4.0.0 (2026-09-26)
⚠ BREAKING CHANGES
- grzctl: the grzctl config has no
keyssection. Each inbox names its private key. An inbox'sprivate_key_passphrasecomes beforeC4GH_PASSPHRASE. - grz-cli:
Crypt4GH.prepare_c4gh_keys,Crypt4GH.decrypt_file,Submission.encrypt,EncryptedSubmission.decrypt,Worker.encryptandWorker.decrypttakeX25519PrivateKeyandX25519PublicKeyobjects instead of paths. TheCrypt4GHkey loaders return these objects. - grzctl,grz-common:
S3ConnectionBase.secret,S3ConnectionBase.session_token,Author.private_key_passphrase,InboxConfig.private_key_passphrase,InboxTarget.private_key_passphraseandPruefberichtModel.client_secretare nowSecretStr | None. Read them with.get_secret_value()orgrz_common.models.base.get_secret_value(). - grzctl: unified config (#635)
Features
- grz-cli,grz-common,grz-db,grzctl: record why a submission failed and classify S3 errors (#690) (f1d3fc8)
- grz-cli: accept the submitter private key inline (06f12e6)
- grz-cli: add keys.submitter_private_key_passphrase (06f12e6)
- grz-common: load crypt4gh keys in memory (06f12e6)
- grz-common: recommend grz-cli 3.0.0 in the bundled version policy (bf3e6bf)
- grz-common: sign encrypted files with the submitter's private key (#691) (449258c)
- grz-db,grzctl: track which inbox a submission came from and use it for decryption (#696) (ce95f8c)
- grz-pydantic-models,grz-common: keep a parsed submission lossless and redact it by one rule (#654) (ec46603)
- grz-pydantic-models: add get_raw_dict for the document as (ec46603)
- grzctl,grz-common: store sensitive config values as SecretStr and dump config without revealing them (#680) (b383ac4)
- grzctl: accept every crypt4gh key in the config inline (06f12e6)
- grzctl: Centralized version.json and its distribution using grzctl (#667) (6ed9cb0)
- grzctl: configure each crypt4gh key where grzctl uses it (#694) (06f12e6)
- grzctl: sign archived files with the private key of the (ce95f8c)
- grzctl: unified config (#635) (f993399)
Bug Fixes
- grz-cli,grz-common,grz-db,grzctl: require grz-common 4, grz-db 4 and grz-pydantic-models 4 (#688) (bf3e6bf)
- grz-common: keep crypt4gh private keys out of DEBUG logs (06f12e6)
- grz-common: KeyModel/KeyConfigModel use BaseModel not BaseSettings (f993399)
- grz-common: leave the raw input out of config validation errors (06f12e6)
- grz-common: require grz-pydantic-models >=3.1 for (ec46603)
- grz-db: apply a change set as one transaction (ec46603)
- grz-db: export db_backend from grz_db.testing (ec46603)
- grzctl,grz-common,grz-cli: drop grzctl submit and grzctl's grz-cli dependency (#675) (e6f27c1)
- grzctl: keep the stored upload date in db submission populate (f1d3fc8)
- grzctl: mask db.author.private_key in dump-config (06f12e6)
- grzctl: name the submission fields the database actually has (ec46603)