CVEtracker
What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.
ZetlynHubTHE HUB · PUBLIC
Every one here is public and free to use: open it in the browser, or subscribe and keep a copy on your own machine that stays current.
13 results
What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.
A model, every quantisation somebody made of it, and what each one costs to run.
Whether working code exists, which is a different question from how severe it is.
The ecosystem packages no distribution ships, and the CVE each advisory names.
The vulnerabilities CISA has evidence of being exploited, and the date a federal agency has to have fixed each one by.
Every module in the Metasploit Framework that names a CVE, which is whether the tool an attacker actually runs has one.
The CVSS baseline, and an anchor for CVEs the other publishers never reach.
Red Hat's own severity for a vulnerability, and the packages it tracks it in.
Ubuntu's own priority for a vulnerability, and its notes on it.
The prose that explains a vulnerability after the advisories have stopped.
Read from catalogue.xlsx.
Which quantisations exist, and which model each was made from.
The models people quantise: their licences, their tasks and how many people fetch them.
Nothing here matches. Show everything
TAKING ONE
WHAT SUBSCRIBING DOES
a trackerzetlyn tracker subscribe zetlyn/cve fetches the statement and every source it names, and builds it on your machine. A reference that names no host means this hub, so there is nothing else to typea sourcezetlyn source subscribe zetlyn/cve-kev takes one on its own, to put in a tracker of yoursthe claimsPublished as bytes, not as the instructions for producing them: a subscriber needs none of the publisher's credentials and is not subject to the source's rate limitsan updateOnly what changed. Five claims altered out of 1,726 is 3,022 bytes against 2,102,623 for the whole. zetlyn run asks for it on its ownsignedEvery version carries its publisher's signature, and a version signed by another key than the one you took the first from is refusedA hub serves files and nothing else. It holds no index, answers no query and never learns what you asked: the question is answered by your copy, on your machine. A tracker you can open here is a workspace standing beside the hub, with its own store.
PUBLISHING YOUR OWN
TWO WAYS TO PUT ONE HERE
openzetlyn tracker publish trackers/books: the statement and its sources as they are, recipes included, for somebody to copy and changesealedzetlyn tracker publish trackers/books --sealed: one signed file with every claim, its history, the conflicts and what changed, in the tracker's own words. Where each source is read, their own field names, the mappings and the receipts stay with youpublicOnly where every source it names has said it may be shown: licence: { republish: yes | summary | no }. Otherwise it is for the accounts you give access toThe name you publish under is yours, first come, and it belongs to a
key rather than to a password: zetlyn id new, then
zetlyn hub register. See the docs.
RUNNING IT YOURSELF
WHAT IS IN IT
sources/One directory per source. Its declaration, its store, its run historytrackers/One directory per topic. Which sources are in it, what they join on, and what it promiseswatches/Saved queries, and where each one's answer goesworkspace.yamlThe title, the contact address, and the mailer that already knows how to reach your readersOne binary, Apache-2.0: curl -fsSL https://zetlyn.com/install.sh | sh
for macOS and Linux on x86-64, everywhere else cargo install --git. Clone it,
build it, run it, change it, and sell what you do with it; the name is not in the grant, so
a fork takes the code and another name. No database server, no message queue, no
container: SQLite inside each source. Copy the directory and you have copied the
workspace, including how far behind each source currently is.
A folder on a fileshare, an export from a ticket system, a wiki, a table in your own database. They are sources like any other and they are declared the same way. Nothing is uploaded, nothing calls home, and the program has no opinion about where it is running. This is the case the licence exists for: a closed implementation cannot serve it, because you could not run it.
MIXING THE TWO
A REMOTE MEMBER
remoteThe address of a source somebody else operateskeyIf they ask for onewhyWhat it contributes that your own do not. Required, as for any sourceThe same six calls, over HTTP, against the surface a source already serves. A tracker cannot tell which of its sources is local except by looking at where it was named. Your supplier list stays on your machine and the vulnerability data comes from somebody who keeps it current, and one page joins them. A remote source that will not answer says so, beside the sources that did.
WHAT IS BUILT, AND WHAT NOT YET
AS IT STANDS
more than one hubA reference can name any host, and any web server, folder or object store is a hub. Nothing looks across them, so finding a source elsewhere still means somebody telling you about ithosted workspacesBuilt: the same program at zetlyn.com/<name>/, its owner signed in by a mailed link. Not open for sign-up yet
ZETLYN