Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

OPA’s documentation says a leading v makes a SemVer string invalid, yet the same page shows semver.is_valid("v1.1.12-rc1+foo") returning true. The SemVer 2.0.0 specification says v1.2.3 is not a semantic version. That is a documentation conflict—not proof of how any particular OPA release evaluates the input.

What does OPA document?

OPA describes semver.is_valid(vsn) as a built-in that accepts vsn (any) and returns a boolean: true for a valid semantic version and false otherwise. The reference describes the version format as MAJOR.MINOR.PATCH[-PRERELEASE][+METADATA], with the bracketed parts optional. It lists the built-in as available beginning with OPA v0.22.0 and notes that WebAssembly support is SDK-dependent. OPA’s Semantic Version Built-ins reference

The conflict is within that reference. Its warning says: “When working with Go-style semantic versions, remember to remove the leading v character, or the semver string will be marked as invalid!” But its example output marks both semver.is_valid("v1.1.12-rc1+foo") and semver.is_valid("1.1.12-rc1+foo") as true. The warning and the displayed result do not straightforwardly agree about the same input.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why does SemVer reject a leading v?

In SemVer 2.0.0, a version has three numeric core components—major, minor, and patch—written as X.Y.Z. Prerelease identifiers can follow a hyphen, and build metadata can follow a plus sign. The specification also disallows leading zeroes in those numeric components.

Its FAQ answers the prefix question directly: “No, ‘v1.2.3’ is not a semantic version.” A leading v is often used in a tag name or as notation indicating a version, but it is not part of the SemVer string itself. Under the specification, 1.2.3 is the semantic version. Semantic Versioning 2.0.0

Does a specific OPA release accept v1.2.3?

The documentation conflict alone does not establish runtime behavior for a particular OPA release or evaluator. Keep two questions separate: whether the input conforms to SemVer 2.0.0, and what a particular OPA build does when semver.is_valid receives it. The specification answers the first; the contradictory example does not settle the second.

OPA’s Operations documentation shows the built-in used as a policy predicate, for example semver.is_valid(input.version). It also explains that capabilities files can be used to check built-in compatibility for policies. Those compatibility details address whether a policy can use a built-in in a given environment; they do not resolve whether a leading-v input is accepted by a specific evaluator. OPA Operations

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Game Programming Patterns
  • Brand New in box. The product ships with all relevant accessories
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should you handle a leading-v value?

  1. Define the input contract. Decide whether the field must contain a SemVer string or may contain a tag or other version notation. If the contract requires SemVer 2.0.0, a leading v is outside that format.
  2. Check the actual environment. Confirm the OPA release and evaluator in use, then verify the result there rather than treating the documentation example as conclusive for every release.
  3. Normalize only when appropriate. If your input contract treats a leading-v tag as a representation of a SemVer version, remove the prefix before validation. Do not silently normalize if the prefix has meaning in your application or if the contract requires the original value to be preserved.
  4. Check built-in compatibility separately. Use the capabilities information for the target environment to confirm policy compatibility; that check is distinct from testing the input format.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.