rainloop (1.12.1-2+deb10u1) buster-security; urgency=high

  * Non-maintainer upload by the LTS Security Team.
  * CVE-2019-13389: RainLoop Webmail lacks XSS protection mechanisms such as
    xlink:href validation, the X-XSS-Protection header, and the
    Content-Security-Policy header.
  * CVE-2022-29360: RainLoop's Email Viewer allows XSS via a crafted email
    message (closes: #1004548).

 -- Guilhem Moulin <guilhem@debian.org>  Sat, 27 May 2023 22:20:58 +0200

rainloop (1.12.1-2) unstable; urgency=medium

  * Install default config files to /etc (Closes: #920674)
  * Remove symlinks to default config files on uninstall

 -- Daniel Ring <dring@wolfishly.me>  Wed, 06 Feb 2019 23:59:52 -0800

rainloop (1.12.1-1) unstable; urgency=medium

  * New upstream release

 -- Daniel Ring <dring@wolfishly.me>  Sun, 13 Jan 2019 00:30:06 -0800

rainloop (1.11.1-2) unstable; urgency=medium

  * Depend on php-nrk-predis instead of libphp-predis (Closes: #917605)
  * Update default webserver config files for PHP-FPM 7.3

 -- Daniel Ring <dring@wolfishly.me>  Sat, 05 Jan 2019 01:06:30 -0800

rainloop (1.11.1-1) unstable; urgency=medium

  * Initial release (Closes: #861581)

 -- Daniel Ring <dring@wolfishly.me>  Mon, 17 Dec 2018 20:42:00 -0700
