← Home

@volo/qa

ABP Framework is a complete open-source infrastructure to create modern web applications by following the best practices and conventions of software development. This package is a part of the [ABP Framework](https://abp.io) and contains client-side files.

12
Versions
LGPL-3.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

volo

Keywords

aspnetcoreboilerplateframeworkwebbest-practicesangularmauiblazormvccsharpwebapp

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:qs AI (typosquat): @volo/qa is a scoped ABP framework module, not a typosquat of qs; name reflects product line. ai
typosquat typosquat.levenshtein:koa AI (typosquat): Same rationale; scoped ABP package unrelated to koa. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Same rationale; scoped ABP package unrelated to pg. ai
bogus-package bogus-package AI (bogus-package): ABP meta-packages are intentionally thin aggregators; link-dump README and tiny payload are expected for this package type. ai
phantom-deps phantom-dep:@abp/signalr AI (phantom-deps): ABP aggregator package; deps referenced in config files is the expected pattern. ai
phantom-deps phantom-dep:@abp/tui-editor AI (phantom-deps): Same as above; config-file references are expected for ABP aggregator packages. ai
phantom-deps phantom-dep:@volo/abp.aspnetcore.mvc.ui.theme.commercial AI (phantom-deps): Same-org aggregator dependency; config-file references are expected. ai

Versions (showing 12 of 12)

Version Deps Published
10.4.1 3 / 0
10.4.0 3 / 0
10.3.0 3 / 0
10.2.1 3 / 0
10.2.0 3 / 0
10.1.1 3 / 0
10.1.0 3 / 0
10.0.3 3 / 0
10.0.2 3 / 0
10.0.1 3 / 0
10.0.0 3 / 0
9.3.7 3 / 0

v10.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.4.0

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'qs' typosquat

Package name '@volo/qa' is 1 edit(s) away from popular package 'qs'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.3.0

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'qs' typosquat

Package name '@volo/qa' is 1 edit(s) away from popular package 'qs'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.2.1

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'qs' typosquat

Package name '@volo/qa' is 1 edit(s) away from popular package 'qs'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.2.0

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'qs' typosquat

Package name '@volo/qa' is 1 edit(s) away from popular package 'qs'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.1.1

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'qs' typosquat

Package name '@volo/qa' is 1 edit(s) away from popular package 'qs'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.1.0

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'qs' typosquat

Package name '@volo/qa' is 1 edit(s) away from popular package 'qs'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.0.3

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'qs' typosquat

Package name '@volo/qa' is 1 edit(s) away from popular package 'qs'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.0.2

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'qs' typosquat

Package name '@volo/qa' is 1 edit(s) away from popular package 'qs'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.0.1

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'qs' typosquat

Package name '@volo/qa' is 1 edit(s) away from popular package 'qs'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.0.0

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'qs' typosquat

Package name '@volo/qa' is 1 edit(s) away from popular package 'qs'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v9.3.7

2 findings
HIGH typosquat.levenshtein: Possible typosquat of 'qs' typosquat

Package name '@volo/qa' is 1 edit(s) away from popular package 'qs'.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.