Maybe the person you are replying to should have qualified “popular open source repositories”.
Plus. many companies, Microsoft included, open up their source code to partners.
The openness of source code has little correlation to its security.
> [...] OpenSSL adds a wrapper around malloc & free so that the library will cache memory on it's own, and not free it to the protective malloc. [...] So then a bug shows up which leaks the content of memory mishandled by that layer. [...]
> OpenSSL is not developed by a responsible team.
Heartbleed is reading beyond the intended bounds remotely. I don't think there were similar attacks before hand, but I could be wrong. I only have a base level knowledge here.