{"schema_version":"1.9.0","id":"openSUSE-SU-2026:21567-1","published":"2026-08-11T17:23:42Z","modified":"2026-08-12T17:45:23.332633765Z","related":["CVE-2025-58181"],"upstream":["CVE-2025-58181"],"summary":"Security update for zk","details":"This update for zk fixes the following issues:\n\nChanges in zk:\n\n- Update to version 0.15.6:\n  * Parse links to notes in frontmatter\n  * Set filters for lsp completion items from the config\n  * Set a note's modification time in frontmatter and allow for custom key\n    naming for both creation and modification keys\n  * Indexing made significantly more performant\n  * Support filtering by date and time with \"<date> <time>\" instead of\n    <date>T<time> only\n  * Exclude globs now prune matching directories from indexing, improving\n    speed of indexing\n\n- Update to version 0.15.5:\n  * List, edit and filter for broken links with --broken-links\n  * Update strftime package, supporting %g and %G formats in the\n    {{format-date}} helper\n  * Option to append links to selected text, instead of replacing\n  * Paths with ~ and env variables no longer error when passed to\n    --notebook-dir and --working-dir\n  * Guard LSP against unnecessary erroring on missing textDocument/definition\n    capabilities\n\n- Update to version 0.15.4:\n  * fix \"jump to definition\" follows wrong link\n  * zk config --list <object> (by @andrebauer, 484)\n  * Ignore commented links for LSP diagnostics. Use an AST to parse files, fixing\n  * other similar edge cases.\n  * Links in markdown footnotes now included in :ZkLinks\n  * Indexing notebook now 35% and 74% faster for full and incremental indexing\n  * respectively\n  * Stop crashing lsp server when server received textDocument/completion request with out of range parameters.\n  * lsp: Provide completion after [[ on lines with multi-byte characters\n  * Prevent crash in LookForward when the parameters is out of characters number.\n\n- Update to version 0.15.2\n  * Find notes with missing backlinks using zk list --missing-backlink\n  * LSP diagnostic for missing backlinks when other notes link to current note\n    without reciprocal links\n  * Code action to add missing backlinks\n  * LSP diagnostic for self-referential links\n  * Release tarballs now output the program version\n  * Config path can be set with $ZK_CONFIG_DIR\n  * bump deps: golang.org/x/crypto v0.45.0 fixes CVE-2025-58181\n\n- Update to version 0.15.0\n  * fixed LSP crashes when editing code fences and/or working in text files\n    with code fences\n  * new feature to set a group path \"by name\", in that any directory with the\n    same name can share the same group rules, no matter how deep in the\n    notebook. See references below.\n\n- Update to version 0.14.2\n  * Path in .zk/config.toml for the default note template now accepts\n    UNIX \"~/paths\"\n  * Find notes without tags with zk list --tagless\n  * fix: LSP ignores magnet links as links to notes\n  * fix: Note titles with double quoted words no longer break json output\n  * fix: Grammar in error output\n  * fix: Group rules could not be nested\n","affected":[{"package":{"name":"zk","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/zk&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.15.6-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"zk":"0.15.6-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21567-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253784"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58181"}]}