1 roundcube (0.3.1-4) unstable; urgency=low
3 * Update README.Debian to state that the variable to modify is
4 'htmleditor' instead of 'enable_htmleditor'. Thanks to Hans
5 Spaans. Closes: #575556.
6 * Add Brazilian Portuguese debconf translation, thanks to Eder
7 L. Marques. Closes: #581745.
8 * Switch default encoding to UTF-8 instead of ISO-8859-1.
10 * Add more explanations on how to install roundcube in a Debian system
11 in README.Debian. Closes: #584458, #582894.
12 * Bump Standards-Version. No changes required.
13 * Switch to 3.0 (quilt) format.
14 * Use Breaks instead of Conflicts to move files from older roundcube
17 -- Vincent Bernat <bernat@debian.org> Sat, 17 Jul 2010 17:23:30 +0200
19 roundcube (0.3.1-3) unstable; urgency=high
21 * RFC 5321, section 4.5.3.1, asks to not impose any limits on length if
22 possible. We respect this by dropping limitation of the local-part of
23 an email address. Closes: #568360, #568537.
24 * Suggests php-auth-sasl to enable use of SASL mechanisms for mail
25 servers. Closes: #567550.
26 * Disable DNS prefetching to avoid information leakage through links
27 embedded in messages. This fixes CVE-2010-0464. Closes: #569660.
28 * Bump Standards-Version. No changes required.
30 -- Vincent Bernat <bernat@debian.org> Sat, 13 Feb 2010 10:21:49 +0100
32 roundcube (0.3.1-2) unstable; urgency=low
34 * Fix VCS links in debian/control, thanks to Torsten Landschoff.
36 * Really ship NEWS.Debian.
37 * Add changesets 3170 and 3202 from upstream to handle gracefully jQuery
38 1.4. Thanks to Volker Gropp for the report. Closes: #565715.
40 -- Vincent Bernat <bernat@debian.org> Mon, 18 Jan 2010 23:11:01 +0100
42 roundcube (0.3.1-1) unstable; urgency=low
44 * New upstream release.
45 * Add a notice in NEWS.Debian about php.ini options that should be set
46 to get Roundcube working properly. Closes: #549428, #552508.
48 -- Vincent Bernat <bernat@debian.org> Sat, 07 Nov 2009 17:41:37 +0100
50 roundcube (0.3-2) unstable; urgency=low
52 * Really fix #544579 since the default value is null without
53 quotes. This really Closes: #544579.
54 * Enlarge login box to accommodate sk_SK locale. Closes: #542933.
56 -- Vincent Bernat <bernat@debian.org> Sun, 27 Sep 2009 11:26:56 +0200
58 roundcube (0.3-1) unstable; urgency=low
60 * New upstream release. Closes: #545498.
61 * Update debconf translations:
62 + Italian, thanks to Luca Monducci. Closes: #544199.
63 + Czech, thanks to Miroslav Kure. Closes: #546413.
64 * Roundcube configuration now uses 'language' instead of 'locale_string'
65 to specify the default language. Update postinst to reflect this
66 change. Thanks to Richard van den Berg for noticing this. Closes: #544579.
67 * Depends on libjs-jquery (>= 1.3) since this is now used by roundcube.
68 * Don't ship any plugins for now but ship an empty plugins directory.
69 * Ship main .htaccess since it is needed to setup correctly PHP (for
70 example, to disable PHP Suhosin cookie encryption).
71 * Bump Standards-Version. No changes required.
73 -- Vincent Bernat <bernat@debian.org> Sun, 27 Sep 2009 11:00:30 +0200
75 roundcube (0.2.2-1) unstable; urgency=low
77 * New upstream release
78 * Bump Standards-Version. No changes required.
79 * Remove *.js.src which are not needed at runtime.
80 * Don't send email contents to Google by default by using php5-pspell
81 instead. Thanks to Anand Kumria. Closes: #529563.
82 * Update debconf translations:
83 + Basque, thanks to Piarres Beobide. Closes: #534282.
85 -- Vincent Bernat <bernat@debian.org> Sun, 05 Jul 2009 09:53:17 +0200
87 roundcube (0.2.1-2) unstable; urgency=low
89 * Update debconf translations:
90 + German, thanks to Helge Kreutzmann. Closes: #520004.
91 + Japanese, thanks to Hideki Yamane. Closes: #520024.
92 + Spanish, thanks to Francisco Javier. Closes: #526696.
93 + Russian, thanks to Yuri Kozlov. Closes: #528796.
94 * Depend on php-mdb2-* (>= 1.5.0b2) since it is needed to fix some
95 bugs. Closes: #519104, #519293. Remove not needed any more patch from
96 debian/patches/series. Keep it in debian/patches to help backports.
98 -- Vincent Bernat <bernat@debian.org> Sat, 16 May 2009 15:30:17 +0200
100 roundcube (0.2.1-1) unstable; urgency=low
102 * New upstream release:
103 + Fix use_packaged_tinymce.patch to apply to this new version
104 + Remove cve-2009-0413.patch which has been applied upstream
106 -- Vincent Bernat <bernat@debian.org> Sat, 14 Mar 2009 17:42:07 +0100
108 roundcube (0.2~stable-2) unstable; urgency=low
110 * Update debconf translations:
111 + French, thanks to Christian Perrier. Closes: #515806.
112 + Swedish, thanks to Martin Bagge. Closes: #516683.
113 * Drop virtual package roundcube-db and add dependencies on real package
114 instead: this way, we can have versioned dependencies on those to avoid
115 version mismatch between packages.
116 * Add a patch to not use a MDB2 feature not present in the Debian
117 package. Thanks to Grzegorz Sobański for the patch. Closes: #519104.
119 -- Vincent Bernat <bernat@debian.org> Wed, 11 Mar 2009 18:49:32 +0100
121 roundcube (0.2~stable-1) unstable; urgency=low
123 * New upstream version. Closes: #503573, #504570.
124 + Add SQL update scripts for this new release and for
125 0.2~alpha. Remove copy of SQL upgrade script from debian/rules.
126 + Remove patch for CVE-2008-5620 which is now fixed upstream.
127 + Remove patch correcting a vulnerability in html2text.php.
128 + Remove patch fixing login issue. This is fixed upstream.
129 + Remove patch setting the default backend to db instead of mdb2:
130 this is not possible any more. We depend on php-mdb2 now.
131 + Update patch to use packaged tinymce.
132 * Upload to unstable since Lenny is out.
133 * Apply fix for XSS issue (CVE-2009-0413). Closes: #514179.
134 * Remove hack to update a SQLite table for an upgrade from a quite old
135 version of roundcube.
136 * Fix pending l10n issues:
137 + Update English debconf template. Closes: #473794.
138 + Add Swedish translation thanks to Martin Bagge. Closes: #508752.
139 * Fix debian/copyright to make lintian happy.
141 -- Vincent Bernat <bernat@debian.org> Sun, 15 Feb 2009 16:18:58 +0100
143 roundcube (0.2~alpha-4) experimental; urgency=low
145 * Add missing ${misc:Depends} to make Lintian happy.
146 * Add description to each patch.
147 * Execute cron job only if the directory to clean exists.
148 * Reload web server configuration instead of restart, thanks to a patch
149 from Tiago Bortoletto Vaz. Closes: #508633.
150 * Fix a vulnerability in quota image generation. This fixes
151 CVE-2008-5620. Thanks to Nico Golde for reporting it. Closes: #509596.
152 * Add missing dependency on php5-gd, used for quota bar.
153 * For roundcube-pgsql, depends on postgresql-client only. This package
154 is provided by the currently supported real package.
156 -- Vincent Bernat <bernat@debian.org> Thu, 25 Dec 2008 11:38:13 +0100
158 roundcube (0.2~alpha-3) experimental; urgency=high
161 * Fix a vulnerability in the use of preg_replace (Closes: #508628).
162 * Adapt descriptions of roundcube-database packages to refer them as
163 metapackages instead of virtual package (Closes: #495434).
164 * Add robots.txt from upstream, even if in some configuration, it will
165 not be considered (Closes: #499108).
166 * Do not ship .htaccess files. Restrictions are set in Apache or
167 Lighttpd configuration files (Closes: #500202).
170 * Changed versioned dependency of rouncube from binary:Version to
171 source:Version since these are all architecture independent packages.
173 -- Vincent Bernat <bernat@debian.org> Sat, 13 Dec 2008 14:36:02 +0100
175 roundcube (0.2~alpha-2) experimental; urgency=low
178 * Fix lintian warnings introduced by previous upload
179 * Fix lighttpd.conf to make it work with latest versions (Closes: #494044)
180 * Do not prepend path to lighty util in postinst and postrm, as per
181 Policy Manual section 6.1
182 * Ship a bug/control file to have all bugs submitted against roundcube
184 * Fix debian/roundcube-core.cron.daily to use
185 /etc/default/roundcube-core instead of /etc/default/roundcube which
186 should not exist any more
189 * Versioned roundcube-core dependency for roundcube
191 -- Vincent Bernat <bernat@debian.org> Sat, 16 Aug 2008 13:22:08 +0200
193 roundcube (0.2~alpha-1) experimental; urgency=low
195 * New upstream release
196 * Update debian/watch file to correctly consider those new releases
197 * Remove the following patches:
198 + messageid-headers-ordering
200 + disable-tinymce-spellchecker
201 * Update the following patches:
202 + correct_install_path
203 + use_packaged_tinymce
204 * Add a new patch to fix a login problem
205 * Depends on tinymce >= 3
207 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 14:10:44 +0200
209 roundcube (0.1.1-7) unstable; urgency=low
211 * Another fix for incorrect tinymce path. This should be the last one!
213 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 12:36:59 +0200
215 roundcube (0.1.1-6) unstable; urgency=low
217 * Fix use_packaged_tinymce patch which was incorrect after switch to
220 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 12:19:16 +0200
222 roundcube (0.1.1-5) unstable; urgency=low
224 * Fix ordering of message-id in message headers, thanks to Reinhard
225 Tartler (Closes: #486493)
226 * Update Standards-Version to 3.8.0
228 -- Vincent Bernat <bernat@debian.org> Tue, 17 Jun 2008 00:33:40 +0200
230 roundcube (0.1.1-4) unstable; urgency=low
232 * Add Slovak debconf translation, thanks to Ivan Masár (Closes: #481376)
233 * Fix debian/copyright:
234 + RoundCube is GPL-2 licensed, not GPL-2+
235 + Add an explanation on the BSD license present at the top of
236 index.php (Closes: #477119)
237 * We do not support tinymce 3, yet. Depends on tinymce2 | tinymce (<<
238 3). Closes: #481145, #483053, #482295
240 -- Vincent Bernat <bernat@debian.org> Tue, 20 May 2008 20:51:52 +0200
242 roundcube (0.1.1-3) unstable; urgency=low
244 * Fix an error introduced when fixing bug #476803. Thanks to Micah
245 Anderson for spotting it (Closes: #479775).
246 * Avoid to pop language question at every upgrade. Thanks to Ivan Vucica
247 for spotting this. The problem lied in the use of db_metaget to get
248 the value of a key set by db_subst in a previous invocation. It seems
249 this is not possible any more (Closes: #480043). The fix implies that
250 we won't ask the question again if more languages are available since
253 -- Vincent Bernat <bernat@debian.org> Thu, 08 May 2008 09:50:24 +0200
255 roundcube (0.1.1-2) unstable; urgency=low
257 * Comment by default Alias directive for tinymce in Apache configuration
258 file (Closes: #476162).
259 * Allow to preseed language value (Closes: #476803).
261 -- Vincent Bernat <bernat@luffy.cx> Sat, 19 Apr 2008 16:50:28 +0200
263 roundcube (0.1.1-1) unstable; urgency=low
265 * New upstream release
266 - Copy old SQL upgrade scripts into debian/sql to allow upgrade from
267 versions older than 0.1
268 - Patch new MySQL upgrade script to fix a typo
269 * Debconf translation updates:
270 - Spanish. Closes: #473788
271 * Depends on php-mail-mime (>= 1.5.0) and drop compatibility patch
272 * Install upstream changelog in /usr/share/doc/roundcube*
274 -- Vincent Bernat <bernat@luffy.cx> Sat, 05 Apr 2008 18:16:33 +0200
276 roundcube (0.1-4) unstable; urgency=low
278 * Debconf translation updates:
279 - French. Closes: #469802
280 - Russian. Closes: #469847
281 - Galician. Closes: #469866
282 - German. Closes: #469875
283 - Finnish. Closes: #469922
284 - Italian. Closes: #469987
285 - Czech. Closes: #470150
286 - Portuguese. Closes: #470156
287 - Spanish. Closes: #470732
288 - Basque. Closes: #470871
289 - Arabic. Closes: #471470
291 -- Vincent Bernat <bernat@luffy.cx> Sat, 08 Mar 2008 11:15:00 +0100
293 roundcube (0.1-3) unstable; urgency=low
295 * Fix problem with too old php-mail-mime package (Closes: #469814)
297 -- Vincent Bernat <bernat@luffy.cx> Fri, 07 Mar 2008 11:06:49 +0100
299 roundcube (0.1-2) unstable; urgency=low
301 * Ship bin/ directory as well. This fix conversion from HTML to text in
303 * Disable spellchecker for tinymce since it is not shipped with Debian
306 -- Vincent Bernat <bernat@luffy.cx> Fri, 07 Mar 2008 09:42:39 +0100
308 roundcube (0.1-1) unstable; urgency=low
310 * New upstream release (Closes: #469487).
311 - This release seems to fix failure to set some fields when replying,
312 with bincimap as IMAP server (Closes: #443562)
313 - It also fixes the deletion of multiple messages, still with
314 bincimap (Closes: #451404)
315 * Remove 'ob_gzhandler.patch' and 'xss-fix.patch'. They have been
317 * Upstream has switched to MDB2 database backend which is not packaged
318 in Debian yet. We switch back to old backend.
319 * Fix debian/watch to handle correctly detection of new versions.
320 * Add support for lighttpd and remove support for older version of
321 Apache. The debconf question about webserver autoconfiguration is
322 reworded (Closes: #462961).
323 * Do not depend on a specific revision of cdbs.
324 * Move po-debconf from Build-Depends-Indep to Build-Depends since it is
325 needed for clean target.
326 * Correct path to /usr/share/file/magic, provided by libmagic1. Provide
327 license information about this file in debian/copyright.
329 -- Vincent Bernat <bernat@luffy.cx> Wed, 05 Mar 2008 20:49:03 +0100
331 roundcube (0.1~rc2-6) unstable; urgency=high
333 * Bug fix: "CVE-2007-6321: Cross-site scripting (XSS) vulnerability",
334 thanks to Micah Anderson (Closes: #455840). The patch is from
335 http://lists.roundcube.net/mail-archive/dev/2007-12/0000038.html and
336 provided by Robin Elfrink. It has been modified with some functions
337 stolen from Squirrelmail.
338 * Finnish debconf template, thanks to Esko Arajärvi (Closes: #458244).
340 -- Vincent Bernat <bernat@luffy.cx> Sat, 29 Dec 2007 21:55:17 +0100
342 roundcube (0.1~rc2-5) unstable; urgency=low
344 * Deal with old /etc/logrotate.d/roundcube by removing it if left
345 untouched (Closes: #456546). Also deal with /etc/default/roundcube and
346 /etc/cron.daily/roundcube.
348 -- Vincent Bernat <bernat@luffy.cx> Tue, 18 Dec 2007 23:02:46 +0100
350 roundcube (0.1~rc2-4) unstable; urgency=low
352 * Thightened dependencies for a safe upgrade
353 * Finally removed any circular dependency, -db packages no longer pull
354 a full roundcube install
356 -- Romain Beauxis <toots@rastageeks.org> Sun, 09 Dec 2007 14:24:24 +0100
358 roundcube (0.1~rc2-3) unstable; urgency=low
361 * Bumped standard version to 3.7.3 (no changes)
363 -- Romain Beauxis <toots@rastageeks.org> Sun, 09 Dec 2007 14:19:28 +0100
365 roundcube (0.1~rc2-2) experimental; urgency=low
368 * Fix a conflict between ob_gzhandler and zlib output compression,
369 thanks to kaouete (Closes: #450482).
372 * Fix tinymce patch and inclusion
374 * Splitted virtual packages to avoid circular dependencies.
375 Uploading to experimental, as this is an important change and we may
378 -- Romain Beauxis <toots@rastageeks.org> Mon, 26 Nov 2007 11:54:21 +0100
380 roundcube (0.1~rc2-1) unstable; urgency=low
382 * New upstream, thanks to Nicolas Stransky (Closes: #447503). This
383 release support tinymce as HTML editor. Look at README.Debian for more
385 * Update Galician debconf template, thanks to Jacobo Tarrio (Closes: #447943).
387 -- Vincent Bernat <bernat@luffy.cx> Mon, 29 Oct 2007 22:08:43 +0100
389 roundcube (0.1~rc1-3) unstable; urgency=low
391 * In respect to policy 12.3, do not put main.inc.php.dist in
392 /usr/share/doc, thanks to Jonas Smedegaard (Closes: #446502).
393 * Update German and French debconf templates, thanks to Christian
394 Perrier (Closes: #446458) and Helge Kreutzmann (Closes: #446532).
396 -- Vincent Bernat <bernat@luffy.cx> Sun, 14 Oct 2007 08:41:24 +0200
398 roundcube (0.1~rc1-2) unstable; urgency=low
400 * Fix dependencies by creating virtual packages for each database
401 backend, thanks to Joey Hess (Closes: #444925).
403 -- Vincent Bernat <bernat@luffy.cx> Tue, 02 Oct 2007 20:09:19 +0200
405 roundcube (0.1~rc1-1) unstable; urgency=low
407 * New upstream release
408 * Removed non gpl file des.inc
410 -- Romain Beauxis <toots@rastageeks.org> Tue, 24 Jul 2007 13:36:20 +0200
412 roundcube (0.1~rc1~dfsg-3) unstable; urgency=low
414 * Add php5-mcrypt dependency (Closes: #431177)
416 -- Vincent Bernat <bernat@luffy.cx> Sat, 30 Jun 2007 19:36:21 +0200
418 roundcube (0.1~rc1~dfsg-2) unstable; urgency=low
420 * Removed custom unix_timestamp for sqlite: solved upstream
421 * Debconf templates and debian/control reviewed by the debian-l10n-
422 english team as part of the Smith review project.
423 Closes: #426086, #427546, #427546
424 * Debconf translation updates:
425 - Galician. Closes: #426140
426 - Basque. Closes: #426150
427 - Czech. Closes: #426428
428 - Portuguese. Closes: #426451
429 - Arabic. Closes: #427110
430 - Italian. Closes: #427206
431 - German. Closes: #427536
432 - French. Closes: #427736
433 - Tamil. Closes: #428254
434 - Russian. Closes: #428364
435 - Spanish. Closes: #428573
437 -- Romain Beauxis <toots@rastageeks.org> Tue, 05 Jun 2007 15:22:36 +0200
439 roundcube (0.1~rc1~dfsg-1) unstable; urgency=low
442 * New upstream release
443 * Update script for sqlite in postinst
445 * Fixed dh_link calls
447 * Added custom patch to use php unix timestamp support
448 with sqlite since UNIX_TIMESTAMP is not supported by sqlite.
449 * Dropped php4 dependencies
451 -- Vincent Bernat <bernat@luffy.cx> Sun, 20 May 2007 13:59:44 +0200
453 roundcube (0.1~beta2.2~dfsg-2) unstable; urgency=low
455 * Fix a security issue by disallowing access to logs.
456 * First upload to unstable.
458 -- Vincent Bernat <bernat@luffy.cx> Sat, 5 May 2007 00:23:40 +0200
460 roundcube (0.1~beta2.2~dfsg-1) experimental; urgency=low
462 * Initial release. (Closes: #333756, #344949)
464 -- Romain Beauxis <toots@rastageeks.org> Tue, 13 Mar 2007 13:28:05 +0100