github BfArM-MVH/grz-tools grzctl-v5.0.0
grzctl: v5.0.0

5.0.0 (2026-09-26)

⚠ BREAKING CHANGES

  • grzctl: pruefbericht.authorization_url, client_id, client_secret and api_base_url are required. A config without them stops every grzctl command.
  • grzctl: the grzctl config has no keys section. Each inbox names its private key. An inbox's private_key_passphrase comes before C4GH_PASSPHRASE.
  • grz-cli: Crypt4GH.prepare_c4gh_keys, Crypt4GH.decrypt_file, Submission.encrypt, EncryptedSubmission.decrypt, Worker.encrypt and Worker.decrypt take X25519PrivateKey and X25519PublicKey objects instead of paths. The Crypt4GH key loaders return these objects.
  • grzctl: db.known_public_keys in the grzctl config takes a list of keys. Move a path to a file to db.known_public_keys_file.
  • grz-db,grzctl: grzctl db submission populate refuses to replace or remove a stored value without --force or --allow-overwrite. Its --submission_date option is renamed to --submission-date. Without it, populate takes the upload date from the metadata.json object in the inbox, and stops if the inbox has none. grzctl upload is removed. Use grz-cli upload. grzctl db backfill skips a submission with an undeclared destructive change, instead of writing the rest of it. grz-db removes SubmissionChangeSet.withhold_destructive, SubmissionDiffCollection.withhold_destructive, SubmissionDiffCollection.has_pending_destructive and DonorsDiffCollection.has_pending_destructive. Use SubmissionChangeSet.undeclared_destructive_changes() instead.
  • grzctl,grz-common: S3ConnectionBase.secret, S3ConnectionBase.session_token, Author.private_key_passphrase, InboxConfig.private_key_passphrase, InboxTarget.private_key_passphrase and PruefberichtModel.client_secret are now SecretStr | None. Read them with .get_secret_value() or grz_common.models.base.get_secret_value().
  • grzctl: db submission modify and --ignore-field take local_case_id where they took pseudonym. In JSON output pseudonym is now the case's psn (null until assigned); the former value is under local_case_id.
  • grzctl: unified config (#635)

Features

  • grz-cli,grz-common,grz-db,grzctl: record why a submission failed and classify S3 errors (#690) (f1d3fc8)
  • grz-cli: accept the submitter private key inline (06f12e6)
  • grz-cli: add keys.submitter_private_key_passphrase (06f12e6)
  • grz-common: load crypt4gh keys in memory (06f12e6)
  • grz-common: recommend grz-cli 3.0.0 in the bundled version policy (bf3e6bf)
  • grz-db,grzctl: add case tracking for submissions (#633) (68c75dc)
  • grz-db,grzctl: add db case list-unlinked and list-ambiguous-keys (68c75dc)
  • grz-db,grzctl: add processing states and make populate and backfill overwrite only declared fields (#681) (4c012dc)
  • grz-db,grzctl: track which inbox a submission came from and use it for decryption (#696) (ce95f8c)
  • grz-db: let a psn-keyed deployment resolve cases through diff and (68c75dc)
  • grz-db: withhold destructive changes from a whole change set (bdd6321)
  • grz-pydantic-models,grz-common: keep a parsed submission lossless and redact it by one rule (#654) (ec46603)
  • grz-pydantic-models: add get_raw_dict for the document as (ec46603)
  • grz-pydantic-models: publish PCT_DEV_CUTOFF (a0e1bfe)
  • grzctl,grz-common: store sensitive config values as SecretStr and dump config without revealing them (#680) (b383ac4)
  • grzctl: accept every crypt4gh key in the config inline (06f12e6)
  • grzctl: add db case commands and link submissions to cases on (68c75dc)
  • grzctl: Centralized version.json and its distribution using grzctl (#667) (6ed9cb0)
  • grzctl: configure each crypt4gh key where grzctl uses it (#694) (06f12e6)
  • grzctl: explain why a case is listed in the Detailprüfung report (a0e1bfe)
  • grzctl: fail a rival initial submission's basic QC during validate (68c75dc)
  • grzctl: list the known public keys in the config (#693) (d0d8a26)
  • grzctl: report QC deviations without failing and add recompute-qc backfill (#656) (a0e1bfe)
  • grzctl: require the four pruefbericht config fields (#697) (22cc669)
  • grzctl: sign archived files with the private key of the (ce95f8c)
  • grzctl: unified config (#635) (f993399)

Bug Fixes

  • grz-cli,grz-common,grz-db,grzctl: require grz-common 4, grz-db 4 and grz-pydantic-models 4 (#688) (bf3e6bf)
  • grz-common: keep crypt4gh private keys out of DEBUG logs (06f12e6)
  • grz-common: KeyModel/KeyConfigModel use BaseModel not BaseSettings (f993399)
  • grz-common: leave the raw input out of config validation errors (06f12e6)
  • grz-common: require grz-pydantic-models >=3.1 for (ec46603)
  • grz-db: apply a change set as one transaction (ec46603)
  • grz-db: consult the resolver assert_no_duplicate_initial is (68c75dc)
  • grz-db: export db_backend from grz_db.testing (ec46603)
  • grz-db: leave a local case ID reused across patients unlinked (68c75dc)
  • grz-db: let SQLite connections wait 60 s for a lock (#699) (700868f)
  • grz-db: pass the database password to the migrations (700868f)
  • grz-db: raise the grz-pydantic-models floor to 3.1 (a0e1bfe)
  • grz-db: require grz-pydantic-models >=3.1 for (68c75dc), closes #632
  • grzctl,grz-common,grz-cli: drop grzctl submit and grzctl's grz-cli dependency (#675) (e6f27c1)
  • grzctl: abort cleanly on a duplicate case key and a malformed (68c75dc)
  • grzctl: during encrypt and archive, automatically derive consented (7c81954)
  • grzctl: expand ~ in db.author.private_key_path (d0d8a26)
  • grzctl: hold back donor overwrites in db backfill (#677) (bdd6321)
  • grzctl: keep the stored upload date in db submission populate (f1d3fc8)
  • grzctl: mask db.author.private_key in dump-config (06f12e6)
  • grzctl: name the submission fields the database actually has (ec46603)
  • grzctl: read both archives before db backfill writes (#676) (20e13a9)
  • grzctl: skip blank and comment lines in known_public_keys (20e13a9)
  • grzctl: stop backfill counting an updated submission as not updated (68c75dc)
  • grzctl: stop the state history warning on every upload (20e13a9)
  • grzctl: use grz private key during grzctl encrypt if available and (7c81954)
  • grzctl: use standalone subcommands, not grz-cli wrappers (#659) (7c81954)

Don't miss a new grz-tools release

NewReleases is sending notifications on new releases.