Quasar Framework - Build high-performance VueJS user interfaces in record time
Installations
npm install quasar
Releases
@quasar/app-webpack-v3.15.1
Published on 22 Nov 2024
@quasar/app-webpack-v4.0.0-rc.4
Published on 22 Nov 2024
@quasar/app-vite-v2.0.0-rc.4
Published on 22 Nov 2024
@quasar/app-webpack-v4.0.0-rc.3
Published on 20 Nov 2024
@quasar/app-vite-v2.0.0-rc.3
Published on 20 Nov 2024
quasar-v2.17.4
Published on 18 Nov 2024
Developer
Developer Guide
Module System
ESM
Min. Node Version
>= 10.18.1
Typescript Support
No
Node Version
20.16.0
NPM Version
10.8.2
Statistics
26,013 Stars
14,690 Commits
3,539 Forks
458 Watching
10 Branches
727 Contributors
Updated on 28 Nov 2024
Bundle Size
522.91 kB
Minified
149.28 kB
Minified + Gzipped
Languages
JavaScript (87.81%)
CSS (6.05%)
Vue (4.91%)
Sass (0.72%)
TypeScript (0.35%)
HTML (0.1%)
Shell (0.03%)
SCSS (0.03%)
Total Downloads
Cumulative downloads
Total Downloads
20,597,431
Last day
-1.9%
28,920
Compared to previous day
Last week
-3.8%
157,861
Compared to previous week
Last month
15.7%
670,790
Compared to previous month
Last year
11.9%
6,606,882
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
Quasar Framework
Build high-performance VueJS user interfaces in record time: responsive Single Page Apps, SSR Apps, PWAs, Browser extensions, Hybrid Mobile Apps and Electron Apps. If you want, all using the same codebase!
Please submit a PR to https://github.com/quasarframework/quasar-awesome with your website/app/Quasar tutorial/video etc. Thank you!
Supporting Quasar
Quasar Framework is an MIT-licensed open source project. Its ongoing development is made possible thanks to the support by these awesome backers.
Please read our manifest on Why donations are important. If you'd like to become a donator, check out Quasar Framework's Donator campaign.
Proudly sponsored by:
 | |
 |
Documentation
Head on to the Quasar Framework official website: https://quasar.dev
Stay in Touch
For latest releases and announcements, follow us on our Twitter account: @quasarframework
Chat Support
Ask questions at the official community Discord server: https://chat.quasar.dev
Community Forum
Ask questions at the official community forum: https://forum.quasar.dev
Contributing
Please make sure to read the Contributing Guide before making a pull request. If you have a Quasar-related project/component/tool, add it with a pull request to this curated list!
Thank you to all the people who already contributed to Quasar!
Semver
Quasar is following Semantic Versioning 2.0.
License
Copyright (c) 2015-present Razvan Stoenescu
No vulnerabilities found.
Reason
30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
Reason
security policy file detected
Details
- Info: security policy file detected: SECURITY.md:1
- Info: Found linked content: SECURITY.md:1
- Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1
- Info: Found text in security policy: SECURITY.md:1
Reason
no dangerous workflow patterns detected
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Info: FSF or OSI recognized license: MIT License: LICENSE:0
Reason
no binaries found in the repo
Reason
0 existing vulnerabilities detected
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Info: jobLevel 'contents' permission set to 'read': .github/workflows/build-types.yml:47
- Warn: jobLevel 'actions' permission set to 'write': .github/workflows/build-types.yml:48
- Info: jobLevel 'actions' permission set to 'read': .github/workflows/comment-build-results.yml:17
- Info: jobLevel 'actions' permission set to 'read': .github/workflows/comment-build-results.yml:50
- Info: jobLevel 'contents' permission set to 'read': .github/workflows/process-created-issue.yml:10
- Info: jobLevel 'contents' permission set to 'read': .github/workflows/project-creation-tests.yml:30
- Info: jobLevel 'contents' permission set to 'read': .github/workflows/project-creation-tests.yml:62
- Info: jobLevel 'contents' permission set to 'read': .github/workflows/release-notes.yml:13
- Info: found token with 'none' permissions: .github/workflows/release-notes.yml:1
- Warn: jobLevel 'checks' permission set to 'write': .github/workflows/tests-on-pr-report.yml:17
- Info: jobLevel 'actions' permission set to 'read': .github/workflows/tests-on-pr-report.yml:23
- Info: jobLevel 'contents' permission set to 'read': .github/workflows/tests-on-pr.yml:17
- Info: jobLevel 'contents' permission set to 'read': .github/workflows/tests-on-pr.yml:65
- Info: jobLevel 'actions' permission set to 'read': .github/workflows/tests-on-pr.yml:66
- Warn: no topLevel permission defined: .github/workflows/build-types.yml:1
- Warn: no topLevel permission defined: .github/workflows/comment-build-results.yml:1
- Warn: no topLevel permission defined: .github/workflows/process-created-issue.yml:1
- Warn: no topLevel permission defined: .github/workflows/project-creation-tests.yml:1
- Warn: no topLevel permission defined: .github/workflows/release-notes.yml:1
- Warn: no topLevel permission defined: .github/workflows/tests-on-pr-report.yml:1
- Warn: no topLevel permission defined: .github/workflows/tests-on-pr.yml:1
Reason
badge detected: InProgress
Reason
Found 1/30 approved changesets -- score normalized to 0
Reason
branch protection not enabled on development/release branches
Details
- Warn: branch protection not enabled for branch 'dev'
- Warn: branch protection not enabled for branch 'legacy-v2-app'
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
- Warn: 0 commits out of 1 are checked with a SAST tool
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-types.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/build-types.yml/dev?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-types.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/build-types.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-types.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/build-types.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-types.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/build-types.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/comment-build-results.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/comment-build-results.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/comment-build-results.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/comment-build-results.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/comment-build-results.yml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/comment-build-results.yml/dev?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/comment-build-results.yml:152: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/comment-build-results.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/process-created-issue.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/process-created-issue.yml/dev?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/process-created-issue.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/process-created-issue.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/process-created-issue.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/process-created-issue.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/project-creation-tests.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/project-creation-tests.yml/dev?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/project-creation-tests.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/project-creation-tests.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/project-creation-tests.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/project-creation-tests.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/project-creation-tests.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/project-creation-tests.yml/dev?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/project-creation-tests.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/project-creation-tests.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/project-creation-tests.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/project-creation-tests.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/project-creation-tests.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/project-creation-tests.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/project-creation-tests.yml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/project-creation-tests.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/project-creation-tests.yml:140: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/project-creation-tests.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-notes.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/release-notes.yml/dev?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notes.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/release-notes.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-notes.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/release-notes.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-notes.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/release-notes.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-notes.yml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/release-notes.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-notes.yml:170: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/release-notes.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-notes.yml:176: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/release-notes.yml/dev?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notes.yml:181: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/release-notes.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-on-pr-report.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/tests-on-pr-report.yml/dev?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests-on-pr-report.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/tests-on-pr-report.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-on-pr.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/tests-on-pr.yml/dev?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests-on-pr.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/tests-on-pr.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-on-pr.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/tests-on-pr.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-on-pr.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/tests-on-pr.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-on-pr.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/tests-on-pr.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-on-pr.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/tests-on-pr.yml/dev?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests-on-pr.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/tests-on-pr.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-on-pr.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/tests-on-pr.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-on-pr.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/tests-on-pr.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-on-pr.yml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/tests-on-pr.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-on-pr.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/tests-on-pr.yml/dev?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-on-pr.yml:120: update your workflow using https://app.stepsecurity.io/secureworkflow/quasarframework/quasar/tests-on-pr.yml/dev?enable=pin
- Info: 0 out of 32 GitHub-owned GitHubAction dependencies pinned
- Info: 0 out of 10 third-party GitHubAction dependencies pinned
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Score
5.6
/10
Last Scanned on 2024-11-18
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More