We put a lot of effort into the test suite which makes it easy for others to test various experimental security checkers. This has been detailed in the "third party testing" section at: http://www.pixelbeat.org/docs/coreutils-testing.html
I recently did a lot of work using AFL-fast[2] (poking mostly Perl & Lua and crappy IoT products). My experience is that AFL-fast yielded far better results (in a fraction of the time) when compared to AFL.
[0] http://www.syssec-project.eu/m/page-media/3/johansson_tfuzz_...
We've had a quick look at using oss-fuzz, which will need a bit of work since it's more suited to libraries rather than standalone utils.
https://minds.wisconsin.edu/bitstream/handle/1793/59964/TR12...
Looks like at least _some_ GNU tools are covered: https://github.com/google/oss-fuzz/tree/master/projects/gnut...
Having said that, a lot of the core command line tools (not just the GNU coreutils) that are run against untrusted input could certainly be improved. I'd prefer the OpenBSD method though - if it can't exec then I don't need to worry about the bugs the auditor/fuzzer didn't find.
And that’s 2.5.4, 1.0.0 could have been released in 1985 for all we know.
I guess we have many eyeballs, yet not enough still :)