PageSourceSearch

https://www.openpolicyagent.org/assets/js/b81d7f5e.609dce75.js

js openpolicyagent.org collected 2026-09-24 08:27:40 UTC 9,458 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkopa_website=self.webpackChunkopa_website||[]).push([[887],{28453:(e,n,i)=>{i.d(n,{R:()=>c,x:()=>l});var r=i(96540);const s={},t=r.createContext(s);function c(e){const n=r.useContext(t);return r.useMemo((function(){return"function"==typeof e?e(n):{...n,...e}}),[n,e])}function l(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:c(e.components),r.createElement(t.Provider,{value:n},e.children)}},32961:(e,n,i)=>{i.r(n),i.d(n,{assets:()=>o,contentTitle:()=>l,default:()=>u,frontMatter:()=>c,metadata:()=>r,toc:()=>a});const r=JSON.parse('{"id":"rules/bugs/deprecated-builtin","title":"deprecated-builtin","description":"Summary: Avoid using deprecated built-in functions","source":"@site/projects/regal/rules/bugs/deprecated-builtin.md","sourceDirName":"rules/bugs","slug":"/rules/bugs/deprecated-builtin","permalink":"/projects/regal/rules/bugs/deprecated-builtin","draft":false,"unlisted":false,"tags":[],"version":"current","frontMatter":{},"sidebar":"autoSidebar","previous":{"title":"constant-condition","permalink":"/projects/regal/rules/bugs/constant-condition"},"next":{"title":"duplicate-rule","permalink":"/projects/regal/rules/bugs/duplicate-rule"}}');var s=i(74848),t=i(28453);const c={},l="deprecated-builtin",o={},a=[{value:"Notice: Rule disabled with OPA 1.0",id:"notice-rule-disabled-with-opa-10",level:2},{value:"Rationale",id:"rationale",level:2},{value:"Replacing Deprecated Built-in Functions",id:"replacing-deprecated-built-in-functions",level:2},{value:"<code>any</code>",id:"any",level:3},{value:"<code>all</code>",id:"all",level:3},{value:"<code>set_diff</code>",id:"set_diff",level:3},{value:"<code>re_match</code> and <code>net.cidr_overlap</code>",id:"re_match-and-netcidr_overlap",level:3},{value:"<code>cast_array</code>, <code>cast_set</code>, <code>cast_string</code>, <code>cast_boolean</code>, <code>cast_null</code>, <code>cast_object</code>",id:"cast_array-cast_set-cast_string-cast_boolean-cast_null-cast_object",level:3},{value:"Configuration Options",id:"configuration-options",level:2},{value:"Related Resources",id:"related-resources",level:2}];function d(e){const n={a:"a",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,t.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(n.header,{children:(0,s.jsx)(n.h1,{id:"deprecated-builtin",children:"deprecated-builtin"})}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"Summary"}),": Avoid using deprecated built-in functions"]}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"Category"}),": Bugs"]}),"\n",(0,s.jsx)(n.h2,{id:"notice-rule-disabled-with-opa-10",children:"Notice: Rule disabled with OPA 1.0"}),"\n",(0,s.jsxs)(n.p,{children:["Since Regal v0.30.0, this rule is only enabled for projects that have either been explicitly configured to target\nversions of OPA before 1.0, or if no configuration is provided \u2014 where Regal is able to determine that an older version\nof OPA/Rego is being targeted. Consult the documentation on Regal's\n",(0,s.jsx)(n.a,{href:"https://www.openpolicyagent.org/projects/regal#configuration",children:"configuration"})," for information on how to best work with older versions of\nOPA and Rego."]}),"\n",(0,s.jsx)(n.p,{children:"Since OPA v1.0, this rule is automatically disabled, as there currently are no deprecated built-in functions\nin that version, and trying to use a previously deprecated function will result in a parser error. Note however that\nthis may change if later OPA versions deprecate current built-in functions. If/when that happens, this rule will be\nre-enabled."}),"\n",(0,s.jsx)(n.p,{children:(0,s.jsx)(n.strong,{children:"Avoid"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-rego",children:"package policy\n\nimport future.keywords.if\n\n# call to deprecated `any` built-in function\nallow if any([input.user.is_admin, input.user.is_root])\n"})}),"\n",(0,s.jsx)(n.p,{children:(0,s.jsx)(n.strong,{children:"Prefer"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-rego",children:"package policy\n\nimport future.keywords.if\n\nallow if input.user.is_admin\nallow if input.user.is_root\n"})}),"\n",(0,s.jsx)(n.h2,{id:"rationale",children:"Rationale"}),"\n",(0,s.jsx)(n.p,{children:"Calling deprecated built-in functions should always be avoided, and replacing them is usually trivial."}),"\n",(0,s.jsx)(n.h2,{id:"replacing-deprecated-built-in-functions",children:"Replacing Deprecated Built-in Functions"}),"\n",(0,s.jsx)(n.h3,{id:"any",children:(0,s.jsx)(n.code,{children:"any"})}),"\n",(0,s.jsxs)(n.p,{children:["Use the ",(0,s.jsx)(n.code,{children:"in"})," keyword (OPA v0.34.0+) to replace the ",(0,s.jsx)(n.code,{children:"any"})," function:"]}),"\n",(0,s.jsx)(n.p,{children:(0,s.jsx)(n.strong,{children:"Instead of"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-rego",children:"a := any([input.foo, input.bar])\n"})}),"\n",(0,s.jsx)(n.p,{children:(0,s.jsx)(n.strong,{children:"Do this"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-rego",children:"import future.keywords.in # or `import rego.v1` (OPA v0.59.0+)\n\na := true in [input.foo, input.bar]\n"})}),"\n",(0,s.jsxs)(n.p,{children:["Using ",(0,s.jsx)(n.code,{children:"in"})," additionally has the benefit that it can be used to check for any type of value, and not just boolean\n",(0,s.jsx)(n.code,{children:"true"}),"!"]}),"\n",(0,s.jsx)(n.h3,{id:"all",children:(0,s.jsx)(n.code,{children:"all"})}),"\n",(0,s.jsxs)(n.p,{children:["Use the ",(0,s.jsx)(n.code,{children:"every"})," keyword (OPA v0.34.0+) to replace the ",(0,s.jsx)(n.code,{children:"all"})," function:"]}),"\n",(0,s.jsx)(n.p,{children:(0,s.jsx)(n.strong,{children:"Instead of"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-rego",children:"a {\n    all([input.foo, input.bar])\n}\n"})}),"\n",(0,s.jsx)(n.p,{children:(0,s.jsx)(n.strong,{children:"Do this"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-rego",children:"import future.keywords.every # or `import rego.v1` (OPA v0.59.0+)\n\na {\n    every x in [input.foo, input.bar] {\n        x == true\n    }\n}\n"})}),"\n",(0,s.jsxs)(n.p,{children:["Just like ",(0,s.jsx)(n.code,{children:"in"})," may be used for much more than ",(0,s.jsx)(n.code,{children:"any"}),", ",(0,s.jsx)(n.code,{children:"every"})," can be used to evaluate complex expressions!"]}),"\n",(0,s.jsx)(n.h3,{id:"set_diff",children:(0,s.jsx)(n.code,{children:"set_diff"})}),"\n",(0,s.jsxs)(n.p,{children:["Use the minus (",(0,s.jsx)(n.code,{children:"-"}),") operator instead, of ",(0,s.jsx)(n.code,{children:"set_diff"}),":"]}),"\n",(0,s.jsx)(n.p,{children:(0,s.jsx)(n.strong,{children:"Instead of"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-rego",children:"a := set_diff(s1, s2)\n"})}),"\n",(0,s.jsx)(n.p,{children:(0,s.jsx)(n.strong,{children:"Do this"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-rego",children:"a := s1 - s2\n"})}),"\n",(0,s.jsxs)(n.h3,{id:"re_match-and-netcidr_overlap",children:[(0,s.jsx)(n.code,{children:"re_match"})," and ",(0,s.jsx)(n.code,{children:"net.cidr_overlap"})]}),"\n",(0,s.jsxs)(n.p,{children:["These built-in function were renamed ",(0,s.jsx)(n.code,{children:"regex.match"})," and ",(0,s.jsx)(n.code,{children:"net.cidr_intersects"})," respectively, so simply use the new names\ninstead."]}),"\n",(0,s.jsxs)(n.h3,{id:"cast_array-cast_set-cast_string-cast_boolean-cast_null-cast_object",children:[(0,s.jsx)(n.code,{children:"cast_array"}),", ",(0,s.jsx)(n.code,{children:"cast_set"}
1),", ",(0,s.jsx)(n.code,{children:"cast_string"}),", ",(0,s.jsx)(n.code,{children:"cast_boolean"}),", ",(0,s.jsx)(n.code,{children:"cast_null"}),", ",(0,s.jsx)(n.code,{children:"cast_object"})]}),"\n",(0,s.jsxs)(n.p,{children:["Use the ",(0,s.jsx)(n.code,{children:"is_X"})," equivalent built-in function in their place:"]}),"\n",(0,s.jsx)(n.p,{children:(0,s.jsx)(n.strong,{children:"Instead of"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-rego",children:"a {\n    cast_string(input.name)\n}\n"})}),"\n",(0,s.jsx)(n.p,{children:(0,s.jsx)(n.strong,{children:"Do this"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-rego",children:"a {\n    is_string(input.name)\n}\n"})}),"\n",(0,s.jsx)(n.h2,{id:"configuration-options",children:"Configuration Options"}),"\n",(0,s.jsx)(n.p,{children:"This linter rule provides the following configuration options:"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-yaml",children:'rules:\n  bugs:\n    deprecated-builtin:\n      # one of "error", "warning", "ignore"\n      level: error\n'})}),"\n",(0,s.jsx)(n.h2,{id:"related-resources",children:"Related Resources"}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsxs)(n.li,{children:["OPA Docs: ",(0,s.jsx)(n.a,{href:"https://www.openpolicyagent.org/docs/policy-language/#strict-mode",children:"Strict Mode"})]}),"\n",(0,s.jsxs)(n.li,{children:["GitHub: ",(0,s.jsx)(n.a,{href:"https://github.com/open-policy-agent/regal/blob/main/bundle/regal/rules/bugs/deprecated-builtin/deprecated_builtin.rego",children:"Source Code"})]}),"\n"]})]})}function u(e={}){const{wrapper:n}={...(0,t.R)(),...e.components};return n?(0,s.jsx)(n,{...e,children:(0,s.jsx)(d,{...e})}):d(e)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.