roast, replace call to ast.InternedBoolTerm() (#1613) (@srenatus)
- ed0ead4: build(deps): bump github.com/go-viper/mapstructure/v2 in /e2e/testbuild (#1615) (@dependabot[bot])
- 0d65ef0: build(deps): bump github.com/go-viper/mapstructure/v2 (#1614) (@dependabot[bot])





