Trackers
A tracker is a list of sources, what joins them, and what it promises. It is a small file. Two run here, and yours is one file away.
- What a tracker is
- zetlyn/cve: one security flaw, seven publishers
- zetlyn/local-models: models you can run yourself
- Compose your own
- Before promising one to other people
1. What a tracker is
Each tracker names its thing: the kind of thing it holds one of per thing. Below, a security flaw and an AI model. Those are not words Zetlyn knows. It knows two, a source and a tracker; a flaw and a model are what these two happen to be about, and yours will be about something else.
Both answer at zetlyn.com/hub, so you can ask one before you take it. Every number on this page is one the tracker itself shows you, through the same calls a reader uses, and it moves every time a source publishes.
2. zetlyn/cve: one security flaw, seven publishers
A thing here is one flaw in one piece of software, named by the number the whole industry
already uses for it: a CVE number, like CVE-2021-44228. Seven sources publish about
those, each knowing one part. Counted on
2026-09-27:
| Source | Why it is there | Claims |
|---|---|---|
zetlyn/cve-kev | The only source that says a vulnerability is being exploited right now. Asked hourly. | 1,728 |
zetlyn/cve-redhat | Its own severity, and the packages it tracks a vulnerability in. | 22,388 |
zetlyn/cve-nvd | The CVSS baseline, and an anchor for CVEs the other sources never reach. | 14,738 |
zetlyn/cve-ghsa | The ecosystem packages no distribution ships. | 3,813 |
zetlyn/cve-metasploit | Whether a module exists for the tool an attacker actually runs. | 2,698 |
zetlyn/cve-exploitdb | Whether working code exists at all, which is a different question from how severe it is. | 46,688 |
zetlyn/cve-writeups | The prose that explains a vulnerability after the advisories have stopped. | 10 |
What it is for. 1,685 things are being exploited right now, and twenty-nine of those are also rated high or critical by a publisher who ships the package. No source answers that on its own: CISA has never heard of the severity and Red Hat has never heard of the exploitation. Putting the two together in one place is what a tracker is for.
What it covers, and what it leaves out
| Covers | Excludes |
|---|---|
| Every CVE in CISA KEV | Vulnerabilities with no CVE number |
| Red Hat, from 2025-01-01 | Ubuntu (see below) |
| NVD, from 2026-08-01 | |
| GitHub advisories, from 2026-09-01 | |
| Every Exploit-DB entry and Metasploit module naming a CVE |
Ubuntu was measured and dropped, not assumed away: its list endpoint answers twenty claims in between twenty-three and forty seconds, which is about thirty-four hours for one pass. It is a source the day that changes.
Its promise: every source has finished an update within 24 hours, or its front page says the promise does not hold and names the source that is behind. Open zetlyn/cve.
3. zetlyn/local-models: models you can run yourself
A second topic, to show that the shape is not about security. Here a thing is one AI language model: the kind somebody downloads and runs on their own computer instead of sending their text to somebody else's. Two sources publish about them and neither holds what the other does. 2,717 things, counted on 2026-09-27:
| Source | Why it is there | Claims |
|---|---|---|
zetlyn/models-hf | The model itself: who made it, what licence it carries, what it is for, how many people fetch it. | 1,496 |
zetlyn/models-gguf | The shrunk-down copies other people have made of it. A model in its original form needs a machine most people do not have; a shrunk copy decides whether it runs on the one they do. | 10,271 |
The join is the model's name on Hugging Face, which is where both sources already put it. Without that there would be no tracker here, only two lists.
It is not finished, and the reason is worth reading. Without a Hugging Face token the update is throttled off after roughly six to seven hundred models; measured twice on 26 September, 734 and then 578, both ended by the source after the retries ran out. The tracker says partial on its own face, and the promise it makes is the one it keeps. It has no cadence of its own: it asks about the models the other source names, so it runs when that one finds something and not on a clock.
4. Compose your own
Which sources are in it, what number joins them, and what each one contributes that the others do not. The sentence is not documentation: the format requires it, the form that adds a source requires it, and a source nobody can justify in a sentence is one somebody added and nobody removed.
Where two sources use different words for the same thing, a scale says which words mean which.
The raw word is kept and shown beside the translation, so a reader can always see what the
publisher actually wrote. The parts of the file: sources, identified_by,
align, view and promise.
# trackers/cve/tracker.yaml
name: zetlyn/cve
title: CVE
sources:
- source: zetlyn/cve-kev
priority: primary
why: The only source that says a vulnerability is being
exploited right now.
- source: zetlyn/cve-exploitdb
why: Whether working code exists at all, which is a
different question from how severe it is.
identified_by:
- cve
align:
# The same number from every source that scores one, and a
# difference between them is a difference of judgement.
cvss: {}
severity:
scale: [critical, high, medium, low, unknown]
zetlyn/cve-redhat:
important: high
moderate: medium
zetlyn/cve-ghsa:
moderate: medium
promise:
fresh_within: 24h
covers: Every CVE in CISA KEV. Red Hat since 2025-01-01…
excludes: Vulnerabilities with no CVE number…
5. Before promising one to other people
Five questions, and all five have to answer yes:
| A shared key | Several bodies publish about the same thing and at least one states the other's identifier. Where they do not, a tracker is a download with extra steps. |
| Permission | The sources may be fetched, indexed and republished. Checked per source before a line of code. |
| It changes | A subject that is finished has no currency to sell. |
| A buyer | Somebody already pays for this, to a consultancy, a vendor or an analyst. |
| What changed | Each source can be asked, by a watermark, a modification date or a commit. A source that can only be read whole is affordable at a thousand claims and is not at four hundred thousand. |
Four of the five drop away for a topic you keep to yourself: nobody needs permission to index their own documents and nobody has to be sold anything. The first one does not. Measure the key in the real data before promising the topic. A sanctions tracker was proposed on the belief that the EU, OFSI and OFAC lists share one; the measurement found 86 of 6,241 EU entries carrying a UN reference, 1.4%, against zero on the OFAC list. A week, and the right answer.
Next: how a source works, or make a first tracker in five minutes.