Open-source software isn't automatically more secure than proprietary code, despite what many developers claim. I've audited projects where critical vulnerabilities sat unfixed for months simply because no one was paid to care. The Linux kernel gets constant scrutiny, but smaller open-source libraries often rely on one overworked maintainer. That reality makes me doubt the mantra that 'many eyes make bugs shallow'—sometimes those eyes are too busy to look.