1<!doctype html> 2<html lang="en" dir="ltr" class="mdx-wrapper mdx-page plugin-pages plugin-id-default" data-has-hydrated="false"> 3<head> 4<meta charset="UTF-8"> 5<meta name="generator" content="Docusaurus v3.10.2"> 6<title data-rh="true">Security Policy | Open Policy Agent</title><meta data-rh="true" name="viewport" content="width=device-width,initial-scale=1"><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" property="og:url" content="https://openpolicyagent.org/security"><meta data-rh="true" property="og:locale" content="en"><meta data-rh="true" name="docusaurus_locale" content="en"><meta data-rh="true" name="docusaurus_tag" content="default"><meta data-rh="true" name="docsearch:language" content="en"><meta data-rh="true" name="docsearch:docusaurus_tag" content="default"><meta data-rh="true" name="msapplication-TileColor" content="#2b5797"><meta data-rh="true" name="theme-color" content="#ffffff"><meta data-rh="true" property="og:title" content="Security Policy | Open Policy Agent"><meta data-rh="true" name="description" content="The Open Policy Agent (OPA) community has adopted this security disclosures and"><meta data-rh="true" property="og:description" content="The Open Policy Agent (OPA) community has adopted this security disclosures and"><link data-rh="true" rel="canonical" href="https://openpolicyagent.org/security"><link data-rh="true" rel="alternate" href="https://openpolicyagent.org/security" hreflang="en"><link data-rh="true" rel="alternate" href="https://openpolicyagent.org/security" hreflang="x-default"><link data-rh="true" href="/pagefind/pagefind-component-ui.css" rel="stylesheet">
6<script data-rh="true" src="/pagefind/pagefind-component-ui.js" type="module"></script>
6<link rel="alternate" type="application/rss+xml" href="/blog/rss.xml" title="Open Policy Agent Blog RSS Feed"> 7<link rel="alternate" type="application/atom+xml" href="/blog/atom.xml" title="Open Policy Agent Blog Atom Feed"> 8 9 10 11 12<link rel="preconnect" href="https://www.google-analytics.com"> 13<link rel="preconnect" href="https://www.googletagmanager.com">
vendor: 64 bytes, lines 13-14
13 14<script async src="https://www.googletagmanager.com/gtag/js?id=
14G-JNBNV64PDX
vendor: 12 bytes, line 14
14"></script>
15<script>function gtag(){dataLayer.push(arguments)}window.dataLayer=window.dataLayer||[],gtag("js",new Date),gtag("config","G-JNBNV64PDX",{anonymize_ip:!0})</script>
15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35<link rel="stylesheet" href="https://unpkg.com/@antonz/[email protected]/dist/snippet.css">
36<script src="https://unpkg.com/@antonz/[email protected]/dist/snippet.js" defer="defer"></script>
vendor: 1 bytes, line 36
36
37<script src="https://widget.kapa.ai/kapa-widget.bundle.js" data-website-id="5c4af137-a024-4ba2-9488-826f1055852c" data-project-name="Open Policy Agent" data-project-logo="https://openpolicyagent.org/img/nav/logo.png" data-search-mode-enabled="false" data-deep-thinking-button-hover-background-color="#f1f8f1" data-deep-thinking-button-hover-color="#2e7d32" data-deep-thinking-button-enabled-background-color="#e8f5e9" data-deep-thinking-button-enabled-color="#2e7d32" data-deep-thinking-button-enabled-hover-background-color="#c8e6c9" data-deep-thinking-button-enabled-hover-color="#1b5e20" data-deep-thinking-button-hover-background-color-dark="#1e3320" data-deep-thinking-button-hover-color-dark="#81c784" data-deep-thinking-button-enabled-background-color-dark="#1a3d1c" data-deep-thinking-button-enabled-color-dark="#a5d6a7" data-deep-thinking-button-enabled-hover-background-color-dark="#245427" data-deep-thinking-button-enabled-hover-color-dark="#c8e6c9" data-modal-title="OPA Documentation Chat" data-color-scheme-selector="[data-theme='dark']" data-launcher-button-hidden="true" async></script>
37<link rel="stylesheet" href="/assets/css/styles.249294ae.css">
38<script src="/assets/js/runtime~main.4dc2c317.js" defer="defer"></script>
vendor: 1 bytes, line 38
38
39<script src="/assets/js/main.15b0de56.js" defer="defer"></script>
vendor: 65 bytes, lines 39-41
39 40 41<script async src="https://www.googletagmanager.com/gtag/js?id=
41G-JNBNV64PDX
vendor: 12 bytes, line 41
41"></script>
42<script> 43
vendor: 134 bytes, lines 43-47
43window.dataLayer = window.dataLayer || []; 44 function gtag(){dataLayer.push(arguments);} 45 gtag('js', new Date()); 46 47 gtag('config', '
47G-JNBNV64PDX
vendor: 4 bytes, line 47
47');
48</script>
48 49</head> 50<body> 51<svg style="display: none;"><defs> 52<symbol id="theme-svg-external-link" viewBox="0 0 24 24"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"/></symbol> 53</defs></svg>
54<script>!function(){var t=function(){try{return new URLSearchParams(window.location.search).get("docusaurus-theme")}catch(t){}}()||function(){try{return window.localStorage.getItem("theme")}catch(t){}}();document.documentElement.setAttribute("data-theme",t||(window.matchMedia("(prefers-color-scheme: dark)").matches?"dark":"light")),document.documentElement.setAttribute("data-theme-choice",t||"system")}(),function(){try{const c=new URLSearchParams(window.location.search).entries();for(var[t,e]of c)if(t.startsWith("docusaurus-data-")){var a=t.replace("docusaurus-data-","data-");document.documentElement.setAttribute(a,e)}}catch(t){}}()</script>
54<div id="__docusaurus"><link rel="preload" as="image" href="/img/nav/logo.png"><div role="region" aria-label="Skip to main content"><a class="skipToContent_fXgn" href="#__docusaurus_skipToContent_fallback">Skip to main content</a></div><nav aria-label="Main" class="theme-layout-navbar navbar navbar--fixed-top"><div class="navbar__inner"><div class="theme-layout-navbar-left navbar__items"><button aria-label="Toggle navigation bar" aria-expanded="false" class="navbar__toggle clean-btn" type="button"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/"><div class="navbar__logo"><img src="/img/nav/logo.png" alt="OPA Logo" class="themedComponent_mlkZ themedComponent--light_NVdE"><img src="/img/nav/logo.png" alt="OPA Logo" class="themedComponent_mlkZ themedComponent--dark_xIcU"></div><b class="navbar__title text--truncate">Open Policy Agent</b></a></div><div class="theme-layout-navbar-right navbar__items navbar__items--right"><a class="navbar__item navbar__link" href="/docs">Docs</a><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">Resources</a><ul class="dropdown__menu"><li><a aria-current="page" class="dropdown__link dropdown__link--active" href="/security">Security</a></li><li><a class="dropdown__link" href="/support">Support</a></li><li><a class="dropdown__link" href="/community">Community</a></li><li><a class="dropdown__link" href="/survey">Survey</a></li><li><a class="dropdown__link" href="/blog">Blog</a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">Projects</a><ul class="dropdown__menu"><li><a class="dropdown__link" href="/docs">OPA</a></li><li><a class="dropdown__link" href="/projects/regal">Regal</a></li><li class=""><hr style="margin: 0.3rem 1rem"></li><li><a href="https://open-policy-agent.github.io/gatekeeper/website/" target="_blank" rel="noopener noreferrer" class="dropdown__link">OPA Gatekeeper<svg width="12" height="12" aria-label="(opens in new tab)" class="iconExternalLink_nPIU"><use href="#theme-svg-external-link"></use></svg></a></li><li><a href="https://www.conftest.dev" target="_blank" rel="noopener noreferrer" class="dropdown__link">Conftest<svg width="12" height="12" aria-label="(opens in new tab)" class="iconExternalLink_nPIU"><use href="#theme-svg-external-link"></use></svg></a></li></ul></div><a class="navbar__item navbar__link" href="/ecosystem">Ecosystem</a><a href="https://play.openpolicyagent.org/" target="_blank" rel="noopener noreferrer" class="navbar__item navbar__link">Play<svg width="13.5" height="13.5" aria-label="(opens in new tab)" class="iconExternalLink_nPIU"><use href="#theme-svg-external-link"></use></svg></a><div class="navbar__item"><a href="https://github.com/open-policy-agent" target="_blank" rel="noopener noreferrer" aria-label="GitHub repository" class="iconButton_Mvpl"><svg viewBox="0 0 24 24" class="icon_o_fq" aria-hidden="true"><path fill="currentColor" d="M12,2A10,10 0 0,0 2,12C2,16.42 4.87,20.17 8.84,21.5C9.34,21.58 9.5,21.27 9.5,21C9.5,20.77 9.5,20.14 9.5,19.31C6.73,19.91 6.14,17.97 6.14,17.97C5.68,16.81 5.03,16.5 5.03,16.5C4.12,15.88 5.1,15.9 5.1,15.9C6.1,15.97 6.63,16.93 6.63,16.93C7.5,18.45 8.97,18 9.54,17.76C9.63,17.11 9.89,16.67 10.17,16.42C7.95,16.17 5.62,15.31 5.62,11.5C5.62,10.39 6,9.5 6.65,8.79C6.55,8.54 6.2,7.5 6.75,6.15C6.75,6.15 7.59,5.88 9.5,7.17C10.29,6.95 11.15,6.84 12,6.84C12.85,6.84 13.71,6.95 14.5,7.17C16.41,5.88 17.25,6.15 17.25,6.15C17.8,7.5 17.45,8.54 17.35,8.79C18,9.5 18.38,10.39 18.38,11.5C18.38,15.32 16.04,16.16 13.81,16.41C14.17,16.72 14.5,17.33 14.5,18.26C14.5,19.6 14.5,20.68 14.5,21C14.5,21.27 14.66,21.59 15.17,21.5C19.14,20.16 22,16.42 22,12A10,10 0 0,0 12,2Z"></path></svg></a></div><div class="navbar__item"><a href="https://slack.openpolicyagent.org/" target="_blank" rel="noopener noreferrer" aria-label="Slack community" class="iconButton_Mvpl"><svg viewBox="0 0 24 24" class="icon_o_fq" aria-hidden="true">
54<path fill="currentColor" d="M6,15A2,2 0 0,1 4,17A2,2 0 0,1 2,15A2,2 0 0,1 4,13H6V15M7,15A2,2 0 0,1 9,13A2,2 0 0,1 11,15V20A2,2 0 0,1 9,22A2,2 0 0,1 7,20V15M9,7A2,2 0 0,1 7,5A2,2 0 0,1 9,3A2,2 0 0,1 11,5V7H9M9,8A2,2 0 0,1 11,10A2,2 0 0,1 9,12H4A2,2 0 0,1 2,10A2,2 0 0,1 4,8H9M17,10A2,2 0 0,1 19,8A2,2 0 0,1 21,10A2,2 0 0,1 19,12H17V10M16,10A2,2 0 0,1 14,12A2,2 0 0,1 12,10V5A2,2 0 0,1 14,3A2,2 0 0,1 16,5V10M14,18A2,2 0 0,1 16,20A2,2 0 0,1 14,22A2,2 0 0,1 12,20V18H14M14,17A2,2 0 0,1 12,15A2,2 0 0,1 14,13H19A2,2 0 0,1 21,15A2,2 0 0,1 19,17H14Z"></path></svg></a></div><div class="item_ug64 navbar__item"><div class="toggle_MW0i colorModeToggle_DEke"><button class="clean-btn toggleButton_yw5v toggleButtonDisabled_BJd7" type="button" disabled="" title="Switch between dark and light mode (currently light mode)" aria-label="Switch between dark and light mode (currently light mode)" aria-live="polite" aria-pressed="false"><svg viewBox="0 0 24 24" width="24" height="24" class="lightToggleIcon_SFTY"><path fill="currentColor" d="M12,9c1.65,0,3,1.35,3,3s-1.35,3-3,3s-3-1.35-3-3S10.35,9,12,9 M12,7c-2.76,0-5,2.24-5,5s2.24,5,5,5s5-2.24,5-5 S14.76,7,12,7L12,7z M2,13l2,0c0.55,0,1-0.45,1-1s-0.45-1-1-1l-2,0c-0.55,0-1,0.45-1,1S1.45,13,2,13z M20,13l2,0c0.55,0,1-0.45,1-1 s-0.45-1-1-1l-2,0c-0.55,0-1,0.45-1,1S19.45,13,20,13z M11,2v2c0,0.55,0.45,1,1,1s1-0.45,1-1V2c0-0.55-0.45-1-1-1S11,1.45,11,2z M11,20v2c0,0.55,0.45,1,1,1s1-0.45,1-1v-2c0-0.55-0.45-1-1-1C11.45,19,11,19.45,11,20z M5.99,4.58c-0.39-0.39-1.03-0.39-1.41,0 c-0.39,0.39-0.39,1.03,0,1.41l1.06,1.06c0.39,0.39,1.03,0.39,1.41,0s0.39-1.03,0-1.41L5.99,4.58z M18.36,16.95 c-0.39-0.39-1.03-0.39-1.41,0c-0.39,0.39-0.39,1.03,0,1.41l1.06,1.06c0.39,0.39,1.03,0.39,1.41,0c0.39-0.39,0.39-1.03,0-1.41 L18.36,16.95z M19.42,5.99c0.39-0.39,0.39-1.03,0-1.41c-0.39-0.39-1.03-0.39-1.41,0l-1.06,1.06c-0.39,0.39-0.39,1.03,0,1.41 s1.03,0.39,1.41,0L19.42,5.99z M7.05,18.36c0.39-0.39,0.39-1.03,0-1.41c-0.39-0.39-1.03-0.39-1.41,0l-1.06,1.06 c-0.39,0.39-0.39,1.03,0,1.41s1.03,0.39,1.41,0L7.05,18.36z"></path></svg><svg viewBox="0 0 24 24" width="24" height="24" class="darkToggleIcon_ekgs"><path fill="currentColor" d="M9.37,5.51C9.19,6.15,9.1,6.82,9.1,7.5c0,4.08,3.32,7.4,7.4,7.4c0.68,0,1.35-0.09,1.99-0.27C17.45,17.19,14.93,19,12,19 c-3.86,0-7-3.14-7-7C5,9.07,6.81,6.55,9.37,5.51z M12,3c-4.97,0-9,4.03-9,9s4.03,9,9,9s9-4.03,9-9c0-0.46-0.04-0.92-0.1-1.36 c-0.98,1.37-2.58,2.26-4.4,2.26c-2.98,0-5.4-2.42-5.4-5.4c0-1.81,0.89-3.42,2.26-4.4C12.92,3.04,12.46,3,12,3L12,3z"></path></svg></button></div></div><div class="item_VFEI navbar__item"><button class="searchButton_t6wW" aria-label="Search"><span></span><span class="searchText_maYD">Search</span></button></div><div class="item_pPdM navbar__item"><button class="chatButton_CMgU" aria-label="Ask AI"><span></span><span>Ask AI</span></button></div><div class="navbarSearchContainer_Bca1"></div></div></div><div role="presentation" class="navbar-sidebar__backdrop"></div></nav><div id="__docusaurus_skipToContent_fallback" class="theme-layout-main main-wrapper mainWrapper_z2l0"><main class="container container--fluid margin-vert--lg"><div class="row mdxPageWrapper_j9I6"><div class="col col--8"><article><header><h1>Security Policy</h1></header> 55<p>The Open Policy Agent (OPA) community has adopted this security disclosures and 56response policy to ensure we responsibly handle critical issues.</p> 57<hr> 58<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="reporting-a-security-bug">Reporting a Security Bug<a href="#reporting-a-security-bug" class="hash-link" aria-label="Direct link to Reporting a Security Bug" title="Direct link to Reporting a Security Bug" translate="no">â</a></h2> 59<ul> 60<li class=""> 61<p>Before reporting a suspected security issue, make sure to read the documentation on OPA's 62<a href="https://www.openpolicyagent.org/docs/security" target="_blank" rel="noopener noreferrer" class="">security</a> model. Attack vectors that depend on the OPA server running 63without authentication/authorization enabled will not be considered, as none of OPAs APIs are protected at that point.</p> 64</li> 65<li class=""> 66<p>If you think you have found a security issue in an OPA project, please send an email to 67<a href="mailto:[email protected]" target="_blank" rel="noopener noreferrer" class="">[email protected]</a>. 68This list is delivered to a small security team. We will then acknowledge receipt of your report and prioritize initial analysis of severity.</p> 69</li> 70<li class=""> 71<p>After the initial reply to your report, the security team will endeavor to keep you informed of the progress being made towards a fix and full announcement, and may ask for additional information or guidance surrounding the reported issue.</p> 72</li> 73<li class=""> 74<p>If you have not received a reply to your report within two days, please reach out on our <a href="https://slack.openpolicyagent.org" target="_blank" rel="noopener noreferrer" class="">Slack</a> by posting a message in the <code>#contributors</code> channel.</p> 75</li> 76<li class=""> 77<p>Note that the <code>#contributors</code> channel is public, so please don't discuss details of your issue there. Instead, simply say that you're trying to get a hold of someone from the security team.</p> 78</li> 79</ul> 80<hr> 81<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="disclosure-policy">
81Disclosure Policy<a href="#disclosure-policy" class="hash-link" aria-label="Direct link to Disclosure Policy" title="Direct link to Disclosure Policy" translate="no">â</a></h2> 82<ol> 83<li class=""> 84<p>The security report is received and is assigned a primary handler. This person will coordinate the fix and release process. 85The problem is confirmed and a list of all affected versions is determined. Code is audited to find any potential similar problems. 86Fixes are prepared for all releases which are still under maintenance. These fixes are not committed to the public repository but rather held locally or in a private fork pending the announcement.</p> 87</li> 88<li class=""> 89<p>A suggested embargo date for this vulnerability is chosen and a CVE (Common Vulnerabilities and Exposures (CVE®)) is requested for the vulnerability, through the GitHub Advisory database.</p> 90</li> 91<li class=""> 92<p>A prenotification may be published on the security announcements channels listed below, providing information about affected projects, severity, and the embargo date.</p> 93</li> 94<li class=""> 95<p>On the embargo date, the announcement is published. The changes are pushed to the public repository and new builds are deployed.</p> 96</li> 97<li class=""> 98<p>Typically the embargo date will be set 72 hours from the time the CVE is issued. However, this may vary depending on the severity of the bug or difficulty in applying a fix.</p> 99</li> 100<li class=""> 101<p>This process can take some time, especially when coordination is required with maintainers of other projects. Every effort will be made to handle the bug in as timely a manner as possible; however, itâs important that we follow the release process above to ensure that the disclosure is handled in a consistent manner.</p> 102</li> 103</ol> 104<hr> 105<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="receiving-security-updates">Receiving Security Updates<a href="#receiving-security-updates" class="hash-link" aria-label="Direct link to Receiving Security Updates" title="Direct link to Receiving Security Updates" translate="no">â</a></h2> 106<ul> 107<li class=""><a href="https://github.com/open-policy-agent/opa/security/advisories" target="_blank" rel="noopener noreferrer" class="">Security Advisories for OPA</a></li> 108<li class=""><a href="https://github.com/orgs/open-policy-agent/discussions/categories/announcements" target="_blank" rel="noopener noreferrer" class="">GitHub Discussions Announcements</a></li> 109<li class=""><a href="https://slack.openpolicyagent.org" target="_blank" rel="noopener noreferrer" class="">Slack</a> <code>#announcements</code> channel</li> 110<li class=""><a href="https://nvd.nist.gov/vuln/search/results?form_type=Advanced&results_type=overview&search_type=all&isCpeNameSearch=false&cpe_vendor=cpe%3A%2F%3Aopenpolicyagent&cpe_product=cpe%3A%2F%3Aopenpolicyagent%3Aopen_policy_agent" target="_blank" rel="noopener noreferrer" class="">NIST Vulnerability Database: Search Results for OPA</a></li> 111</ul></article></div><div class="col col--2"><div class="tableOfContents_bqdL thin-scrollbar"><ul class="table-of-contents table-of-contents__left-border"><li><a href="#reporting-a-security-bug" class="table-of-contents__link toc-highlight">Reporting a Security Bug</a></li><li><a href="#disclosure-policy" class="table-of-contents__link toc-highlight">Disclosure Policy</a></li><li><a href="#receiving-security-updates" class="table-of-contents__link toc-highlight">Receiving Security Updates</a></li></ul></div></div></div></main></div><footer class="theme-layout-footer footer"><div class="container container-fluid"><div class="footer__bottom text--center"><div class="footer__copyright">Open Policy Agent is a <a href="https://www.cncf.io/">Cloud Native Computing Foundation</a> Graduated project. 112 113<img src="/img/footer/cncf-light.svg" alt="CNCF Logo" class="light-only" style="max-width: 10rem; vertical-align: middle; margin: 0 10px;"> 114<img src="/img/footer/cncf-dark.svg" alt="CNCF Logo" class="dark-only" style="max-width: 10rem; vertical-align: middle; margin: 0 10px;"> 115<br> 116 117© 2026 118Open Policy Agent contributors. 119<a href="https://github.com/open-policy-agent/opa/blob/main/LICENSE">Licensed under the Apache License, Version 2.0</a>. 120See the <a href="/docs/contributing">contributing documentation</a> for information about contributing. 121 122The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our Trademark Usage page.</div></div></div></footer></div> 123</body> 124</html>
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.