chore(deps): update dependency open-policy-agent/regal to v0.43.0 #9

Open
CSRBot wants to merge 1 commits from renovate/open-policy-agent-regal-0.x into master
Collaborator

This PR contains the following updates:

Package Update Change
open-policy-agent/regal minor 0.42.0 → 0.43.0

Release Notes

open-policy-agent/regal (open-policy-agent/regal)

v0.43.0

Compare Source

This release brings support for OPA's experimental and/or keywords and three new linter rules.

Note: This is the last Regal release built with Go 1.26. Starting with the next release, Regal moves to Go 1.27.

New Rule: idiomatic/prefer-string-interpolation

Category: idiomatic

The prefer-string-interpolation rule recommends OPA's string interpolation over sprintf and concat where possible (#​2092, #​2093).

Avoid

package policy

request_formatted := sprintf("%s: %s", [method, path]) if {
    # extract method and path from the request
}

full_name := concat(" ", [first_name, last_name])

Prefer

package policy

request_formatted := $"{method}: ${path}" if {
    # extract method and path from the request
}

full_name := $"{first_name} ${last_name}"

New Rule: bugs/unconditional-with-conditions

Category: bugs

The unconditional-with-conditions rule flags a rule with an unconditional definition alongside other definitions that carry conditions. Since the unconditional definition always applies, the conditions on the others can never decide anything. Either the values differ and evaluation fails with a conflict, or the values agree and the conditional definitions are dead code. This rule was contributed by @​kmadan — thanks!

Avoid

package policy

allow := true if input.user.is_admin

# `allow` is now defined for every input, so the conditions above never decide

# anything. If `input.user.is_admin` is true, evaluation fails with a conflict.
allow := false

Prefer

package policy

default allow := false

allow := true if input.user.is_admin

New Rule: performance/repeated-computation

Category: performance

The repeated-computation rule flags a deterministic built-in call, like count(input.items), when it runs more than once in the same scope. The rule suggests assigning the result to a variable instead (#​2026) — thanks @​mvanhorn!

Avoid

package policy

allow if {
    count(input.subjects) > 0
    count(input.subjects) < 100
}

Prefer

package policy

allow if {
    subject_count := count(input.subjects)
    subject_count > 0
    subject_count < 100
}

New Feature: Experimental and/or keyword support

Regal can now parse and lint policies using OPA's experimental and/or keywords (#​2075) — thanks @​sspaink! This includes support in both RoAST encoders. The constant-condition rule no longer reports an operand that makes up an entire and/or expression, because removing it leaves the expression without one. A new check also reports a constant and/or operand with a range covering the operator. Removing it then collapses the expression to the operand that is kept (#​2079).

Language Server Improvements

When the client indicates support for inline coverage, the language server now includes a coverage report in eval responses (#​2094). See the related PR open-policy-agent/vscode-opa#498 for the client side of this feature.

Performance

One-shot commands like lint, test and fix allocate in bulk and then exit, so garbage collecting at the default pace was largely wasted work. Relaxing the GC pacing for these commands makes Regal about 15% faster when linting its own 350+ Rego policies (#​2095).

Documentation

  • Link each rule's configuration options to the configuration docs, and add the missing configuration section for disallow-rego-v1 (#​2077) — thanks @​pttydou!
  • Clarify where rule configuration files live (fixes #​533).
  • Update some links to the OPA blog. The links now point to the blog on the OPA website, not the separate Medium-hosted blog (#​2059).

New Contributors

Changelog


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [open-policy-agent/regal](https://github.com/open-policy-agent/regal) | minor | `0.42.0` → `0.43.0` | --- ### Release Notes <details> <summary>open-policy-agent/regal (open-policy-agent/regal)</summary> ### [`v0.43.0`](https://github.com/open-policy-agent/regal/releases/tag/v0.43.0) [Compare Source](https://github.com/open-policy-agent/regal/compare/v0.42.0...v0.43.0) This release brings support for OPA's experimental `and`/`or` keywords and three new linter rules. **Note:** This is the last Regal release built with Go 1.26. Starting with the next release, Regal moves to Go 1.27. #### New Rule: `idiomatic/prefer-string-interpolation` **Category:** idiomatic The [prefer-string-interpolation](https://www.openpolicyagent.org/projects/regal/rules/idiomatic/prefer-string-interpolation) rule recommends OPA's string interpolation over `sprintf` and `concat` where possible ([#&#8203;2092](https://github.com/open-policy-agent/regal/issues/2092), [#&#8203;2093](https://github.com/open-policy-agent/regal/issues/2093)). **Avoid** ```rego package policy request_formatted := sprintf("%s: %s", [method, path]) if { # extract method and path from the request } full_name := concat(" ", [first_name, last_name]) ``` **Prefer** ```rego package policy request_formatted := $"{method}: ${path}" if { # extract method and path from the request } full_name := $"{first_name} ${last_name}" ``` #### New Rule: `bugs/unconditional-with-conditions` **Category:** bugs The [unconditional-with-conditions](https://www.openpolicyagent.org/projects/regal/rules/bugs/unconditional-with-conditions) rule flags a rule with an unconditional definition alongside other definitions that carry conditions. Since the unconditional definition always applies, the conditions on the others can never decide anything. Either the values differ and evaluation fails with a conflict, or the values agree and the conditional definitions are dead code. This rule was contributed by [@&#8203;kmadan](https://github.com/kmadan) — thanks! **Avoid** ```rego package policy allow := true if input.user.is_admin # `allow` is now defined for every input, so the conditions above never decide # anything. If `input.user.is_admin` is true, evaluation fails with a conflict. allow := false ``` **Prefer** ```rego package policy default allow := false allow := true if input.user.is_admin ``` #### New Rule: `performance/repeated-computation` **Category:** performance The [repeated-computation](https://www.openpolicyagent.org/projects/regal/rules/performance/repeated-computation) rule flags a deterministic built-in call, like `count(input.items)`, when it runs more than once in the same scope. The rule suggests assigning the result to a variable instead ([#&#8203;2026](https://github.com/open-policy-agent/regal/issues/2026)) — thanks [@&#8203;mvanhorn](https://github.com/mvanhorn)! **Avoid** ```rego package policy allow if { count(input.subjects) > 0 count(input.subjects) < 100 } ``` **Prefer** ```rego package policy allow if { subject_count := count(input.subjects) subject_count > 0 subject_count < 100 } ``` #### New Feature: Experimental `and`/`or` keyword support Regal can now parse and lint policies using OPA's experimental `and`/`or` keywords ([#&#8203;2075](https://github.com/open-policy-agent/regal/issues/2075)) — thanks [@&#8203;sspaink](https://github.com/sspaink)! This includes support in both RoAST encoders. The `constant-condition` rule no longer reports an operand that makes up an entire `and`/`or` expression, because removing it leaves the expression without one. A new check also reports a constant `and`/`or` operand with a range covering the operator. Removing it then collapses the expression to the operand that is kept ([#&#8203;2079](https://github.com/open-policy-agent/regal/issues/2079)). #### Language Server Improvements When the client indicates support for inline coverage, the language server now includes a coverage report in eval responses ([#&#8203;2094](https://github.com/open-policy-agent/regal/issues/2094)). See the related PR [open-policy-agent/vscode-opa#498](https://github.com/open-policy-agent/vscode-opa/pull/498) for the client side of this feature. #### Performance One-shot commands like `lint`, `test` and `fix` allocate in bulk and then exit, so garbage collecting at the default pace was largely wasted work. Relaxing the GC pacing for these commands makes Regal about 15% faster when linting its own 350+ Rego policies ([#&#8203;2095](https://github.com/open-policy-agent/regal/issues/2095)). #### Documentation - Link each rule's configuration options to the configuration docs, and add the missing configuration section for `disallow-rego-v1` ([#&#8203;2077](https://github.com/open-policy-agent/regal/issues/2077)) — thanks [@&#8203;pttydou](https://github.com/pttydou)! - Clarify where rule configuration files live (fixes [#&#8203;533](https://github.com/open-policy-agent/regal/issues/533)). - Update some links to the OPA blog. The links now point to the blog on the OPA website, not the separate Medium-hosted blog ([#&#8203;2059](https://github.com/open-policy-agent/regal/issues/2059)). #### New Contributors - [@&#8203;kmadan](https://github.com/kmadan) made their first contribution in [#&#8203;2081](https://github.com/open-policy-agent/regal/pull/2081) - [@&#8203;pttydou](https://github.com/pttydou) made their first contribution in [#&#8203;2077](https://github.com/open-policy-agent/regal/pull/2077) #### Changelog - [`9670442`](https://github.com/open-policy-agent/regal/commit/96704424fbcf37638cd41806b27072301bdf94ca): build(deps): bump linkify-it from 5.0.1 to 5.0.2 in /build ([#&#8203;2063](https://github.com/open-policy-agent/regal/issues/2063)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot]) - [`44d3372`](https://github.com/open-policy-agent/regal/commit/44d33727357d558ff0866e20bad8b27feadf0b39): build(deps): bump brace-expansion from 5.0.6 to 5.0.7 in /build ([#&#8203;2061](https://github.com/open-policy-agent/regal/issues/2061)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot]) - [`2e89cce`](https://github.com/open-policy-agent/regal/commit/2e89ccedc0fa0fde2eb5879d61a2f1520e57cc03): build(deps): bump the dependencies group across 1 directory with 7 updates ([#&#8203;2064](https://github.com/open-policy-agent/regal/issues/2064)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot]) - [`db756a9`](https://github.com/open-policy-agent/regal/commit/db756a95ce046083f0c5a412d959e4bc5141a064): build(deps): bump js-yaml and markdownlint-cli in /build ([#&#8203;2065](https://github.com/open-policy-agent/regal/issues/2065)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot]) - [`9635851`](https://github.com/open-policy-agent/regal/commit/963585147557ce3bcb89670a0ea307f8c25e54ce): docs: Update some links to OPA blog to new host ([#&#8203;2059](https://github.com/open-policy-agent/regal/issues/2059)) ([@&#8203;charlieegan3](https://github.com/charlieegan3)) - [`e3dd92f`](https://github.com/open-policy-agent/regal/commit/e3dd92f3276b58127d548900baa185eec808d43c): build(deps): bump brace-expansion from 5.0.7 to 5.0.9 in /build ([#&#8203;2067](https://github.com/open-policy-agent/regal/issues/2067)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot]) - [`2d6d5ff`](https://github.com/open-policy-agent/regal/commit/2d6d5ff231712e16888ac378f607288e1c4e8e91): build(deps): bump the dependencies group with 4 updates ([#&#8203;2069](https://github.com/open-policy-agent/regal/issues/2069)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot]) - [`440615b`](https://github.com/open-policy-agent/regal/commit/440615b95899847280043aeaa2a4c3995a1532cb): build(deps): bump the dependencies group with 2 updates ([#&#8203;2068](https://github.com/open-policy-agent/regal/issues/2068)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot]) - [`f046663`](https://github.com/open-policy-agent/regal/commit/f04666366276d712bd52a5e7e6b78938d41182ba): build: Run all dependabots monthly ([#&#8203;2071](https://github.com/open-policy-agent/regal/issues/2071)) ([@&#8203;charlieegan3](https://github.com/charlieegan3)) - [`e9ce4a5`](https://github.com/open-policy-agent/regal/commit/e9ce4a5bd98a7d93ca7a0c7559271c5f525cfd00): OPA v1.19.0 ([#&#8203;2070](https://github.com/open-policy-agent/regal/issues/2070)) ([@&#8203;anderseknert](https://github.com/anderseknert)) - [`4f50e60`](https://github.com/open-policy-agent/regal/commit/4f50e604e7b46d8a5a1e3a0523c2a0686e302dda): build(deps): bump github.com/sourcegraph/jsonrpc2 ([#&#8203;2074](https://github.com/open-policy-agent/regal/issues/2074)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot]) - [`2ed6af2`](https://github.com/open-policy-agent/regal/commit/2ed6af2d6298b4d0858c0fc86138b1a7e528e04a): build(deps): bump dprint in /build in the dependencies group ([#&#8203;2073](https://github.com/open-policy-agent/regal/issues/2073)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot]) - [`b2cff49`](https://github.com/open-policy-agent/regal/commit/b2cff49c9e5ed982b915cc26c7faac698208a43f): Support the experimental `and`/`or` keywords ([#&#8203;2075](https://github.com/open-policy-agent/regal/issues/2075)) ([@&#8203;sspaink](https://github.com/sspaink)) - [`abfc0db`](https://github.com/open-policy-agent/regal/commit/abfc0dbccc274f73e7ed3de557206fee7e75cff8): internal/io: drop stale experimental-keywords capability assertion ([#&#8203;2078](https://github.com/open-policy-agent/regal/issues/2078)) ([@&#8203;sspaink](https://github.com/sspaink)) - [`f4b817f`](https://github.com/open-policy-agent/regal/commit/f4b817f5d1f9cb2d88ec1cb8d9a50bfea7ea84b5): build(deps): bump gobwas/glob to v1.0.0 and OPA to the commit that supports it ([#&#8203;2089](https://github.com/open-policy-agent/regal/issues/2089)) ([@&#8203;sspaink](https://github.com/sspaink)) - [`55418b7`](https://github.com/open-policy-agent/regal/commit/55418b71fef9798960ff5297258fee925700d9e1): build(deps): bump dprint ([#&#8203;2087](https://github.com/open-policy-agent/regal/issues/2087)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot]) - [`3236e6b`](https://github.com/open-policy-agent/regal/commit/3236e6bd1b15da9235ad5dc71f34a4b26da64f48): build(deps): bump github.com/arl/statsviz ([#&#8203;2090](https://github.com/open-policy-agent/regal/issues/2090)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot]) - [`d71df5d`](https://github.com/open-policy-agent/regal/commit/d71df5dd2f1faba9647bd8f81797f35cbd5abcdc): build(deps): bump the dependencies group across 1 directory with 4 updates ([#&#8203;2086](https://github.com/open-policy-agent/regal/issues/2086)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot]) - [`ebf3586`](https://github.com/open-policy-agent/regal/commit/ebf35861bf5770a035dc5119314fe756dc5a963f): docs: clarify rule configuration file locations ([#&#8203;2077](https://github.com/open-policy-agent/regal/issues/2077)) ([@&#8203;pttydou](https://github.com/pttydou)) - [`529ef41`](https://github.com/open-policy-agent/regal/commit/529ef41d263607f1a58543d625d9490dcfc15711): Prepare for getting back to Regal hacking ([#&#8203;2091](https://github.com/open-policy-agent/regal/issues/2091)) ([@&#8203;anderseknert](https://github.com/anderseknert)) - [`173a897`](https://github.com/open-policy-agent/regal/commit/173a897ff4642d28099d3280ce7bd3bc607857d2): feat(rules): add bugs/unconditional-with-conditions ([#&#8203;2081](https://github.com/open-policy-agent/regal/issues/2081)) ([@&#8203;kmadan](https://github.com/kmadan)) - [`948ed07`](https://github.com/open-policy-agent/regal/commit/948ed0748ef50f57131770237699d6e6e5e552c6): Report constant `and`/`or` operands ([#&#8203;2079](https://github.com/open-policy-agent/regal/issues/2079)) ([@&#8203;sspaink](https://github.com/sspaink)) - [`bb38183`](https://github.com/open-policy-agent/regal/commit/bb381833f0296a0162367459459f74d49c68ece2): feat: add performance rule repeated-computation ([#&#8203;2026](https://github.com/open-policy-agent/regal/issues/2026)) ([@&#8203;mvanhorn](https://github.com/mvanhorn)) - [`79a32f8`](https://github.com/open-policy-agent/regal/commit/79a32f82d531021674f6906869f06ab7e59de63e): Rule: prefer-string-interpolation ([#&#8203;2092](https://github.com/open-policy-agent/regal/issues/2092)) ([@&#8203;anderseknert](https://github.com/anderseknert)) - [`3d1898b`](https://github.com/open-policy-agent/regal/commit/3d1898b6b27874e21dcbc56190b8019d0fa68627): perf: relax GC pacing for one-shot commands ([#&#8203;2095](https://github.com/open-policy-agent/regal/issues/2095)) ([@&#8203;srenatus](https://github.com/srenatus)) - [`18a6354`](https://github.com/open-policy-agent/regal/commit/18a6354afbd3f11ed1787c760a95ffbf4f86b94a): lsp: Add support for coverage in eval inline ([#&#8203;2094](https://github.com/open-policy-agent/regal/issues/2094)) ([@&#8203;charlieegan3](https://github.com/charlieegan3)) - [`530542d`](https://github.com/open-policy-agent/regal/commit/530542d159214a8568fdad444c0f3bad5ba808f6): Include `concat` in `prefer-string-interpolation` ([#&#8203;2093](https://github.com/open-policy-agent/regal/issues/2093)) ([@&#8203;anderseknert](https://github.com/anderseknert)) - [`83f08ac`](https://github.com/open-policy-agent/regal/commit/83f08acd235912b379720c5194abf24d08848cb6): OPA v1.21.0 ([#&#8203;2098](https://github.com/open-policy-agent/regal/issues/2098)) ([@&#8203;anderseknert](https://github.com/anderseknert)) - [`6df283a`](https://github.com/open-policy-agent/regal/commit/6df283a341a07853d1f78f17d42582a0e6cf75d6): Get rid of mapstructure dependency ([#&#8203;2099](https://github.com/open-policy-agent/regal/issues/2099)) ([@&#8203;anderseknert](https://github.com/anderseknert)) - [`c1c119e`](https://github.com/open-policy-agent/regal/commit/c1c119ee780e382df6aa10b19fc860d5878b41b2): Result handler functions -> interfaces ([#&#8203;2097](https://github.com/open-policy-agent/regal/issues/2097)) ([@&#8203;anderseknert](https://github.com/anderseknert)) - [`df0d0a6`](https://github.com/open-policy-agent/regal/commit/df0d0a6794344daa5f1a5905d5051b1412721b1b): Remove accidental yaml/v2 dependency ([#&#8203;2101](https://github.com/open-policy-agent/regal/issues/2101)) ([@&#8203;anderseknert](https://github.com/anderseknert)) - [`6189089`](https://github.com/open-policy-agent/regal/commit/6189089eff8c384af8a0e821f2ef9bad594970e9): Use custom `filepath.Abs` implementation ([#&#8203;2100](https://github.com/open-policy-agent/regal/issues/2100)) ([@&#8203;anderseknert](https://github.com/anderseknert)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTYuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjExNi4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->
CSRBot added 1 commit 2026-10-07 12:11:34 +02:00
volker.raschek was assigned by CSRBot 2026-10-07 12:11:34 +02:00
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/open-policy-agent-regal-0.x:renovate/open-policy-agent-regal-0.x
git checkout renovate/open-policy-agent-regal-0.x
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: volker.raschek/opa-regal-pkg#9