Trackers

A tracker is a list of sources, what joins them, and what it promises. It is a small file. Two run here, and yours is one file away.

  1. What a tracker is
  2. zetlyn/cve: one security flaw, seven publishers
  3. zetlyn/local-models: models you can run yourself
  4. Compose your own
  5. Before promising one to other people

1. What a tracker is

Each tracker names its thing: the kind of thing it holds one of per thing. Below, a security flaw and an AI model. Those are not words Zetlyn knows. It knows two, a source and a tracker; a flaw and a model are what these two happen to be about, and yours will be about something else.

Both answer at zetlyn.com/hub, so you can ask one before you take it. Every number on this page is one the tracker itself shows you, through the same calls a reader uses, and it moves every time a source publishes.

2. zetlyn/cve: one security flaw, seven publishers

A thing here is one flaw in one piece of software, named by the number the whole industry already uses for it: a CVE number, like CVE-2021-44228. Seven sources publish about those, each knowing one part. Counted on 2026-09-27:

SourceWhy it is thereClaims
zetlyn/cve-kevThe only source that says a vulnerability is being exploited right now. Asked hourly.1,728
zetlyn/cve-redhatIts own severity, and the packages it tracks a vulnerability in.22,388
zetlyn/cve-nvdThe CVSS baseline, and an anchor for CVEs the other sources never reach.14,738
zetlyn/cve-ghsaThe ecosystem packages no distribution ships.3,813
zetlyn/cve-metasploitWhether a module exists for the tool an attacker actually runs.2,698
zetlyn/cve-exploitdbWhether working code exists at all, which is a different question from how severe it is.46,688
zetlyn/cve-writeupsThe prose that explains a vulnerability after the advisories have stopped.10

What it is for. 1,685 things are being exploited right now, and twenty-nine of those are also rated high or critical by a publisher who ships the package. No source answers that on its own: CISA has never heard of the severity and Red Hat has never heard of the exploitation. Putting the two together in one place is what a tracker is for.

What it covers, and what it leaves out

CoversExcludes
Every CVE in CISA KEVVulnerabilities with no CVE number
Red Hat, from 2025-01-01Ubuntu (see below)
NVD, from 2026-08-01
GitHub advisories, from 2026-09-01
Every Exploit-DB entry and Metasploit module naming a CVE

Ubuntu was measured and dropped, not assumed away: its list endpoint answers twenty claims in between twenty-three and forty seconds, which is about thirty-four hours for one pass. It is a source the day that changes.

Its promise: every source has finished an update within 24 hours, or its front page says the promise does not hold and names the source that is behind. Open zetlyn/cve.

3. zetlyn/local-models: models you can run yourself

A second topic, to show that the shape is not about security. Here a thing is one AI language model: the kind somebody downloads and runs on their own computer instead of sending their text to somebody else's. Two sources publish about them and neither holds what the other does. 2,717 things, counted on 2026-09-27:

SourceWhy it is thereClaims
zetlyn/models-hfThe model itself: who made it, what licence it carries, what it is for, how many people fetch it.1,496
zetlyn/models-ggufThe shrunk-down copies other people have made of it. A model in its original form needs a machine most people do not have; a shrunk copy decides whether it runs on the one they do.10,271

The join is the model's name on Hugging Face, which is where both sources already put it. Without that there would be no tracker here, only two lists.

It is not finished, and the reason is worth reading. Without a Hugging Face token the update is throttled off after roughly six to seven hundred models; measured twice on 26 September, 734 and then 578, both ended by the source after the retries ran out. The tracker says partial on its own face, and the promise it makes is the one it keeps. It has no cadence of its own: it asks about the models the other source names, so it runs when that one finds something and not on a clock.

4. Compose your own

Which sources are in it, what number joins them, and what each one contributes that the others do not. The sentence is not documentation: the format requires it, the form that adds a source requires it, and a source nobody can justify in a sentence is one somebody added and nobody removed.

Where two sources use different words for the same thing, a scale says which words mean which. The raw word is kept and shown beside the translation, so a reader can always see what the publisher actually wrote. The parts of the file: sources, identified_by, align, view and promise.

# trackers/cve/tracker.yaml
name: zetlyn/cve
title: CVE
sources:
- source: zetlyn/cve-kev
  priority: primary
  why: The only source that says a vulnerability is being
    exploited right now.
- source: zetlyn/cve-exploitdb
  why: Whether working code exists at all, which is a
    different question from how severe it is.
identified_by:
- cve
align:
  # The same number from every source that scores one, and a
  # difference between them is a difference of judgement.
  cvss: {}
  severity:
    scale: [critical, high, medium, low, unknown]
    zetlyn/cve-redhat:
      important: high
      moderate: medium
    zetlyn/cve-ghsa:
      moderate: medium
promise:
  fresh_within: 24h
  covers: Every CVE in CISA KEV. Red Hat since 2025-01-01…
  excludes: Vulnerabilities with no CVE number…

5. Before promising one to other people

Five questions, and all five have to answer yes:

A shared keySeveral bodies publish about the same thing and at least one states the other's identifier. Where they do not, a tracker is a download with extra steps.
PermissionThe sources may be fetched, indexed and republished. Checked per source before a line of code.
It changesA subject that is finished has no currency to sell.
A buyerSomebody already pays for this, to a consultancy, a vendor or an analyst.
What changedEach source can be asked, by a watermark, a modification date or a commit. A source that can only be read whole is affordable at a thousand claims and is not at four hundred thousand.

Four of the five drop away for a topic you keep to yourself: nobody needs permission to index their own documents and nobody has to be sold anything. The first one does not. Measure the key in the real data before promising the topic. A sanctions tracker was proposed on the belief that the EU, OFSI and OFAC lists share one; the measurement found 86 of 6,241 EU entries carrying a UN reference, 1.4%, against zero on the OFAC list. A week, and the right answer.

Next: how a source works, or make a first tracker in five minutes.