RainLoop / rainloop-webmail

Simple, modern & fast web-based email client
http://rainloop.net
MIT License
4.1k stars 890 forks source link

Rainloop under active development? #2172

Open mandusm opened 2 years ago

mandusm commented 2 years ago

Is this project still under active development? It's been a year since the last updates were made.

daffydock commented 2 years ago

It seems dead, or semi-dead. However, and if interested, there is an active fork called Snappymail. Don't get me wrong, I like Rainloop, I just worry about some issues that have as far as I can tell remain unfixed.

https://github.com/the-djmaze/snappymail

mandusm commented 2 years ago

Well, you sir, is what we call a scholar and a gentlemen! Thanks for the redirect! Already switched over my deployment!

Pofilo commented 2 years ago

Whatever is your choice, be careful with Rainloop right now:

https://thehackernews.com/2022/04/unpatched-bug-in-rainloop-webmail-could.html?m=1

daffydock commented 2 years ago

Yeah, that company literally opened an issue here earlier and no one answered. I used Rainloop on my Nextcloud install yet since the issue is still open and the security flaw is still at play, I had to remove it from my install. Shame.

As per your own article, SnappyMail does not suffer the same security issues.

smac0 commented 2 years ago

Now there's a new version, but with the appendix "legacy" and I can't find a changelog anywhere nor any announcement explaining this. Can anyone make sense of this?

Neustradamus commented 2 years ago

I have done a comment here:


Please use SnappyMail from @the-djmaze, we can thanks for this work!

Please note that SnappyMail supports SCRAM-SHA-* for connection, very good security:

Linked to: