Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add new security-release of roundcube 1.4.10 and an update to carddav-plugin #1739

Closed

Conversation

sholl
Copy link
Contributor

@sholl sholl commented Jan 18, 2021

What type of PR?

Security-update for roundcube-webmailer.

What does this PR do?

This PR updates the Roundcube webmail to the latest version, also updates the roundcube carddav-plugin to a new version.

Related issue(s)

This PR superseeds PR #1699

Prerequistes

Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

  • In case of feature or enhancement: documentation updated accordingly
  • Unless it's docs or a minor change: add changelog entry file.

@mergify
Copy link
Contributor

mergify bot commented Jan 18, 2021

Thanks for submitting this pull request.
Bors-ng will now build test images. When it succeeds, we will continue to review and test your PR.

bors try

Note: if this build fails, read this.

bors bot added a commit that referenced this pull request Jan 18, 2021
@sholl sholl marked this pull request as ready for review January 18, 2021 13:12
@bors
Copy link
Contributor

bors bot commented Jan 18, 2021

try

Build failed:

@lub
Copy link
Member

lub commented Jan 22, 2021

bors retry

@bors
Copy link
Contributor

bors bot commented Jan 22, 2021

🔒 Permission denied

Existing reviewers: click here to make lub a reviewer

@micw
Copy link
Contributor

micw commented Jan 22, 2021

bors try

bors bot added a commit that referenced this pull request Jan 22, 2021
@bors
Copy link
Contributor

bors bot commented Jan 22, 2021

try

Build failed:

@micw
Copy link
Contributor

micw commented Jan 22, 2021

bors try

bors bot added a commit that referenced this pull request Jan 22, 2021
@bors
Copy link
Contributor

bors bot commented Jan 22, 2021

try

Build succeeded:

@nextgens
Copy link
Contributor

nextgens commented Mar 9, 2021

Using composer and not pinning versions is a substantial change... please update the PR to pull the current version of roundcube (they've fixed another XSS) and RCMCardDAV v4.1.0 (which has reverted back to shipping its dependencies: composer isn't required anymore)

@nextgens nextgens added status/response_needed Waiting for a response from the author type/security Related to security labels Mar 9, 2021
@nextgens nextgens mentioned this pull request Jun 17, 2021
3 tasks
bors bot added a commit that referenced this pull request Jul 3, 2021
1841: Update version of roundcube webmail and carddav plugin. r=mergify[bot] a=ghostwheel42

## What type of PR?

Security-update for roundcube-webmailer.

## What does this PR do?

This PR updates the Roundcube webmail to the latest version, also updates the roundcube carddav-plugin to a new version.

- roundcube 1.4.11
- carddav 4.1.2

### Related issue(s)

This PR superseeds PR #1739

## Prerequistes
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.

- [ ] In case of feature or enhancement: documentation updated accordingly
- [X] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/guide.html#changelog) entry file.


Co-authored-by: Alexander Graf <ghostwheel42@users.noreply.github.com>
@bors bors bot closed this in #1841 Jul 3, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status/response_needed Waiting for a response from the author type/security Related to security
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants