Dear subscribers
We just recently published a security update to the LTS version 1.0. It
contains some important fixes and improvements we backported from the
master version. See the details in the release notes [1].
This release is considered stable and we recommend to update all productive
installations of Roundcube 1.0.x with this version if you're unable to
upgrade to a more recent series. Download it from GitHub via
https://roundcube.net/download.
As usual, don’t forget to backup your data before updating!
Best,
Thomas
[1] https://github.com/roundcube/roundcubemail/releases/tag/1.0.10
Dear subscribers
We just published another update to both stable versions 1.2 and 1.1
delivering important bug fixes and improvements which we picked from the
upstream branch.
Included is a fix for a recently reported XSS vulnerability within CSS
styles inside an SVG tag. See the full changelog for 1.2.4 in the wiki [1]
and for version 1.1.8 in the release notes [2].
Both versions are considered stable and we recommend to update all
productive installations of Roundcube with either of these versions.
Download them from GitHub via https://roundcube.net/download.
As usual, don't forget to backup your data before updating!
Best,
Thomas
[1] https://github.com/roundcube/roundcubemail/wiki/Changelog#release-123
[2] https://github.com/roundcube/roundcubemail/releases/tag/1.1.8
Dear subscribers, we wish you all a happy new year!
Today we published the beta release of the next major version 1.3 of
Roundcube webmail.
With this milestone we introduce some new features:
- Widescreen layout aka Three Column View
- Possibility to display QR code for contacts data
- New identicon plugin
- Attach contact vCards to composed message
- Support WEBP images and MathML preview
- Preview, download and rename attachments when composing a message
- message/rfc822 attachment preview
- Various Enigma (PGP) and Managesieve plugin improvements
Plus security and deployment improvements:
- Improve randomness of password salts and random hashes
- Fixed redundancy in sql caching system and compatibility with Galera
Cluster
And finally some code-cleanup:
- Dropped support for legacy browsers (IE < 10; removed 'legacy_browser'
plugin)
- Require PHP >= 5.4
- Removed PHP mail() support
- Removed 3rd party javascript libraries from repo
IMPORTANT: The code-cleanup part brings major changes and possibly
incompatibilities to your existing Roundcube installations. So please read
the changelog [1] carefully and thoroughly test your upgrade scenario.
Please note that Roundcube 1.3
1. no longer runs on PHP 5.3
2. no longer supports IE < 10 and old versions of Firefox, Chrome and Safari
3. requires an SMTP server connection to send mails
That last item means you need to review your SMTP server settings as
described in our wiki [2] if you have set the smtp_server option to an
empty value and are thus using PHP’s mail() function.
In case you're running Roundcube directly from source, you now need to
install the removed 3rd party javascript modules by executing the following
install script:
$ bin/install-jsdeps.sh
See the complete Changelog [1] and download the new packages from Github
[3].
This is a beta release and we recommend to test it on a separate
environment.
And as usual, don't forget to backup your data before installing it.
We're keen to hear your feedback about the new release.
Best,
Thomas & Alec
[1] https://github.com/roundcube/roundcubemail/wiki/Changelog
[2] https://github.com/roundcube/roundcubemail/wiki/Configuration#sending-
messages-via-smtp
[3] https://roundcube.net/download
Dear subscribers
We just published another update to the both stable versions 1.2 and
1.1 delivering important bug fixes and improvements which we picked
from the upstream branch.
Included is a fix for a recently revealed security issue when using
PHP's mail() function. It has been discovered and kindly reported by
Robin Peraglie using the static code analyzer RIPS [1] and more
details along with a CVE number will be published shortly.
See the full changelog for 1.2.3 in the wiki [2]. Version 1.1.7 is a
security update fixing the mail() issue and thus only relevant to
Roundcube installations not having an SMTP server configured for mail
delivery.
Both versions are considered stable and we recommend to update all
productive installations of Roundcube with either of these versions.
Download them from GitHub via https://roundcube.net/download.
As usual, don't forget to backup your data before updating!
Best,
Thomas
[1] https://www.ripstech.com/
[2] https://github.com/roundcube/roundcubemail/wiki/Changelog#release-123
Dear subscribers
We just published updates to both stable versions 1.2 and 1.1 delivering
important bug fixes and again more improvements of the Enigma plugin
introduced in version 1.2. Version 1.1.6 comes with cherry-picked fixes
from the more recent version and improvements in contacts searching as
well as a few localization fixes.
See the full changelog in the wiki [1] and the selection for 1.1.6 on
the release page [2].
Both versions are considered stable and we recommend to update all
productive installations of Roundcube with either of these versions.
Download them from GitHub via https://roundcube.net/download.
As usual, don’t forget to backup your data before updating!
Best,
Alec
[1] https://github.com/roundcube/roundcubemail/wiki/Changelog#release-122
[2] https://github.com/roundcube/roundcubemail/releases/tag/1.1.6
Dear subscribers
We just published the first service release to update the stable
version 1.2. It contains some important bug fixes and improvements in
the recently introduced Enigma plugin for PGP encryption. See the
detailed Changelog in the wiki [1] or on the the release page [2].
This release is considered stable and we recommend to update all
productive installations of Roundcube with this version. Download it
from GitHub via https://roundcube.net/download.
As usual, don’t forget to backup your data before updating!
Best,
Thomas
[1] https://github.com/roundcube/roundcubemail/wiki/Changelog#release-121
[2] https://github.com/roundcube/roundcubemail/releases/tag/1.2.1
Dear subscribers
Today we proudly announce the stable version 1.2.0 of Roundcube
Webmail which is now available for download. It introduces new
features since version 1.1 covering security and PGP encryption
topics:
- PHP7 compatibility
- PGP encryption
- Drag-n-drop attachments from mail preview to compose window
- Mail messages searching with pre-defined date interval
- Improved security measures to protect from brute-force attacks
And of course plenty of small improvements and bug fixes.
There wasn't much feedback on the 1.2-beta version and the release
candidate which we consider a good sign. Some cleanup and
stabilization of the Enigma plugin just happened for the now stable
version.
As already announced with the 1.2-beta release [1], PGP encryption
comes in two flavors: client-side using the Mailvelope browser
extension and server-side with the Enigma plugin using GnuPG on the
server.
Support with the Mailvelope browser plugin comes out of the box and is
automatically enabled if the Mailvelope API is detected in a user’s
browser. The Mailvelope documentation [2] explains how to enable it
for your site.
The features of the Enigma plugin, which comes with the release
package and simply needs to be activated for your Roundcube
installation are explained in Alec's blog post [3].
With the release of Roundcube 1.2.0, the previous stable release
branches 1.0.x and 1.1.x will switch in to LTS low maintenance mode
which means they will only receive important security updates but no
longer any regular improvements from upstream.
See the complete Changelog in our wiki [4] and download the new
packages from https://roundcube.net/download.
Roundcube 1.2.0 is considered stable and we recommend to update all
productive installations of Roundcube. As usual, don’t forget to
backup your data before updating ;-)
Best,
Thomas
[1] https://roundcube.net/news/2015/11/23/roundcube-webmail-1.2-beta-out-now
[2] https://www.mailvelope.com/en/help#watchlist
[3] https://kolabian.wordpress.com/2015/10/13/enigma-plugin-pgp-encryption/
[4] https://github.com/roundcube/roundcubemail/wiki/Changelog
Dear subscribers
We just published updates to both stable versions 1.0 and 1.1
delivering important bug fixes and helps protecting Roundcube against
more XSS and CSRF attacks. Version 1.1.5 also has two new plugin hooks
integrated and version 1.0.9 comes with cherry-picked fixes from the
more recent version to ensure proper long term support.
See the full changelog in the wiki [1] and the selection for 1.0.9 on
the release page [2].
Both versions are considered stable and we recommend to update all
productive installations of Roundcube with either one of these
versions. Download them from GitHub via
https://roundcube.net/download.
As usual, don’t forget to backup your data before updating!
Best,
Thomas
[1] https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115
[2] https://github.com/roundcube/roundcubemail/releases/tag/1.0.9
Hello folks
Roundcube 1.2 is pretty much complete and after adding some
last-minute improvements we just published a release candidate to give
it another round of testing before we slap the 'stable' tag on it. We
hereby invite you all to test the release candidate and report
remaining bugs to our issue tracker.
The most important features we added in 1.2 are:
* PHP7 compatibility
* PGP encryption in two flavours
* Improved security measures to protect from brute-force and CSRF attacks
See the full Changelog in our wiki:
https://github.com/roundcube/roundcubemail/wiki/Changelog
Download the packages or the signed source directly from Github:
https://github.com/roundcube/roundcubemail/releases/tag/1.2-rc
Please note that we recommend to test it on a separate environment.
And don't forget to backup your data before installing it.
Another note: with the upcoming stable release of 1.2.0 the old 1.0.x
and the 1.1.x series will only receive important security fixes.
Updates to these two branches are to be released soon. So stay tuned!
Best,
Thomas
Dear subscribers
After many ups and downs with our Trac platform which hosted our wiki
and the ticket system for years now, we finally migrated the data over
to Github where we already host the git repositories. Therefore,
on March 25th 2016 the trac.roundcube.net site will be shut down
Starting today, the site is in read-only mode meaning that user logins
and ticket reporting have been disabled already.
This means that submitting new tickets now goes through Github and so
does the roadmap planning and overview. The entry point for that is
our Github project page at https://github.com/roundcube/roundcubemail
Today we just migrated 4.8K tickets from the Trac database to Github
issues [1], leaving the invalid and duplicate ones behind.
Unfortunately the ticket numbers could not be kept and have all been
re-assigned. The original trac ticket numbers are mentioned in the
migrated issue body and can be used for searching. We'll also install
a redirect service which will translate old Trac urls to the
corresponding issue pages.
The wiki will also be translated into Github markdown pages. There's
some manual reviewing involved in order to update or remove outdated
information during this process. Please give us some more days to
complete that task.
Thank you for your understanding and see you on Github
Best,
Thomas
[1] https://github.com/roundcube/roundcubemail/issues