packagepolicyrequest_formatted:=sprintf("%s: %s",[method,path])if{# extract method and path from the request}full_name:=concat(" ",[first_name,last_name])
Prefer
packagepolicyrequest_formatted:=$"{method}: ${path}"if{# extract method and path from the request}full_name:=$"{first_name} ${last_name}"
New Rule: bugs/unconditional-with-conditions
Category: bugs
The unconditional-with-conditions rule flags a rule with an unconditional definition alongside other definitions that carry conditions. Since the unconditional definition always applies, the conditions on the others can never decide anything. Either the values differ and evaluation fails with a conflict, or the values agree and the conditional definitions are dead code. This rule was contributed by @kmadan — thanks!
Avoid
packagepolicyallow:=trueifinput.user.is_admin# `allow` is now defined for every input, so the conditions above never decide# anything. If `input.user.is_admin` is true, evaluation fails with a conflict.allow:=false
The repeated-computation rule flags a deterministic built-in call, like count(input.items), when it runs more than once in the same scope. The rule suggests assigning the result to a variable instead (#2026) — thanks @mvanhorn!
Regal can now parse and lint policies using OPA's experimental and/or keywords (#2075) — thanks @sspaink! This includes support in both RoAST encoders. The constant-condition rule no longer reports an operand that makes up an entire and/or expression, because removing it leaves the expression without one. A new check also reports a constant and/or operand with a range covering the operator. Removing it then collapses the expression to the operand that is kept (#2079).
Language Server Improvements
When the client indicates support for inline coverage, the language server now includes a coverage report in eval responses (#2094). See the related PR open-policy-agent/vscode-opa#498 for the client side of this feature.
Performance
One-shot commands like lint, test and fix allocate in bulk and then exit, so garbage collecting at the default pace was largely wasted work. Relaxing the GC pacing for these commands makes Regal about 15% faster when linting its own 350+ Rego policies (#2095).
Documentation
Link each rule's configuration options to the configuration docs, and add the missing configuration section for disallow-rego-v1 (#2077) — thanks @pttydou!
Clarify where rule configuration files live (fixes #533).
Update some links to the OPA blog. The links now point to the blog on the OPA website, not the separate Medium-hosted blog (#2059).
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [open-policy-agent/regal](https://github.com/open-policy-agent/regal) | minor | `0.42.0` → `0.43.0` |
---
### Release Notes
<details>
<summary>open-policy-agent/regal (open-policy-agent/regal)</summary>
### [`v0.43.0`](https://github.com/open-policy-agent/regal/releases/tag/v0.43.0)
[Compare Source](https://github.com/open-policy-agent/regal/compare/v0.42.0...v0.43.0)
This release brings support for OPA's experimental `and`/`or` keywords and three new linter rules.
**Note:** This is the last Regal release built with Go 1.26. Starting with the next release, Regal moves to Go 1.27.
#### New Rule: `idiomatic/prefer-string-interpolation`
**Category:** idiomatic
The [prefer-string-interpolation](https://www.openpolicyagent.org/projects/regal/rules/idiomatic/prefer-string-interpolation) rule recommends OPA's string interpolation over `sprintf` and `concat` where possible ([#​2092](https://github.com/open-policy-agent/regal/issues/2092), [#​2093](https://github.com/open-policy-agent/regal/issues/2093)).
**Avoid**
```rego
package policy
request_formatted := sprintf("%s: %s", [method, path]) if {
# extract method and path from the request
}
full_name := concat(" ", [first_name, last_name])
```
**Prefer**
```rego
package policy
request_formatted := $"{method}: ${path}" if {
# extract method and path from the request
}
full_name := $"{first_name} ${last_name}"
```
#### New Rule: `bugs/unconditional-with-conditions`
**Category:** bugs
The [unconditional-with-conditions](https://www.openpolicyagent.org/projects/regal/rules/bugs/unconditional-with-conditions) rule flags a rule with an unconditional definition alongside other definitions that carry conditions. Since the unconditional definition always applies, the conditions on the others can never decide anything. Either the values differ and evaluation fails with a conflict, or the values agree and the conditional definitions are dead code. This rule was contributed by [@​kmadan](https://github.com/kmadan) — thanks!
**Avoid**
```rego
package policy
allow := true if input.user.is_admin
# `allow` is now defined for every input, so the conditions above never decide
# anything. If `input.user.is_admin` is true, evaluation fails with a conflict.
allow := false
```
**Prefer**
```rego
package policy
default allow := false
allow := true if input.user.is_admin
```
#### New Rule: `performance/repeated-computation`
**Category:** performance
The [repeated-computation](https://www.openpolicyagent.org/projects/regal/rules/performance/repeated-computation) rule flags a deterministic built-in call, like `count(input.items)`, when it runs more than once in the same scope. The rule suggests assigning the result to a variable instead ([#​2026](https://github.com/open-policy-agent/regal/issues/2026)) — thanks [@​mvanhorn](https://github.com/mvanhorn)!
**Avoid**
```rego
package policy
allow if {
count(input.subjects) > 0
count(input.subjects) < 100
}
```
**Prefer**
```rego
package policy
allow if {
subject_count := count(input.subjects)
subject_count > 0
subject_count < 100
}
```
#### New Feature: Experimental `and`/`or` keyword support
Regal can now parse and lint policies using OPA's experimental `and`/`or` keywords ([#​2075](https://github.com/open-policy-agent/regal/issues/2075)) — thanks [@​sspaink](https://github.com/sspaink)! This includes support in both RoAST encoders. The `constant-condition` rule no longer reports an operand that makes up an entire `and`/`or` expression, because removing it leaves the expression without one. A new check also reports a constant `and`/`or` operand with a range covering the operator. Removing it then collapses the expression to the operand that is kept ([#​2079](https://github.com/open-policy-agent/regal/issues/2079)).
#### Language Server Improvements
When the client indicates support for inline coverage, the language server now includes a coverage report in eval responses ([#​2094](https://github.com/open-policy-agent/regal/issues/2094)). See the related PR [open-policy-agent/vscode-opa#498](https://github.com/open-policy-agent/vscode-opa/pull/498) for the client side of this feature.
#### Performance
One-shot commands like `lint`, `test` and `fix` allocate in bulk and then exit, so garbage collecting at the default pace was largely wasted work. Relaxing the GC pacing for these commands makes Regal about 15% faster when linting its own 350+ Rego policies ([#​2095](https://github.com/open-policy-agent/regal/issues/2095)).
#### Documentation
- Link each rule's configuration options to the configuration docs, and add the missing configuration section for `disallow-rego-v1` ([#​2077](https://github.com/open-policy-agent/regal/issues/2077)) — thanks [@​pttydou](https://github.com/pttydou)!
- Clarify where rule configuration files live (fixes [#​533](https://github.com/open-policy-agent/regal/issues/533)).
- Update some links to the OPA blog. The links now point to the blog on the OPA website, not the separate Medium-hosted blog ([#​2059](https://github.com/open-policy-agent/regal/issues/2059)).
#### New Contributors
- [@​kmadan](https://github.com/kmadan) made their first contribution in [#​2081](https://github.com/open-policy-agent/regal/pull/2081)
- [@​pttydou](https://github.com/pttydou) made their first contribution in [#​2077](https://github.com/open-policy-agent/regal/pull/2077)
#### Changelog
- [`9670442`](https://github.com/open-policy-agent/regal/commit/96704424fbcf37638cd41806b27072301bdf94ca): build(deps): bump linkify-it from 5.0.1 to 5.0.2 in /build ([#​2063](https://github.com/open-policy-agent/regal/issues/2063)) ([@​dependabot](https://github.com/dependabot)\[bot])
- [`44d3372`](https://github.com/open-policy-agent/regal/commit/44d33727357d558ff0866e20bad8b27feadf0b39): build(deps): bump brace-expansion from 5.0.6 to 5.0.7 in /build ([#​2061](https://github.com/open-policy-agent/regal/issues/2061)) ([@​dependabot](https://github.com/dependabot)\[bot])
- [`2e89cce`](https://github.com/open-policy-agent/regal/commit/2e89ccedc0fa0fde2eb5879d61a2f1520e57cc03): build(deps): bump the dependencies group across 1 directory with 7 updates ([#​2064](https://github.com/open-policy-agent/regal/issues/2064)) ([@​dependabot](https://github.com/dependabot)\[bot])
- [`db756a9`](https://github.com/open-policy-agent/regal/commit/db756a95ce046083f0c5a412d959e4bc5141a064): build(deps): bump js-yaml and markdownlint-cli in /build ([#​2065](https://github.com/open-policy-agent/regal/issues/2065)) ([@​dependabot](https://github.com/dependabot)\[bot])
- [`9635851`](https://github.com/open-policy-agent/regal/commit/963585147557ce3bcb89670a0ea307f8c25e54ce): docs: Update some links to OPA blog to new host ([#​2059](https://github.com/open-policy-agent/regal/issues/2059)) ([@​charlieegan3](https://github.com/charlieegan3))
- [`e3dd92f`](https://github.com/open-policy-agent/regal/commit/e3dd92f3276b58127d548900baa185eec808d43c): build(deps): bump brace-expansion from 5.0.7 to 5.0.9 in /build ([#​2067](https://github.com/open-policy-agent/regal/issues/2067)) ([@​dependabot](https://github.com/dependabot)\[bot])
- [`2d6d5ff`](https://github.com/open-policy-agent/regal/commit/2d6d5ff231712e16888ac378f607288e1c4e8e91): build(deps): bump the dependencies group with 4 updates ([#​2069](https://github.com/open-policy-agent/regal/issues/2069)) ([@​dependabot](https://github.com/dependabot)\[bot])
- [`440615b`](https://github.com/open-policy-agent/regal/commit/440615b95899847280043aeaa2a4c3995a1532cb): build(deps): bump the dependencies group with 2 updates ([#​2068](https://github.com/open-policy-agent/regal/issues/2068)) ([@​dependabot](https://github.com/dependabot)\[bot])
- [`f046663`](https://github.com/open-policy-agent/regal/commit/f04666366276d712bd52a5e7e6b78938d41182ba): build: Run all dependabots monthly ([#​2071](https://github.com/open-policy-agent/regal/issues/2071)) ([@​charlieegan3](https://github.com/charlieegan3))
- [`e9ce4a5`](https://github.com/open-policy-agent/regal/commit/e9ce4a5bd98a7d93ca7a0c7559271c5f525cfd00): OPA v1.19.0 ([#​2070](https://github.com/open-policy-agent/regal/issues/2070)) ([@​anderseknert](https://github.com/anderseknert))
- [`4f50e60`](https://github.com/open-policy-agent/regal/commit/4f50e604e7b46d8a5a1e3a0523c2a0686e302dda): build(deps): bump github.com/sourcegraph/jsonrpc2 ([#​2074](https://github.com/open-policy-agent/regal/issues/2074)) ([@​dependabot](https://github.com/dependabot)\[bot])
- [`2ed6af2`](https://github.com/open-policy-agent/regal/commit/2ed6af2d6298b4d0858c0fc86138b1a7e528e04a): build(deps): bump dprint in /build in the dependencies group ([#​2073](https://github.com/open-policy-agent/regal/issues/2073)) ([@​dependabot](https://github.com/dependabot)\[bot])
- [`b2cff49`](https://github.com/open-policy-agent/regal/commit/b2cff49c9e5ed982b915cc26c7faac698208a43f): Support the experimental `and`/`or` keywords ([#​2075](https://github.com/open-policy-agent/regal/issues/2075)) ([@​sspaink](https://github.com/sspaink))
- [`abfc0db`](https://github.com/open-policy-agent/regal/commit/abfc0dbccc274f73e7ed3de557206fee7e75cff8): internal/io: drop stale experimental-keywords capability assertion ([#​2078](https://github.com/open-policy-agent/regal/issues/2078)) ([@​sspaink](https://github.com/sspaink))
- [`f4b817f`](https://github.com/open-policy-agent/regal/commit/f4b817f5d1f9cb2d88ec1cb8d9a50bfea7ea84b5): build(deps): bump gobwas/glob to v1.0.0 and OPA to the commit that supports it ([#​2089](https://github.com/open-policy-agent/regal/issues/2089)) ([@​sspaink](https://github.com/sspaink))
- [`55418b7`](https://github.com/open-policy-agent/regal/commit/55418b71fef9798960ff5297258fee925700d9e1): build(deps): bump dprint ([#​2087](https://github.com/open-policy-agent/regal/issues/2087)) ([@​dependabot](https://github.com/dependabot)\[bot])
- [`3236e6b`](https://github.com/open-policy-agent/regal/commit/3236e6bd1b15da9235ad5dc71f34a4b26da64f48): build(deps): bump github.com/arl/statsviz ([#​2090](https://github.com/open-policy-agent/regal/issues/2090)) ([@​dependabot](https://github.com/dependabot)\[bot])
- [`d71df5d`](https://github.com/open-policy-agent/regal/commit/d71df5dd2f1faba9647bd8f81797f35cbd5abcdc): build(deps): bump the dependencies group across 1 directory with 4 updates ([#​2086](https://github.com/open-policy-agent/regal/issues/2086)) ([@​dependabot](https://github.com/dependabot)\[bot])
- [`ebf3586`](https://github.com/open-policy-agent/regal/commit/ebf35861bf5770a035dc5119314fe756dc5a963f): docs: clarify rule configuration file locations ([#​2077](https://github.com/open-policy-agent/regal/issues/2077)) ([@​pttydou](https://github.com/pttydou))
- [`529ef41`](https://github.com/open-policy-agent/regal/commit/529ef41d263607f1a58543d625d9490dcfc15711): Prepare for getting back to Regal hacking ([#​2091](https://github.com/open-policy-agent/regal/issues/2091)) ([@​anderseknert](https://github.com/anderseknert))
- [`173a897`](https://github.com/open-policy-agent/regal/commit/173a897ff4642d28099d3280ce7bd3bc607857d2): feat(rules): add bugs/unconditional-with-conditions ([#​2081](https://github.com/open-policy-agent/regal/issues/2081)) ([@​kmadan](https://github.com/kmadan))
- [`948ed07`](https://github.com/open-policy-agent/regal/commit/948ed0748ef50f57131770237699d6e6e5e552c6): Report constant `and`/`or` operands ([#​2079](https://github.com/open-policy-agent/regal/issues/2079)) ([@​sspaink](https://github.com/sspaink))
- [`bb38183`](https://github.com/open-policy-agent/regal/commit/bb381833f0296a0162367459459f74d49c68ece2): feat: add performance rule repeated-computation ([#​2026](https://github.com/open-policy-agent/regal/issues/2026)) ([@​mvanhorn](https://github.com/mvanhorn))
- [`79a32f8`](https://github.com/open-policy-agent/regal/commit/79a32f82d531021674f6906869f06ab7e59de63e): Rule: prefer-string-interpolation ([#​2092](https://github.com/open-policy-agent/regal/issues/2092)) ([@​anderseknert](https://github.com/anderseknert))
- [`3d1898b`](https://github.com/open-policy-agent/regal/commit/3d1898b6b27874e21dcbc56190b8019d0fa68627): perf: relax GC pacing for one-shot commands ([#​2095](https://github.com/open-policy-agent/regal/issues/2095)) ([@​srenatus](https://github.com/srenatus))
- [`18a6354`](https://github.com/open-policy-agent/regal/commit/18a6354afbd3f11ed1787c760a95ffbf4f86b94a): lsp: Add support for coverage in eval inline ([#​2094](https://github.com/open-policy-agent/regal/issues/2094)) ([@​charlieegan3](https://github.com/charlieegan3))
- [`530542d`](https://github.com/open-policy-agent/regal/commit/530542d159214a8568fdad444c0f3bad5ba808f6): Include `concat` in `prefer-string-interpolation` ([#​2093](https://github.com/open-policy-agent/regal/issues/2093)) ([@​anderseknert](https://github.com/anderseknert))
- [`83f08ac`](https://github.com/open-policy-agent/regal/commit/83f08acd235912b379720c5194abf24d08848cb6): OPA v1.21.0 ([#​2098](https://github.com/open-policy-agent/regal/issues/2098)) ([@​anderseknert](https://github.com/anderseknert))
- [`6df283a`](https://github.com/open-policy-agent/regal/commit/6df283a341a07853d1f78f17d42582a0e6cf75d6): Get rid of mapstructure dependency ([#​2099](https://github.com/open-policy-agent/regal/issues/2099)) ([@​anderseknert](https://github.com/anderseknert))
- [`c1c119e`](https://github.com/open-policy-agent/regal/commit/c1c119ee780e382df6aa10b19fc860d5878b41b2): Result handler functions -> interfaces ([#​2097](https://github.com/open-policy-agent/regal/issues/2097)) ([@​anderseknert](https://github.com/anderseknert))
- [`df0d0a6`](https://github.com/open-policy-agent/regal/commit/df0d0a6794344daa5f1a5905d5051b1412721b1b): Remove accidental yaml/v2 dependency ([#​2101](https://github.com/open-policy-agent/regal/issues/2101)) ([@​anderseknert](https://github.com/anderseknert))
- [`6189089`](https://github.com/open-policy-agent/regal/commit/6189089eff8c384af8a0e821f2ef9bad594970e9): Use custom `filepath.Abs` implementation ([#​2100](https://github.com/open-policy-agent/regal/issues/2100)) ([@​anderseknert](https://github.com/anderseknert))
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTYuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjExNi4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
0.42.0→0.43.0Release Notes
open-policy-agent/regal (open-policy-agent/regal)
v0.43.0Compare Source
This release brings support for OPA's experimental
and/orkeywords and three new linter rules.Note: This is the last Regal release built with Go 1.26. Starting with the next release, Regal moves to Go 1.27.
New Rule:
idiomatic/prefer-string-interpolationCategory: idiomatic
The prefer-string-interpolation rule recommends OPA's string interpolation over
sprintfandconcatwhere possible (#2092, #2093).Avoid
Prefer
New Rule:
bugs/unconditional-with-conditionsCategory: bugs
The unconditional-with-conditions rule flags a rule with an unconditional definition alongside other definitions that carry conditions. Since the unconditional definition always applies, the conditions on the others can never decide anything. Either the values differ and evaluation fails with a conflict, or the values agree and the conditional definitions are dead code. This rule was contributed by @kmadan — thanks!
Avoid
Prefer
New Rule:
performance/repeated-computationCategory: performance
The repeated-computation rule flags a deterministic built-in call, like
count(input.items), when it runs more than once in the same scope. The rule suggests assigning the result to a variable instead (#2026) — thanks @mvanhorn!Avoid
Prefer
New Feature: Experimental
and/orkeyword supportRegal can now parse and lint policies using OPA's experimental
and/orkeywords (#2075) — thanks @sspaink! This includes support in both RoAST encoders. Theconstant-conditionrule no longer reports an operand that makes up an entireand/orexpression, because removing it leaves the expression without one. A new check also reports a constantand/oroperand with a range covering the operator. Removing it then collapses the expression to the operand that is kept (#2079).Language Server Improvements
When the client indicates support for inline coverage, the language server now includes a coverage report in eval responses (#2094). See the related PR open-policy-agent/vscode-opa#498 for the client side of this feature.
Performance
One-shot commands like
lint,testandfixallocate in bulk and then exit, so garbage collecting at the default pace was largely wasted work. Relaxing the GC pacing for these commands makes Regal about 15% faster when linting its own 350+ Rego policies (#2095).Documentation
disallow-rego-v1(#2077) — thanks @pttydou!New Contributors
Changelog
9670442: build(deps): bump linkify-it from 5.0.1 to 5.0.2 in /build (#2063) (@dependabot[bot])44d3372: build(deps): bump brace-expansion from 5.0.6 to 5.0.7 in /build (#2061) (@dependabot[bot])2e89cce: build(deps): bump the dependencies group across 1 directory with 7 updates (#2064) (@dependabot[bot])db756a9: build(deps): bump js-yaml and markdownlint-cli in /build (#2065) (@dependabot[bot])9635851: docs: Update some links to OPA blog to new host (#2059) (@charlieegan3)e3dd92f: build(deps): bump brace-expansion from 5.0.7 to 5.0.9 in /build (#2067) (@dependabot[bot])2d6d5ff: build(deps): bump the dependencies group with 4 updates (#2069) (@dependabot[bot])440615b: build(deps): bump the dependencies group with 2 updates (#2068) (@dependabot[bot])f046663: build: Run all dependabots monthly (#2071) (@charlieegan3)e9ce4a5: OPA v1.19.0 (#2070) (@anderseknert)4f50e60: build(deps): bump github.com/sourcegraph/jsonrpc2 (#2074) (@dependabot[bot])2ed6af2: build(deps): bump dprint in /build in the dependencies group (#2073) (@dependabot[bot])b2cff49: Support the experimentaland/orkeywords (#2075) (@sspaink)abfc0db: internal/io: drop stale experimental-keywords capability assertion (#2078) (@sspaink)f4b817f: build(deps): bump gobwas/glob to v1.0.0 and OPA to the commit that supports it (#2089) (@sspaink)55418b7: build(deps): bump dprint (#2087) (@dependabot[bot])3236e6b: build(deps): bump github.com/arl/statsviz (#2090) (@dependabot[bot])d71df5d: build(deps): bump the dependencies group across 1 directory with 4 updates (#2086) (@dependabot[bot])ebf3586: docs: clarify rule configuration file locations (#2077) (@pttydou)529ef41: Prepare for getting back to Regal hacking (#2091) (@anderseknert)173a897: feat(rules): add bugs/unconditional-with-conditions (#2081) (@kmadan)948ed07: Report constantand/oroperands (#2079) (@sspaink)bb38183: feat: add performance rule repeated-computation (#2026) (@mvanhorn)79a32f8: Rule: prefer-string-interpolation (#2092) (@anderseknert)3d1898b: perf: relax GC pacing for one-shot commands (#2095) (@srenatus)18a6354: lsp: Add support for coverage in eval inline (#2094) (@charlieegan3)530542d: Includeconcatinprefer-string-interpolation(#2093) (@anderseknert)83f08ac: OPA v1.21.0 (#2098) (@anderseknert)6df283a: Get rid of mapstructure dependency (#2099) (@anderseknert)c1c119e: Result handler functions -> interfaces (#2097) (@anderseknert)df0d0a6: Remove accidental yaml/v2 dependency (#2101) (@anderseknert)6189089: Use customfilepath.Absimplementation (#2100) (@anderseknert)Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.