If anyone can commit anything and nobody ever reads what is to be commited, the repository must be regarded as attacker controlled. Some people will likely find that problematic.
http://web.cs.ucdavis.edu/~filkov/papers/lang_github.pdf (https://news.ycombinator.com/item?id=8558740)
However, JavaScript ends up a being less prone to defective commits than C++ and C, as well as PHP and Python, but there are a number of issues that don't allow us to conclude all that much from these results (imo).
It's just bias. Python code is riddled with vulns - especially since it's all C under the hood.
https://hackernoon.com/python-sandbox-escape-via-a-memory-co...
Here's a great post that covers some issues in Python modules and why they're extra exploitable because they execute under CPython.
This is a particularly relevant quote:
> Perhaps less recognized is the fact that memory corruption bugs are reported in popular Python modules all the time without so much as a CVE, a security advisory, or even a mention of security fixes in release notes.