Roundcube 1.3.1 has been released. It's a bug fix release, but does fix a "potential XSS vulnerability." https://github.com/roundcube/roundcubemail/releases/tag/1.3.1
Thank you for the bump request. You can help the maintainer with further information: Does a simple bump [1] work on your system? Chances are high, because a first look on the bump revealed only small changes. [1] https://wiki.gentoo.org/wiki/Custom_repository#Simple_version_bump_of_an_ebuild_in_the_local_overlay
Yeah, a simple rename worked for me.
The bug has been closed via the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c24d60648cc27a25676b2de23c8cdfa28d5e7497 commit c24d60648cc27a25676b2de23c8cdfa28d5e7497 Author: Tim Harder <radhermit@gentoo.org> AuthorDate: 2017-10-18 07:51:45 +0000 Commit: Tim Harder <radhermit@gentoo.org> CommitDate: 2017-10-18 07:53:19 +0000 mail-client/roundcube: version bumps to 1.2.6 and 1.3.1 Closes: https://bugs.gentoo.org/630144 Closes: https://bugs.gentoo.org/630504 mail-client/roundcube/Manifest | 2 + mail-client/roundcube/roundcube-1.2.6.ebuild | 74 +++++++++++++++++++++++++++ mail-client/roundcube/roundcube-1.3.1.ebuild | 76 ++++++++++++++++++++++++++++ 3 files changed, 152 insertions(+)