Security is important.

Policies

Information security policy

Reporting a vulnerability

Please follow these guides to report a vulnerability privately:

External audits

securityscorecards.dev

This automation runs the following checks: https://github.com/ossf/scorecard/tree/main#checks-1.

Reports for MUI Core are published at https://github.com/mui/material-ui/security/code-scanning (private). The public details of the score: https://api.securityscorecards.dev/projects/github.com/mui/material-ui.

https://img.shields.io/ossf-scorecard/github.com/mui/material-ui?label=openssf scorecard&style=flat

The same tools are used for the other repositories:

CodeQL

CodeQL runs SAST (Static Application Security Testing) on the codebase. The reports for MUI Core are published at https://github.com/mui/material-ui/security/code-scanning (private).