Thats a good point. And because of this they are limited in their mitigation strategies.
https://www.theverge.com/2019/7/12/20691957/mastodon-decentr...
ofc there is that whole discussion about whether open sourcing actually affects application security, having your security model assume that attackers already have access to the source code, etc. Not to mention it looks like they did make quite extensive modifications on top of the mastodon code. Some of the code that people have discovered lying around in the gab codebase is really embarrassing.