1 roundcube (0.5-3) UNRELEASED; urgency=low
3 * Don't assign "skins" directory to www-data. Closes: #612552.
4 * Add instructions on how to install and upgrade when not using
5 dbconfig-common. We do not ship UPGRADING file any more since it is
6 misleading. Closes: #612511.
7 * Fix MySQL indexes if upgrading from 0.5-2 or lesser. Closes: #610725.
8 * Rework how symlinks work. The only directory to use is
9 /var/lib/roundcube. We use symlink from /usr/share/roundcube to
10 /var/lib/roundcube and not the other way. Moreover, plugins and skins
11 are also symlinked. A user should be able to add plugins and skins in
12 /var/lib/roundcube while default ones are in
13 /usr/share/roundcube. Closes: #612553.
15 -- Vincent Bernat <bernat@debian.org> Wed, 09 Feb 2011 07:32:42 +0100
17 roundcube (0.5-2) experimental; urgency=low
19 * If 0.3.1 was installed from scratch, upgrade does not work on MySQL
20 and PostgreSQL because we try to create an index which already
21 exists. With SQLite, the error is ignored, no fix needed. When using
22 PostgreSQL, fix this by dropping the index if it already
23 exists. Nothing similar seems to exist with MySQL. Therefore, just
24 don't create the index. We need to handle this later. See bug
27 -- Vincent Bernat <bernat@debian.org> Fri, 21 Jan 2011 21:44:05 +0100
29 roundcube (0.5-1) experimental; urgency=low
31 * New upstream release. Closes: #592312.
32 + Drop patches included upstream (DNS prefetching, jQuery 1.4
33 handling, email address validation, duplicate headers, incorrectly
34 formatted received headers). Adapt other patches. One of the patch
35 now correctly states to use dpkg-reconfigure roundcube-core.
37 + Update SQL commands to use to upgrade database.
38 That also closes: #602922. Unfortunately, the user may get some
39 harmless error messages because there is no way to know if
40 0.3.1 was installed from scratch or upgraded from 0.3.
41 + Update dependencies to match INSTALL file. Only exception is the
42 use of Mail_Mime 1.8.0 in place of 1.8.1 which is not available in
43 Debian. We depends on jQuery 1.4.2 because 1.4.4 is not available in
45 + All folders are correctly checked since 0.4. Closes: #552430.
46 + Also, closes: #553194 since it seems to have been fixed too.
47 + There is also the possibility to not top-quote since 0.4.
49 + Closes: #602144. Also fixed.
50 * Move .htaccess to /etc/roundcube and use a symlink (Closes: #591369).
51 * Don't let www-data overwrite debian-db.php. Closes: #608976.
52 * Bump Standards-Version. No changes required.
54 -- Vincent Bernat <bernat@debian.org> Sat, 15 Jan 2011 12:40:27 +0100
56 roundcube (0.3.1-6) unstable; urgency=low
58 * Update Arabic debconf translation, thanks to Ossama Khayat.
60 * Update Portuguese debconf translation, thanks to Christian Perrier.
62 * Add a patch to avoid duplicate boundaries in headers when adding an
63 attachment. Closes: #599586.
65 -- Vincent Bernat <bernat@debian.org> Mon, 18 Oct 2010 23:14:37 +0200
67 roundcube (0.3.1-5) unstable; urgency=low
69 * Depends on php-mail-mime 1.7.0 or more recent to handle correctly
70 'mime_param_folding' directive. Closes: #588295.
71 * Add Danish debconf translation, thanks to Joe Dalton.
73 * Add a patch to fix Received header to behave better with Spam
74 Assassin. Closes: #595204.
76 -- Vincent Bernat <bernat@debian.org> Thu, 02 Sep 2010 07:54:58 +0200
78 roundcube (0.3.1-4) unstable; urgency=low
80 * Update README.Debian to state that the variable to modify is
81 'htmleditor' instead of 'enable_htmleditor'. Thanks to Hans
82 Spaans. Closes: #575556.
83 * Add Brazilian Portuguese debconf translation, thanks to Eder
84 L. Marques. Closes: #581745.
85 * Switch default encoding to UTF-8 instead of ISO-8859-1.
87 * Add more explanations on how to install roundcube in a Debian system
88 in README.Debian. Closes: #584458, #582894.
89 * Bump Standards-Version. No changes required.
90 * Switch to 3.0 (quilt) format.
91 * Use Breaks instead of Conflicts to move files from older roundcube
94 -- Vincent Bernat <bernat@debian.org> Sat, 17 Jul 2010 17:23:30 +0200
96 roundcube (0.3.1-3) unstable; urgency=high
98 * RFC 5321, section 4.5.3.1, asks to not impose any limits on length if
99 possible. We respect this by dropping limitation of the local-part of
100 an email address. Closes: #568360, #568537.
101 * Suggests php-auth-sasl to enable use of SASL mechanisms for mail
102 servers. Closes: #567550.
103 * Disable DNS prefetching to avoid information leakage through links
104 embedded in messages. This fixes CVE-2010-0464. Closes: #569660.
105 * Bump Standards-Version. No changes required.
107 -- Vincent Bernat <bernat@debian.org> Sat, 13 Feb 2010 10:21:49 +0100
109 roundcube (0.3.1-2) unstable; urgency=low
111 * Fix VCS links in debian/control, thanks to Torsten Landschoff.
113 * Really ship NEWS.Debian.
114 * Add changesets 3170 and 3202 from upstream to handle gracefully jQuery
115 1.4. Thanks to Volker Gropp for the report. Closes: #565715.
117 -- Vincent Bernat <bernat@debian.org> Mon, 18 Jan 2010 23:11:01 +0100
119 roundcube (0.3.1-1) unstable; urgency=low
121 * New upstream release.
122 * Add a notice in NEWS.Debian about php.ini options that should be set
123 to get Roundcube working properly. Closes: #549428, #552508.
125 -- Vincent Bernat <bernat@debian.org> Sat, 07 Nov 2009 17:41:37 +0100
127 roundcube (0.3-2) unstable; urgency=low
129 * Really fix #544579 since the default value is null without
130 quotes. This really Closes: #544579.
131 * Enlarge login box to accommodate sk_SK locale. Closes: #542933.
133 -- Vincent Bernat <bernat@debian.org> Sun, 27 Sep 2009 11:26:56 +0200
135 roundcube (0.3-1) unstable; urgency=low
137 * New upstream release. Closes: #545498.
138 * Update debconf translations:
139 + Italian, thanks to Luca Monducci. Closes: #544199.
140 + Czech, thanks to Miroslav Kure. Closes: #546413.
141 * Roundcube configuration now uses 'language' instead of 'locale_string'
142 to specify the default language. Update postinst to reflect this
143 change. Thanks to Richard van den Berg for noticing this. Closes: #544579.
144 * Depends on libjs-jquery (>= 1.3) since this is now used by roundcube.
145 * Don't ship any plugins for now but ship an empty plugins directory.
146 * Ship main .htaccess since it is needed to setup correctly PHP (for
147 example, to disable PHP Suhosin cookie encryption).
148 * Bump Standards-Version. No changes required.
150 -- Vincent Bernat <bernat@debian.org> Sun, 27 Sep 2009 11:00:30 +0200
152 roundcube (0.2.2-1) unstable; urgency=low
154 * New upstream release
155 * Bump Standards-Version. No changes required.
156 * Remove *.js.src which are not needed at runtime.
157 * Don't send email contents to Google by default by using php5-pspell
158 instead. Thanks to Anand Kumria. Closes: #529563.
159 * Update debconf translations:
160 + Basque, thanks to Piarres Beobide. Closes: #534282.
162 -- Vincent Bernat <bernat@debian.org> Sun, 05 Jul 2009 09:53:17 +0200
164 roundcube (0.2.1-2) unstable; urgency=low
166 * Update debconf translations:
167 + German, thanks to Helge Kreutzmann. Closes: #520004.
168 + Japanese, thanks to Hideki Yamane. Closes: #520024.
169 + Spanish, thanks to Francisco Javier. Closes: #526696.
170 + Russian, thanks to Yuri Kozlov. Closes: #528796.
171 * Depend on php-mdb2-* (>= 1.5.0b2) since it is needed to fix some
172 bugs. Closes: #519104, #519293. Remove not needed any more patch from
173 debian/patches/series. Keep it in debian/patches to help backports.
175 -- Vincent Bernat <bernat@debian.org> Sat, 16 May 2009 15:30:17 +0200
177 roundcube (0.2.1-1) unstable; urgency=low
179 * New upstream release:
180 + Fix use_packaged_tinymce.patch to apply to this new version
181 + Remove cve-2009-0413.patch which has been applied upstream
183 -- Vincent Bernat <bernat@debian.org> Sat, 14 Mar 2009 17:42:07 +0100
185 roundcube (0.2~stable-2) unstable; urgency=low
187 * Update debconf translations:
188 + French, thanks to Christian Perrier. Closes: #515806.
189 + Swedish, thanks to Martin Bagge. Closes: #516683.
190 * Drop virtual package roundcube-db and add dependencies on real package
191 instead: this way, we can have versioned dependencies on those to avoid
192 version mismatch between packages.
193 * Add a patch to not use a MDB2 feature not present in the Debian
194 package. Thanks to Grzegorz Sobański for the patch. Closes: #519104.
196 -- Vincent Bernat <bernat@debian.org> Wed, 11 Mar 2009 18:49:32 +0100
198 roundcube (0.2~stable-1) unstable; urgency=low
200 * New upstream version. Closes: #503573, #504570.
201 + Add SQL update scripts for this new release and for
202 0.2~alpha. Remove copy of SQL upgrade script from debian/rules.
203 + Remove patch for CVE-2008-5620 which is now fixed upstream.
204 + Remove patch correcting a vulnerability in html2text.php.
205 + Remove patch fixing login issue. This is fixed upstream.
206 + Remove patch setting the default backend to db instead of mdb2:
207 this is not possible any more. We depend on php-mdb2 now.
208 + Update patch to use packaged tinymce.
209 * Upload to unstable since Lenny is out.
210 * Apply fix for XSS issue (CVE-2009-0413). Closes: #514179.
211 * Remove hack to update a SQLite table for an upgrade from a quite old
212 version of roundcube.
213 * Fix pending l10n issues:
214 + Update English debconf template. Closes: #473794.
215 + Add Swedish translation thanks to Martin Bagge. Closes: #508752.
216 * Fix debian/copyright to make lintian happy.
218 -- Vincent Bernat <bernat@debian.org> Sun, 15 Feb 2009 16:18:58 +0100
220 roundcube (0.2~alpha-4) experimental; urgency=low
222 * Add missing ${misc:Depends} to make Lintian happy.
223 * Add description to each patch.
224 * Execute cron job only if the directory to clean exists.
225 * Reload web server configuration instead of restart, thanks to a patch
226 from Tiago Bortoletto Vaz. Closes: #508633.
227 * Fix a vulnerability in quota image generation. This fixes
228 CVE-2008-5620. Thanks to Nico Golde for reporting it. Closes: #509596.
229 * Add missing dependency on php5-gd, used for quota bar.
230 * For roundcube-pgsql, depends on postgresql-client only. This package
231 is provided by the currently supported real package.
233 -- Vincent Bernat <bernat@debian.org> Thu, 25 Dec 2008 11:38:13 +0100
235 roundcube (0.2~alpha-3) experimental; urgency=high
238 * Fix a vulnerability in the use of preg_replace (Closes: #508628).
239 * Adapt descriptions of roundcube-database packages to refer them as
240 metapackages instead of virtual package (Closes: #495434).
241 * Add robots.txt from upstream, even if in some configuration, it will
242 not be considered (Closes: #499108).
243 * Do not ship .htaccess files. Restrictions are set in Apache or
244 Lighttpd configuration files (Closes: #500202).
247 * Changed versioned dependency of rouncube from binary:Version to
248 source:Version since these are all architecture independent packages.
250 -- Vincent Bernat <bernat@debian.org> Sat, 13 Dec 2008 14:36:02 +0100
252 roundcube (0.2~alpha-2) experimental; urgency=low
255 * Fix lintian warnings introduced by previous upload
256 * Fix lighttpd.conf to make it work with latest versions (Closes: #494044)
257 * Do not prepend path to lighty util in postinst and postrm, as per
258 Policy Manual section 6.1
259 * Ship a bug/control file to have all bugs submitted against roundcube
261 * Fix debian/roundcube-core.cron.daily to use
262 /etc/default/roundcube-core instead of /etc/default/roundcube which
263 should not exist any more
266 * Versioned roundcube-core dependency for roundcube
268 -- Vincent Bernat <bernat@debian.org> Sat, 16 Aug 2008 13:22:08 +0200
270 roundcube (0.2~alpha-1) experimental; urgency=low
272 * New upstream release
273 * Update debian/watch file to correctly consider those new releases
274 * Remove the following patches:
275 + messageid-headers-ordering
277 + disable-tinymce-spellchecker
278 * Update the following patches:
279 + correct_install_path
280 + use_packaged_tinymce
281 * Add a new patch to fix a login problem
282 * Depends on tinymce >= 3
284 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 14:10:44 +0200
286 roundcube (0.1.1-7) unstable; urgency=low
288 * Another fix for incorrect tinymce path. This should be the last one!
290 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 12:36:59 +0200
292 roundcube (0.1.1-6) unstable; urgency=low
294 * Fix use_packaged_tinymce patch which was incorrect after switch to
297 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 12:19:16 +0200
299 roundcube (0.1.1-5) unstable; urgency=low
301 * Fix ordering of message-id in message headers, thanks to Reinhard
302 Tartler (Closes: #486493)
303 * Update Standards-Version to 3.8.0
305 -- Vincent Bernat <bernat@debian.org> Tue, 17 Jun 2008 00:33:40 +0200
307 roundcube (0.1.1-4) unstable; urgency=low
309 * Add Slovak debconf translation, thanks to Ivan Masár (Closes: #481376)
310 * Fix debian/copyright:
311 + RoundCube is GPL-2 licensed, not GPL-2+
312 + Add an explanation on the BSD license present at the top of
313 index.php (Closes: #477119)
314 * We do not support tinymce 3, yet. Depends on tinymce2 | tinymce (<<
315 3). Closes: #481145, #483053, #482295
317 -- Vincent Bernat <bernat@debian.org> Tue, 20 May 2008 20:51:52 +0200
319 roundcube (0.1.1-3) unstable; urgency=low
321 * Fix an error introduced when fixing bug #476803. Thanks to Micah
322 Anderson for spotting it (Closes: #479775).
323 * Avoid to pop language question at every upgrade. Thanks to Ivan Vucica
324 for spotting this. The problem lied in the use of db_metaget to get
325 the value of a key set by db_subst in a previous invocation. It seems
326 this is not possible any more (Closes: #480043). The fix implies that
327 we won't ask the question again if more languages are available since
330 -- Vincent Bernat <bernat@debian.org> Thu, 08 May 2008 09:50:24 +0200
332 roundcube (0.1.1-2) unstable; urgency=low
334 * Comment by default Alias directive for tinymce in Apache configuration
335 file (Closes: #476162).
336 * Allow to preseed language value (Closes: #476803).
338 -- Vincent Bernat <bernat@luffy.cx> Sat, 19 Apr 2008 16:50:28 +0200
340 roundcube (0.1.1-1) unstable; urgency=low
342 * New upstream release
343 - Copy old SQL upgrade scripts into debian/sql to allow upgrade from
344 versions older than 0.1
345 - Patch new MySQL upgrade script to fix a typo
346 * Debconf translation updates:
347 - Spanish. Closes: #473788
348 * Depends on php-mail-mime (>= 1.5.0) and drop compatibility patch
349 * Install upstream changelog in /usr/share/doc/roundcube*
351 -- Vincent Bernat <bernat@luffy.cx> Sat, 05 Apr 2008 18:16:33 +0200
353 roundcube (0.1-4) unstable; urgency=low
355 * Debconf translation updates:
356 - French. Closes: #469802
357 - Russian. Closes: #469847
358 - Galician. Closes: #469866
359 - German. Closes: #469875
360 - Finnish. Closes: #469922
361 - Italian. Closes: #469987
362 - Czech. Closes: #470150
363 - Portuguese. Closes: #470156
364 - Spanish. Closes: #470732
365 - Basque. Closes: #470871
366 - Arabic. Closes: #471470
368 -- Vincent Bernat <bernat@luffy.cx> Sat, 08 Mar 2008 11:15:00 +0100
370 roundcube (0.1-3) unstable; urgency=low
372 * Fix problem with too old php-mail-mime package (Closes: #469814)
374 -- Vincent Bernat <bernat@luffy.cx> Fri, 07 Mar 2008 11:06:49 +0100
376 roundcube (0.1-2) unstable; urgency=low
378 * Ship bin/ directory as well. This fix conversion from HTML to text in
380 * Disable spellchecker for tinymce since it is not shipped with Debian
383 -- Vincent Bernat <bernat@luffy.cx> Fri, 07 Mar 2008 09:42:39 +0100
385 roundcube (0.1-1) unstable; urgency=low
387 * New upstream release (Closes: #469487).
388 - This release seems to fix failure to set some fields when replying,
389 with bincimap as IMAP server (Closes: #443562)
390 - It also fixes the deletion of multiple messages, still with
391 bincimap (Closes: #451404)
392 * Remove 'ob_gzhandler.patch' and 'xss-fix.patch'. They have been
394 * Upstream has switched to MDB2 database backend which is not packaged
395 in Debian yet. We switch back to old backend.
396 * Fix debian/watch to handle correctly detection of new versions.
397 * Add support for lighttpd and remove support for older version of
398 Apache. The debconf question about webserver autoconfiguration is
399 reworded (Closes: #462961).
400 * Do not depend on a specific revision of cdbs.
401 * Move po-debconf from Build-Depends-Indep to Build-Depends since it is
402 needed for clean target.
403 * Correct path to /usr/share/file/magic, provided by libmagic1. Provide
404 license information about this file in debian/copyright.
406 -- Vincent Bernat <bernat@luffy.cx> Wed, 05 Mar 2008 20:49:03 +0100
408 roundcube (0.1~rc2-6) unstable; urgency=high
410 * Bug fix: "CVE-2007-6321: Cross-site scripting (XSS) vulnerability",
411 thanks to Micah Anderson (Closes: #455840). The patch is from
412 http://lists.roundcube.net/mail-archive/dev/2007-12/0000038.html and
413 provided by Robin Elfrink. It has been modified with some functions
414 stolen from Squirrelmail.
415 * Finnish debconf template, thanks to Esko Arajärvi (Closes: #458244).
417 -- Vincent Bernat <bernat@luffy.cx> Sat, 29 Dec 2007 21:55:17 +0100
419 roundcube (0.1~rc2-5) unstable; urgency=low
421 * Deal with old /etc/logrotate.d/roundcube by removing it if left
422 untouched (Closes: #456546). Also deal with /etc/default/roundcube and
423 /etc/cron.daily/roundcube.
425 -- Vincent Bernat <bernat@luffy.cx> Tue, 18 Dec 2007 23:02:46 +0100
427 roundcube (0.1~rc2-4) unstable; urgency=low
429 * Thightened dependencies for a safe upgrade
430 * Finally removed any circular dependency, -db packages no longer pull
431 a full roundcube install
433 -- Romain Beauxis <toots@rastageeks.org> Sun, 09 Dec 2007 14:24:24 +0100
435 roundcube (0.1~rc2-3) unstable; urgency=low
438 * Bumped standard version to 3.7.3 (no changes)
440 -- Romain Beauxis <toots@rastageeks.org> Sun, 09 Dec 2007 14:19:28 +0100
442 roundcube (0.1~rc2-2) experimental; urgency=low
445 * Fix a conflict between ob_gzhandler and zlib output compression,
446 thanks to kaouete (Closes: #450482).
449 * Fix tinymce patch and inclusion
451 * Splitted virtual packages to avoid circular dependencies.
452 Uploading to experimental, as this is an important change and we may
455 -- Romain Beauxis <toots@rastageeks.org> Mon, 26 Nov 2007 11:54:21 +0100
457 roundcube (0.1~rc2-1) unstable; urgency=low
459 * New upstream, thanks to Nicolas Stransky (Closes: #447503). This
460 release support tinymce as HTML editor. Look at README.Debian for more
462 * Update Galician debconf template, thanks to Jacobo Tarrio (Closes: #447943).
464 -- Vincent Bernat <bernat@luffy.cx> Mon, 29 Oct 2007 22:08:43 +0100
466 roundcube (0.1~rc1-3) unstable; urgency=low
468 * In respect to policy 12.3, do not put main.inc.php.dist in
469 /usr/share/doc, thanks to Jonas Smedegaard (Closes: #446502).
470 * Update German and French debconf templates, thanks to Christian
471 Perrier (Closes: #446458) and Helge Kreutzmann (Closes: #446532).
473 -- Vincent Bernat <bernat@luffy.cx> Sun, 14 Oct 2007 08:41:24 +0200
475 roundcube (0.1~rc1-2) unstable; urgency=low
477 * Fix dependencies by creating virtual packages for each database
478 backend, thanks to Joey Hess (Closes: #444925).
480 -- Vincent Bernat <bernat@luffy.cx> Tue, 02 Oct 2007 20:09:19 +0200
482 roundcube (0.1~rc1-1) unstable; urgency=low
484 * New upstream release
485 * Removed non gpl file des.inc
487 -- Romain Beauxis <toots@rastageeks.org> Tue, 24 Jul 2007 13:36:20 +0200
489 roundcube (0.1~rc1~dfsg-3) unstable; urgency=low
491 * Add php5-mcrypt dependency (Closes: #431177)
493 -- Vincent Bernat <bernat@luffy.cx> Sat, 30 Jun 2007 19:36:21 +0200
495 roundcube (0.1~rc1~dfsg-2) unstable; urgency=low
497 * Removed custom unix_timestamp for sqlite: solved upstream
498 * Debconf templates and debian/control reviewed by the debian-l10n-
499 english team as part of the Smith review project.
500 Closes: #426086, #427546, #427546
501 * Debconf translation updates:
502 - Galician. Closes: #426140
503 - Basque. Closes: #426150
504 - Czech. Closes: #426428
505 - Portuguese. Closes: #426451
506 - Arabic. Closes: #427110
507 - Italian. Closes: #427206
508 - German. Closes: #427536
509 - French. Closes: #427736
510 - Tamil. Closes: #428254
511 - Russian. Closes: #428364
512 - Spanish. Closes: #428573
514 -- Romain Beauxis <toots@rastageeks.org> Tue, 05 Jun 2007 15:22:36 +0200
516 roundcube (0.1~rc1~dfsg-1) unstable; urgency=low
519 * New upstream release
520 * Update script for sqlite in postinst
522 * Fixed dh_link calls
524 * Added custom patch to use php unix timestamp support
525 with sqlite since UNIX_TIMESTAMP is not supported by sqlite.
526 * Dropped php4 dependencies
528 -- Vincent Bernat <bernat@luffy.cx> Sun, 20 May 2007 13:59:44 +0200
530 roundcube (0.1~beta2.2~dfsg-2) unstable; urgency=low
532 * Fix a security issue by disallowing access to logs.
533 * First upload to unstable.
535 -- Vincent Bernat <bernat@luffy.cx> Sat, 5 May 2007 00:23:40 +0200
537 roundcube (0.1~beta2.2~dfsg-1) experimental; urgency=low
539 * Initial release. (Closes: #333756, #344949)
541 -- Romain Beauxis <toots@rastageeks.org> Tue, 13 Mar 2007 13:28:05 +0100