
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
mineral-ui
Advanced tools
NOTE: We’re just getting started. While we appreciate any feedback, we’re not yet ready to accept public contributions.
A design system and React component library for the web brought to you by CA Technologies.
Install the Mineral UI package.
npm install --save mineral-ui
Then install any missing peer dependencies reported by npm or yarn.
import React from 'react';
import { render } from 'react-dom';
import Button from 'mineral-ui/Button';
import ThemeProvider from 'mineral-ui/ThemeProvider';
function App() {
return (
<ThemeProvider>
<Button>
Hello World
</Button>
</ThemeProvider>
);
}
render(<App />, document.getElementById('app'));
Your app must be wrapped in a ThemeProvider at its root in order for the styles to apply correctly.
Also, please see our import syntax guidelines.
Mineral UI was designed around Open Sans. To get the components to look right, you will need to include this font in your project yourself or our styles will fall back to system fonts. To quickly include this font in your app, copy this code into the <head> of your HTML document.
<link href="https://fonts.googleapis.com/css?family=Open+Sans:300,300i,400,400i,600,600i,700,700i,800,800i" rel="stylesheet">
For more options loading this font from Google, check out the Seleted Family popup, in the specimen. You can also download the font file and serve it yourself if you'd like, but we'll leave that to you.
This project uses Glamorous for its styling. Please see our documentation for details.
We welcome all contributors who abide by our Code of Conduct. Please see the Contributors Guide and Developer Docs for more details on submitting a PR, setting up a local dev environment, running tests, etc...
All of the work for this project is accomplished via pull requests and issues. You can submit a PR or issue to:
Thank you for offering your time, expertise, and feedback. It’s greatly appreciated!
Until this project reaches a 1.0 milestone, minor version numbers will simply be incremented during each release. The Changelog will continue to document the different types of updates, including any "breaking changes".
After the 1.0 milestone, this project will follow SemVer.
Mineral UI supports the latest versions of Chrome, Firefox, Safari, Edge, and Internet Explorer 11.
Future plans and high priority features and enhancements can be found in the Roadmap file.
This project is licensed under the Apache 2.0 License — see the License file for details.
FAQs
Mineral UI component library
We found that mineral-ui demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.