github BfArM-MVH/grz-tools grz-cli-v3.0.0
grz-cli: v3.0.0

3.0.0 (2026-09-26)

⚠ BREAKING CHANGES

  • grzctl: the grzctl config has no keys section. Each inbox names its private key. An inbox's private_key_passphrase comes before C4GH_PASSPHRASE.
  • grz-cli: Crypt4GH.prepare_c4gh_keys, Crypt4GH.decrypt_file, Submission.encrypt, EncryptedSubmission.decrypt, Worker.encrypt and Worker.decrypt take X25519PrivateKey and X25519PublicKey objects instead of paths. The Crypt4GH key loaders return these objects.

Features

  • grz-cli,grz-common,grz-db,grzctl: record why a submission failed and classify S3 errors (#690) (f1d3fc8)
  • grz-cli: accept the submitter private key inline (06f12e6)
  • grz-cli: add keys.submitter_private_key_passphrase (06f12e6)
  • grz-common: load crypt4gh keys in memory (06f12e6)
  • grz-common: recommend grz-cli 3.0.0 in the bundled version policy (bf3e6bf)
  • grzctl: accept every crypt4gh key in the config inline (06f12e6)
  • grzctl: Centralized version.json and its distribution using grzctl (#667) (6ed9cb0)
  • grzctl: configure each crypt4gh key where grzctl uses it (#694) (06f12e6)

Bug Fixes

  • grz-cli,grz-common,grz-db,grzctl: require grz-common 4, grz-db 4 and grz-pydantic-models 4 (#688) (bf3e6bf)
  • grz-common: keep crypt4gh private keys out of DEBUG logs (06f12e6)
  • grz-common: leave the raw input out of config validation errors (06f12e6)
  • grzctl,grz-common,grz-cli: drop grzctl submit and grzctl's grz-cli dependency (#675) (e6f27c1)
  • grzctl: keep the stored upload date in db submission populate (f1d3fc8)
  • grzctl: mask db.author.private_key in dump-config (06f12e6)

Don't miss a new grz-tools release

NewReleases is sending notifications on new releases.