Prerequisites
ScubaGear Version
Almost v2.0.0
Operating System
Windows 11
PowerShell Version
5.1
M365 Environment and License(s)
N/A
馃悰 Summary
The latest automated OPA version bump PR to OPA v1.21.0 had it's smoke test fail. This version introduced some changes that broke ScubaGear.
Notably this one in their release notes.
In the smoke test. This file is pointed to as the culprit with a similar exception described in those release notes ScubaGear\PowerShell\ScubaGear\Rego\Utils\TestAssertions.rego:206 : rego_type_error: undefined ref: [***[0***
Tracing the error back to file indicated there. The culprit seems to be this Fail function in the Rego utils.
This is NOT one of the functions we created. The original file appears to be a lift and shift from this repo originally (one of the OPA maintainers). We do use some of the functions in this file but I don't think we use this Fail function specifically.
# METADATA
# description: Fail with provided message
Fail(msg) := [][0] if {
# regal ignore: print-or-trace-call
print(msg)
}
This is essentially a hack function to throw an exception in OPA at any time.
It trying to take the 0th index of an empty array which will fail. But before it happens it prints the message in the body.
The new changes in OPA v1.21.0 catch this error at "compile time" now instead of "run time" causing an exception when ScubaGear first invokes the OPA executable.
Fix should be just to remove this function as we don't seem to be using it. But, since they made other breaking changes in this release.
There are 2 issues that have surfaced now from updating.
Test thoroughly before bumping the version and fix anything that pops up.
Update

The unit tests action (and local) is breaking as well.
Rules := {
"SSN": [Rule.Name | some Rule in SensitiveRules; SensitiveContent[0] in Rule.ContentNames], # This line is causing the unsafe error.
"ITIN": [Rule.Name | some Rule in SensitiveRules; SensitiveContent[1] in Rule.ContentNames],
"Credit_Card": [Rule.Name | some Rule in SensitiveRules; SensitiveContent[2] in Rule.ContentNames]
}
Similar case. If Rule.ContentNames is an empty array SensitiveContent[0] would throw an exception.
OPA doesn't like that.
Steps to reproduce
- Update ScubaGear's pinned OPA version to
v1.21.0. This requires manually downloading it or updating the Pinned OPA in the ScubaGearConfigDefaults.
- Attempt to run ScubaGear
Expected behavior
For ScubaGear not to crash.
Prerequisites
ScubaGear Version
Almost v2.0.0
Operating System
Windows 11
PowerShell Version
5.1
M365 Environment and License(s)
N/A
馃悰 Summary
The latest automated OPA version bump PR to OPA v1.21.0 had it's smoke test fail. This version introduced some changes that broke ScubaGear.
Notably this one in their release notes.
In the smoke test. This file is pointed to as the culprit with a similar exception described in those release notes
ScubaGear\PowerShell\ScubaGear\Rego\Utils\TestAssertions.rego:206 : rego_type_error: undefined ref: [***[0***Tracing the error back to file indicated there. The culprit seems to be this
Failfunction in the Rego utils.This is NOT one of the functions we created. The original file appears to be a lift and shift from this repo originally (one of the OPA maintainers). We do use some of the functions in this file but I don't think we use this
Failfunction specifically.This is essentially a hack function to throw an exception in OPA at any time.
It trying to take the 0th index of an empty array which will fail. But before it happens it prints the message in the body.
The new changes in OPA v1.21.0 catch this error at "compile time" now instead of "run time" causing an exception when ScubaGear first invokes the OPA executable.
Fix should be just to remove this function as we don't seem to be using it. But, since they made other breaking changes in this release.There are 2 issues that have surfaced now from updating.
Test thoroughly before bumping the version and fix anything that pops up.
Update
Similar case. If
Rule.ContentNamesis an empty arraySensitiveContent[0]would throw an exception.OPA doesn't like that.
Steps to reproduce
v1.21.0. This requires manually downloading it or updating the Pinned OPA in the ScubaGearConfigDefaults.Expected behavior
For ScubaGear not to crash.