1 roundcube (0.5.1-1) unstable; urgency=low
3 * New upstream version. Some bugs are corrected in this release or in a
5 + when switching to HTML mode, content type is now correctly set.
7 + header delimiters handling has been fixed in 0.5.
9 * Don't assign "skins" directory to www-data. Closes: #612552.
10 * Add instructions on how to install and upgrade when not using
11 dbconfig-common. We do not ship UPGRADING file any more since it is
12 misleading. Closes: #612511.
13 * Fix MySQL indexes if upgrading from 0.5-2 or lesser. Closes: #610725.
14 * Rework how symlinks work. The only directory to use is
15 /var/lib/roundcube. We use symlink from /usr/share/roundcube to
16 /var/lib/roundcube and not the other way. Moreover, plugins and skins
17 are also symlinked. A user should be able to add plugins and skins in
18 /var/lib/roundcube while default ones are in
19 /usr/share/roundcube. Closes: #612553.
21 -- Vincent Bernat <bernat@debian.org> Wed, 09 Feb 2011 07:32:42 +0100
23 roundcube (0.5-2) experimental; urgency=low
25 * If 0.3.1 was installed from scratch, upgrade does not work on MySQL
26 and PostgreSQL because we try to create an index which already
27 exists. With SQLite, the error is ignored, no fix needed. When using
28 PostgreSQL, fix this by dropping the index if it already
29 exists. Nothing similar seems to exist with MySQL. Therefore, just
30 don't create the index. We need to handle this later. See bug
33 -- Vincent Bernat <bernat@debian.org> Fri, 21 Jan 2011 21:44:05 +0100
35 roundcube (0.5-1) experimental; urgency=low
37 * New upstream release. Closes: #592312.
38 + Drop patches included upstream (DNS prefetching, jQuery 1.4
39 handling, email address validation, duplicate headers, incorrectly
40 formatted received headers). Adapt other patches. One of the patch
41 now correctly states to use dpkg-reconfigure roundcube-core.
43 + Update SQL commands to use to upgrade database.
44 That also closes: #602922. Unfortunately, the user may get some
45 harmless error messages because there is no way to know if
46 0.3.1 was installed from scratch or upgraded from 0.3.
47 + Update dependencies to match INSTALL file. Only exception is the
48 use of Mail_Mime 1.8.0 in place of 1.8.1 which is not available in
49 Debian. We depends on jQuery 1.4.2 because 1.4.4 is not available in
51 + All folders are correctly checked since 0.4. Closes: #552430.
52 + Also, closes: #553194 since it seems to have been fixed too.
53 + There is also the possibility to not top-quote since 0.4.
55 + Closes: #602144. Also fixed.
56 * Move .htaccess to /etc/roundcube and use a symlink (Closes: #591369).
57 * Don't let www-data overwrite debian-db.php. Closes: #608976.
58 * Bump Standards-Version. No changes required.
60 -- Vincent Bernat <bernat@debian.org> Sat, 15 Jan 2011 12:40:27 +0100
62 roundcube (0.3.1-6) unstable; urgency=low
64 * Update Arabic debconf translation, thanks to Ossama Khayat.
66 * Update Portuguese debconf translation, thanks to Christian Perrier.
68 * Add a patch to avoid duplicate boundaries in headers when adding an
69 attachment. Closes: #599586.
71 -- Vincent Bernat <bernat@debian.org> Mon, 18 Oct 2010 23:14:37 +0200
73 roundcube (0.3.1-5) unstable; urgency=low
75 * Depends on php-mail-mime 1.7.0 or more recent to handle correctly
76 'mime_param_folding' directive. Closes: #588295.
77 * Add Danish debconf translation, thanks to Joe Dalton.
79 * Add a patch to fix Received header to behave better with Spam
80 Assassin. Closes: #595204.
82 -- Vincent Bernat <bernat@debian.org> Thu, 02 Sep 2010 07:54:58 +0200
84 roundcube (0.3.1-4) unstable; urgency=low
86 * Update README.Debian to state that the variable to modify is
87 'htmleditor' instead of 'enable_htmleditor'. Thanks to Hans
88 Spaans. Closes: #575556.
89 * Add Brazilian Portuguese debconf translation, thanks to Eder
90 L. Marques. Closes: #581745.
91 * Switch default encoding to UTF-8 instead of ISO-8859-1.
93 * Add more explanations on how to install roundcube in a Debian system
94 in README.Debian. Closes: #584458, #582894.
95 * Bump Standards-Version. No changes required.
96 * Switch to 3.0 (quilt) format.
97 * Use Breaks instead of Conflicts to move files from older roundcube
100 -- Vincent Bernat <bernat@debian.org> Sat, 17 Jul 2010 17:23:30 +0200
102 roundcube (0.3.1-3) unstable; urgency=high
104 * RFC 5321, section 4.5.3.1, asks to not impose any limits on length if
105 possible. We respect this by dropping limitation of the local-part of
106 an email address. Closes: #568360, #568537.
107 * Suggests php-auth-sasl to enable use of SASL mechanisms for mail
108 servers. Closes: #567550.
109 * Disable DNS prefetching to avoid information leakage through links
110 embedded in messages. This fixes CVE-2010-0464. Closes: #569660.
111 * Bump Standards-Version. No changes required.
113 -- Vincent Bernat <bernat@debian.org> Sat, 13 Feb 2010 10:21:49 +0100
115 roundcube (0.3.1-2) unstable; urgency=low
117 * Fix VCS links in debian/control, thanks to Torsten Landschoff.
119 * Really ship NEWS.Debian.
120 * Add changesets 3170 and 3202 from upstream to handle gracefully jQuery
121 1.4. Thanks to Volker Gropp for the report. Closes: #565715.
123 -- Vincent Bernat <bernat@debian.org> Mon, 18 Jan 2010 23:11:01 +0100
125 roundcube (0.3.1-1) unstable; urgency=low
127 * New upstream release.
128 * Add a notice in NEWS.Debian about php.ini options that should be set
129 to get Roundcube working properly. Closes: #549428, #552508.
131 -- Vincent Bernat <bernat@debian.org> Sat, 07 Nov 2009 17:41:37 +0100
133 roundcube (0.3-2) unstable; urgency=low
135 * Really fix #544579 since the default value is null without
136 quotes. This really Closes: #544579.
137 * Enlarge login box to accommodate sk_SK locale. Closes: #542933.
139 -- Vincent Bernat <bernat@debian.org> Sun, 27 Sep 2009 11:26:56 +0200
141 roundcube (0.3-1) unstable; urgency=low
143 * New upstream release. Closes: #545498.
144 * Update debconf translations:
145 + Italian, thanks to Luca Monducci. Closes: #544199.
146 + Czech, thanks to Miroslav Kure. Closes: #546413.
147 * Roundcube configuration now uses 'language' instead of 'locale_string'
148 to specify the default language. Update postinst to reflect this
149 change. Thanks to Richard van den Berg for noticing this. Closes: #544579.
150 * Depends on libjs-jquery (>= 1.3) since this is now used by roundcube.
151 * Don't ship any plugins for now but ship an empty plugins directory.
152 * Ship main .htaccess since it is needed to setup correctly PHP (for
153 example, to disable PHP Suhosin cookie encryption).
154 * Bump Standards-Version. No changes required.
156 -- Vincent Bernat <bernat@debian.org> Sun, 27 Sep 2009 11:00:30 +0200
158 roundcube (0.2.2-1) unstable; urgency=low
160 * New upstream release
161 * Bump Standards-Version. No changes required.
162 * Remove *.js.src which are not needed at runtime.
163 * Don't send email contents to Google by default by using php5-pspell
164 instead. Thanks to Anand Kumria. Closes: #529563.
165 * Update debconf translations:
166 + Basque, thanks to Piarres Beobide. Closes: #534282.
168 -- Vincent Bernat <bernat@debian.org> Sun, 05 Jul 2009 09:53:17 +0200
170 roundcube (0.2.1-2) unstable; urgency=low
172 * Update debconf translations:
173 + German, thanks to Helge Kreutzmann. Closes: #520004.
174 + Japanese, thanks to Hideki Yamane. Closes: #520024.
175 + Spanish, thanks to Francisco Javier. Closes: #526696.
176 + Russian, thanks to Yuri Kozlov. Closes: #528796.
177 * Depend on php-mdb2-* (>= 1.5.0b2) since it is needed to fix some
178 bugs. Closes: #519104, #519293. Remove not needed any more patch from
179 debian/patches/series. Keep it in debian/patches to help backports.
181 -- Vincent Bernat <bernat@debian.org> Sat, 16 May 2009 15:30:17 +0200
183 roundcube (0.2.1-1) unstable; urgency=low
185 * New upstream release:
186 + Fix use_packaged_tinymce.patch to apply to this new version
187 + Remove cve-2009-0413.patch which has been applied upstream
189 -- Vincent Bernat <bernat@debian.org> Sat, 14 Mar 2009 17:42:07 +0100
191 roundcube (0.2~stable-2) unstable; urgency=low
193 * Update debconf translations:
194 + French, thanks to Christian Perrier. Closes: #515806.
195 + Swedish, thanks to Martin Bagge. Closes: #516683.
196 * Drop virtual package roundcube-db and add dependencies on real package
197 instead: this way, we can have versioned dependencies on those to avoid
198 version mismatch between packages.
199 * Add a patch to not use a MDB2 feature not present in the Debian
200 package. Thanks to Grzegorz Sobański for the patch. Closes: #519104.
202 -- Vincent Bernat <bernat@debian.org> Wed, 11 Mar 2009 18:49:32 +0100
204 roundcube (0.2~stable-1) unstable; urgency=low
206 * New upstream version. Closes: #503573, #504570.
207 + Add SQL update scripts for this new release and for
208 0.2~alpha. Remove copy of SQL upgrade script from debian/rules.
209 + Remove patch for CVE-2008-5620 which is now fixed upstream.
210 + Remove patch correcting a vulnerability in html2text.php.
211 + Remove patch fixing login issue. This is fixed upstream.
212 + Remove patch setting the default backend to db instead of mdb2:
213 this is not possible any more. We depend on php-mdb2 now.
214 + Update patch to use packaged tinymce.
215 * Upload to unstable since Lenny is out.
216 * Apply fix for XSS issue (CVE-2009-0413). Closes: #514179.
217 * Remove hack to update a SQLite table for an upgrade from a quite old
218 version of roundcube.
219 * Fix pending l10n issues:
220 + Update English debconf template. Closes: #473794.
221 + Add Swedish translation thanks to Martin Bagge. Closes: #508752.
222 * Fix debian/copyright to make lintian happy.
224 -- Vincent Bernat <bernat@debian.org> Sun, 15 Feb 2009 16:18:58 +0100
226 roundcube (0.2~alpha-4) experimental; urgency=low
228 * Add missing ${misc:Depends} to make Lintian happy.
229 * Add description to each patch.
230 * Execute cron job only if the directory to clean exists.
231 * Reload web server configuration instead of restart, thanks to a patch
232 from Tiago Bortoletto Vaz. Closes: #508633.
233 * Fix a vulnerability in quota image generation. This fixes
234 CVE-2008-5620. Thanks to Nico Golde for reporting it. Closes: #509596.
235 * Add missing dependency on php5-gd, used for quota bar.
236 * For roundcube-pgsql, depends on postgresql-client only. This package
237 is provided by the currently supported real package.
239 -- Vincent Bernat <bernat@debian.org> Thu, 25 Dec 2008 11:38:13 +0100
241 roundcube (0.2~alpha-3) experimental; urgency=high
244 * Fix a vulnerability in the use of preg_replace (Closes: #508628).
245 * Adapt descriptions of roundcube-database packages to refer them as
246 metapackages instead of virtual package (Closes: #495434).
247 * Add robots.txt from upstream, even if in some configuration, it will
248 not be considered (Closes: #499108).
249 * Do not ship .htaccess files. Restrictions are set in Apache or
250 Lighttpd configuration files (Closes: #500202).
253 * Changed versioned dependency of rouncube from binary:Version to
254 source:Version since these are all architecture independent packages.
256 -- Vincent Bernat <bernat@debian.org> Sat, 13 Dec 2008 14:36:02 +0100
258 roundcube (0.2~alpha-2) experimental; urgency=low
261 * Fix lintian warnings introduced by previous upload
262 * Fix lighttpd.conf to make it work with latest versions (Closes: #494044)
263 * Do not prepend path to lighty util in postinst and postrm, as per
264 Policy Manual section 6.1
265 * Ship a bug/control file to have all bugs submitted against roundcube
267 * Fix debian/roundcube-core.cron.daily to use
268 /etc/default/roundcube-core instead of /etc/default/roundcube which
269 should not exist any more
272 * Versioned roundcube-core dependency for roundcube
274 -- Vincent Bernat <bernat@debian.org> Sat, 16 Aug 2008 13:22:08 +0200
276 roundcube (0.2~alpha-1) experimental; urgency=low
278 * New upstream release
279 * Update debian/watch file to correctly consider those new releases
280 * Remove the following patches:
281 + messageid-headers-ordering
283 + disable-tinymce-spellchecker
284 * Update the following patches:
285 + correct_install_path
286 + use_packaged_tinymce
287 * Add a new patch to fix a login problem
288 * Depends on tinymce >= 3
290 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 14:10:44 +0200
292 roundcube (0.1.1-7) unstable; urgency=low
294 * Another fix for incorrect tinymce path. This should be the last one!
296 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 12:36:59 +0200
298 roundcube (0.1.1-6) unstable; urgency=low
300 * Fix use_packaged_tinymce patch which was incorrect after switch to
303 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 12:19:16 +0200
305 roundcube (0.1.1-5) unstable; urgency=low
307 * Fix ordering of message-id in message headers, thanks to Reinhard
308 Tartler (Closes: #486493)
309 * Update Standards-Version to 3.8.0
311 -- Vincent Bernat <bernat@debian.org> Tue, 17 Jun 2008 00:33:40 +0200
313 roundcube (0.1.1-4) unstable; urgency=low
315 * Add Slovak debconf translation, thanks to Ivan Masár (Closes: #481376)
316 * Fix debian/copyright:
317 + RoundCube is GPL-2 licensed, not GPL-2+
318 + Add an explanation on the BSD license present at the top of
319 index.php (Closes: #477119)
320 * We do not support tinymce 3, yet. Depends on tinymce2 | tinymce (<<
321 3). Closes: #481145, #483053, #482295
323 -- Vincent Bernat <bernat@debian.org> Tue, 20 May 2008 20:51:52 +0200
325 roundcube (0.1.1-3) unstable; urgency=low
327 * Fix an error introduced when fixing bug #476803. Thanks to Micah
328 Anderson for spotting it (Closes: #479775).
329 * Avoid to pop language question at every upgrade. Thanks to Ivan Vucica
330 for spotting this. The problem lied in the use of db_metaget to get
331 the value of a key set by db_subst in a previous invocation. It seems
332 this is not possible any more (Closes: #480043). The fix implies that
333 we won't ask the question again if more languages are available since
336 -- Vincent Bernat <bernat@debian.org> Thu, 08 May 2008 09:50:24 +0200
338 roundcube (0.1.1-2) unstable; urgency=low
340 * Comment by default Alias directive for tinymce in Apache configuration
341 file (Closes: #476162).
342 * Allow to preseed language value (Closes: #476803).
344 -- Vincent Bernat <bernat@luffy.cx> Sat, 19 Apr 2008 16:50:28 +0200
346 roundcube (0.1.1-1) unstable; urgency=low
348 * New upstream release
349 - Copy old SQL upgrade scripts into debian/sql to allow upgrade from
350 versions older than 0.1
351 - Patch new MySQL upgrade script to fix a typo
352 * Debconf translation updates:
353 - Spanish. Closes: #473788
354 * Depends on php-mail-mime (>= 1.5.0) and drop compatibility patch
355 * Install upstream changelog in /usr/share/doc/roundcube*
357 -- Vincent Bernat <bernat@luffy.cx> Sat, 05 Apr 2008 18:16:33 +0200
359 roundcube (0.1-4) unstable; urgency=low
361 * Debconf translation updates:
362 - French. Closes: #469802
363 - Russian. Closes: #469847
364 - Galician. Closes: #469866
365 - German. Closes: #469875
366 - Finnish. Closes: #469922
367 - Italian. Closes: #469987
368 - Czech. Closes: #470150
369 - Portuguese. Closes: #470156
370 - Spanish. Closes: #470732
371 - Basque. Closes: #470871
372 - Arabic. Closes: #471470
374 -- Vincent Bernat <bernat@luffy.cx> Sat, 08 Mar 2008 11:15:00 +0100
376 roundcube (0.1-3) unstable; urgency=low
378 * Fix problem with too old php-mail-mime package (Closes: #469814)
380 -- Vincent Bernat <bernat@luffy.cx> Fri, 07 Mar 2008 11:06:49 +0100
382 roundcube (0.1-2) unstable; urgency=low
384 * Ship bin/ directory as well. This fix conversion from HTML to text in
386 * Disable spellchecker for tinymce since it is not shipped with Debian
389 -- Vincent Bernat <bernat@luffy.cx> Fri, 07 Mar 2008 09:42:39 +0100
391 roundcube (0.1-1) unstable; urgency=low
393 * New upstream release (Closes: #469487).
394 - This release seems to fix failure to set some fields when replying,
395 with bincimap as IMAP server (Closes: #443562)
396 - It also fixes the deletion of multiple messages, still with
397 bincimap (Closes: #451404)
398 * Remove 'ob_gzhandler.patch' and 'xss-fix.patch'. They have been
400 * Upstream has switched to MDB2 database backend which is not packaged
401 in Debian yet. We switch back to old backend.
402 * Fix debian/watch to handle correctly detection of new versions.
403 * Add support for lighttpd and remove support for older version of
404 Apache. The debconf question about webserver autoconfiguration is
405 reworded (Closes: #462961).
406 * Do not depend on a specific revision of cdbs.
407 * Move po-debconf from Build-Depends-Indep to Build-Depends since it is
408 needed for clean target.
409 * Correct path to /usr/share/file/magic, provided by libmagic1. Provide
410 license information about this file in debian/copyright.
412 -- Vincent Bernat <bernat@luffy.cx> Wed, 05 Mar 2008 20:49:03 +0100
414 roundcube (0.1~rc2-6) unstable; urgency=high
416 * Bug fix: "CVE-2007-6321: Cross-site scripting (XSS) vulnerability",
417 thanks to Micah Anderson (Closes: #455840). The patch is from
418 http://lists.roundcube.net/mail-archive/dev/2007-12/0000038.html and
419 provided by Robin Elfrink. It has been modified with some functions
420 stolen from Squirrelmail.
421 * Finnish debconf template, thanks to Esko Arajärvi (Closes: #458244).
423 -- Vincent Bernat <bernat@luffy.cx> Sat, 29 Dec 2007 21:55:17 +0100
425 roundcube (0.1~rc2-5) unstable; urgency=low
427 * Deal with old /etc/logrotate.d/roundcube by removing it if left
428 untouched (Closes: #456546). Also deal with /etc/default/roundcube and
429 /etc/cron.daily/roundcube.
431 -- Vincent Bernat <bernat@luffy.cx> Tue, 18 Dec 2007 23:02:46 +0100
433 roundcube (0.1~rc2-4) unstable; urgency=low
435 * Thightened dependencies for a safe upgrade
436 * Finally removed any circular dependency, -db packages no longer pull
437 a full roundcube install
439 -- Romain Beauxis <toots@rastageeks.org> Sun, 09 Dec 2007 14:24:24 +0100
441 roundcube (0.1~rc2-3) unstable; urgency=low
444 * Bumped standard version to 3.7.3 (no changes)
446 -- Romain Beauxis <toots@rastageeks.org> Sun, 09 Dec 2007 14:19:28 +0100
448 roundcube (0.1~rc2-2) experimental; urgency=low
451 * Fix a conflict between ob_gzhandler and zlib output compression,
452 thanks to kaouete (Closes: #450482).
455 * Fix tinymce patch and inclusion
457 * Splitted virtual packages to avoid circular dependencies.
458 Uploading to experimental, as this is an important change and we may
461 -- Romain Beauxis <toots@rastageeks.org> Mon, 26 Nov 2007 11:54:21 +0100
463 roundcube (0.1~rc2-1) unstable; urgency=low
465 * New upstream, thanks to Nicolas Stransky (Closes: #447503). This
466 release support tinymce as HTML editor. Look at README.Debian for more
468 * Update Galician debconf template, thanks to Jacobo Tarrio (Closes: #447943).
470 -- Vincent Bernat <bernat@luffy.cx> Mon, 29 Oct 2007 22:08:43 +0100
472 roundcube (0.1~rc1-3) unstable; urgency=low
474 * In respect to policy 12.3, do not put main.inc.php.dist in
475 /usr/share/doc, thanks to Jonas Smedegaard (Closes: #446502).
476 * Update German and French debconf templates, thanks to Christian
477 Perrier (Closes: #446458) and Helge Kreutzmann (Closes: #446532).
479 -- Vincent Bernat <bernat@luffy.cx> Sun, 14 Oct 2007 08:41:24 +0200
481 roundcube (0.1~rc1-2) unstable; urgency=low
483 * Fix dependencies by creating virtual packages for each database
484 backend, thanks to Joey Hess (Closes: #444925).
486 -- Vincent Bernat <bernat@luffy.cx> Tue, 02 Oct 2007 20:09:19 +0200
488 roundcube (0.1~rc1-1) unstable; urgency=low
490 * New upstream release
491 * Removed non gpl file des.inc
493 -- Romain Beauxis <toots@rastageeks.org> Tue, 24 Jul 2007 13:36:20 +0200
495 roundcube (0.1~rc1~dfsg-3) unstable; urgency=low
497 * Add php5-mcrypt dependency (Closes: #431177)
499 -- Vincent Bernat <bernat@luffy.cx> Sat, 30 Jun 2007 19:36:21 +0200
501 roundcube (0.1~rc1~dfsg-2) unstable; urgency=low
503 * Removed custom unix_timestamp for sqlite: solved upstream
504 * Debconf templates and debian/control reviewed by the debian-l10n-
505 english team as part of the Smith review project.
506 Closes: #426086, #427546, #427546
507 * Debconf translation updates:
508 - Galician. Closes: #426140
509 - Basque. Closes: #426150
510 - Czech. Closes: #426428
511 - Portuguese. Closes: #426451
512 - Arabic. Closes: #427110
513 - Italian. Closes: #427206
514 - German. Closes: #427536
515 - French. Closes: #427736
516 - Tamil. Closes: #428254
517 - Russian. Closes: #428364
518 - Spanish. Closes: #428573
520 -- Romain Beauxis <toots@rastageeks.org> Tue, 05 Jun 2007 15:22:36 +0200
522 roundcube (0.1~rc1~dfsg-1) unstable; urgency=low
525 * New upstream release
526 * Update script for sqlite in postinst
528 * Fixed dh_link calls
530 * Added custom patch to use php unix timestamp support
531 with sqlite since UNIX_TIMESTAMP is not supported by sqlite.
532 * Dropped php4 dependencies
534 -- Vincent Bernat <bernat@luffy.cx> Sun, 20 May 2007 13:59:44 +0200
536 roundcube (0.1~beta2.2~dfsg-2) unstable; urgency=low
538 * Fix a security issue by disallowing access to logs.
539 * First upload to unstable.
541 -- Vincent Bernat <bernat@luffy.cx> Sat, 5 May 2007 00:23:40 +0200
543 roundcube (0.1~beta2.2~dfsg-1) experimental; urgency=low
545 * Initial release. (Closes: #333756, #344949)
547 -- Romain Beauxis <toots@rastageeks.org> Tue, 13 Mar 2007 13:28:05 +0100