Does that also happen with, say, German or French governments? Or US government? What about the Chinese?
Do they not ask to review source code of the tools they buy and use?
Do they not ask to review source code of the tools they buy and use?
The idea that they're doing it to develop backdoors is at least sort of silly, on the grounds that they are perfectly capable of dumping the firmware of these boxes once they import one and developing exploits against the actual image. In fact, that's not even a "nation-state" level of capability, there are plenty of individuals who can and do accomplish that for merely "bug bounty" money. Given the restrictions they have at looking at the source code it's not clear to me that it's going to be much easier for them than just doing it based on firmware dumps.