1 roundcube (0.5.1-2) unstable; urgency=low
3 * Add plugins. Closes: #550454.
4 * Update debian/copyright.
6 -- Vincent Bernat <bernat@debian.org> Sun, 13 Feb 2011 15:25:45 +0100
8 roundcube (0.5.1-1) unstable; urgency=low
10 * New upstream version. Some bugs are corrected in this release or in a
12 + when switching to HTML mode, content type is now correctly set.
14 + header delimiters handling has been fixed in 0.5.
16 * Don't assign "skins" directory to www-data. Closes: #612552.
17 * Add instructions on how to install and upgrade when not using
18 dbconfig-common. We do not ship UPGRADING file any more since it is
19 misleading. Closes: #612511.
20 * Fix MySQL indexes if upgrading from 0.5-2 or lesser. Closes: #610725.
21 * Rework how symlinks work. The only directory to use is
22 /var/lib/roundcube. We use symlink from /usr/share/roundcube to
23 /var/lib/roundcube and not the other way. Moreover, plugins and skins
24 are also symlinked. A user should be able to add plugins and skins in
25 /var/lib/roundcube while default ones are in
26 /usr/share/roundcube. Closes: #612553.
28 -- Vincent Bernat <bernat@debian.org> Wed, 09 Feb 2011 07:32:42 +0100
30 roundcube (0.5-2) experimental; urgency=low
32 * If 0.3.1 was installed from scratch, upgrade does not work on MySQL
33 and PostgreSQL because we try to create an index which already
34 exists. With SQLite, the error is ignored, no fix needed. When using
35 PostgreSQL, fix this by dropping the index if it already
36 exists. Nothing similar seems to exist with MySQL. Therefore, just
37 don't create the index. We need to handle this later. See bug
40 -- Vincent Bernat <bernat@debian.org> Fri, 21 Jan 2011 21:44:05 +0100
42 roundcube (0.5-1) experimental; urgency=low
44 * New upstream release. Closes: #592312.
45 + Drop patches included upstream (DNS prefetching, jQuery 1.4
46 handling, email address validation, duplicate headers, incorrectly
47 formatted received headers). Adapt other patches. One of the patch
48 now correctly states to use dpkg-reconfigure roundcube-core.
50 + Update SQL commands to use to upgrade database.
51 That also closes: #602922. Unfortunately, the user may get some
52 harmless error messages because there is no way to know if
53 0.3.1 was installed from scratch or upgraded from 0.3.
54 + Update dependencies to match INSTALL file. Only exception is the
55 use of Mail_Mime 1.8.0 in place of 1.8.1 which is not available in
56 Debian. We depends on jQuery 1.4.2 because 1.4.4 is not available in
58 + All folders are correctly checked since 0.4. Closes: #552430.
59 + Also, closes: #553194 since it seems to have been fixed too.
60 + There is also the possibility to not top-quote since 0.4.
62 + Closes: #602144. Also fixed.
63 * Move .htaccess to /etc/roundcube and use a symlink (Closes: #591369).
64 * Don't let www-data overwrite debian-db.php. Closes: #608976.
65 * Bump Standards-Version. No changes required.
67 -- Vincent Bernat <bernat@debian.org> Sat, 15 Jan 2011 12:40:27 +0100
69 roundcube (0.3.1-6) unstable; urgency=low
71 * Update Arabic debconf translation, thanks to Ossama Khayat.
73 * Update Portuguese debconf translation, thanks to Christian Perrier.
75 * Add a patch to avoid duplicate boundaries in headers when adding an
76 attachment. Closes: #599586.
78 -- Vincent Bernat <bernat@debian.org> Mon, 18 Oct 2010 23:14:37 +0200
80 roundcube (0.3.1-5) unstable; urgency=low
82 * Depends on php-mail-mime 1.7.0 or more recent to handle correctly
83 'mime_param_folding' directive. Closes: #588295.
84 * Add Danish debconf translation, thanks to Joe Dalton.
86 * Add a patch to fix Received header to behave better with Spam
87 Assassin. Closes: #595204.
89 -- Vincent Bernat <bernat@debian.org> Thu, 02 Sep 2010 07:54:58 +0200
91 roundcube (0.3.1-4) unstable; urgency=low
93 * Update README.Debian to state that the variable to modify is
94 'htmleditor' instead of 'enable_htmleditor'. Thanks to Hans
95 Spaans. Closes: #575556.
96 * Add Brazilian Portuguese debconf translation, thanks to Eder
97 L. Marques. Closes: #581745.
98 * Switch default encoding to UTF-8 instead of ISO-8859-1.
100 * Add more explanations on how to install roundcube in a Debian system
101 in README.Debian. Closes: #584458, #582894.
102 * Bump Standards-Version. No changes required.
103 * Switch to 3.0 (quilt) format.
104 * Use Breaks instead of Conflicts to move files from older roundcube
107 -- Vincent Bernat <bernat@debian.org> Sat, 17 Jul 2010 17:23:30 +0200
109 roundcube (0.3.1-3) unstable; urgency=high
111 * RFC 5321, section 4.5.3.1, asks to not impose any limits on length if
112 possible. We respect this by dropping limitation of the local-part of
113 an email address. Closes: #568360, #568537.
114 * Suggests php-auth-sasl to enable use of SASL mechanisms for mail
115 servers. Closes: #567550.
116 * Disable DNS prefetching to avoid information leakage through links
117 embedded in messages. This fixes CVE-2010-0464. Closes: #569660.
118 * Bump Standards-Version. No changes required.
120 -- Vincent Bernat <bernat@debian.org> Sat, 13 Feb 2010 10:21:49 +0100
122 roundcube (0.3.1-2) unstable; urgency=low
124 * Fix VCS links in debian/control, thanks to Torsten Landschoff.
126 * Really ship NEWS.Debian.
127 * Add changesets 3170 and 3202 from upstream to handle gracefully jQuery
128 1.4. Thanks to Volker Gropp for the report. Closes: #565715.
130 -- Vincent Bernat <bernat@debian.org> Mon, 18 Jan 2010 23:11:01 +0100
132 roundcube (0.3.1-1) unstable; urgency=low
134 * New upstream release.
135 * Add a notice in NEWS.Debian about php.ini options that should be set
136 to get Roundcube working properly. Closes: #549428, #552508.
138 -- Vincent Bernat <bernat@debian.org> Sat, 07 Nov 2009 17:41:37 +0100
140 roundcube (0.3-2) unstable; urgency=low
142 * Really fix #544579 since the default value is null without
143 quotes. This really Closes: #544579.
144 * Enlarge login box to accommodate sk_SK locale. Closes: #542933.
146 -- Vincent Bernat <bernat@debian.org> Sun, 27 Sep 2009 11:26:56 +0200
148 roundcube (0.3-1) unstable; urgency=low
150 * New upstream release. Closes: #545498.
151 * Update debconf translations:
152 + Italian, thanks to Luca Monducci. Closes: #544199.
153 + Czech, thanks to Miroslav Kure. Closes: #546413.
154 * Roundcube configuration now uses 'language' instead of 'locale_string'
155 to specify the default language. Update postinst to reflect this
156 change. Thanks to Richard van den Berg for noticing this. Closes: #544579.
157 * Depends on libjs-jquery (>= 1.3) since this is now used by roundcube.
158 * Don't ship any plugins for now but ship an empty plugins directory.
159 * Ship main .htaccess since it is needed to setup correctly PHP (for
160 example, to disable PHP Suhosin cookie encryption).
161 * Bump Standards-Version. No changes required.
163 -- Vincent Bernat <bernat@debian.org> Sun, 27 Sep 2009 11:00:30 +0200
165 roundcube (0.2.2-1) unstable; urgency=low
167 * New upstream release
168 * Bump Standards-Version. No changes required.
169 * Remove *.js.src which are not needed at runtime.
170 * Don't send email contents to Google by default by using php5-pspell
171 instead. Thanks to Anand Kumria. Closes: #529563.
172 * Update debconf translations:
173 + Basque, thanks to Piarres Beobide. Closes: #534282.
175 -- Vincent Bernat <bernat@debian.org> Sun, 05 Jul 2009 09:53:17 +0200
177 roundcube (0.2.1-2) unstable; urgency=low
179 * Update debconf translations:
180 + German, thanks to Helge Kreutzmann. Closes: #520004.
181 + Japanese, thanks to Hideki Yamane. Closes: #520024.
182 + Spanish, thanks to Francisco Javier. Closes: #526696.
183 + Russian, thanks to Yuri Kozlov. Closes: #528796.
184 * Depend on php-mdb2-* (>= 1.5.0b2) since it is needed to fix some
185 bugs. Closes: #519104, #519293. Remove not needed any more patch from
186 debian/patches/series. Keep it in debian/patches to help backports.
188 -- Vincent Bernat <bernat@debian.org> Sat, 16 May 2009 15:30:17 +0200
190 roundcube (0.2.1-1) unstable; urgency=low
192 * New upstream release:
193 + Fix use_packaged_tinymce.patch to apply to this new version
194 + Remove cve-2009-0413.patch which has been applied upstream
196 -- Vincent Bernat <bernat@debian.org> Sat, 14 Mar 2009 17:42:07 +0100
198 roundcube (0.2~stable-2) unstable; urgency=low
200 * Update debconf translations:
201 + French, thanks to Christian Perrier. Closes: #515806.
202 + Swedish, thanks to Martin Bagge. Closes: #516683.
203 * Drop virtual package roundcube-db and add dependencies on real package
204 instead: this way, we can have versioned dependencies on those to avoid
205 version mismatch between packages.
206 * Add a patch to not use a MDB2 feature not present in the Debian
207 package. Thanks to Grzegorz Sobański for the patch. Closes: #519104.
209 -- Vincent Bernat <bernat@debian.org> Wed, 11 Mar 2009 18:49:32 +0100
211 roundcube (0.2~stable-1) unstable; urgency=low
213 * New upstream version. Closes: #503573, #504570.
214 + Add SQL update scripts for this new release and for
215 0.2~alpha. Remove copy of SQL upgrade script from debian/rules.
216 + Remove patch for CVE-2008-5620 which is now fixed upstream.
217 + Remove patch correcting a vulnerability in html2text.php.
218 + Remove patch fixing login issue. This is fixed upstream.
219 + Remove patch setting the default backend to db instead of mdb2:
220 this is not possible any more. We depend on php-mdb2 now.
221 + Update patch to use packaged tinymce.
222 * Upload to unstable since Lenny is out.
223 * Apply fix for XSS issue (CVE-2009-0413). Closes: #514179.
224 * Remove hack to update a SQLite table for an upgrade from a quite old
225 version of roundcube.
226 * Fix pending l10n issues:
227 + Update English debconf template. Closes: #473794.
228 + Add Swedish translation thanks to Martin Bagge. Closes: #508752.
229 * Fix debian/copyright to make lintian happy.
231 -- Vincent Bernat <bernat@debian.org> Sun, 15 Feb 2009 16:18:58 +0100
233 roundcube (0.2~alpha-4) experimental; urgency=low
235 * Add missing ${misc:Depends} to make Lintian happy.
236 * Add description to each patch.
237 * Execute cron job only if the directory to clean exists.
238 * Reload web server configuration instead of restart, thanks to a patch
239 from Tiago Bortoletto Vaz. Closes: #508633.
240 * Fix a vulnerability in quota image generation. This fixes
241 CVE-2008-5620. Thanks to Nico Golde for reporting it. Closes: #509596.
242 * Add missing dependency on php5-gd, used for quota bar.
243 * For roundcube-pgsql, depends on postgresql-client only. This package
244 is provided by the currently supported real package.
246 -- Vincent Bernat <bernat@debian.org> Thu, 25 Dec 2008 11:38:13 +0100
248 roundcube (0.2~alpha-3) experimental; urgency=high
251 * Fix a vulnerability in the use of preg_replace (Closes: #508628).
252 * Adapt descriptions of roundcube-database packages to refer them as
253 metapackages instead of virtual package (Closes: #495434).
254 * Add robots.txt from upstream, even if in some configuration, it will
255 not be considered (Closes: #499108).
256 * Do not ship .htaccess files. Restrictions are set in Apache or
257 Lighttpd configuration files (Closes: #500202).
260 * Changed versioned dependency of rouncube from binary:Version to
261 source:Version since these are all architecture independent packages.
263 -- Vincent Bernat <bernat@debian.org> Sat, 13 Dec 2008 14:36:02 +0100
265 roundcube (0.2~alpha-2) experimental; urgency=low
268 * Fix lintian warnings introduced by previous upload
269 * Fix lighttpd.conf to make it work with latest versions (Closes: #494044)
270 * Do not prepend path to lighty util in postinst and postrm, as per
271 Policy Manual section 6.1
272 * Ship a bug/control file to have all bugs submitted against roundcube
274 * Fix debian/roundcube-core.cron.daily to use
275 /etc/default/roundcube-core instead of /etc/default/roundcube which
276 should not exist any more
279 * Versioned roundcube-core dependency for roundcube
281 -- Vincent Bernat <bernat@debian.org> Sat, 16 Aug 2008 13:22:08 +0200
283 roundcube (0.2~alpha-1) experimental; urgency=low
285 * New upstream release
286 * Update debian/watch file to correctly consider those new releases
287 * Remove the following patches:
288 + messageid-headers-ordering
290 + disable-tinymce-spellchecker
291 * Update the following patches:
292 + correct_install_path
293 + use_packaged_tinymce
294 * Add a new patch to fix a login problem
295 * Depends on tinymce >= 3
297 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 14:10:44 +0200
299 roundcube (0.1.1-7) unstable; urgency=low
301 * Another fix for incorrect tinymce path. This should be the last one!
303 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 12:36:59 +0200
305 roundcube (0.1.1-6) unstable; urgency=low
307 * Fix use_packaged_tinymce patch which was incorrect after switch to
310 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 12:19:16 +0200
312 roundcube (0.1.1-5) unstable; urgency=low
314 * Fix ordering of message-id in message headers, thanks to Reinhard
315 Tartler (Closes: #486493)
316 * Update Standards-Version to 3.8.0
318 -- Vincent Bernat <bernat@debian.org> Tue, 17 Jun 2008 00:33:40 +0200
320 roundcube (0.1.1-4) unstable; urgency=low
322 * Add Slovak debconf translation, thanks to Ivan Masár (Closes: #481376)
323 * Fix debian/copyright:
324 + RoundCube is GPL-2 licensed, not GPL-2+
325 + Add an explanation on the BSD license present at the top of
326 index.php (Closes: #477119)
327 * We do not support tinymce 3, yet. Depends on tinymce2 | tinymce (<<
328 3). Closes: #481145, #483053, #482295
330 -- Vincent Bernat <bernat@debian.org> Tue, 20 May 2008 20:51:52 +0200
332 roundcube (0.1.1-3) unstable; urgency=low
334 * Fix an error introduced when fixing bug #476803. Thanks to Micah
335 Anderson for spotting it (Closes: #479775).
336 * Avoid to pop language question at every upgrade. Thanks to Ivan Vucica
337 for spotting this. The problem lied in the use of db_metaget to get
338 the value of a key set by db_subst in a previous invocation. It seems
339 this is not possible any more (Closes: #480043). The fix implies that
340 we won't ask the question again if more languages are available since
343 -- Vincent Bernat <bernat@debian.org> Thu, 08 May 2008 09:50:24 +0200
345 roundcube (0.1.1-2) unstable; urgency=low
347 * Comment by default Alias directive for tinymce in Apache configuration
348 file (Closes: #476162).
349 * Allow to preseed language value (Closes: #476803).
351 -- Vincent Bernat <bernat@luffy.cx> Sat, 19 Apr 2008 16:50:28 +0200
353 roundcube (0.1.1-1) unstable; urgency=low
355 * New upstream release
356 - Copy old SQL upgrade scripts into debian/sql to allow upgrade from
357 versions older than 0.1
358 - Patch new MySQL upgrade script to fix a typo
359 * Debconf translation updates:
360 - Spanish. Closes: #473788
361 * Depends on php-mail-mime (>= 1.5.0) and drop compatibility patch
362 * Install upstream changelog in /usr/share/doc/roundcube*
364 -- Vincent Bernat <bernat@luffy.cx> Sat, 05 Apr 2008 18:16:33 +0200
366 roundcube (0.1-4) unstable; urgency=low
368 * Debconf translation updates:
369 - French. Closes: #469802
370 - Russian. Closes: #469847
371 - Galician. Closes: #469866
372 - German. Closes: #469875
373 - Finnish. Closes: #469922
374 - Italian. Closes: #469987
375 - Czech. Closes: #470150
376 - Portuguese. Closes: #470156
377 - Spanish. Closes: #470732
378 - Basque. Closes: #470871
379 - Arabic. Closes: #471470
381 -- Vincent Bernat <bernat@luffy.cx> Sat, 08 Mar 2008 11:15:00 +0100
383 roundcube (0.1-3) unstable; urgency=low
385 * Fix problem with too old php-mail-mime package (Closes: #469814)
387 -- Vincent Bernat <bernat@luffy.cx> Fri, 07 Mar 2008 11:06:49 +0100
389 roundcube (0.1-2) unstable; urgency=low
391 * Ship bin/ directory as well. This fix conversion from HTML to text in
393 * Disable spellchecker for tinymce since it is not shipped with Debian
396 -- Vincent Bernat <bernat@luffy.cx> Fri, 07 Mar 2008 09:42:39 +0100
398 roundcube (0.1-1) unstable; urgency=low
400 * New upstream release (Closes: #469487).
401 - This release seems to fix failure to set some fields when replying,
402 with bincimap as IMAP server (Closes: #443562)
403 - It also fixes the deletion of multiple messages, still with
404 bincimap (Closes: #451404)
405 * Remove 'ob_gzhandler.patch' and 'xss-fix.patch'. They have been
407 * Upstream has switched to MDB2 database backend which is not packaged
408 in Debian yet. We switch back to old backend.
409 * Fix debian/watch to handle correctly detection of new versions.
410 * Add support for lighttpd and remove support for older version of
411 Apache. The debconf question about webserver autoconfiguration is
412 reworded (Closes: #462961).
413 * Do not depend on a specific revision of cdbs.
414 * Move po-debconf from Build-Depends-Indep to Build-Depends since it is
415 needed for clean target.
416 * Correct path to /usr/share/file/magic, provided by libmagic1. Provide
417 license information about this file in debian/copyright.
419 -- Vincent Bernat <bernat@luffy.cx> Wed, 05 Mar 2008 20:49:03 +0100
421 roundcube (0.1~rc2-6) unstable; urgency=high
423 * Bug fix: "CVE-2007-6321: Cross-site scripting (XSS) vulnerability",
424 thanks to Micah Anderson (Closes: #455840). The patch is from
425 http://lists.roundcube.net/mail-archive/dev/2007-12/0000038.html and
426 provided by Robin Elfrink. It has been modified with some functions
427 stolen from Squirrelmail.
428 * Finnish debconf template, thanks to Esko Arajärvi (Closes: #458244).
430 -- Vincent Bernat <bernat@luffy.cx> Sat, 29 Dec 2007 21:55:17 +0100
432 roundcube (0.1~rc2-5) unstable; urgency=low
434 * Deal with old /etc/logrotate.d/roundcube by removing it if left
435 untouched (Closes: #456546). Also deal with /etc/default/roundcube and
436 /etc/cron.daily/roundcube.
438 -- Vincent Bernat <bernat@luffy.cx> Tue, 18 Dec 2007 23:02:46 +0100
440 roundcube (0.1~rc2-4) unstable; urgency=low
442 * Thightened dependencies for a safe upgrade
443 * Finally removed any circular dependency, -db packages no longer pull
444 a full roundcube install
446 -- Romain Beauxis <toots@rastageeks.org> Sun, 09 Dec 2007 14:24:24 +0100
448 roundcube (0.1~rc2-3) unstable; urgency=low
451 * Bumped standard version to 3.7.3 (no changes)
453 -- Romain Beauxis <toots@rastageeks.org> Sun, 09 Dec 2007 14:19:28 +0100
455 roundcube (0.1~rc2-2) experimental; urgency=low
458 * Fix a conflict between ob_gzhandler and zlib output compression,
459 thanks to kaouete (Closes: #450482).
462 * Fix tinymce patch and inclusion
464 * Splitted virtual packages to avoid circular dependencies.
465 Uploading to experimental, as this is an important change and we may
468 -- Romain Beauxis <toots@rastageeks.org> Mon, 26 Nov 2007 11:54:21 +0100
470 roundcube (0.1~rc2-1) unstable; urgency=low
472 * New upstream, thanks to Nicolas Stransky (Closes: #447503). This
473 release support tinymce as HTML editor. Look at README.Debian for more
475 * Update Galician debconf template, thanks to Jacobo Tarrio (Closes: #447943).
477 -- Vincent Bernat <bernat@luffy.cx> Mon, 29 Oct 2007 22:08:43 +0100
479 roundcube (0.1~rc1-3) unstable; urgency=low
481 * In respect to policy 12.3, do not put main.inc.php.dist in
482 /usr/share/doc, thanks to Jonas Smedegaard (Closes: #446502).
483 * Update German and French debconf templates, thanks to Christian
484 Perrier (Closes: #446458) and Helge Kreutzmann (Closes: #446532).
486 -- Vincent Bernat <bernat@luffy.cx> Sun, 14 Oct 2007 08:41:24 +0200
488 roundcube (0.1~rc1-2) unstable; urgency=low
490 * Fix dependencies by creating virtual packages for each database
491 backend, thanks to Joey Hess (Closes: #444925).
493 -- Vincent Bernat <bernat@luffy.cx> Tue, 02 Oct 2007 20:09:19 +0200
495 roundcube (0.1~rc1-1) unstable; urgency=low
497 * New upstream release
498 * Removed non gpl file des.inc
500 -- Romain Beauxis <toots@rastageeks.org> Tue, 24 Jul 2007 13:36:20 +0200
502 roundcube (0.1~rc1~dfsg-3) unstable; urgency=low
504 * Add php5-mcrypt dependency (Closes: #431177)
506 -- Vincent Bernat <bernat@luffy.cx> Sat, 30 Jun 2007 19:36:21 +0200
508 roundcube (0.1~rc1~dfsg-2) unstable; urgency=low
510 * Removed custom unix_timestamp for sqlite: solved upstream
511 * Debconf templates and debian/control reviewed by the debian-l10n-
512 english team as part of the Smith review project.
513 Closes: #426086, #427546, #427546
514 * Debconf translation updates:
515 - Galician. Closes: #426140
516 - Basque. Closes: #426150
517 - Czech. Closes: #426428
518 - Portuguese. Closes: #426451
519 - Arabic. Closes: #427110
520 - Italian. Closes: #427206
521 - German. Closes: #427536
522 - French. Closes: #427736
523 - Tamil. Closes: #428254
524 - Russian. Closes: #428364
525 - Spanish. Closes: #428573
527 -- Romain Beauxis <toots@rastageeks.org> Tue, 05 Jun 2007 15:22:36 +0200
529 roundcube (0.1~rc1~dfsg-1) unstable; urgency=low
532 * New upstream release
533 * Update script for sqlite in postinst
535 * Fixed dh_link calls
537 * Added custom patch to use php unix timestamp support
538 with sqlite since UNIX_TIMESTAMP is not supported by sqlite.
539 * Dropped php4 dependencies
541 -- Vincent Bernat <bernat@luffy.cx> Sun, 20 May 2007 13:59:44 +0200
543 roundcube (0.1~beta2.2~dfsg-2) unstable; urgency=low
545 * Fix a security issue by disallowing access to logs.
546 * First upload to unstable.
548 -- Vincent Bernat <bernat@luffy.cx> Sat, 5 May 2007 00:23:40 +0200
550 roundcube (0.1~beta2.2~dfsg-1) experimental; urgency=low
552 * Initial release. (Closes: #333756, #344949)
554 -- Romain Beauxis <toots@rastageeks.org> Tue, 13 Mar 2007 13:28:05 +0100