![22.Lock ScreenEffect Esm W900](/images/gen/articles/1200x667/22.Lock_ScreenEffect-esm-w900.webp)
There is no shortage of challenges when it comes to securing open source software and no shortage of ideas for how to mitigate risks.
On September 7, 2022 the organization announced the latest iteration of its Scorecards effort, an initiative designed to help open source projects and their users identify the state of security within a project. The updated scorecards come a week after the OpenSSF issued new guidance and best practices on how to secure npm, which is a widely used, and often abused, open source package management system for JavaScript.