1 roundcube (0.5-3) UNRELEASED; urgency=low
3 * Don't assign "skins" directory to www-data. Closes: #612552.
5 -- Vincent Bernat <bernat@debian.org> Wed, 09 Feb 2011 07:32:42 +0100
7 roundcube (0.5-2) experimental; urgency=low
9 * If 0.3.1 was installed from scratch, upgrade does not work on MySQL
10 and PostgreSQL because we try to create an index which already
11 exists. With SQLite, the error is ignored, no fix needed. When using
12 PostgreSQL, fix this by dropping the index if it already
13 exists. Nothing similar seems to exist with MySQL. Therefore, just
14 don't create the index. We need to handle this later. See bug
17 -- Vincent Bernat <bernat@debian.org> Fri, 21 Jan 2011 21:44:05 +0100
19 roundcube (0.5-1) experimental; urgency=low
21 * New upstream release. Closes: #592312.
22 + Drop patches included upstream (DNS prefetching, jQuery 1.4
23 handling, email address validation, duplicate headers, incorrectly
24 formatted received headers). Adapt other patches. One of the patch
25 now correctly states to use dpkg-reconfigure roundcube-core.
27 + Update SQL commands to use to upgrade database.
28 That also closes: #602922. Unfortunately, the user may get some
29 harmless error messages because there is no way to know if
30 0.3.1 was installed from scratch or upgraded from 0.3.
31 + Update dependencies to match INSTALL file. Only exception is the
32 use of Mail_Mime 1.8.0 in place of 1.8.1 which is not available in
33 Debian. We depends on jQuery 1.4.2 because 1.4.4 is not available in
35 + All folders are correctly checked since 0.4. Closes: #552430.
36 + Also, closes: #553194 since it seems to have been fixed too.
37 + There is also the possibility to not top-quote since 0.4.
39 + Closes: #602144. Also fixed.
40 * Move .htaccess to /etc/roundcube and use a symlink (Closes: #591369).
41 * Don't let www-data overwrite debian-db.php. Closes: #608976.
42 * Bump Standards-Version. No changes required.
44 -- Vincent Bernat <bernat@debian.org> Sat, 15 Jan 2011 12:40:27 +0100
46 roundcube (0.3.1-6) unstable; urgency=low
48 * Update Arabic debconf translation, thanks to Ossama Khayat.
50 * Update Portuguese debconf translation, thanks to Christian Perrier.
52 * Add a patch to avoid duplicate boundaries in headers when adding an
53 attachment. Closes: #599586.
55 -- Vincent Bernat <bernat@debian.org> Mon, 18 Oct 2010 23:14:37 +0200
57 roundcube (0.3.1-5) unstable; urgency=low
59 * Depends on php-mail-mime 1.7.0 or more recent to handle correctly
60 'mime_param_folding' directive. Closes: #588295.
61 * Add Danish debconf translation, thanks to Joe Dalton.
63 * Add a patch to fix Received header to behave better with Spam
64 Assassin. Closes: #595204.
66 -- Vincent Bernat <bernat@debian.org> Thu, 02 Sep 2010 07:54:58 +0200
68 roundcube (0.3.1-4) unstable; urgency=low
70 * Update README.Debian to state that the variable to modify is
71 'htmleditor' instead of 'enable_htmleditor'. Thanks to Hans
72 Spaans. Closes: #575556.
73 * Add Brazilian Portuguese debconf translation, thanks to Eder
74 L. Marques. Closes: #581745.
75 * Switch default encoding to UTF-8 instead of ISO-8859-1.
77 * Add more explanations on how to install roundcube in a Debian system
78 in README.Debian. Closes: #584458, #582894.
79 * Bump Standards-Version. No changes required.
80 * Switch to 3.0 (quilt) format.
81 * Use Breaks instead of Conflicts to move files from older roundcube
84 -- Vincent Bernat <bernat@debian.org> Sat, 17 Jul 2010 17:23:30 +0200
86 roundcube (0.3.1-3) unstable; urgency=high
88 * RFC 5321, section 4.5.3.1, asks to not impose any limits on length if
89 possible. We respect this by dropping limitation of the local-part of
90 an email address. Closes: #568360, #568537.
91 * Suggests php-auth-sasl to enable use of SASL mechanisms for mail
92 servers. Closes: #567550.
93 * Disable DNS prefetching to avoid information leakage through links
94 embedded in messages. This fixes CVE-2010-0464. Closes: #569660.
95 * Bump Standards-Version. No changes required.
97 -- Vincent Bernat <bernat@debian.org> Sat, 13 Feb 2010 10:21:49 +0100
99 roundcube (0.3.1-2) unstable; urgency=low
101 * Fix VCS links in debian/control, thanks to Torsten Landschoff.
103 * Really ship NEWS.Debian.
104 * Add changesets 3170 and 3202 from upstream to handle gracefully jQuery
105 1.4. Thanks to Volker Gropp for the report. Closes: #565715.
107 -- Vincent Bernat <bernat@debian.org> Mon, 18 Jan 2010 23:11:01 +0100
109 roundcube (0.3.1-1) unstable; urgency=low
111 * New upstream release.
112 * Add a notice in NEWS.Debian about php.ini options that should be set
113 to get Roundcube working properly. Closes: #549428, #552508.
115 -- Vincent Bernat <bernat@debian.org> Sat, 07 Nov 2009 17:41:37 +0100
117 roundcube (0.3-2) unstable; urgency=low
119 * Really fix #544579 since the default value is null without
120 quotes. This really Closes: #544579.
121 * Enlarge login box to accommodate sk_SK locale. Closes: #542933.
123 -- Vincent Bernat <bernat@debian.org> Sun, 27 Sep 2009 11:26:56 +0200
125 roundcube (0.3-1) unstable; urgency=low
127 * New upstream release. Closes: #545498.
128 * Update debconf translations:
129 + Italian, thanks to Luca Monducci. Closes: #544199.
130 + Czech, thanks to Miroslav Kure. Closes: #546413.
131 * Roundcube configuration now uses 'language' instead of 'locale_string'
132 to specify the default language. Update postinst to reflect this
133 change. Thanks to Richard van den Berg for noticing this. Closes: #544579.
134 * Depends on libjs-jquery (>= 1.3) since this is now used by roundcube.
135 * Don't ship any plugins for now but ship an empty plugins directory.
136 * Ship main .htaccess since it is needed to setup correctly PHP (for
137 example, to disable PHP Suhosin cookie encryption).
138 * Bump Standards-Version. No changes required.
140 -- Vincent Bernat <bernat@debian.org> Sun, 27 Sep 2009 11:00:30 +0200
142 roundcube (0.2.2-1) unstable; urgency=low
144 * New upstream release
145 * Bump Standards-Version. No changes required.
146 * Remove *.js.src which are not needed at runtime.
147 * Don't send email contents to Google by default by using php5-pspell
148 instead. Thanks to Anand Kumria. Closes: #529563.
149 * Update debconf translations:
150 + Basque, thanks to Piarres Beobide. Closes: #534282.
152 -- Vincent Bernat <bernat@debian.org> Sun, 05 Jul 2009 09:53:17 +0200
154 roundcube (0.2.1-2) unstable; urgency=low
156 * Update debconf translations:
157 + German, thanks to Helge Kreutzmann. Closes: #520004.
158 + Japanese, thanks to Hideki Yamane. Closes: #520024.
159 + Spanish, thanks to Francisco Javier. Closes: #526696.
160 + Russian, thanks to Yuri Kozlov. Closes: #528796.
161 * Depend on php-mdb2-* (>= 1.5.0b2) since it is needed to fix some
162 bugs. Closes: #519104, #519293. Remove not needed any more patch from
163 debian/patches/series. Keep it in debian/patches to help backports.
165 -- Vincent Bernat <bernat@debian.org> Sat, 16 May 2009 15:30:17 +0200
167 roundcube (0.2.1-1) unstable; urgency=low
169 * New upstream release:
170 + Fix use_packaged_tinymce.patch to apply to this new version
171 + Remove cve-2009-0413.patch which has been applied upstream
173 -- Vincent Bernat <bernat@debian.org> Sat, 14 Mar 2009 17:42:07 +0100
175 roundcube (0.2~stable-2) unstable; urgency=low
177 * Update debconf translations:
178 + French, thanks to Christian Perrier. Closes: #515806.
179 + Swedish, thanks to Martin Bagge. Closes: #516683.
180 * Drop virtual package roundcube-db and add dependencies on real package
181 instead: this way, we can have versioned dependencies on those to avoid
182 version mismatch between packages.
183 * Add a patch to not use a MDB2 feature not present in the Debian
184 package. Thanks to Grzegorz Sobański for the patch. Closes: #519104.
186 -- Vincent Bernat <bernat@debian.org> Wed, 11 Mar 2009 18:49:32 +0100
188 roundcube (0.2~stable-1) unstable; urgency=low
190 * New upstream version. Closes: #503573, #504570.
191 + Add SQL update scripts for this new release and for
192 0.2~alpha. Remove copy of SQL upgrade script from debian/rules.
193 + Remove patch for CVE-2008-5620 which is now fixed upstream.
194 + Remove patch correcting a vulnerability in html2text.php.
195 + Remove patch fixing login issue. This is fixed upstream.
196 + Remove patch setting the default backend to db instead of mdb2:
197 this is not possible any more. We depend on php-mdb2 now.
198 + Update patch to use packaged tinymce.
199 * Upload to unstable since Lenny is out.
200 * Apply fix for XSS issue (CVE-2009-0413). Closes: #514179.
201 * Remove hack to update a SQLite table for an upgrade from a quite old
202 version of roundcube.
203 * Fix pending l10n issues:
204 + Update English debconf template. Closes: #473794.
205 + Add Swedish translation thanks to Martin Bagge. Closes: #508752.
206 * Fix debian/copyright to make lintian happy.
208 -- Vincent Bernat <bernat@debian.org> Sun, 15 Feb 2009 16:18:58 +0100
210 roundcube (0.2~alpha-4) experimental; urgency=low
212 * Add missing ${misc:Depends} to make Lintian happy.
213 * Add description to each patch.
214 * Execute cron job only if the directory to clean exists.
215 * Reload web server configuration instead of restart, thanks to a patch
216 from Tiago Bortoletto Vaz. Closes: #508633.
217 * Fix a vulnerability in quota image generation. This fixes
218 CVE-2008-5620. Thanks to Nico Golde for reporting it. Closes: #509596.
219 * Add missing dependency on php5-gd, used for quota bar.
220 * For roundcube-pgsql, depends on postgresql-client only. This package
221 is provided by the currently supported real package.
223 -- Vincent Bernat <bernat@debian.org> Thu, 25 Dec 2008 11:38:13 +0100
225 roundcube (0.2~alpha-3) experimental; urgency=high
228 * Fix a vulnerability in the use of preg_replace (Closes: #508628).
229 * Adapt descriptions of roundcube-database packages to refer them as
230 metapackages instead of virtual package (Closes: #495434).
231 * Add robots.txt from upstream, even if in some configuration, it will
232 not be considered (Closes: #499108).
233 * Do not ship .htaccess files. Restrictions are set in Apache or
234 Lighttpd configuration files (Closes: #500202).
237 * Changed versioned dependency of rouncube from binary:Version to
238 source:Version since these are all architecture independent packages.
240 -- Vincent Bernat <bernat@debian.org> Sat, 13 Dec 2008 14:36:02 +0100
242 roundcube (0.2~alpha-2) experimental; urgency=low
245 * Fix lintian warnings introduced by previous upload
246 * Fix lighttpd.conf to make it work with latest versions (Closes: #494044)
247 * Do not prepend path to lighty util in postinst and postrm, as per
248 Policy Manual section 6.1
249 * Ship a bug/control file to have all bugs submitted against roundcube
251 * Fix debian/roundcube-core.cron.daily to use
252 /etc/default/roundcube-core instead of /etc/default/roundcube which
253 should not exist any more
256 * Versioned roundcube-core dependency for roundcube
258 -- Vincent Bernat <bernat@debian.org> Sat, 16 Aug 2008 13:22:08 +0200
260 roundcube (0.2~alpha-1) experimental; urgency=low
262 * New upstream release
263 * Update debian/watch file to correctly consider those new releases
264 * Remove the following patches:
265 + messageid-headers-ordering
267 + disable-tinymce-spellchecker
268 * Update the following patches:
269 + correct_install_path
270 + use_packaged_tinymce
271 * Add a new patch to fix a login problem
272 * Depends on tinymce >= 3
274 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 14:10:44 +0200
276 roundcube (0.1.1-7) unstable; urgency=low
278 * Another fix for incorrect tinymce path. This should be the last one!
280 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 12:36:59 +0200
282 roundcube (0.1.1-6) unstable; urgency=low
284 * Fix use_packaged_tinymce patch which was incorrect after switch to
287 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 12:19:16 +0200
289 roundcube (0.1.1-5) unstable; urgency=low
291 * Fix ordering of message-id in message headers, thanks to Reinhard
292 Tartler (Closes: #486493)
293 * Update Standards-Version to 3.8.0
295 -- Vincent Bernat <bernat@debian.org> Tue, 17 Jun 2008 00:33:40 +0200
297 roundcube (0.1.1-4) unstable; urgency=low
299 * Add Slovak debconf translation, thanks to Ivan Masár (Closes: #481376)
300 * Fix debian/copyright:
301 + RoundCube is GPL-2 licensed, not GPL-2+
302 + Add an explanation on the BSD license present at the top of
303 index.php (Closes: #477119)
304 * We do not support tinymce 3, yet. Depends on tinymce2 | tinymce (<<
305 3). Closes: #481145, #483053, #482295
307 -- Vincent Bernat <bernat@debian.org> Tue, 20 May 2008 20:51:52 +0200
309 roundcube (0.1.1-3) unstable; urgency=low
311 * Fix an error introduced when fixing bug #476803. Thanks to Micah
312 Anderson for spotting it (Closes: #479775).
313 * Avoid to pop language question at every upgrade. Thanks to Ivan Vucica
314 for spotting this. The problem lied in the use of db_metaget to get
315 the value of a key set by db_subst in a previous invocation. It seems
316 this is not possible any more (Closes: #480043). The fix implies that
317 we won't ask the question again if more languages are available since
320 -- Vincent Bernat <bernat@debian.org> Thu, 08 May 2008 09:50:24 +0200
322 roundcube (0.1.1-2) unstable; urgency=low
324 * Comment by default Alias directive for tinymce in Apache configuration
325 file (Closes: #476162).
326 * Allow to preseed language value (Closes: #476803).
328 -- Vincent Bernat <bernat@luffy.cx> Sat, 19 Apr 2008 16:50:28 +0200
330 roundcube (0.1.1-1) unstable; urgency=low
332 * New upstream release
333 - Copy old SQL upgrade scripts into debian/sql to allow upgrade from
334 versions older than 0.1
335 - Patch new MySQL upgrade script to fix a typo
336 * Debconf translation updates:
337 - Spanish. Closes: #473788
338 * Depends on php-mail-mime (>= 1.5.0) and drop compatibility patch
339 * Install upstream changelog in /usr/share/doc/roundcube*
341 -- Vincent Bernat <bernat@luffy.cx> Sat, 05 Apr 2008 18:16:33 +0200
343 roundcube (0.1-4) unstable; urgency=low
345 * Debconf translation updates:
346 - French. Closes: #469802
347 - Russian. Closes: #469847
348 - Galician. Closes: #469866
349 - German. Closes: #469875
350 - Finnish. Closes: #469922
351 - Italian. Closes: #469987
352 - Czech. Closes: #470150
353 - Portuguese. Closes: #470156
354 - Spanish. Closes: #470732
355 - Basque. Closes: #470871
356 - Arabic. Closes: #471470
358 -- Vincent Bernat <bernat@luffy.cx> Sat, 08 Mar 2008 11:15:00 +0100
360 roundcube (0.1-3) unstable; urgency=low
362 * Fix problem with too old php-mail-mime package (Closes: #469814)
364 -- Vincent Bernat <bernat@luffy.cx> Fri, 07 Mar 2008 11:06:49 +0100
366 roundcube (0.1-2) unstable; urgency=low
368 * Ship bin/ directory as well. This fix conversion from HTML to text in
370 * Disable spellchecker for tinymce since it is not shipped with Debian
373 -- Vincent Bernat <bernat@luffy.cx> Fri, 07 Mar 2008 09:42:39 +0100
375 roundcube (0.1-1) unstable; urgency=low
377 * New upstream release (Closes: #469487).
378 - This release seems to fix failure to set some fields when replying,
379 with bincimap as IMAP server (Closes: #443562)
380 - It also fixes the deletion of multiple messages, still with
381 bincimap (Closes: #451404)
382 * Remove 'ob_gzhandler.patch' and 'xss-fix.patch'. They have been
384 * Upstream has switched to MDB2 database backend which is not packaged
385 in Debian yet. We switch back to old backend.
386 * Fix debian/watch to handle correctly detection of new versions.
387 * Add support for lighttpd and remove support for older version of
388 Apache. The debconf question about webserver autoconfiguration is
389 reworded (Closes: #462961).
390 * Do not depend on a specific revision of cdbs.
391 * Move po-debconf from Build-Depends-Indep to Build-Depends since it is
392 needed for clean target.
393 * Correct path to /usr/share/file/magic, provided by libmagic1. Provide
394 license information about this file in debian/copyright.
396 -- Vincent Bernat <bernat@luffy.cx> Wed, 05 Mar 2008 20:49:03 +0100
398 roundcube (0.1~rc2-6) unstable; urgency=high
400 * Bug fix: "CVE-2007-6321: Cross-site scripting (XSS) vulnerability",
401 thanks to Micah Anderson (Closes: #455840). The patch is from
402 http://lists.roundcube.net/mail-archive/dev/2007-12/0000038.html and
403 provided by Robin Elfrink. It has been modified with some functions
404 stolen from Squirrelmail.
405 * Finnish debconf template, thanks to Esko Arajärvi (Closes: #458244).
407 -- Vincent Bernat <bernat@luffy.cx> Sat, 29 Dec 2007 21:55:17 +0100
409 roundcube (0.1~rc2-5) unstable; urgency=low
411 * Deal with old /etc/logrotate.d/roundcube by removing it if left
412 untouched (Closes: #456546). Also deal with /etc/default/roundcube and
413 /etc/cron.daily/roundcube.
415 -- Vincent Bernat <bernat@luffy.cx> Tue, 18 Dec 2007 23:02:46 +0100
417 roundcube (0.1~rc2-4) unstable; urgency=low
419 * Thightened dependencies for a safe upgrade
420 * Finally removed any circular dependency, -db packages no longer pull
421 a full roundcube install
423 -- Romain Beauxis <toots@rastageeks.org> Sun, 09 Dec 2007 14:24:24 +0100
425 roundcube (0.1~rc2-3) unstable; urgency=low
428 * Bumped standard version to 3.7.3 (no changes)
430 -- Romain Beauxis <toots@rastageeks.org> Sun, 09 Dec 2007 14:19:28 +0100
432 roundcube (0.1~rc2-2) experimental; urgency=low
435 * Fix a conflict between ob_gzhandler and zlib output compression,
436 thanks to kaouete (Closes: #450482).
439 * Fix tinymce patch and inclusion
441 * Splitted virtual packages to avoid circular dependencies.
442 Uploading to experimental, as this is an important change and we may
445 -- Romain Beauxis <toots@rastageeks.org> Mon, 26 Nov 2007 11:54:21 +0100
447 roundcube (0.1~rc2-1) unstable; urgency=low
449 * New upstream, thanks to Nicolas Stransky (Closes: #447503). This
450 release support tinymce as HTML editor. Look at README.Debian for more
452 * Update Galician debconf template, thanks to Jacobo Tarrio (Closes: #447943).
454 -- Vincent Bernat <bernat@luffy.cx> Mon, 29 Oct 2007 22:08:43 +0100
456 roundcube (0.1~rc1-3) unstable; urgency=low
458 * In respect to policy 12.3, do not put main.inc.php.dist in
459 /usr/share/doc, thanks to Jonas Smedegaard (Closes: #446502).
460 * Update German and French debconf templates, thanks to Christian
461 Perrier (Closes: #446458) and Helge Kreutzmann (Closes: #446532).
463 -- Vincent Bernat <bernat@luffy.cx> Sun, 14 Oct 2007 08:41:24 +0200
465 roundcube (0.1~rc1-2) unstable; urgency=low
467 * Fix dependencies by creating virtual packages for each database
468 backend, thanks to Joey Hess (Closes: #444925).
470 -- Vincent Bernat <bernat@luffy.cx> Tue, 02 Oct 2007 20:09:19 +0200
472 roundcube (0.1~rc1-1) unstable; urgency=low
474 * New upstream release
475 * Removed non gpl file des.inc
477 -- Romain Beauxis <toots@rastageeks.org> Tue, 24 Jul 2007 13:36:20 +0200
479 roundcube (0.1~rc1~dfsg-3) unstable; urgency=low
481 * Add php5-mcrypt dependency (Closes: #431177)
483 -- Vincent Bernat <bernat@luffy.cx> Sat, 30 Jun 2007 19:36:21 +0200
485 roundcube (0.1~rc1~dfsg-2) unstable; urgency=low
487 * Removed custom unix_timestamp for sqlite: solved upstream
488 * Debconf templates and debian/control reviewed by the debian-l10n-
489 english team as part of the Smith review project.
490 Closes: #426086, #427546, #427546
491 * Debconf translation updates:
492 - Galician. Closes: #426140
493 - Basque. Closes: #426150
494 - Czech. Closes: #426428
495 - Portuguese. Closes: #426451
496 - Arabic. Closes: #427110
497 - Italian. Closes: #427206
498 - German. Closes: #427536
499 - French. Closes: #427736
500 - Tamil. Closes: #428254
501 - Russian. Closes: #428364
502 - Spanish. Closes: #428573
504 -- Romain Beauxis <toots@rastageeks.org> Tue, 05 Jun 2007 15:22:36 +0200
506 roundcube (0.1~rc1~dfsg-1) unstable; urgency=low
509 * New upstream release
510 * Update script for sqlite in postinst
512 * Fixed dh_link calls
514 * Added custom patch to use php unix timestamp support
515 with sqlite since UNIX_TIMESTAMP is not supported by sqlite.
516 * Dropped php4 dependencies
518 -- Vincent Bernat <bernat@luffy.cx> Sun, 20 May 2007 13:59:44 +0200
520 roundcube (0.1~beta2.2~dfsg-2) unstable; urgency=low
522 * Fix a security issue by disallowing access to logs.
523 * First upload to unstable.
525 -- Vincent Bernat <bernat@luffy.cx> Sat, 5 May 2007 00:23:40 +0200
527 roundcube (0.1~beta2.2~dfsg-1) experimental; urgency=low
529 * Initial release. (Closes: #333756, #344949)
531 -- Romain Beauxis <toots@rastageeks.org> Tue, 13 Mar 2007 13:28:05 +0100