1 roundcube (0.5.1-1) unstable; urgency=low
3 * New upstream version. Some bugs are corrected in this release or in a
5 + when switching to HTML mode, content type is now correctly set.
7 + header delimiters handling has been fixed in 0.5.
9 * Don't assign "skins" directory to www-data. Closes: #612552.
10 * Add instructions on how to install and upgrade when not using
11 dbconfig-common. We do not ship UPGRADING file any more since it is
12 misleading. Closes: #612511.
13 * Fix MySQL indexes if upgrading from 0.5-2 or lesser. Closes: #610725.
14 * Rework how symlinks work. The only directory to use is
15 /var/lib/roundcube. We use symlink from /usr/share/roundcube to
16 /var/lib/roundcube and not the other way. Moreover, plugins and skins
17 are also symlinked. A user should be able to add plugins and skins in
18 /var/lib/roundcube while default ones are in
19 /usr/share/roundcube. Closes: #612553.
21 -- Vincent Bernat <bernat@debian.org> Wed, 09 Feb 2011 07:32:42 +0100
23 roundcube (0.5-3) UNRELEASED; urgency=low
25 * Don't assign "skins" directory to www-data. Closes: #612552.
26 * Add instructions on how to install and upgrade when not using
27 dbconfig-common. We do not ship UPGRADING file any more since it is
28 misleading. Closes: #612511.
30 -- Vincent Bernat <bernat@debian.org> Wed, 09 Feb 2011 07:32:42 +0100
32 roundcube (0.5-2) experimental; urgency=low
34 * If 0.3.1 was installed from scratch, upgrade does not work on MySQL
35 and PostgreSQL because we try to create an index which already
36 exists. With SQLite, the error is ignored, no fix needed. When using
37 PostgreSQL, fix this by dropping the index if it already
38 exists. Nothing similar seems to exist with MySQL. Therefore, just
39 don't create the index. We need to handle this later. See bug
42 -- Vincent Bernat <bernat@debian.org> Fri, 21 Jan 2011 21:44:05 +0100
44 roundcube (0.5-1) experimental; urgency=low
46 * New upstream release. Closes: #592312.
47 + Drop patches included upstream (DNS prefetching, jQuery 1.4
48 handling, email address validation, duplicate headers, incorrectly
49 formatted received headers). Adapt other patches. One of the patch
50 now correctly states to use dpkg-reconfigure roundcube-core.
52 + Update SQL commands to use to upgrade database.
53 That also closes: #602922. Unfortunately, the user may get some
54 harmless error messages because there is no way to know if
55 0.3.1 was installed from scratch or upgraded from 0.3.
56 + Update dependencies to match INSTALL file. Only exception is the
57 use of Mail_Mime 1.8.0 in place of 1.8.1 which is not available in
58 Debian. We depends on jQuery 1.4.2 because 1.4.4 is not available in
60 + All folders are correctly checked since 0.4. Closes: #552430.
61 + Also, closes: #553194 since it seems to have been fixed too.
62 + There is also the possibility to not top-quote since 0.4.
64 + Closes: #602144. Also fixed.
65 * Move .htaccess to /etc/roundcube and use a symlink (Closes: #591369).
66 * Don't let www-data overwrite debian-db.php. Closes: #608976.
67 * Bump Standards-Version. No changes required.
69 -- Vincent Bernat <bernat@debian.org> Sat, 15 Jan 2011 12:40:27 +0100
71 roundcube (0.3.1-6) unstable; urgency=low
73 * Update Arabic debconf translation, thanks to Ossama Khayat.
75 * Update Portuguese debconf translation, thanks to Christian Perrier.
77 * Add a patch to avoid duplicate boundaries in headers when adding an
78 attachment. Closes: #599586.
80 -- Vincent Bernat <bernat@debian.org> Mon, 18 Oct 2010 23:14:37 +0200
82 roundcube (0.3.1-5) unstable; urgency=low
84 * Depends on php-mail-mime 1.7.0 or more recent to handle correctly
85 'mime_param_folding' directive. Closes: #588295.
86 * Add Danish debconf translation, thanks to Joe Dalton.
88 * Add a patch to fix Received header to behave better with Spam
89 Assassin. Closes: #595204.
91 -- Vincent Bernat <bernat@debian.org> Thu, 02 Sep 2010 07:54:58 +0200
93 roundcube (0.3.1-4) unstable; urgency=low
95 * Update README.Debian to state that the variable to modify is
96 'htmleditor' instead of 'enable_htmleditor'. Thanks to Hans
97 Spaans. Closes: #575556.
98 * Add Brazilian Portuguese debconf translation, thanks to Eder
99 L. Marques. Closes: #581745.
100 * Switch default encoding to UTF-8 instead of ISO-8859-1.
102 * Add more explanations on how to install roundcube in a Debian system
103 in README.Debian. Closes: #584458, #582894.
104 * Bump Standards-Version. No changes required.
105 * Switch to 3.0 (quilt) format.
106 * Use Breaks instead of Conflicts to move files from older roundcube
109 -- Vincent Bernat <bernat@debian.org> Sat, 17 Jul 2010 17:23:30 +0200
111 roundcube (0.3.1-3) unstable; urgency=high
113 * RFC 5321, section 4.5.3.1, asks to not impose any limits on length if
114 possible. We respect this by dropping limitation of the local-part of
115 an email address. Closes: #568360, #568537.
116 * Suggests php-auth-sasl to enable use of SASL mechanisms for mail
117 servers. Closes: #567550.
118 * Disable DNS prefetching to avoid information leakage through links
119 embedded in messages. This fixes CVE-2010-0464. Closes: #569660.
120 * Bump Standards-Version. No changes required.
122 -- Vincent Bernat <bernat@debian.org> Sat, 13 Feb 2010 10:21:49 +0100
124 roundcube (0.3.1-2) unstable; urgency=low
126 * Fix VCS links in debian/control, thanks to Torsten Landschoff.
128 * Really ship NEWS.Debian.
129 * Add changesets 3170 and 3202 from upstream to handle gracefully jQuery
130 1.4. Thanks to Volker Gropp for the report. Closes: #565715.
132 -- Vincent Bernat <bernat@debian.org> Mon, 18 Jan 2010 23:11:01 +0100
134 roundcube (0.3.1-1) unstable; urgency=low
136 * New upstream release.
137 * Add a notice in NEWS.Debian about php.ini options that should be set
138 to get Roundcube working properly. Closes: #549428, #552508.
140 -- Vincent Bernat <bernat@debian.org> Sat, 07 Nov 2009 17:41:37 +0100
142 roundcube (0.3-2) unstable; urgency=low
144 * Really fix #544579 since the default value is null without
145 quotes. This really Closes: #544579.
146 * Enlarge login box to accommodate sk_SK locale. Closes: #542933.
148 -- Vincent Bernat <bernat@debian.org> Sun, 27 Sep 2009 11:26:56 +0200
150 roundcube (0.3-1) unstable; urgency=low
152 * New upstream release. Closes: #545498.
153 * Update debconf translations:
154 + Italian, thanks to Luca Monducci. Closes: #544199.
155 + Czech, thanks to Miroslav Kure. Closes: #546413.
156 * Roundcube configuration now uses 'language' instead of 'locale_string'
157 to specify the default language. Update postinst to reflect this
158 change. Thanks to Richard van den Berg for noticing this. Closes: #544579.
159 * Depends on libjs-jquery (>= 1.3) since this is now used by roundcube.
160 * Don't ship any plugins for now but ship an empty plugins directory.
161 * Ship main .htaccess since it is needed to setup correctly PHP (for
162 example, to disable PHP Suhosin cookie encryption).
163 * Bump Standards-Version. No changes required.
165 -- Vincent Bernat <bernat@debian.org> Sun, 27 Sep 2009 11:00:30 +0200
167 roundcube (0.2.2-1) unstable; urgency=low
169 * New upstream release
170 * Bump Standards-Version. No changes required.
171 * Remove *.js.src which are not needed at runtime.
172 * Don't send email contents to Google by default by using php5-pspell
173 instead. Thanks to Anand Kumria. Closes: #529563.
174 * Update debconf translations:
175 + Basque, thanks to Piarres Beobide. Closes: #534282.
177 -- Vincent Bernat <bernat@debian.org> Sun, 05 Jul 2009 09:53:17 +0200
179 roundcube (0.2.1-2) unstable; urgency=low
181 * Update debconf translations:
182 + German, thanks to Helge Kreutzmann. Closes: #520004.
183 + Japanese, thanks to Hideki Yamane. Closes: #520024.
184 + Spanish, thanks to Francisco Javier. Closes: #526696.
185 + Russian, thanks to Yuri Kozlov. Closes: #528796.
186 * Depend on php-mdb2-* (>= 1.5.0b2) since it is needed to fix some
187 bugs. Closes: #519104, #519293. Remove not needed any more patch from
188 debian/patches/series. Keep it in debian/patches to help backports.
190 -- Vincent Bernat <bernat@debian.org> Sat, 16 May 2009 15:30:17 +0200
192 roundcube (0.2.1-1) unstable; urgency=low
194 * New upstream release:
195 + Fix use_packaged_tinymce.patch to apply to this new version
196 + Remove cve-2009-0413.patch which has been applied upstream
198 -- Vincent Bernat <bernat@debian.org> Sat, 14 Mar 2009 17:42:07 +0100
200 roundcube (0.2~stable-2) unstable; urgency=low
202 * Update debconf translations:
203 + French, thanks to Christian Perrier. Closes: #515806.
204 + Swedish, thanks to Martin Bagge. Closes: #516683.
205 * Drop virtual package roundcube-db and add dependencies on real package
206 instead: this way, we can have versioned dependencies on those to avoid
207 version mismatch between packages.
208 * Add a patch to not use a MDB2 feature not present in the Debian
209 package. Thanks to Grzegorz Sobański for the patch. Closes: #519104.
211 -- Vincent Bernat <bernat@debian.org> Wed, 11 Mar 2009 18:49:32 +0100
213 roundcube (0.2~stable-1) unstable; urgency=low
215 * New upstream version. Closes: #503573, #504570.
216 + Add SQL update scripts for this new release and for
217 0.2~alpha. Remove copy of SQL upgrade script from debian/rules.
218 + Remove patch for CVE-2008-5620 which is now fixed upstream.
219 + Remove patch correcting a vulnerability in html2text.php.
220 + Remove patch fixing login issue. This is fixed upstream.
221 + Remove patch setting the default backend to db instead of mdb2:
222 this is not possible any more. We depend on php-mdb2 now.
223 + Update patch to use packaged tinymce.
224 * Upload to unstable since Lenny is out.
225 * Apply fix for XSS issue (CVE-2009-0413). Closes: #514179.
226 * Remove hack to update a SQLite table for an upgrade from a quite old
227 version of roundcube.
228 * Fix pending l10n issues:
229 + Update English debconf template. Closes: #473794.
230 + Add Swedish translation thanks to Martin Bagge. Closes: #508752.
231 * Fix debian/copyright to make lintian happy.
233 -- Vincent Bernat <bernat@debian.org> Sun, 15 Feb 2009 16:18:58 +0100
235 roundcube (0.2~alpha-4) experimental; urgency=low
237 * Add missing ${misc:Depends} to make Lintian happy.
238 * Add description to each patch.
239 * Execute cron job only if the directory to clean exists.
240 * Reload web server configuration instead of restart, thanks to a patch
241 from Tiago Bortoletto Vaz. Closes: #508633.
242 * Fix a vulnerability in quota image generation. This fixes
243 CVE-2008-5620. Thanks to Nico Golde for reporting it. Closes: #509596.
244 * Add missing dependency on php5-gd, used for quota bar.
245 * For roundcube-pgsql, depends on postgresql-client only. This package
246 is provided by the currently supported real package.
248 -- Vincent Bernat <bernat@debian.org> Thu, 25 Dec 2008 11:38:13 +0100
250 roundcube (0.2~alpha-3) experimental; urgency=high
253 * Fix a vulnerability in the use of preg_replace (Closes: #508628).
254 * Adapt descriptions of roundcube-database packages to refer them as
255 metapackages instead of virtual package (Closes: #495434).
256 * Add robots.txt from upstream, even if in some configuration, it will
257 not be considered (Closes: #499108).
258 * Do not ship .htaccess files. Restrictions are set in Apache or
259 Lighttpd configuration files (Closes: #500202).
262 * Changed versioned dependency of rouncube from binary:Version to
263 source:Version since these are all architecture independent packages.
265 -- Vincent Bernat <bernat@debian.org> Sat, 13 Dec 2008 14:36:02 +0100
267 roundcube (0.2~alpha-2) experimental; urgency=low
270 * Fix lintian warnings introduced by previous upload
271 * Fix lighttpd.conf to make it work with latest versions (Closes: #494044)
272 * Do not prepend path to lighty util in postinst and postrm, as per
273 Policy Manual section 6.1
274 * Ship a bug/control file to have all bugs submitted against roundcube
276 * Fix debian/roundcube-core.cron.daily to use
277 /etc/default/roundcube-core instead of /etc/default/roundcube which
278 should not exist any more
281 * Versioned roundcube-core dependency for roundcube
283 -- Vincent Bernat <bernat@debian.org> Sat, 16 Aug 2008 13:22:08 +0200
285 roundcube (0.2~alpha-1) experimental; urgency=low
287 * New upstream release
288 * Update debian/watch file to correctly consider those new releases
289 * Remove the following patches:
290 + messageid-headers-ordering
292 + disable-tinymce-spellchecker
293 * Update the following patches:
294 + correct_install_path
295 + use_packaged_tinymce
296 * Add a new patch to fix a login problem
297 * Depends on tinymce >= 3
299 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 14:10:44 +0200
301 roundcube (0.1.1-7) unstable; urgency=low
303 * Another fix for incorrect tinymce path. This should be the last one!
305 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 12:36:59 +0200
307 roundcube (0.1.1-6) unstable; urgency=low
309 * Fix use_packaged_tinymce patch which was incorrect after switch to
312 -- Vincent Bernat <bernat@debian.org> Sun, 22 Jun 2008 12:19:16 +0200
314 roundcube (0.1.1-5) unstable; urgency=low
316 * Fix ordering of message-id in message headers, thanks to Reinhard
317 Tartler (Closes: #486493)
318 * Update Standards-Version to 3.8.0
320 -- Vincent Bernat <bernat@debian.org> Tue, 17 Jun 2008 00:33:40 +0200
322 roundcube (0.1.1-4) unstable; urgency=low
324 * Add Slovak debconf translation, thanks to Ivan Masár (Closes: #481376)
325 * Fix debian/copyright:
326 + RoundCube is GPL-2 licensed, not GPL-2+
327 + Add an explanation on the BSD license present at the top of
328 index.php (Closes: #477119)
329 * We do not support tinymce 3, yet. Depends on tinymce2 | tinymce (<<
330 3). Closes: #481145, #483053, #482295
332 -- Vincent Bernat <bernat@debian.org> Tue, 20 May 2008 20:51:52 +0200
334 roundcube (0.1.1-3) unstable; urgency=low
336 * Fix an error introduced when fixing bug #476803. Thanks to Micah
337 Anderson for spotting it (Closes: #479775).
338 * Avoid to pop language question at every upgrade. Thanks to Ivan Vucica
339 for spotting this. The problem lied in the use of db_metaget to get
340 the value of a key set by db_subst in a previous invocation. It seems
341 this is not possible any more (Closes: #480043). The fix implies that
342 we won't ask the question again if more languages are available since
345 -- Vincent Bernat <bernat@debian.org> Thu, 08 May 2008 09:50:24 +0200
347 roundcube (0.1.1-2) unstable; urgency=low
349 * Comment by default Alias directive for tinymce in Apache configuration
350 file (Closes: #476162).
351 * Allow to preseed language value (Closes: #476803).
353 -- Vincent Bernat <bernat@luffy.cx> Sat, 19 Apr 2008 16:50:28 +0200
355 roundcube (0.1.1-1) unstable; urgency=low
357 * New upstream release
358 - Copy old SQL upgrade scripts into debian/sql to allow upgrade from
359 versions older than 0.1
360 - Patch new MySQL upgrade script to fix a typo
361 * Debconf translation updates:
362 - Spanish. Closes: #473788
363 * Depends on php-mail-mime (>= 1.5.0) and drop compatibility patch
364 * Install upstream changelog in /usr/share/doc/roundcube*
366 -- Vincent Bernat <bernat@luffy.cx> Sat, 05 Apr 2008 18:16:33 +0200
368 roundcube (0.1-4) unstable; urgency=low
370 * Debconf translation updates:
371 - French. Closes: #469802
372 - Russian. Closes: #469847
373 - Galician. Closes: #469866
374 - German. Closes: #469875
375 - Finnish. Closes: #469922
376 - Italian. Closes: #469987
377 - Czech. Closes: #470150
378 - Portuguese. Closes: #470156
379 - Spanish. Closes: #470732
380 - Basque. Closes: #470871
381 - Arabic. Closes: #471470
383 -- Vincent Bernat <bernat@luffy.cx> Sat, 08 Mar 2008 11:15:00 +0100
385 roundcube (0.1-3) unstable; urgency=low
387 * Fix problem with too old php-mail-mime package (Closes: #469814)
389 -- Vincent Bernat <bernat@luffy.cx> Fri, 07 Mar 2008 11:06:49 +0100
391 roundcube (0.1-2) unstable; urgency=low
393 * Ship bin/ directory as well. This fix conversion from HTML to text in
395 * Disable spellchecker for tinymce since it is not shipped with Debian
398 -- Vincent Bernat <bernat@luffy.cx> Fri, 07 Mar 2008 09:42:39 +0100
400 roundcube (0.1-1) unstable; urgency=low
402 * New upstream release (Closes: #469487).
403 - This release seems to fix failure to set some fields when replying,
404 with bincimap as IMAP server (Closes: #443562)
405 - It also fixes the deletion of multiple messages, still with
406 bincimap (Closes: #451404)
407 * Remove 'ob_gzhandler.patch' and 'xss-fix.patch'. They have been
409 * Upstream has switched to MDB2 database backend which is not packaged
410 in Debian yet. We switch back to old backend.
411 * Fix debian/watch to handle correctly detection of new versions.
412 * Add support for lighttpd and remove support for older version of
413 Apache. The debconf question about webserver autoconfiguration is
414 reworded (Closes: #462961).
415 * Do not depend on a specific revision of cdbs.
416 * Move po-debconf from Build-Depends-Indep to Build-Depends since it is
417 needed for clean target.
418 * Correct path to /usr/share/file/magic, provided by libmagic1. Provide
419 license information about this file in debian/copyright.
421 -- Vincent Bernat <bernat@luffy.cx> Wed, 05 Mar 2008 20:49:03 +0100
423 roundcube (0.1~rc2-6) unstable; urgency=high
425 * Bug fix: "CVE-2007-6321: Cross-site scripting (XSS) vulnerability",
426 thanks to Micah Anderson (Closes: #455840). The patch is from
427 http://lists.roundcube.net/mail-archive/dev/2007-12/0000038.html and
428 provided by Robin Elfrink. It has been modified with some functions
429 stolen from Squirrelmail.
430 * Finnish debconf template, thanks to Esko Arajärvi (Closes: #458244).
432 -- Vincent Bernat <bernat@luffy.cx> Sat, 29 Dec 2007 21:55:17 +0100
434 roundcube (0.1~rc2-5) unstable; urgency=low
436 * Deal with old /etc/logrotate.d/roundcube by removing it if left
437 untouched (Closes: #456546). Also deal with /etc/default/roundcube and
438 /etc/cron.daily/roundcube.
440 -- Vincent Bernat <bernat@luffy.cx> Tue, 18 Dec 2007 23:02:46 +0100
442 roundcube (0.1~rc2-4) unstable; urgency=low
444 * Thightened dependencies for a safe upgrade
445 * Finally removed any circular dependency, -db packages no longer pull
446 a full roundcube install
448 -- Romain Beauxis <toots@rastageeks.org> Sun, 09 Dec 2007 14:24:24 +0100
450 roundcube (0.1~rc2-3) unstable; urgency=low
453 * Bumped standard version to 3.7.3 (no changes)
455 -- Romain Beauxis <toots@rastageeks.org> Sun, 09 Dec 2007 14:19:28 +0100
457 roundcube (0.1~rc2-2) experimental; urgency=low
460 * Fix a conflict between ob_gzhandler and zlib output compression,
461 thanks to kaouete (Closes: #450482).
464 * Fix tinymce patch and inclusion
466 * Splitted virtual packages to avoid circular dependencies.
467 Uploading to experimental, as this is an important change and we may
470 -- Romain Beauxis <toots@rastageeks.org> Mon, 26 Nov 2007 11:54:21 +0100
472 roundcube (0.1~rc2-1) unstable; urgency=low
474 * New upstream, thanks to Nicolas Stransky (Closes: #447503). This
475 release support tinymce as HTML editor. Look at README.Debian for more
477 * Update Galician debconf template, thanks to Jacobo Tarrio (Closes: #447943).
479 -- Vincent Bernat <bernat@luffy.cx> Mon, 29 Oct 2007 22:08:43 +0100
481 roundcube (0.1~rc1-3) unstable; urgency=low
483 * In respect to policy 12.3, do not put main.inc.php.dist in
484 /usr/share/doc, thanks to Jonas Smedegaard (Closes: #446502).
485 * Update German and French debconf templates, thanks to Christian
486 Perrier (Closes: #446458) and Helge Kreutzmann (Closes: #446532).
488 -- Vincent Bernat <bernat@luffy.cx> Sun, 14 Oct 2007 08:41:24 +0200
490 roundcube (0.1~rc1-2) unstable; urgency=low
492 * Fix dependencies by creating virtual packages for each database
493 backend, thanks to Joey Hess (Closes: #444925).
495 -- Vincent Bernat <bernat@luffy.cx> Tue, 02 Oct 2007 20:09:19 +0200
497 roundcube (0.1~rc1-1) unstable; urgency=low
499 * New upstream release
500 * Removed non gpl file des.inc
502 -- Romain Beauxis <toots@rastageeks.org> Tue, 24 Jul 2007 13:36:20 +0200
504 roundcube (0.1~rc1~dfsg-3) unstable; urgency=low
506 * Add php5-mcrypt dependency (Closes: #431177)
508 -- Vincent Bernat <bernat@luffy.cx> Sat, 30 Jun 2007 19:36:21 +0200
510 roundcube (0.1~rc1~dfsg-2) unstable; urgency=low
512 * Removed custom unix_timestamp for sqlite: solved upstream
513 * Debconf templates and debian/control reviewed by the debian-l10n-
514 english team as part of the Smith review project.
515 Closes: #426086, #427546, #427546
516 * Debconf translation updates:
517 - Galician. Closes: #426140
518 - Basque. Closes: #426150
519 - Czech. Closes: #426428
520 - Portuguese. Closes: #426451
521 - Arabic. Closes: #427110
522 - Italian. Closes: #427206
523 - German. Closes: #427536
524 - French. Closes: #427736
525 - Tamil. Closes: #428254
526 - Russian. Closes: #428364
527 - Spanish. Closes: #428573
529 -- Romain Beauxis <toots@rastageeks.org> Tue, 05 Jun 2007 15:22:36 +0200
531 roundcube (0.1~rc1~dfsg-1) unstable; urgency=low
534 * New upstream release
535 * Update script for sqlite in postinst
537 * Fixed dh_link calls
539 * Added custom patch to use php unix timestamp support
540 with sqlite since UNIX_TIMESTAMP is not supported by sqlite.
541 * Dropped php4 dependencies
543 -- Vincent Bernat <bernat@luffy.cx> Sun, 20 May 2007 13:59:44 +0200
545 roundcube (0.1~beta2.2~dfsg-2) unstable; urgency=low
547 * Fix a security issue by disallowing access to logs.
548 * First upload to unstable.
550 -- Vincent Bernat <bernat@luffy.cx> Sat, 5 May 2007 00:23:40 +0200
552 roundcube (0.1~beta2.2~dfsg-1) experimental; urgency=low
554 * Initial release. (Closes: #333756, #344949)
556 -- Romain Beauxis <toots@rastageeks.org> Tue, 13 Mar 2007 13:28:05 +0100