THE HUB · PUBLIC

Find a tracker or a source

Every one here is public and free to use: open it in the browser, or subscribe and keep a copy on your own machine that stays current.

13 results

CVEtracker

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

zetlyn/cve · 7 sources · 99,705 claims · published 4d ago

Models you can run yourselftracker

A model, every quantisation somebody made of it, and what each one costs to run.

zetlyn/local-models · 2 sources · 11,119 claims · published 5d ago

Exploit-DBsource

Whether working code exists, which is a different question from how severe it is.

zetlyn/cve-exploitdb · 46,698 claims · titles, values and a link · published 10h ago

GitHub advisoriessource

The ecosystem packages no distribution ships, and the CVE each advisory names.

zetlyn/cve-ghsa · 6,155 claims · in full · published 4h ago

CISA Known Exploited Vulnerabilitiessource

The vulnerabilities CISA has evidence of being exploited, and the date a federal agency has to have fixed each one by.

zetlyn/cve-kev · 1,733 claims · in full · published 21m ago

Metasploit exploit modulessource

Every module in the Metasploit Framework that names a CVE, which is whether the tool an attacker actually runs has one.

zetlyn/cve-metasploit · 2,698 claims · in full · published 32m ago

NVDsource

The CVSS baseline, and an anchor for CVEs the other publishers never reach.

zetlyn/cve-nvd · 19,646 claims · in full · published 4h ago

Red Hatsource

Red Hat's own severity for a vulnerability, and the packages it tracks it in.

zetlyn/cve-redhat · 22,765 claims · in full · published 4h ago

Ubuntusource

Ubuntu's own priority for a vulnerability, and its notes on it.

zetlyn/cve-ubuntu · 340 claims · titles, values and a link · published 46h ago

Write-upssource

The prose that explains a vulnerability after the advisories have stopped.

zetlyn/cve-writeups · 10 claims · titles, values and a link · published 30m ago

Cataloguesource

Read from catalogue.xlsx.

zetlyn/iso-catalogue · 10 claims · titles, values and a link · published 22h ago

GGUF quantisationssource

Which quantisations exist, and which model each was made from.

zetlyn/models-gguf · 9,465 claims · titles, values and a link · published 4h ago

Hugging Face modelssource

The models people quantise: their licences, their tasks and how many people fetch them.

zetlyn/models-hf · 1,654 claims · titles, values and a link · published 4h ago

TAKING ONE

Open it here.
Or keep a copy that stays current.

WHAT SUBSCRIBING DOES

  • a trackerzetlyn tracker subscribe zetlyn/cve fetches the statement and every source it names, and builds it on your machine. A reference that names no host means this hub, so there is nothing else to type
  • a sourcezetlyn source subscribe zetlyn/cve-kev takes one on its own, to put in a tracker of yours
  • the claimsPublished as bytes, not as the instructions for producing them: a subscriber needs none of the publisher's credentials and is not subject to the source's rate limits
  • an updateOnly what changed. Five claims altered out of 1,726 is 3,022 bytes against 2,102,623 for the whole. zetlyn run asks for it on its own
  • signedEvery version carries its publisher's signature, and a version signed by another key than the one you took the first from is refused

A hub serves files and nothing else. It holds no index, answers no query and never learns what you asked: the question is answered by your copy, on your machine. A tracker you can open here is a workspace standing beside the hub, with its own store.

PUBLISHING YOUR OWN

Open, for others to change.
Or sealed, for others to use.

TWO WAYS TO PUT ONE HERE

  • openzetlyn tracker publish trackers/books: the statement and its sources as they are, recipes included, for somebody to copy and change
  • sealedzetlyn tracker publish trackers/books --sealed: one signed file with every claim, its history, the conflicts and what changed, in the tracker's own words. Where each source is read, their own field names, the mappings and the receipts stay with you
  • publicOnly where every source it names has said it may be shown: licence: { republish: yes | summary | no }. Otherwise it is for the accounts you give access to

The name you publish under is yours, first come, and it belongs to a key rather than to a password: zetlyn id new, then zetlyn hub register. See the docs.

RUNNING IT YOURSELF

Take the program.
A workspace is a directory.

WHAT IS IN IT

  • sources/One directory per source. Its declaration, its store, its run history
  • trackers/One directory per topic. Which sources are in it, what they join on, and what it promises
  • watches/Saved queries, and where each one's answer goes
  • workspace.yamlThe title, the contact address, and the mailer that already knows how to reach your readers

One binary, Apache-2.0: curl -fsSL https://zetlyn.com/install.sh | sh for macOS and Linux on x86-64, everywhere else cargo install --git. Clone it, build it, run it, change it, and sell what you do with it; the name is not in the grant, so a fork takes the code and another name. No database server, no message queue, no container: SQLite inside each source. Copy the directory and you have copied the workspace, including how far behind each source currently is.

OVER YOUR OWN SOURCES

The documents you will
not send anywhere.

A folder on a fileshare, an export from a ticket system, a wiki, a table in your own database. They are sources like any other and they are declared the same way. Nothing is uploaded, nothing calls home, and the program has no opinion about where it is running. This is the case the licence exists for: a closed implementation cannot serve it, because you could not run it.

MIXING THE TWO

A source can be
on somebody else's machine.

A REMOTE MEMBER

  • remoteThe address of a source somebody else operates
  • keyIf they ask for one
  • whyWhat it contributes that your own do not. Required, as for any source

The same six calls, over HTTP, against the surface a source already serves. A tracker cannot tell which of its sources is local except by looking at where it was named. Your supplier list stays on your machine and the vulnerability data comes from somebody who keeps it current, and one page joins them. A remote source that will not answer says so, beside the sources that did.

WHAT IS BUILT, AND WHAT NOT YET

One hub today.
Any web server can be one.

AS IT STANDS

  • more than one hubA reference can name any host, and any web server, folder or object store is a hub. Nothing looks across them, so finding a source elsewhere still means somebody telling you about it
  • hosted workspacesBuilt: the same program at zetlyn.com/<name>/, its owner signed in by a mailed link. Not open for sign-up yet

ZETLYN

One binary, one file per source, your own machine.