
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
@canimmunize/cvc
Advanced tools
The Canadian Vaccine Catalogue contains up-to-date information on Canadian vaccine terminology standards and product information. This repository is used to track the CVC source files and release artifacts.
The master branch of this repository always contains the latest version of the catalogue.
The releases directory contains subdirectories for each version of the CVC. Within each version subdirectory, there is a source directory that contains the CVC's source files, and a gen directory which contains the generated artifacts for that version.
New versions of the catalogue
| Directory | Sub | Purpose |
|---|---|---|
| source | This directory contains csv files for each of the CVC's subsets. | |
| gen | ||
| _ | csv | Contains generated CSV files that match the tables in the CVC.xlsx file. |
| _ | diff | Contains generates CSV files that highlight the changes between the current version and the latest published version. |
| _ | quality | Contains the quality report that is generated for the current version. |
| _ | tests | Contains the test output generated for the current version. |
| _ | CanadianVaccineCatalogue_vX.X.X.xlsx | The generated CVC excel workbook for the current version. |
If you find an issue with the CVC, or have a question about how to use it or a specific terminology question, you can create an issue here.
FAQs
The Canadian Vaccine Catalogue JSON Output Files
We found that @canimmunize/cvc demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 15 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.