Anna Paykina
03/09/2026, 11:20 AMLisa Dziuba
03/10/2026, 10:25 AMLisa Dziuba
03/12/2026, 10:22 AMLisa Dziuba
03/20/2026, 3:07 PMLisa Dziuba
03/26/2026, 4:08 PMAnna Paykina
04/07/2026, 1:06 PMAnna Paykina
04/10/2026, 5:34 PMAnna Paykina
04/14/2026, 1:44 PMAnna Paykina
04/22/2026, 4:13 PMGitHub
04/28/2026, 6:16 AMGitHub
05/05/2026, 11:34 AMcerbos/actions (#3120)
• 2e8e054 Move Helm release to its own workflow (#3135)
• 7cd3152 Move path functions documentation to correct place (#3139)
• d72ef61 Remove JWT verification cache (#3138)
• 5028a6f Remove voxmedia/github-action-slack-notify-build (#3129)
• ccc98e9 Remove incorrect default tag value from Helm chart (#3131)
• ea252b9 Set Content-Type to application/x-ndjson on streaming responses (#3130)
• cc293e2 Update GitHub Actions deps (#3124)
• 2261983 Update cerbos/actions to bb55708 (#3142)
• 51ab843 Update to <http://github.com/ory/dockertest/v4|github.com/ory/dockertest/v4> (#3136)
• 78d494c chore(release): Prepare release 0.53.0
• 47b23a4 chore(version): Bump version to 0.53.0
• c1d70c9 fix planner ignoring OVERRIDE_PARENT for parent DENYs (#3137)
cerbos/cerbosAnna Paykina
05/26/2026, 3:13 PMAnna Paykina
05/27/2026, 11:35 AMYAML for a single OTA deploy action across five principals (vehicle engineer, production manager, owner, OEM partner, telematics agent), plus supplier data scoping and ECU diagnostics.
Full write-up, with the allow/deny matrix and YAML per principalAnna Paykina
06/08/2026, 3:05 PMAnna Paykina
06/17/2026, 11:19 AMAnna Paykina
06/18/2026, 10:04 AMAnna Paykina
06/30/2026, 11:16 AMdocuments:* grant shows up as broad instead of hiding in a pattern.
It’s live now for any deployment in Cerbos Hub cerbie🚀
Full write-up hereAnna Paykina
07/06/2026, 11:31 AMAnna Paykina
07/08/2026, 9:50 AMGitHub
07/20/2026, 9:38 AMcerbos.audit.v1.PolicySource.Hub.EmbeddedBundle.bundle_id field (#3155)
• 0bacbd6 Add cerbos compile-store command (#3251)
• b6fb643 Add dimension filters to ruletable index key queries (#3235)
• f77ba9c Add new documentation homepage and cross linking (#3264)
• ffc7e76 Add proxy support for Hub client (#3221)
• 9e8e948 Add role policy outputs, constants and variables (#3156)
• 44dd5de Add v0.54.0 release notes (#3282)
• 3fb9576 Allow disabling TLS verification for Hub client (#3220)
• a39c824 Build binaries at AMD64 microarchitecture level v2 (#3218)
• db8f3fb Bump fast-uri from 3.1.0 to 3.1.2 in /npm/test/registry (#3162)
• 9d46168 Bump github.com/go-git/go-billy/v6 from 6.0.0-20260424211911-732291493fb8 to 6.0.0-alpha.1 (#3178)
• 305bfbf Bump github.com/go-git/go-billy/v6 from 6.0.0-20260424211911-732291493fb8 to 6.0.0-alpha.1 in /hack/tools/changelog (#3177)
• fc7f84f Bump golang.org/x/crypto from 0.51.0 to 0.52.0 in /hack/loadtest (#3272)
• 322a56c Bump golang.org/x/crypto from 0.51.0 to 0.52.0 in /hack/tools/changelog (#3271)
• 3ae505b De-duplicate and re-allocate rule table objects (#3209)
• bdaf976 Disable telemetry in CI performance regression test (#3277)
• 69be648 Display output errors in passing tests and JUnit report (#3202)
• 54046f0 Downgrade to go1.25 (#3237)
• 588fc4b Enable incremental rule table marshalling (#3270)
• 1891961 Export binary path from npm packages (#3180)
• 96880d9 Expose parser (#3276)
• 35f56ca Extend the load-test framework to measure PDP memory demand and GC behaviour under load (#3258)
• 2acd6f2 Fix E2E SDK test (#3239)
• 2a7007c Fix Siteline edge function (#3186)
• 79d90eb Fix npm package templates (#3181)
• f09accf Fix panic in E2E blob test (#3242)
• 1bda684 Fix parser bugs (#3223)
• 3352262 Fix typo in performance regression check workflow (#3179)
• f2c6387 Handle permission denied error from Hub API (#3248)
• 9ea7f61 Ignore helm/* tags when building snapshots (#3152)
• 218362c Import GPG key for Helm Secrets before installation (#3219)
• 5ac3bd8 Iterable stores (#3253)
• ae6972a Lazy load sparse bitmaps (#3200)
• 16888ec Lock file maintenance (npm) (#3168)
• 6b49993 Lock file maintenance (npm) (#3195)
• 72a094b Lock file maintenance (npm) (#3226)
• bed9c7d Log CEL runtime errors and record them in audit entries (#3260)
• cd8a94c More compact fqnBindings dimension (#3154)
• <https://github.com/cerbos/cerbos/commit/8465b2ece823a4e079…
cerbos/cerbosAnna Paykina
07/20/2026, 2:32 PMAnna Paykina
08/06/2026, 4:30 PMGitHub
08/13/2026, 8:14 AMAnna Paykina
08/18/2026, 2:53 PMAnna Paykina
08/31/2026, 10:21 AMAnna Paykina
09/08/2026, 12:17 PMTristan Colgate-McFarlane
09/14/2026, 8:59 AM./hack/loadtest/conf/grafana/*dash*boards/cerbos.json
grafana.com/grafana/dashboards/25769-cerbosAnna Paykina
09/21/2026, 9:26 AMGitHub
09/30/2026, 6:35 AMurl.verified from GoReleaser Homebrew cask config (#3386)
• f9fcaa9 Remove deprecated config (#3392)
• e2b3e7f Return correct error code for context errors (#3385)
• 000a0d5 Support specifying a target for Hub audit log ingest (#3400)
• 02b6c2a Tune BadgerDB settings (#3378)
• 9d83c3c Update CONTRIBUTING.md regarding profile-padding attempts (#3362)
• 89fb858 Update GitHub Actions deps (#3330)
• c13d1e0 Update GitHub Actions deps (#3360)
• 75e7a26 Update GitHub Actions deps (#3383)
• 04bbc1e Update Go deps (#3329)
• baabfca Update Go deps (#3339)
• 0730ed1 Update Go deps (#3349)
• 7a4a6bc Update Go deps (#3365)
• 5d64431 Update Go deps (#3372)
• 466ce7f Update Go deps (#3384)
• 11afd2a Update Go deps (#3396)
• 32f0ff1 Update Go deps to v1 (#3398)
• 7d223b5 Update Grafana dashboard (#3354)
• 223c514 Update Helm release seaweedfs to v4.41.0 (#3331)
• d780713 Update Helm release seaweedfs to v4.42.0 (#3343)
• 3561142 Update Helm release seaweedfs to v4.45.0 (#3366)
• 70a2286 Update Helm release seaweedfs to v4.46.0 (#3373)
• 53bbe7d Update Helm release seaweedfs to v4.47.0 (#3397)
• e340081 Update Node.js deps (#3332)
• e340c61 Update Node.js deps (<https://github.com/cerbos/cerbos/p…
cerbos/cerbosAnna Paykina
10/07/2026, 3:28 PMCODEOWNERS.
When authorization rules are scattered through application code, ownership turns into an org chart argument. The identity team’s job ends once the user is logged in, every product team writes its own permission checks, and security has no single place to review any of it.
Once the rules live as policies in one repository, the question has a literal answer. CODEOWNERS says which team owns which policy, the pull request history shows who approved each change, and CI shows the policy was tested before it shipped.
The guide builds the rest of the ownership model around that. A platform team runs the service that makes each allow or deny decision and keeps the audit logs, product teams own the policies for what they build, security owns the standard and the review, and the identity team keeps the user attributes those decisions rely on accurate.
It also covers how to try this on one workflow first, like a support tool that needs write access to production, so the first team sees a permission change go out as a policy commit rather than a code deploy.
Full write-up here: cerbos.dev/blog/who-owns-authorization-in-large-engineering-organization